The Cloud Pod is your one-stop-shop for all things Public, Hybrid, Multi-cloud, and private cloud. Cloud providers continue to accelerate with new features, capabilities, and changes to their APIs. Let Justin, Jonathan, Ryan and Peter help navigate you through this changing cloud landscape via our weekly podcast.
Welcome to episode 265 of the Cloud Pod Podcast – where the forecast is always cloudy! This week, Jonathan, Ryan, and Justin are trying to keep cool in new WorkSpaces Pools, avoiding the Heatwave with Oracle’s new LLM, taking a look at AWS Jamba (hold the straw) and taking a look at the ever elusive Cloud Maturity.
All this news and more, this week on The Cloud Pod!
Titles we almost went with this week:* The Cloud Pod takes a dip in the Workspaces Pool * The Cloud Pod Lineage view is suspect * A Gitlab, A BitBucket, and a Blueprint build a Workspaces Pool * AWS goes for a Jamba Juice * Google Cloud Autokey does exactly what it sounds like * Oracle LLM Heatwaves send us to the Amazon Workspace Pool * Jonathan is unimpressed with this weeks show * Highway to the DataZone
A big thanks to this week’s sponsor:We’re sponsorless! Want to reach a dedicated audience of cloud engineers? Send us an email or hit us up on our Slack Channel and let’s chat! General News01:03 HashiCorp State of Cloud Strategy Survey 2024: Cloud Maturity is Elusive but Valuable
03:22 Jonathan – “The skill shortage thing really bugs me sometimes because there are plenty of skilled workers around and the reccs aren’t open for them. So I don’t think there aren’t qualified staff… yeah, it’s not a shortage because of the lack of people. It’s a shortage because we’re not prepared to spend the money on the people.”
08:24 Terraform AWS provider tops 3 billion downloads
08:40 Ryan – “To be fair, about a billion of those downloads are me trying to figure out which version I need. Do I switch between Brew Link or some other tool to trick my operating system into doing the right thing?”
AI Is Going Great – Or, How ML Makes All It’s Money09:13 Announcing the General Availability of Databricks Assistant and AI-Generated Comments
AWS12:35 Amazon WorkSpaces Pools: Cost-effective, non-persistent virtual desktops
Each user gets the same applications and the same experience. When they login they always get a fresh workspace thats based on the latest configuration for the pool, centrally managed by their administrator.
If you enable application setting persistence for the pool, users can configure certain applications settings such as browser favorites, plugins and UI customizations to persist. You can also access persistent files or object storage external to the desktop.
Persistent: 2 VCPU, 8GB of memory, 45.00 per month
Pool: $148 dollars for 720 hours.
More reasonable: 20 days a month for 8 hours a day. $36.19
Make sure you scale it, and make sure you do your maths.
14:03 Jonathan – “There was a time when the API for workspaces was absolutely terrible or missing. So the fact that they’ve called it out in the blog post is good news.”
14:19 Amazon WorkSpaces introduces support for Red Hat Enterprise Linux
17:54 Introducing end-to-end data lineage (preview) visualization in Amazon DataZone
19:16 Jonathan – “It’s just a chain of custody for data instead of a physical object. So you kind of attach metadata to the data to say where it came from. And every time you do something to it, you record in a log that you did something to it, especially in data science, where we’re enriching things or transforming things or cleaning out some types of records or whatever. It’s just a way of keeping track of who’s changed what since it came from where it came from. If stuff goes wrong in the future, you know where it went wrong.”
20:35 Amazon CodeCatalyst now supports GitLab and Bitbucket repositories, with blueprints and Amazon Q feature development
22:16 Ryan – “Yeah, standardization in general is fantastic for this. And it’s so much easier to navigate lots of many, many separate little repos when you know how they’re organized, you know what’s supposed to be where. And it really removes a lot of the need for as much documentation because of that too. And what documentation you do need, you can include in the blueprint or at least the templates.”
23:22 AI21 Labs’ Jamba-Instruct model now available in Amazon Bedrock
24:45 Jonathan – “You can get Jamba for free, I think, from Hugging Face. It’s a good model though, and it’s a lot more efficient. It’s significantly more efficient than other LLMs that are around. It uses a hybrid algorithm, hybrid model. So you’ve got the kind of traditional LLM generator, and then you’ve got this new thing called Mamba, which is like a selective attention thing.”
27:34 Optimizing Amazon Simple Queue Service (SQS) for speed and scale
31:25 Justin – “I was thinking about the, you know, the fact that using 128 bit ID to check some, to rent the cross talk and to basically identify the multiplex streams going across the packet. And I was just thinking about how many, how many combinations there are in 64 bit IP space. And then like thinking about what that means at 128 bit ID, I was like, wow, that’s some processing.”
GCP32:55 Making Vertex AI the most enterprise-ready generative AI platform
37:36 Justin – “I think about the coffee use case, right? So the retail point of sale gives you details like, hey, the coffee was sold to Ryan, but then when they gave it to him and it was made wrong and they had to then go remake it, like that’s not that the POS typically doesn’t capture where potentially the video stuff can do that. So you could, there’s all kinds of interesting use cases of how you can start to improve churn in your product margin. You can start helping for training baristas like Hey This barista made 12 coffees today that had to get remade. You know, there’s something wrong. Do we need to retrain them on something? So, it’s maybe a little nanny state -ish, but I also could see how some of these things could benefit some organizations that need to be very cost effective.”
39:58 New Cloud KMS Autokey can help encrypt your resources quickly and efficiently
41:16 Ryan – “Implementation will be key on this one, right? Cause it’s, it’s the difference between, they’ve created a wizard that creates KMS keys or they’ve really, you know, taken stuff, manual toil that, you know, this is probably not the biggest problem, right? But also it just reduces it. And, you know, and also it’s from my perspective, having worked with keys for a long time, I might be more familiar with these practices where someone who’s just learning about these, like it’s great way to kind of learn how to manage these things when it’s sort of automated as part of the backend.”
43:20 Google Cloud expands grounding capabilities on Vertex AI
44:12 Justin – “Wouldn’t it be nice to talk about like a new storage thing or anything but AI?”
45:12 Google Cloud Marketplace now lets customers buy ISV solutions from channel partners
46:07 Ryan – “So it’s like, I still want to pay you, but I also want that to count against my cloud commit.
47:25 Gemma 2 is now available to researchers and developers
49:39 Announcing expanded Sensitive Data Protection for Cloud Storage
50:15 Ryan – “Wow! I just, yeah, I’ve always just assumed that this was available. In fact, like, you know, it’s recently been in talks trying to use this. And so glad they announced this. Yeah, this would have been terrible.”
50:37 Capacity Planner now displays GPU usage and forecasts of the GPU’s in your Google Cloud project or organization.
Azure51:19 How hollow core fiber is accelerating AI
OCI54:46 Oracle Announces Industry First In-Database LLMs and an Automated In-Database Vector Store with HeatWave GenAI
56:43 Jonathan – “It’s like copilot. It’s our copilot, isn’t it?”
ClosingAnd that is the week in the cloud! Visit our website, the home of the Cloud Pod where you can join our newsletter, slack team, send feedback or ask questions at theCloud Pod.net or tweet at us with hashtag #theCloud Pod
Welcome to episode 248 of the CloudPod Podcast – where the forecast is always cloudy! It’s the return of our Cloud Journey Series! Plus, today we’re talking shared VPCs and why you should avoid them, Amazon’s new data centers ( we think they forgot about the sustainability pledge,) new threats to and from AI, and a quick preview of Next ‘24 programs – plus much more!
Titles we almost went with this week:* The Cloud Pod Isn’t a Basic Bitch * New AWS Data Solutions Framework – or – How You Accidentally Spent $100k’s * A PSA on Shared VPCs in AWS * Amazon Doesn’t Even Pay Attention to Climate When it’s on a Building * Vector Search I Hardly Know Her * Google Migs are Less Fun than Russian MigsAI Can Now Attack Us; Who Didn’t See That Coming * Who is Surprised That AWS is Using More Power Than the Rest of the State of Oregon * Spend all the Dinero in Spain
A big thanks to this week’s sponsor:We’re sponsorless this week! Interested in sponsoring us and having access to a specialized and targeted market? We’d love to talk to you. Send us an email or hit us up on our Slack Channel. AI is Going Great (or how ML Makes all Its Money)01:24 Disrupting malicious uses of AI by state-affiliated threat actors
03:59 Ryan – “I do like that all these state-sponsored actors, they’re just like us, asking basic scripting questions.”
AWS06:46 Announcing the Data Solutions Framework on AWS
17:43 Ryan – “…none of the things in this are new, but it’s the packaging of it all together, where you just sort of – with a few simple lines of SDK code – really have the full infrastructure for a full DataLake. And so, it’s super cool, because this is always what, as a customer, you’re sort of wanting, like give me the easy button.”
10:25 API Gateway now supports TLS 1.3
10:45 Justin- “I assume this is also a prerequisite for them to be able to support mutual TLS on API Gateway, which would be probably the last big feature I think they’re missing on the API Gateway.”
11:36 Matthew – “…the one piece of it I don’t like is that they didn’t do it, which makes sense across the board on all the different flavors of API gateway, but that’s because CloudFront would need to actually handle 1.3 also. So I get why they’re slowly rolling it out, but you know, just doing a regional means someone’s going to go in there and try to do it on global and not understand why. And then you’re going to go bang your head on the wall until you really sit down and figure out, oh yeah, this is actually a CloudFront API gateway under the hood.”
12:40 Amazon GuardDuty Runtime Monitoring protects clusters running in shared VPC
13:57 Ryan – “I mean, even I’m glad they’re fixing this with GuardDuty. I hope that they’re not implementing too much complexity on the backend, making it either very complicated to run or changing the results. But like, today I learned that previously you couldn’t run GuardDuty and inspect those workloads, right? And so I’m sure that GuardDuty is one of many.”
18:18 One of Oregon’s smallest utilities is suddenly among the state’s biggest polluters. Why? Amazon data centers
22:13 Matthew – “There was a podcast I listened to at one point where saying there’s a lot of these green initiatives. Everybody wants to do it. The problem comes down to the way all this works is like it has to come down to like transmission lines. And like, if you say, I’m going to build a wind farm over here, you got to pay for all the infrastructure after that to trans to do it. So you end up like, Hey, this 50,000, this hundred thousand dollar project now, it costs you a million dollars. You got to redo it. So like, it almost feels like we have to look at the way we kind of handle our electrical grid to support these. So a simple wind farm over here doesn’t end up costing billions of dollars.”
GCP23:43 Google Cloud expands access to Gemini models for Vertex AI customers
25:29 Ryan – “This is moving way too fast for me. Like, Gemini 1.0 Pro used something like 32,000 tokens, right? Or maxed out at that? I can’t. I think that’s it. And now they’re scaling up to a million, like a week later, like it feels like. Like it’s crazy. You’re going to be able to run this against so many things.”
27:13 Feel the Next ‘24 love: Full session library is now live
33:21 Introducing vector search in BigQuery
35:15 Justin- “I definitely see the advantage of it. Like, you know, I, my trick is I just like, I select SQL server row one. And if that’s the data I want, then I assume that row two is also similar to it. That’s how I do it. It’s not really the right way to do it. Yeah. There’s a wildcard. I just, yeah. Select all put it in an elastic search cluster, do a search, see what I come up with. All kinds of, all kinds of ways to solve this problem.”
35:40 Introducing Managed Instance Groups standby pool: Stop and suspend idle VMs
36:23 Matthew – “So this is the AWS auto scaling cold or whatever they called it, which is like a server that you can have on the side that like you can just boot up. And the only reason I ever saw to use this feature, was if you were auto scaling or MIG scaling in this case, I guess, Windows servers, just because they take so long to boot up. Because Windows…It was a nice feature. We set this up for one person at one point and it did dramatically help it, you know, Windows by default, I think it takes like 15 minutes to boot up. So just having the server there and essentially stopping it off hours; kind of lets you do fake auto scaling without actually doing auto scaling. So you’re stopping/starting servers. It’s a significant savings.”
Azure37:54 Microsoft to invest $2.1B in Spain to expand AI and cloud infrastructure
38:31 Justin – “I mean, if I were to be a betting man, they’re all trying to get ahead of the EU data center moratorium because they can only build for so long before they hit the moratorium limit. Because they also have power transmission problems in Europe, if you didn’t know.”
40:00 General Availability: Azure NetApp Files Standard Network Features – Edit Volumes
42:22 Matthew – “I just feel like it’s kind of also the way Azure is, is security and reliability. You always have to go to the higher tiers, which just drives me a little bit crazy. Like it’s not built in day one whereas with AWS, I feel like, you know, their motto is designed for failure. So like most of the managed services are by default and you don’t have an option. Like you can’t launch a load balancer without two subnets. You can’t launch, you know, your database without multiple subnets; they’re just there where Azure feels like you always have to think about it. I’m like, I don’t want to think about it. This is why I’m paying for a service – do it for me.”
Continuing our Cloud Journey Series Talks50:35 Five key things to consider when building a cloud FinOps team
52:17 Matthew – “…make sure you have executive buy in probably you’re starting this whole fin op started because your CFO is freaking out about the bill, but you know, making sure that not just the CFO, you know, your CTO and other organization members all agreed. This is something you’re going to do so you don’t have one side of the house fighting the other and you’re sitting there in the middle just going cool. We’re here.”
57:35 Ryan – “…it’s super fun to watch that transformation happen, from taking a dev team who hasn’t had any visibility into their costs to the initial stages of bewilderment of why is everything expensive, to actually making architecture choices based off of cost-driven data. And it’s not always comfortable, but almost every team that I’ve seen do that transformation, they’re excited by the end, right? It’s not like, oh, I had to do this and they’re jaded about it. And so like, it is one of those things where it allows some really cool decisions and it’s, you know, when you have the visibility, when you have that insight and, you know, like I said, access is clear and transparency is part of your culture.
ClosingAnd that is the week in the cloud! Just a reminder – if you’re interested in joining us as a sponsor, let us know! Check out our website, the home of the Cloud Pod where you can join our newsletter, slack team, send feedback or ask questions at theCloud Pod.net or tweet at us with hashtag #theCloud Pod
Welcome episode 226 of the Cloud Pod podcast - where the forecast is always cloudy! This week Justin, Matt and Ryan chat about all the news and announcements from Google Next, including - surprise surprise - the hot topic of AI, GKE Enterprise, Duet, Co-Pilot, Code Whisperer and more! There’s even some non-Next news thrown into the episode. So whether you’re interested in BART or Bard, we’ve got the news from SF just for you. Titles we almost went with this week:* 🎙️The cloud pod sings a duet, guess who was singing * 🤖You get AI, you get AI, Everyone Gets AI * 🔍Does a Mandiant Hunt, Or does a Hunter mandiant? * 🌨️The Cloud Pod goes into ROM Mode * 🔎Does a mandalorian Hunt, Or does a Hunter a mandalorian?
A big thanks to this week’s sponsor:Foghorn Consulting provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.📰General News this Week:📰01:23 Introducing Code Llama, a state-of-the-art large language model for coding * So you know Github Copilot, Duet AI, and Codewhisperer…. But do you know Code LLama? (Meta you better get good stickers on this) * Meta has released the source code for the Llama 2 based Code Specialized LLM in three sizes 7B, 13B, and 35B parameters. * Each model is trained with 500b tokens of code and code-related data. * The 7B and 13b base and instructor models have also been trained with fill-in-the-middle capability allowing them to insert code into existing code. * The 7B model can run on a single GPU, the 34B model however returns the best results and for the best for coding assistance… while the 7b and 13b are great for real-time code completions. * Training recipes for Code Llama are available on the Github Repository.
04:08📢 Matthew - “It's interesting; if you go deep into the article there, they start to digress into like ‘Hey, this 7 and the 13 billion are better for near real time response back’ and the 34 billion… is better for fine tuning for yourself. So they really go into a little bit more detail of how to do it. And, you know, I think they also put out some code snippets if you kind of dive into it a little bit more, which I thought was very nice.”05:32 OpenTF Announces Fork of Terraform * Remember when we talked about Open TF’s manifest begging HashiCorp to backtrack on adopting a BSL license? Well guess what? * HashiCorp didn’t listen. Insert sad sound effect. * In response, OpenTF has officially forked Terraform. * They hope to have the repository available to you within the next 1-2 weeks, with their goal to have an OpenTF 1.6 release. * Want to keep up with their progress? They’ve created a public repository where you can track their progress. Check that out here.
06:37 Vlad Ionescu Open TF is a Joke * Some opinions are not as keen on this and think it's a huge distraction and waste of time. * We will definitely be following up on this in the next three months, so stay tuned.
07:39📢 Ryan - “It's gonna be hard to get community support to drive a fork for something as large as Terraform. I agree that it's going to be a challenge. I don't know if I agree with anything else. I was trying to read the thread and trying to sort of not have a visceral reaction to the tone and it's just, it's while complaining about drama in the most dramatic way possible. It sort of defeated the purpose for me and I was like I was looking for a little bit more insight because I haven't. I go very deep and I haven't really formed an opinion on if this is a good idea or not. Yeah, I don't know. I think the jury's still out and continue to watch and see if it takes.”11:44📢 Matthew - “I'm sure you guys remember when elastic search moved over, they like made it so that you can't connect with a non elastic search connector to it. And like, I'm just kind of envisioning that happening where like AWS, you know, Terraform AWS updates their provider to not only allow this, and it becomes a chicken and egg… you did this, we do this. I feel like Palm OS did it with iTunes back in the day… we connected to iTunes and then Apple blocked it. Like I just don't see where this is gonna go for them.”AWS13:32 Create Write-Once-Read-Many Archive Storage with Amazon Glacier * If you’re at all interested in mistakes that will cost you a lot of money for a very long time, well look no further! * AWS is introducing a new glacier feature that allows you to lock your vault with a variety of compliance controls that are designed to support this important record retention use case. * Once locked, the policy cannot be overwritten or deleted. * Glacier will enforce the policy and will protect your records according to the controls. * Creating the wrong policy can make your data undeletable for a long time. Don’t say we didn’t warn you.
15:37 Announcing Amazon Managed Service for Apache Flink Renamed from Amazon Kinesis Data Analytics * Did you know Amazon had a managed Flink service? Neither did we! * In what I hope will be an awesome change in pace for AWS, they are renaming Amazon Kinesis Data Analytics to Amazon Managed Service for Apache Flink. * This relates to a tweet from Ben Kehoe about that people didn’t know AWS had a managed Flink service, and someone tweeted “Wait they have a managed Flink offering?”. (So at least we weren’t the only ones.) * The cute names are fun, but also make it difficult to discover things.
17:10 AWS Compute Optimizer now supports licensing cost optimization for Microsoft SQL Server * AWS Compute Optimizer now supports licensing cost optimization for SQL Server. * Making recommendations like downgrading your SQL server edition to standard or BYOL licensing. * These seem like really dumb recommendations without a lot more understanding and context.
GCP19:18 Welcome to Google Cloud Next ’23* AI Was the theme of the day. Everywhere… I couldn’t escape hearing about AI + Literally. AI. All day. Everyday. * Impressions of the TK/Sundar Keynote (Forced smiles for the win!)? How about going to the DMV? * Event/Sessions/Venues. * Announcements + 23:15 New Titanium backed hardware will allow faster processing of machine learning and AI capabilities. * 23:48 Cloud TPU V5e - Most cost efficient, versatile and scalable purpose built AI accelerator to date. Now customers can use a single cloud TPU platform to run both large scale AI training and inference. (Point to Jonathan!) * 24:12 A3 Vms with NVIDIA H100 GPU to receive better training performance over prior generation 2 * 24:53 GKE Enterprise (formerly known as Anthos in many ways) + Enables Multi-cluster horizontal scaling plus GKE features like autoscaling, workload orchestration, automatic upgrades and now available with the Cloud TPU V5e + GKE Enterprise edition includes: * A new multi-cluster feature (“fleets”) * Managed security features * A fully integrated and fully managed platform * Hybrid and multi-cloud support * GKE Enterprise edition includes: * Group similar workloads into dedicated clusters * Apply custom configurations and policy guardrails * Isolate sensitive workloads * Delegate cluster management * Spend less time managing the platform * Run container workloads anywhere
28:42📢 Ryan - “And it is still the Anthos we've grown to love, right? So it's still a huge multi-cloud or hybrid cloud opportunity for a ton of people and companies, right? So that they can have sort of a consistent experience to offer across their data centers and any one of the cloud hypervisors. So it's pretty cool there too.”29:37 📢 Matthew - “I’d be curious to see and I don't know if you ever would, but like Google put out, Hey, this main number, you know, this percentage of customers actually using it for multi-cloud versus multi-cluster versus, you know, how are people actually leveraging the enterprise product?”* 31:04 Cross-Cloud Network - a global networking platform that helps customers connect and secure applications across clouds. It is open, workload optimized and offers ML-powered security to deliver zero trust. Reduces cross cloud network latency by 35% + Three key tenants: Open, Secure and Optimized + Allows you to address distributed applications, secure access for hybrid workforces and deliver internet facing apps + Cross Cloud Interconnects support Alibaba Cloud, AWS, Azure and OCI. + “Yahoo Mail is moving its backend onto Google Cloud and leveraging the planet-scale network for high performance and secure access to Google's data services. Cross-Cloud Network and Interconnects for high-scaled and high-performing secure access to Spanner and BigQuery will help Yahoo deliver performance and security across hundreds of millions of mailboxes." - Aaron Lake, Senior Vice President and CIO, Yahoo
32:18📢 Ryan - “When I worked for Yahoo, they were very heavy, a data center company. And that was my primary role was automating a lot of that inner company sort of play for launching infrastructure. So building our own versions of AWS and Azure services at the time. And so to see them, you know, taking advantage of the public ones is great, right? Because they're at a scale that is gonna make the product. really good for everyone else.”* 33:29 Global Access and Global Backends allow you to private clients from any region to access internal load balancers in any google cloud region. And Global Backends allow internal ALB to health-check and send traffic to globally distributed backend services * To simplify the network layer, VPC Spokes support in Network Connectivity Center now lets you smoothly scale VPC connectivity, providing reachability between a large number of VPC spokes. * Peered VPC spokes with overlapping RFC1918 addressing will be able to utilize Cloud NAT’s Inter-VPC NAT feature, ensuring that Inter-VPC network traffic stays within the Google Cloud network versus traversing the internet to help ensure privacy and security. * Cloud applications now support cross-project service referencing plus support for MTLS * Cloud NGFW in preview, a cloud first next gen firewall powered by PAN. Provides inline threat protection with 20x higher efficacy compared to other cloud firewalls, a built in distributed firewall architecture, unified network security posture controls and simplified single-policy threat response. * 37:24 Google Distributed Cloud is being expanded to support new Vertex AI integrations and a new managed offering of AlloyDB Omni on GCD-hosted. * If you’ve ever had the need to run Postgres AlloyDB, you can now do that in your data center on Google Managed Hardware. * 37:58 Vertex AI got lots of love at the conference - tons of new goodies. + Palm 2, Image and Codey Upgrades + New tools to tune Palm2 an Codey + New Models with Llama 2 and code llama, as well as Technology Innovative Institutes Falcon LLM, a popular open source model, as well as pre-announced Claude 2 from Anthropic. + Vertex AI extensions will allow developers to access, build and manage extensions that deliver real time information, incorporate company data, and take action on the users behalf. This allows Vertex to take action on third party systems like CRM. + Enterprise Grounding service + Digital Watermarking on Vertex offers a technology powered by Google DeepMind SynthID, offering a state of the art technology that embeds the watermark directly into the image of pixels, making it invisible to the human eye and difficult to tamper with. + Colab Enterprise to allow ease of use of Google’s Colab notebooks with Enterprise level security and compliance. * 39:44 Duet AI + Duet AI in Google Meet and Google Chat are now available. + Duet AI for BigQuery provides contextual assistance for writing SQL queries. + Duet AI for GKE and Cloud run provides gen AI assistance to cut down on the time it takes to run containerized apps. + Duet AI in Spanner, Alloy and Cloud sql, helps you generate code to structure, modify, or query data using natural language. As well as their bringing Deut AI Database Migration Service to help you automate the conversion of database code such as stored procedures, functions, triggers and packages + Duet AI also comes to Security in Chronic Security Operations, Mandiant Threat Intelligence and Security Command Center.
32:18📢 Ryan - “I know what I want, but I do not know the SQL syntax to get what I want. And this is, it is a fantastic feature that I've played around with a little bit for a couple hours. And I, like, I will never ever write SQL any other way.”42:49📢 Justin - “And I'm actually right now trying to backup an RDS MySQL database. And if I could use this to figure out how to make that better. Cause I foolishly thought I'd save time by using MySQL command center or the management center cause we have it set up for this particular database, and I regret everything about it.”* 45:38 Analytics + Big Query Studio is a single interface for data engineering, analytics and predictive analysis, which will increase efficiency for data teams. Plus it integrates into vertex AI foundation models (still gotta get that AI in there.) + Alloy DB AI offers an integrated set of capabilities for easily building GenAI apps, including high performance, vector queries that are up to 10x faster than standard postgres. * 46:33 Security + Mandiunt Hunt for Chronicle to integrate the latest insights into attacker behavior from Mandiant’s frontline experts with Chronicle Security Operations. + Agentless vulnerability scanning: this posture management capability in security command center detects operating system, software and network vulnerabilities on compute engine virtual machines + Cloud Firewall Plus adds advanced threat protection and next-generation firewall capabilities to their distributed firewall service powered by PAN. + Assured Workloads now support the Japan region for Japanese requirements on encryption keys and administrative access transparency.
PredictionsRyan Lucas* Generative AI Prediction - Finops Practice and Cost Management AI solution * A networking feature that only supports IPV6
Jonathan Baker* TPU V5 (Super Computer in a Box) * Generative AI for Contact Center and/or Retail AI
Justin Brodley* Google Bard in workspaces will be GA * Not going to announce anything New.
Matt Kohn* Bard via API * Additional Security tooling Ci/CD * Announcement that they Gain Market Share by @ least 5% * Some sort of competitor for AWS Lattice
Tie Breaker: Justin: 6Jonathan: 9Ryan: 1⭐Gold Star to Jonathan⭐ Azure57:33 Generally Available: Trusted launch as default for VMs deployed through the Azure portal* Trusted launch hardens your Azure VM with security features that allow administrators to deploy virtual machines with verified and signed bootloaders, OS kernels and boot policy. * We aren’t really sure why this took so long, but better late than never.
1:01:01 Generally available: Azure Container Apps jobs* Jobs - a new container app feature previewed at Build is now GA. * Azure Container App jobs support three trigger types: Manual, Scheduled and Event Driven. Manual Jobs are triggered by a user or an external system, such as another container app. * Common scenarios for jobs include: Running a one time containerized data migration job, running a scheduled recurring containerized batch job, such as a nightly inventory processing job, Running a containerized job in response to an event, or running a CI/Cd build process such as Azure Pipelines agents and github action runners.
1:01:49📢 Justin - “If you're into container app jobs and using these to do kind of your scheduled tasks, this is nice, I actually like this feature.”ClosingAnd that is the week in the cloud! We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Google Next Eve! Welcome episode 225 of The CloudPod Podcast - where the forecast is always cloudy! Justin, Jonathan, and Ryan are your hosts this week as we discuss all things Google Next! We talk schedule offerings, make our predictions about announcements, and prepare to be generally wrong about everything. Also - do you like stickers? Everyone likes stickers! Be on the lookout for us, and maybe you can have one. Titles we almost went with this week: None! Google Next is the next big thing, so of course it’s the title. A big thanks to this week’s sponsor: Foghorn Consulting provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰Pre-Show📰 01:23 Following up on some HashiCorp News:
HashiCorp updates licensing FAQ based on community questions * Hashicorp has responded in their FAQ to some of the concerns we brought up when we talked about them moving to the BSL license in our last show. + Question: Can I host the HashiCorp products as a service internal to my organization? + Answer: Yes. The terms of the BSL allow for all non-production and production usage, except for providing competitive offerings to third parties that embed or host our software. Hosting the products for your internal use of your organization is permitted. HashiCorp considers an organization as including all of its affiliates. This means one division can host a HashiCorp product for use by another internal division. + Q: What is a “competitive offering” under the HashiCorp BSL license? + A: A “competitive offering” is a product that is sold to third parties, including through paid support arrangements, that significantly overlaps the capabilities of a HashiCorp commercial product. For example, this definition would include hosting or embedding Terraform as part of a solution that is sold competitively against our commercial versions of Terraform. By contrast, products that are not sold or supported on a paid basis are always allowed under the HashiCorp BSL license because they are not considered competitive. + Q: What does the term “embedded” mean under the HashiCorp BSL license? + A: Under the HashiCorp BSL license, the term “embedded” means including the source code or object code, including executable binaries, from a HashiCorp product in a competitive product. “Embedded” also means packaging the competitive product in such a way that the HashiCorp product must be accessed or downloaded for the competitive product to operate. + Q: What if HashiCorp releases a new product or feature in the future that makes my project competitive? + A: If HashiCorp creates an offering in the future that is competitive with a product you are already offering in production, your continued use of the hosted or embedded HashiCorp product will not be considered a violation of the HashiCorp BSL license.
03:43📢 Ryan - “I think this is the right response, right? And I know that I'm probably in the minority of being sort of appeased by this in the community; because I think that the torches and pitchforks will not go away. But what this does is allow - if there's any kind of gray area in the future - it allows for litigation. And I think that that's sort of important, they're putting their stance out there. This will be referenced if it ever comes to it, as public facing statements. They're not trying to blow up the community. They're not trying to make sure no one uses it. What they're trying to do is make sure that they can still make money, which I think is good, right? I do want HashiCorp to stay around. I want them to be profitable. I want them to continue to deliver products.” 📰General News this Week:📰 AWS 12:37 Amazon EC2 Hpc7a Instances Powered by 4th Gen AMD EPYC Processors Optimized for High Performance Computing * AMD 4th gen EPYC processors (Genoa) continue to roll out across the AWS fleet with the new Hpc7a instances for HPC * These instances offer 300 Gbps Elastic Fabric Adapter (EFA) bandwidth powered by the AWS Nitro System, for fast and low-latency internode communications. * All configurations are coming up at the same price in the calculator at 5256.00 a month or 7.20 an hour for any configuration, so we’re not sure why you would not just choose the largest one.
GCP 13:50 If I were you: Here are the the Google Cloud Next ’23 talks for six different audiences * Attending Google Next? Richard Seroters gives you a great selection of courses to take across 6 different personas. * Richard is director of developer relations and outbound product management at Google Cloud. His blog is a good one to follow if you don’t already!
16:45 Announcing the new Transparency Center * A poor young product manager was given a task… and they were told that it was super important and would be critical for Google Next. That product manager pushed and pushed and shipped only to find out that it wasn’t main stage worthy.. Or that's what we like to think about this announcement at least… + Either way, good job product manager. We’re proud of you. * Google is launching the Transparency Center, a central hub for you to learn more about product policies. * The Transparency Center collects existing resources and policies, and was designed with you in mind. It aims at providing easy access to information on Google policies, how they create and enforce them, and much more, including: + Policy Development Process + Policies by product or service + Reporting and appeal tools + Transparency reports + Googles principles for privacy and AI
17:36📢 Ryan - “I mean, as the owner of the cloud platform that's constantly having to fetch the attestation for compliance of the cloud providers, I love this service. Here's a one-stop shop for the person who has no understanding of our workload, but they understand policy. Thank you very much.”
18:53 Google Next Predictions:
Ryan Lucas * Generative AI Prediction - Finops Practice and Cost Management AI solution * A networking feature that only supports IPV6
Jonathan Baker (Sneaky, sneaky Jonathan…) * TPU V5 (Super Computer in a Box) * Generative AI for Contact Center and/or Retail AI
Justin Brodley * Google Bard in workspaces will be GA * Not going to announce anything New.
Matt Kohn * Bard via API * Additional Security tooling Ci/CD * Announcement that they Gain Market Share by @ least 5% * Some sort of competitor for AWS Lattice
Main Stage New Features / Products (The Tie Breaker)
Justin: 6
Jonathan: 9
Ryan: 1 Azure 32:29 Efficiently store data with Azure Blob Storage Cold Tier — now generally available * + Azure is announcing the GA of Azure BLog Storage Cold Tier. I personally always imagined the blog was cold anyways. + Azure Storage Cold Tier is an online tier specifically designed for efficiently storing data that is infrequently accessed or modified, all while ensuring immediate availability. + The nice part about the cold tier is it is as easy to use as the hot tier with all APIs, SDK, Azure portals, powershell, CLI and Storage Explorer supporting the cold tier natively. * “Commvault is committed to ensuring customers can take advantage of the latest advancements on Azure Blob Storage for their enterprise data protection & management needs. We are proud to support cold tier as a storage option with Commvault Complete and our Metallic SaaS offering later this year. Commvault’s unique compression and data packing approach, integrated with cold tier’s policy-based tiering and cost-efficient retention, empowers customers to efficiently defend and recover against ransomware, all while ensuring compliance and cost-efficient, on-demand access to data.” — David Ngo, Chief Technology Officer, Commvault.
33:39📢 Jonathan - “I have nothing interesting to say about storage.” (He’s either still mad at Windows, or ready to head to a bar. Maybe both.) Closing And that is the week in the cloud! We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome to episode 224 of The CloudPod Podcast - where the forecast is always cloudy! This week, your hosts Justin, Jonathan, and Ryan discuss some major changes at Terraform, including switching from open source to a BSL License. Additionally, we cover updates to Amazon S3, goodies from Storage Day, and Google Gemini vs. Open AI. Titles we almost went with this week: None! This week’s title was ✨chef’s kiss✨ A big thanks to this week’s sponsor: Foghorn Consulting provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰Pre-Show📰 📰General News this Week:📰 00:41 AWS and HashiCorp announce Service Catalog support for Terraform Cloud * AWS is catching up with GCP, with now native support for Terraform in Service Catalog. * The new integration is expanding on the previous support for Open Source; they now support the Terraform Cloud service. * This new feature is available in all AWS Regions where AWS Service Catalog is available.
02:07 HashiCorp adopts Business Source License * Do you use tools like N0 or ScaleSet? Or perhaps some of the other Terraform-adjacent things? You may be in some trouble. * Despite being ok with Amazon and GCP integrating their open source - and now Terraform cloud offering - Hashicorp is mad at companies adopting their technology and productizing it, forcing them to move to the new BSL (Business Source License) model. * This covers all Hashicorp products, not just Terraform. * HashiCorp points out that their approach has enabled them to partner closely with cloud providers to enable tight integrations for their joint users and customers, as well as hundreds of other technology partners. * There are vendors who take advantage of pure OSS models, and the community work on OSS projects, for their own commercial goals, without providing material contributions back. (GASP!) + Hashi doesn’t think this is “the spirit of open source.” * As a result, they believe commercial open source models need to change, as Open Source has reduced the barrier to copying innovation and selling it through existing distribution channels. + They point out they’re in good company; pointing to other OSS projects that have closed source or adopted similar BSL models. * They are officially moving from the Mozilla Public License v2.0 to the BSL v1.1 on all future releases of HashiCorp products. + The APIs, SDKs and almost all other libraries will remain MPL 2.0 * BSL is a source-available license that allows copying, modification, redistribution, non-commercial use, and commercial use under specific conditions. + They point out Couchbase, Cockroach, Sentry and Maria DB developed this license in 2013. * Hashi also would like to point out that they are including additional grants that allow for broadly permissive use of their source code, to make things slightly less scary. * End users can continue to copy, modify and redistribute the code for all non-commercial and commercial use, except where providing a competitive offering to Hashicorp. * They produced a nice FAQ just in case you have more questions that may have been frequently asked. https://www.hashicorp.com/license-faq
Open TF is the response but we still have questions. * It’s clear things are not great in the open source community, and this one has the potential to be especially impactful. We’d love to hear our listeners thoughts on this movement away from open source and to more commercial business models.
03:52 📢 Justin - “So here’s where I get confused. If I make a product internally that uses HashiCorp for my own needs, and that prevents me from buying Terraform Enterprise because I copied all the functionality for my own personal gain in my company... not selling it, not getting any money out of it. Does that count as competing with HashiCorp, or is that okay?”
04:30 📢 Jonathan - “I also have questions about like, is it just the source that they care about in that sense? Because everything about it is the source license. Can I still integrate the next version of Terraform binary if I download it and use it without modification in my own product and compete with HashiCorp? I'm unclear on that.”
07:31 The Open TF Manifesto - a plea to keep TF open Source * For those folks who WERE seriously impacted by the changes (we’re looking at you, Spacelift, Env0, Scaler, and GrantWork) - they have written a full manifesto on why Terraform adopting BSL is bad. This is essentially a plea to keep Terraform open source forever. * They say the BUSL license is a poison pill for Terraform - with unknown legal risk and future legal risks. The use grants are vague and you now have to ask if you are in violation. * The request from the manifest is that Terraform switch back to an open source license. * However, if they do not they will fork Terraform into a foundation such as Linux Foundation or the Cloud Native Computing Foundation.
08:15 📢 Justin - “When I think about what's happened to Docker, that's a really bad thing when that happens because the community moves on from you - and you get kind of left behind. Then you get bought by some company we never heard of, divested a bunch of things, and now you have to pay for licensing for Docker for zero reason. So if I had to pay for a Terraform client natively from Terraform someday - because some PE company bought them, I'm going to be super mad. But I'll just move to OpenTF hopefully by then.”
12:04 📢 Jonathan - “I've got a question for you then. If Terraform had never been open source, do you think it would have gained the same success as it has?”
-We’d be interested in hearing listener feedback to this question! What do you all think? AWS 14:47 Welcome to AWS Storage Day 2023! * The fifth annual storage day took place on the 9th after our editorial cutoff. * There is a replay available if you want to sit through it, but we only care about the announcements so let's get into it! * Generative AI/ML was the big theme of the day - color us surprised. * They want to highlight that EBS has just turned 15 years old. It handles more than 100 trillion I/O operations daily, and over 390 million EBS volumes are created every day, which is just an incredible number. * On their new M7i instances you can attach 128 of the EBS volumes, 28 more than the previous version.
16:55📢 Ryan - “EBS was really one of the key foundational things for really taking advantage of having an elastic workload or having a self-healing workload and anything attached to a server where you could operate it and operate your data as its own thing and move it around. Like it's a big, big advancement over what you could do in the data center.”
17:20📢 Jonathan- “Yeah, I feel like they've still missed an opportunity there. Getting the data off the host themselves and off of SSDs or disks on those instances and using instance storage, that was great because now if a machine goes down, you don't lose all your stuff, but they still don't support live migration of VMs between hosts. And EBS is the key for doing that, but they've never enabled that functionality.”
And now, onto the Storage Day Goodies!
19:15 Mountpoint for Amazon S3 – Generally Available and Ready for Production Workloads * Mountpoint for S3 (or AWS finally agreeing that S3FUSE was thing) is a new open source file client that delivers high throughput access, lowering compute costs for data lakes on Amazon S3. * Mountpoint for S3 is a file client that translates local file system API calls to S3 object API calls. * Mountpoint supports basic file operations, and can read files up to 5tb in size. + It can list and read existing files and create new ones + It cannot modify existing files or delete directories, and it does not support symbolic links or file locking. * Mountpoint will work with all S3 storage classes
20:23 New – Improve Amazon S3 Glacier Flexible Restore Time By Up To 85% Using Standard Retrieval Tier and S3 Batch Operations * S3 Glacier flexible retrieval improves data restore time by up to 85%, at no additional cost. * Faster data restores automatically apply to the standard retrieval tier when using S3 batch operations. * These restores begin to restore objects within minutes, so you can process restored data faster. * Using S3 batch operations you can restore archived data at scale by providing the manifest of objects and specifying the retrieval tier.
21:28📢 Ryan - “This just proves that -I think my theory that Glacier is just all their older EBS hardware and they're just cycling it through. And so now they've moved from spinators to SSDs. I'm certain of it.”
22:22 New — File Release for Amazon FSx for Lustre * Yes, Lustre supports files. This is something different - and it’s actually pretty neat. * Amazon FSX for Lustre provides fully managed shared storage with the scalability and high performance of the open source Lustre file system to support your Linux-based workloads. * At Storage Day they announced the file release for FSx for Lustre. This feature helps you manage your data lifecycle by releasing file data that has been synchronized with S3. * File release frees up storage space so that you can continue writing new data to the file system while retaining on-demand access to release files through the FSX Lustre lazy loading from S3. * This has the potential to be extremely valuable to machine learning workloads.
25:18 Announcing AWS Backup logically air-gapped vault (Preview) * AWS backup is announcing in preview the logically air-gapped vault, a new type of AWS backup vault that allows secure sharing of backups across accounts and organizations, supporting direct restore to help reduce recovery times from a data loss event. * AWS backup is a fully managed service that centralizes and automates data protection across AWS services and hybrid workloads. * This is a TERRIBLE name, but it really does a lot of work, so we’re not mad at it.
26:49 📢 Justin - I'm a little annoyed though that this took so long because like ransomware is not new. Like, I mean, we've been talking about ransomware risks in Amazon for three or four years now, maybe even longer, maybe six. And I do remember there was a magic quadrant that came out recently where they were the magic quadrant actually dinged them for not having A solid answer for ransomware and now all of a sudden they have this…we've all been telling you all over the market, you know in the cloud practitioners that this is something we need To meet compliance requirements. Then why did it take Gartner to get there? So that part annoys me just a little bit.”
28:14📢 Jonathan - “So if you encrypt your data in the vault, where do you store the keys securely so that the keys can't be compromised or attacked or corrupted? Because I think that becomes the next problem down the line. So great, we've got the backups and they're encrypted because that's best practice. But now we've got these keys and we need to also keep someplace safe. And I think attacks on encryption keys is probably going to be the next biggest sort of destructive power against enterprise. Cause if you've got all encrypted backups and you lose the keys, you've got no encrypted backups.”
29:27 Few other items we won’t talk about: * Power ML research and big data analytics with EFS * Multi-AZ file systems on FSX for OpenZFS * Higher throughput capacity levels for FSx for Windows File Server * Copy Data to and from other clouds with AWS datasync
30:51 Network Load Balancer now supports security groups * NLB’s now support security groups, enabling you to filter the traffic that your NLB accepts and forward to your applications. * This was one of the most confusing things to learn when implementing NLB’s and we’re so glad it now aligns to the patterns for all other load balancers.
31:48📢 Ryan - “Yeah. I mean, the poor networking team that had to expand the public subnets in a rush, right? Because the first thing you do is deploy your server into a private subnet and realize you can't actually get to, can't actually have the security group be the source IP. And it just turned into chaos real fast trying to.”
34:45 Amazon EC2 M7a General Purpose Instances Powered by 4th Gen AMD EPYC Processors * Were you excited about those M7i instances we talked about a few weeks ago? Were you perhaps thinking to yourself, “man, I wish I had an AMD version of that?” Well it’s GOOD NEWS! * A few weeks ago Amazon announced the M7I instances, and now they’re back with the M7A instances powered by 5th Gen AMD EPYC (Genoa) processors with maximum frequency of 3.7GHz, which offer up to 50 percent higher performance compared to m6a instances. * M7a instances support AVX-512 Vector Neural Network Instructions and Brain Floating Point (bfloat16). They also support DDR5 memory, which enables high-speed access to data in memory and delivers 2.25 times more memory bandwidth. * Configurations available from m7a.medium 1/4 to m7a.48 xlarge with 192/768. * You can take a look at the pricing here. It’s pricey. Be aware.
GCP 37:37 How Google is Planning to Beat OpenAI (Article - Subscription required) * In a prior episode we talked about Google merging their two large artificial intelligence teams--with distinct cultures and code- to catch up to (and surpass) OpenAI and rivals. * This effort is culminating into a release of large machine-learning models this fall. * The models, known as Gemini, are expected to give Google the ability to build products its competitors can’t, according to a person involved with Gemini’s development. * Open AI can understand and produce conversational text, but Gemini will go beyond that, combining the text capabilities of LLMs like GPT-4 with the ability to create AI images based on a text description, similar to AI image generators like Midjourney and stable diffusion. * It may also be able to analyze charts or create graphics with text descriptions and controlling software using text or voice commands. * Google is planning on having Gemini power its Bard Chatbot, Google Docs and Slides. * Google will charge app developers for access to Gemini through its google cloud product. * “The big question that I think everyone has asked for the last nine months is, ‘When will someone even look like they can catch up to OpenAI?’” says James Cham, an AI startup investor at Bloomberg Beta. “This is going to be the first indication that someone can compete in a legitimate way with GPT-4.” * Google is using its biggest advantage Youtube and the large corpus of Youtube video transcripts, but it could also integrate video and audio into the model, giving them multi-modal capabilities many researchers believe will be the next frontier in AI.
39:24📢 Jonathan - “You know, first to press release is not always first to market or first to success, for sure. And so Google announcing that they're working on this amazing thing, that's great. You can talk about it all you like. Pretty sure OpenAI are already working on this. They've already published models for text and audio and 3D objects. And they're working on video, all kinds of things. Integrating those into a single model, that will be awesome. That's what Google kind of... talking about doing here is having a multimedia evolution of large language models or generative AI. I don't think they're going to be Open AI to it unless Open AI ends up going out of business because they're sued and lose in the courts and that's a huge risk right now for them.”
40:14📢 Ryan- It's interesting. Yeah. Cause you know… I always felt that AI was Google's fight to lose, but they weren't first to market, but in doing so open AI has taken all the risk, and all the weird legal hurdles. And then Google has the advantage of all this data on the backend.”
50:12 Google launches Pricing API to help enterprises optimize cloud costs * Google has launched a new pricing API that will help enterprises optimize their cloud costs. The API will provide businesses with real-time visibility into their cloud usage and costs, and will allow them to set budgets and alerts. The API is also designed to help businesses identify and eliminate waste in their cloud usage. * Let’s be real. Setting budgets doesn't save me money. * Alerts don’t necessarily save you money. * The pricing API is part of Google's Cloud Billing service, which provides businesses with tools to manage their cloud costs. Cloud Billing includes a number of features, such as usage reports, budget alerts, and cost allocation. * Here are some key points from the article: + Google has launched a new pricing API that will help enterprises optimize their cloud costs. + The API will provide businesses with real-time visibility into their cloud usage and costs. + The API will allow businesses to set budgets and alerts. + The API is also designed to help businesses identify and eliminate waste in their cloud usage. + The pricing API is part of Google's Cloud Billing service. + Cloud Billing includes a number of features, such as usage reports, budget alerts, and cost allocation. + The pricing API is now available in beta.
51:38📢 Ryan - “I mean, this is the response to the age old problem, right? The CFO wants to save money. Everyone else in the business wants to empower developers to move faster. Right, and it's sort of like, how do you reconcile those two worlds? So, I mean, these APIs, yes, setting in budgets and stuff via APIs, but what it really does is empower approval workflows so that communication is happening about money being spent. And that's really the value in these things. And so, you know, like you set a budget and then you exceed that budget and that triggers a workflow of approvals. And then you can automatically update that budget to not block the business.” Azure Oracle Continuing our Cloud Journey Series Talks After Show Closing And that is the week in the cloud! We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome episode 223 of The CloudPod Podcast! It’s a full house - Justin, Matt, Ryan, and Jonathan are all here this week to discuss all the cloud news you need. This week, cost optimization is the big one, with a deep dive on the newest AWS blog. Additionally, we’ve got updates to BigQuery, Google’s Health Service, managed services for Prometheus, and more. Titles we almost went with this week: * 🧑💻I swear to you Mr. Compliance Man, Mutator is not as bad as it sounds * 🔢Oracle Cloud customer - or how we let Oracle Audit us internally at will * 🗞️We are all confused by the lack of AWS news * ✨The CloudPod copies other Podcast’s Features * 🛞Get AWS spin on savings with Cost Optimization Flywheel
A big thanks to this week’s sponsor: Foghorn Consulting provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰General News this Week:📰 AWS No AWS news - so that should tell you we’re DEFINITELY getting close to announcement season. GCP 01:35 Introducing new SQL functions to manipulate your JSON data in BigQuery * Enterprises are generating data at an exponential rate, spanning traditional structured transactional data, semi-structured like JSON and unstructured data like images and audio. * Beyond the scale, the divergent types present processing challenges for developers, sometimes requiring a separate processing flow for each. * BigQuery supported semi structured JSON at launch eliminating the need for processing and providing schema flexibility, intuitive querying and the scalability benefits afforded to structured data. * Google is now releasing new sql functions for Bigquery JSON, extending the power and flexibility of their core JSON support. These new functions make it easier to extract and construct JSON data and perform complex data analysis. + Convert JSON values into primitive types (INT64, FLOAT64, BOOL and STRING) - Is anyone else insulted that STRING is considered primitive? + easier and more flexible way with new JSON LAX functions + Easily update and modify existing JSON values in BigQuery with new JSON Mutator functions. + Construct JSON objects and JSON arrays with SQL in BigQuery with new JSON Constructor functions.
03:58 📢 Justin - “Well, you only know that a NoSQL solution makes it once it gets a SQL interface. That's how you know it's truly become web scale.”
06:25 Introducing Personalized Service Health: Upleveling incident response communications * Outages happen to everyone… especially when your AZ’s aren’t really separate. * Google is excited to introduce personalized service health, which provides fast, transparent, relevant and actionable communication about Google Cloud service disruptions. + In preview, it allows you to receive granular alerts about Google Cloud service disruptions, as a stop in your incident response, or integrated with your incident response or monitoring tools. * Today when there is an issue they publish it to Google Cloud Service Health page, but with Personalized Service health they take this a step further by allowing you to decide which service disruptions are relevant to you. + You would think they could figure this out for us, but what do we know? * Integration with your incident management workflow is available via PagerDuty or other tools. * Personalized Service Health emits logs and can push customizable alerts to make incidents more discoverable for your workflow.
07:22 📢 Jonathan - “You can guess how that product turned out, or started out. I guess it's, how do we not tell customers that we have all these outages? Let's make a personalized dashboard that they actually have to configure before it shows anything.”
13:48 Improved cost visibility and 60 percent price drop for Managed Service for Prometheus * Does all your newly generated data need someplace to live? Maybe that someplace is Prometheus. Well, now it’s cheaper! We love a good discount… * Prometheus is the de facto standard for K8 application metrics, but running it yourself can strain engineering time and infra resources, especially at production scale. * Managed services for prometheus can help offload the burden, freeing up your engineers to build your next big application rather than spending time building out metrics infrastructure. * Google is announcing a 60% price reduction for sample ingestion effective immediately. Thanks Google! * Metric samples are tiered into 4 buckets.
15:17📢 Matt - “I always wonder what they do on the backend to get such a good price reduction? And then my next question is, how long has it been there they haven't given me the price reduction that they've been making that much profit on it?”
15:32 📢 Justin - “I was wondering these things too, is the reason why people aren't adopting it is because it's too expensive? And is it really a margin builder for them - or is it that they weren't getting any revenue from it? So now they have an opportunity to get more revenue because customers now aren’t saying, oh, that's too expensive.”
16:33 📢 Ryan - “I've never seen someone like, ‘let's use Prometheus!’ and then be cost aware about that choice… those two things don't happen.” Azure 16:50 Azure Storage Mover support for SMB and Azure Files * Azure storage mover can now migrate your SMB shares to Azure File Shares * Fully managed migration service that enables you to migrate on-premise files and folders to Azure storage while minimizing downtime for your workload.
Oracle 18:55 Introducing Oracle Compute Cloud@Customer * Oracle is pleased to announce the latest addition to the Oracle Distributed Cloud portfolio! (Whatever that is.) * Oracle Compute Cloud@Customer a fully managed, rack-scale infrastructure platform that lets organizations run enterprise and cloud-native workloads on Oracle Cloud infrastructure. * Compute Cloud@Customer is built, installed, owned and remotely managed by Oracle, so you can focus your scarce IT resources on growing your business and improving operating efficiency * The @customer offering is built using 4th generation AMD EPYC processors with 96 cores per processor and DDR5 memory. You can subscribe to increments of 552 available processor cores with 6.7 TB of available memory. + Up to a maximum of 6,624 cores overall. * This is 3.8 times the number of cores per rack as AWS Outpost system and 1.4 times the densest Microsoft Azure Stack Hub systems. * Oracle, unlike Amazon, wisely decided to give you only the pricing by cost per core and not by the actual monthly price you will pay for this unit. + They really would like you to notice that their price per core is only $53 / month
21:37 📢 Justin - “So anytime someone uses @Customer or @Ppartner like this, I have horror stories back to the company I worked at where we did SaaS @partner, which was terrible; where we basically took our SaaS application that we managed and we're like, ‘we're going to go run it in a data center owned by a partner who's going to resell it.’ And that was terrible. And I did it twice with the same leader - the same guy came up with the same dumb idea two different places; failed both times. And yet I had to go implement it both times and have it fail. So it's great. Super awesome.” Continuing our Cloud Journey Series Talks 23:01 Cost optimization flywheel * Today we’re taking a deep dive into the AWS blog post “Cost Optimization Flywheel”. * The article discusses the concept of a "cost optimization flywheel" for managing and reducing costs in the cloud. * The key points of the article are as follows: + The cost optimization flywheel is a continuous cycle of four steps: "Analyze," "Recommend," "Deploy," and "Operate." + The first step, "Analyze," involves gathering data and analyzing it to identify areas where cost optimization is possible. + The second step, "Recommend," includes using automated tools and machine learning algorithms to generate cost-saving recommendations. + The third step, "Deploy," involves implementing the recommended changes identified in the previous steps. + The final step, "Operate," focuses on monitoring and measuring the impact of the changes made and adjusting strategies accordingly. * Amazon Web Services (AWS) provides various services, tools, and resources to assist customers in each step of the cost optimization flywheel. * The article emphasizes the importance of a continuous, iterative approach to cost optimization, rather than treating it as a one-time effort. * It also highlights the role of automation and machine learning in enabling more efficient and effective cost optimization. * The cost optimization flywheel helps organizations achieve cost savings and better align cloud spending with business needs. * The cost optimization flywheel enables organizations to gain greater visibility and control over their cloud costs, allowing them to allocate resources more strategically and make informed decisions about their cloud spending.
26:53 📢 Matt - “So in the rare occasion I defend Azure, this is if you have essentially it's the same thing as AWS with the, like you get X number of IOPS per gigabyte for GP2, they have the same process with Azure file share for like DFS on AWS, where like, or sorry, FSX on AWS, where you like, you get X number of gigabytes per IOPS. And if you need more IOPS, then you have to just provision more storage space.”
27:20 📢 Ryan - “It's more of an artifact of PyOps being too expensive though, right? Then like, that's just the cost model. Like, so it's, it's because you can achieve better results, more cheaper by doing it that way versus, you know, how it's supposed to be, which is if I needed high, high throughput, I should be able to check the box for PyOps, but it's so ridiculously expensive. It doesn't make sense to do so.”
27:55 📢 Jonathan - “Just in general, I don't like this blog post at all. I don't like the diagram. I don't like the write-up. It's really amateurish. My eight-year-old could have drawn a better diagram of this. If you really want the proper diagram, go to Phenom's Foundation and look at their framework and the phases of their framework. They have basically the same thing. Inform, optimize, and operate. going around a little circle, and a really nice cloud-agnostic write-up of the process that you should be following.”
Welcome episode 222 of The Cloud Pod Podcast - where the forecast is always cloudy! This week we take an in depth look at the latest earnings reports from all the major players, changes to IPv4 costs (inflation), Healthscribe, and all the news (in cybersecurity) that’s fit to print. Titles we almost went with this week: * 💊The CloudPod can finally read the doctors notes with HealthScribe * 🩺Amazon Healthscribe it's like transcription, but for doctors who use big words * 📋You get an LLM, you get an LLM; apparently EVERYTHING at Amazon gets an LLM * ☁️Should The Cloud Pod rename itself C? * 🐦Musk Flips Twitter the Bird (just for Jonathan)
A big thanks to this week’s sponsor: Foghorn Consulting provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰Pre-Show📰 00:49 Follow up: Public Preview: Customer Managed Failover for ADLS Gen2 * The guys didn’t talk about this when it came up, as it didn’t get a full blog post and we killed lightning round - but Matt has thoughts! * Azure storage strives to give you an effective disaster recovery offering and are now supporting customer-managed failover for ADLS Gen 2 accounts. * Whether you are performing testing or facing a true disaster your primary endpoint can now initiate a failover from our primary endpoint to your secondary endpoint.
01:40📢 Matt - “It's just one of those features that I'm just dumbfounded that didn't exist day one. You know, encryption, DR - these things should just be there. And the fact that it's ADLS has been around for a decent amount of time.” 📰General News this Week:📰 03:06 The big news this week is EARNINGS: * MSFT - Microsoft’s stock falls as demand for cloud services cools
“The key milestone is that services revenue is, for the first time, more than double that of product revenue, demonstrating how Microsoft is leaving its product legacy behind,” he said. “While product revenue was $8 billion less over the full year, services revenue more than compensated, growing by $22 billion in the same period. Overall, it is clear Microsoft wants to become a services company. It needs to produce a constant stream of services innovations to continue this transformation, and it’s well-placed to do that.” -- Holger Mueller from Constellation Research.
GOOG - Strong cloud growth driven by AI workloads boosts Alphabet’s stock
06:42📢 Jonathan - “I'm okay with servers sticking around until they die. I mean, I architect things for failure anyway, so as long as Google also architecting their services to deal with those failures when they happen, it shouldn't be an issue.”
07:44📢 Justin - “I'm sure the other cloud providers are, you know, assessing this and making a determination of how long they're going to keep hardware and running and, you know, extending from five years to six years, I think is a pretty low risk. you know, it gets more expensive for them from a green computing initiative, right? Like, you know, older hardware is not as efficient, it's more power hungry. So some of those are a challenge for them over time as well. Keep those things running for six years. So I don't think you'll see companies really stretch it out beyond six.”
AMZN - Amazon delivers surprisingly good earnings results as AWS growth starts to stabilize
13:35 ‘Every single’ Amazon team is working on generative AI, says CEO * During earnings, Andy Jassy said “Every Single one of Amazon's businesses have multiple generative AI initiatives going on right now.” * He added “They range from things that help us be more cost-effective and streamlined in how we run operations and various businesses, to the absolute heart of every customer experience in which we offer. It’s true in our Stores business, it’s true in our AWS business, it’s true in our advertising business, it’s true in all our devices — and you can just imagine what we’re working on with respect to Alexa there — it’s true in our entertainment businesses... every single one. It is going to be at the heart of what we do. It’s a significant investment and focus for us.
14:23📢 Justin - “It sort of hearkens back to Gates writing a telling memo about how we ‘need to become an internet company’... Is this that moment for AWS? They're an AI company now?
14:36📢 Jonathan - “I think they've been an AI company for a long time, there's just not a lot of it has been customer facing.”
15:05 What leaked court docs tell us about AWS, Azure and Google cloud market shares * Sometimes we get interesting data from weird sources; this time it's a Silicon Angle article that reports from leaked court documents of the ongoing Activision Blizzard/Microsoft Acquisition hearings. * The data shows that Azure Revenue maybe 25% lower than previous estimates (note they aren’t broken out by the cloud provider) * This means that AWS is probably maintaining a 50% share of Cloud revenue through 2023. It also helps Google Cloud, as its market share isn’t affected much. * The court documents show that Azure revenue for Fiscal 2022 is at 34B, which is 10 billion lower than analysts estimated. * While technically, Microsoft can put the money where it wants, and this may be a play to make it look like they have less of a monopoly than the FTC argues. But they are under oath to tell the truth… so it's unlikely. Maybe. Probably? * Just a reminder: only AWS reports in a clean manner.
AWS 17:31 ALL NEW! New Regions and Availability Zones * Now Open – AWS Israel (Tel Aviv) Region * New: AWS Local Zone in Phoenix, Arizona – More Instance Types, More EBS Storage Classes, and More Services + The AWS Tel Aviv region is now open with the terribly named il-central-1 API name. Is this a problem? That may cause some issues with the i and the l, so users beware… + Also Arizona got a new local zone, which must go with their carbon neutral plans.
18:19 📢 Matt - “I'm still trying to figure out where in Israel you have three zones that are more than 200 miles apart from each other.”
18:40📢 Justin - “We need someone to accidentally leak all that data again, so we get an updated Amazon map, because they don't like to tell you exactly where these things are, but there's that leak that came out a couple years ago, and they had the actual addresses of all of the data center regions and availability zones. We just need one of those to happen so we can tell.”
19:15 New – AWS Public IPv4 Address Charge + Public IP Insights * You know you're in inflationary times or desperate for revenue when even AWS is raising prices on their customers. * Effective Feb 1 2024, AWS will be charging $0.005 (half a penny) per IP hour for all public IPV4 addresses, whether attached to a service or not. + If they’re NOT attached to a service, there will actually be an additional charge, so beware of that. + Managed services or not * AWS explains that IPv4 addresses are a scarce resource, and the cost to acquire them has risen over 300% in the last 5 years. This new cost increase reflects that price increase. * This includes services AWS Manages for you that leverage IPv4 addresses like lnat gateways and load balancers. * AWS will give you 750 hours of one IPv4 address usage per month for the first 12 months. (Just a reminder, a single load balancer uses 3, so…) * You will not be charged for BYOIP. * To help you know how many of these are in use, Amazon VPC IP address Manager is offering a Public IP Insights dashboard, which is free to use.
21:08📢 Matt - “I get why they're doing it. You know, with all the cloud providers, all buying up them, there is a scarcity of resources but the same point it adds up quickly. You have what? Three NAT gateways, so that's three, you have a couple load balancers running your application or NLBs, there's another couple, three, you know, $4 round up here per month, it starts to - you know, per IP address - it starts to add up real quickly. Especially if you're running a small business.”
22:48📢 Jonathan - “I'm disappointed that they're passing that cost on to customers. They're already in possession of 100 million IPv4 addresses. I think they can probably afford to not have done this.”
29:44 New Amazon EC2 Instances (C7gd, M7gd, and R7gd) Powered by AWS Graviton3 Processor with Local NVMe-based SSD Storage
30:07 New – Amazon EC2 P5 Instances Powered by NVIDIA H100 Tensor Core GPUs for Accelerating Generative AI and HPC Applications * New Instances for the Graviton 3 with local VNME with the c7gd, m7gd, and r7gd instance families. ½ to 64/512 configurations * For your AI and HPC needs, the new P6 instance is the next generation GPU instances leveraging the latest NVIDIA H100 Tensor Core GPUs * These new GPUs provide a reduction of up to 6 times in training timing. * Options include 192 VCPU, 8 H100 GPUs, and 2tb of RAM * This is a significant bump over the P4d.24xlarge servers these replace
30:48📢 Jonathan - “Just the cost of the hardware is phenomenal. I mean, I jokingly priced out a server from Supermicro that had a bunch of these GPUs in, you know, for when I win the lottery. And just one of those GPUs is $40,000.”
Now… amortize that over six years instead of 4…
31:32 Introducing AWS HealthScribe – automatically generate clinical notes from patient-clinician conversations using AWS HealthScribe * AWS HealthScribe, is a new HIPAA-eligible service empowering healthcare software vendors to build clinical applications that automatically generate preliminary clinical notes by analyzing patient-clinician conversations is now available in preview. * AWS Healthscribe analyzes the patient-clinician conversation audio to provide: + Rich Consultation Transcripts + Speaker Role Identification + Transcript Segmentation + Summarized Clinical Notes + Evidence Mapping + Structural Medical Terms
32:58📢 Jonathan - “I fear that things like this will be used by insurance companies. They want to see the transcripts of conversations that you had over the years to evidence things for coverage. So I'd be concerned that this wouldn't actually work out in the consumer's favor at all…I can't help but think that the transcriptions will be anonymized and used to train machine learning models and all of a sudden we'll have a virtual Amazon doctor that we can call upon Chime and get a consultation for how many dollars.”
35:08 Preview – Enable Foundation Models to Complete Tasks With Agents for Amazon Bedrock * Bedrock gives you a preview of agents for Amazon Bedrock, a new capability for developers to create fully managed agents in a few clicks. Agents for Bedrock accelerate the delivery of generative AI applications that can manage and perform tasks by making API calls to your company's systems. Agents extend FMs to understand user requests, break down complex tasks into multiple steps, carry on a conversation to collect additional information and take actions to fulfill the request. * We’re on to you AWS - this is 100% the beginnings of Skynet. You heard it here first, folks
GCP 38:00 A new partnership to promote responsible AI * Anthropic, Google, Microsoft and Open AI are announcing the formation of the Frontier Model Forum, a new industry body focused on ensuring safe and responsible development of Frontier AI models. * The Frontier model forum will draw on the technical and operational expertise of its member companies to benefit the entire AI ecosystem, such as through advancing technical evaluations and benchmarks, and developing a public library of solutions to support industry best practices and standards.Those things include: + Advancing AI Safety Research + Identify best practices + Collaborating with Policymakers, academics, civil society and companies + Supporting efforts to develop applications that can help meet society's greatest challenges + Are you in AI? Do you develop and deploy Frontier models? You too can join and participate!
39:29 📢 Jonathan - “Yeah, it makes sense. I mean, Antropic has already been working on AI safety for years. So instead of reinventing things from scratch, Google and Microsoft and OpenAI probably do well to partner with somebody who's already been working on this.”
👂Listener Survey: What do you all think of the reports that ChatGPT has gotten dumber? Let us know your thoughts!
42:15 Attack Path Simulation is now Generally Available * Now available in Security Command Center Premium * This is a new threat prevention capability that automatically analyzes your Google Cloud Environment to discover attack pathways, and generates attack exposure scores so you can prioritize security findings.
42:28 📢 Justin - “What I think is a really nice feature and really good to have, I just don't know why they're insisting that I pay the premium price for Security Command Center. Premium to get it. I think every customer who's trying to secure their Google Cloud environment should have this for free. as just part of the value add of having Google, especially since it's simulations that tell you, hey, you have a potential attack vector.” Azure 47:58 Always learning, always adapting: Unpacking Azure’s continuous cybersecurity evolution * Azure's cybersecurity strategy is based on three pillars: prevention, detection, and response. + Prevention (don’t actually do anything proactive) + Detection (Your customers detect it) + Response (Deny, and then be publicly embarrassed) * Azure uses a variety of tools and techniques to prevent attacks, including artificial intelligence, machine learning, and behavioral analytics. * Azure also has a team of security experts who monitor for attacks and respond to incidents. * Azure is constantly evolving its cybersecurity measures to stay ahead of the latest threats. * Too bad it doesn’t seem to be working. Sad.
49:16 📢 Matt - “That was a Tenable literally saying, hey, we found a bug. And they said, cool, we fixed it. And normally when they fix it, they tell them how, so the pen tester can go back in and confirm that it was fixed. And they just said, hey, we fixed it. No one knows how they fixed it. If they just blocked Tenable IPs or what they did. Like who knows? Continuing our Cloud Journey Series Talks After Show RIP Twitter, Hello X * The bird is dead, long live X * Twitter rebranded to X corp officially, and we still can’t get used to it. * Musk has a much larger vision than 120 character tweets, with the idea that Twitter will evolve into something new, the “everything app” or the public town square. * This was further enforced by hiring Linda Yaccarino as CEO. * Ironically, Linda twitter that it's rare in life or business that you get a second chance to make another big impression... And they sure did with their X HQ neighbors in San Francisco, as the new sign on the building kept many of them awake before being taken down by the city. + Can you say ‘public nuisance’ kids? + Permits? We don’t need no stinkin’ permits.
Closing And that is the week in the cloud! We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome episode 221 of The Cloud Pod podcast - where the forecast is always cloudy! This week your hosts, Justin, Jonathan, Ryan, and Matthew look at some of the announcements from AWS Summit, as well as try to predict the future - probably incorrectly - about what’s in store at Next 2023. Plus, we talk more about the storm attack, SFTP connectors (and no, that isn’t how you get to the Moscone Center for Next) Llama 2, Google Cloud Deploy and more! Titles we almost went with this week: * Now You Too Can Get Ignored by Google Support via Mobile App * The Tech Sector Apparently Believes Multi-Cloud is Great… We Hate You All. * The cloud pod now wants all your HIPAA Data * The Meta Llama is Spreading Everywhere * The Cloud Pod Recursively Deploys Deploy
A big thanks to this week’s sponsor: Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰News this Week:📰 00:33 HashiCorp State of Cloud Strategy Survey 2023: The tech sector perspective * We didn’t find anything in the survey particularly interesting, until they broke it down by respondents who are actively in the tech industry. * Despite strong Macro pressure and recent earnings reports about slowness in growth, 48% of respondents increased their cloud spend in the last 12 months * 94% of tech industry respondents indicated that multi-cloud works, citing that it has advanced or achieved their company’s business goals. + Sure, Jan. * 91% of tech companies rely on platform teams.
01:37📢 Justin - “The thing about that is, I could see the value for Saas vendors, right? Especially if you're dealing with large data ingestion. I think we were talking to New Relic, for example, when they launched a New Relic on Azure.It saves their customers a bunch of money because they're not doing egress charges out to the internet to AWS to basically get the New Relic data in. And they see that as a strategy that helps customers reduce money and also helps increase adoption as well as partnership opportunities.” AWS 05:11 AWS Summit New York just happened, and there were a lot of announcements (and protests.) We won’t spend a lot of time going over each of these in the show, but the link are available for you to peruse at your leisure. * Introducing AWS HealthImaging — purpose-built for medical imaging at scale + AWS is very excited to announce the general availability of AWS HealthImaging, a purpose-built service that helps builders develop cloud-native applications that store, analyze, and share medical imaging data at a petabyte scale. HealthImaging ingests data in the DICOM P10 format. It provides APIs for low-latency retrieval and purpose-built storage.
06:42 Llama 2 foundation models from Meta are now available in Amazon SageMaker JumpStart * After we mentioned Azure getting LLama Support, we couldn’t ignore this article that you now use LLama 2 on Sagemaker.
08:04📢 Jonathan - “There’s an awful lot of models out there, actually. If you go to Huggingface.co there's a guy called Tom Joins known as ‘The Bloke’ and he has available for download like close to 600 different models and a lot of them are like quantized versions of the larger models so you can run them on sensible currency hardware. But yeah, there's dozens to choose from that have been trained on different data sets. Some are tuned for chats, some are tuned for other things. So yeah, don't be restricted by what the cloud providers actually turn into products and sell you when you can use any open source tools like PyTorch to take these models and do whatever you like with them, even in SageMaker.”
09:41 AWS Transfer Family launches SFTP connectors * We would argue that AWS Transfer Family has done more innovation than any other SFTP server vendor in a long time. * This time they are launching SFTP connectors, which is a fully managed and low code capability to securely and reliably copy files at scale between remote SFTP servers and Amazon S3. * Files transferred using SFTP connectors are stored in Amazon S3, enabling you to unlock value from data using analytics, data lakes or AI/ML Services in AWS. * AWS Transfer Family support for SFTP connectors is available in all AWS Regions where the service is available, and pricing information can be found here.
GCP 16:48 Cloud Next 2023 session catalog is live, covering all of your key cloud topics * Google Cloud Next is just about a month away, and Google Cloud Next has launched their session catalog. * There will be sessions on AI, (how surprising) Serverless/Containers, Devops, and more.
17:26 📢 Ryan - “So I want to know if I can use AI to schedule me in these things. Because I, with every single conference, I always have the best of intentions of going through the catalog in advance and figuring out what I want to do and getting all excited and the whole thing. But without fail, it's five minutes before a session and I'm trying to figure out how to get across to wherever I need to go.
18:09 Cloud Deploy gets deploy parameters, new console creation flows, and reduced pricing * Google Cloud Deploy announced new capabilities today, the first to add to their previously announced Parallel deployments capability, is the ability to use deployment parameters to focus your deployed to child targets. * They have also reduced the price of Active Cloud Deploy delivery pipelines and expanded no charge usage to include single-target delivery pipelines, making it easier to get started with cloud deploy. * It's easier than ever to deploy your first pipeline with simple deliver pipelines and targets, and release directly in the Cloud Deploy console for trials and experiments
19:05 📢 Jonathan - “A lot of the business that the cloud providers are seeing now are coming from cloud migrations. I'm sure they're getting some startups and cloud native apps as well, but a lot of the business is going to be from migrations. And people either have Jenkins already or some other kind of CI. set of tooling and build processes and things like that. So if Google is going to provide services for deployments, then it would really be in their interests to make it so that you could also do on-prem deployments with the same set of tools.”
23:13 Introducing Google Cloud Support on mobile: Manage support cases on-the-go * On-Call engineers supporting Google Cloud can be excited that they can now view and manage google cloud support cases right from the google cloud mobile app * This is perfect for anyone who wants to be ignored, or who loves watching your issues not get fixed in a timely manner.
24:14 📢 Justin - “So I will say - definitely support case. It's definitely a use case I would use the mobile apps for. And then rebooting an EC2 box, just as a preliminary, like I'm on my way home, let me reboot this box and hope it fixes it. And sometimes it does, which works. So those are the two use cases I've mostly had, but yeah, like looking at performance metrics, looking at, you know, different things, trying to set up anything like, yeah, forget all that use case. Like no, no time for that on my little teeny tiny phone to look at logs.” Azure 24:43 Compromised Microsoft Key: More Impactful Than We Thought * The Wiz, one of the leading cloud security researching companies, as well as Cloud Security Posture Management firms, did some extensive research in the recent storm attack. * Wiz reports that microsoft indicated only Outlook and Exchange online were impacted by the token forging technique. + Wiz Research has found that the compromised signing key was more powerful than it may have seemed, and was not limited to just those two services. * Wiz concludes that multiple types of Azure AD applications, including every application that supports personal account authentication such as Sharepoint, Teams, Onedrive and any app that supports login with Microsoft under certain conditions could be compromised. * While Microsoft released IOCs for the encryption keys and source ip addresses, Wiz says it will be difficult for customers to detect the use of forged tokens against their applications due to lack of logs on crucial fields related to the token verification process. * Wiz also researched where the key comes from and believes it was able to sign OpenID v2.0 tokens * Microsoft responded to the wiz article: + Many of the claims made in this blog are speculative and not evidence-based. We recommend that customers review our blogs, specifically our Microsoft Threat Intelligence blog, to learn more about this incident and investigate their own environments using the Indicators of Compromise (IOCs) that we've made public. We’ve also recently expanded security logging availability, making it free for more customers by default, to help enterprises manage an increasingly complex threat landscape
24:14 📢 Ryan - “I like changing the security logging to free though. I think that that's a good response. I'll give them credit for that one.” Oracle 33:20 Easily install Oracle Java on Oracle Linux in OCI: It’s a perfect match! * For those of you who leverage Oracle Cloud, you now get a license and full support of Oracle Java SE and Oracle GraalVM versions at no extra cost. * This is a trap if you're multi-cloud. * Oracle Java is supported by Oracle Linux. * It’s also compatible with Intel/AMD and Arm based processors.
Continuing our Cloud Journey Series Talks The Cloud Shared Responsibility model is a framework that defines the security and compliance responsibilities of cloud service providers (CSPs) and their customers.
The model is based on the principle of shared responsibility, which means that both the CSP and the customer share responsibility for security and compliance in the cloud.
The CSP is responsible for the security and compliance of the cloud infrastructure, platform, and services. The customer is responsible for the security and compliance of the data, applications, and workloads that they deploy in the cloud.
The key points of the Cloud Shared Responsibility model are as follows: 1. The CSP is responsible for the security and compliance of the cloud infrastructure, platform, and services. 2. The customer is responsible for the security and compliance of the data, applications, and workloads that they deploy in the cloud. 3. The CSP and the customer must work together to ensure the security and compliance of the cloud environment. 4. The CSP must provide customers with the information and tools they need to meet their security and compliance obligations. 5. The customer must implement appropriate security and compliance controls in the cloud environment. 6. The CSP and the customer must monitor and assess the security and compliance of the cloud environment. 7. The CSP and the customer must respond to security and compliance incidents in a timely and effective manner. 8. The CSP and the customer must cooperate with law enforcement and other government agencies in the event of a security or compliance incident. 9. The CSP and the customer must maintain appropriate documentation of their security and compliance efforts. 10. The CSP and the customer must regularly review and update their security and compliance policies and procedures.
The Cloud Shared Responsibility model is a complex and ever-evolving framework. It is important for both CSPs and customers to stay up-to-date on the latest changes and best practices.
The key differences between shared security model and shared fate security model are: * In a shared security model, each component is responsible for its own security. In a shared fate security model, all components are responsible for the security of the system as a whole. * In a shared security model, a component can be compromised without affecting the security of the other components. In a shared fate security model, a compromise of one component can lead to the compromise of the entire system. * In a shared security model, it is easier to identify and fix security vulnerabilities. In a shared fate security model, it is more difficult to identify and fix security vulnerabilities because all components are interconnected. * In a shared security model, it is easier to recover from a security breach. In a shared fate security model, it is more difficult to recover from a security breach because the entire system is compromised.
Shared security models are typically used in systems where the components are not tightly coupled. Shared fate security models are typically used in systems where the components are tightly coupled. After Show Wholesale copying’: Israel’s Orca Security sues rival Wiz for patent infringement Closing And that is the week in the cloud! We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome episode 220 of The Cloud Pod podcast - where the forecast is always cloudy! This week your hosts, Justin, Jonathan, Ryan, and Matthew discuss all things cloud, including virtual machines, an AI partnership between Microsoft and Meta for Llama 2, Lambda functions, Fargate, and lots of security updates including the Outlook breach and WORM protections. This and much more in our newest episode. Titles we almost went with this week: * Too Many Bees died for Honeycode * Microsoft announces that AI will only cost you 3 arms and a leg. * The Cloud Pod also detects Recursive Loops in cloud news * The cloud pod disables health checks bc who needs them
A big thanks to this week’s sponsor: Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰News this Week:📰 AWS 02:02 Detecting and stopping recursive loops in AWS Lambda functions * Do you utilize AWS Lambda? Here’s an update for you. * AWS Lambda is introducing a recursion control to detect and stop lambda functions running in a recursive or infinite loop. * This supports Lambda Integrations with SQS, SNS or directly via the Invoke API. * Lambda defects functions that appear to be running in a recursive loop and drops the request after exceeding 16 invocations * This can help reduce costs from an unexpected lambda invocation because of recursion. * You’ll receive notification that this action was taken through the AWS Health Dashbboard, email or by configuring Amazon Cloudwatch Alarms. * You can turn this off by reaching out to AWS support, if you have a valid use-case where recursion is intentional, or if you need to loop something through more than 16 times. * This is also the trap - if you say turn it off and then cry about a ridiculous bill due to your runaway recursion - they will now force you to pay it. So, listeners beware.
03:50📢 Matt- “I can definitely say I’ve caused an ‘in the hundreds of dollars’ very rapidly by this in the past in a dev account. So it's definitely something that's easy to do if you are doing recursion and you make an ‘if’ statement the wrong way.”
04:28 AWS Fargate Enables Faster Container Startup using Seekable OCI * Are you a Fargate user who has been jealous of all those folks using ECS who have been able to utilize the seekable OCI or Sochi capability of lazy loading of containers? Well pine away no more! This feature is now available to you! * As you most likely know, AWS last year started supporting lazy loading of containers via the Seekable OCI (SOCI) technology. + This was due to research that said image downloads accounted for 76% of container startup time, but on average only 6.4% of data is needed for the container to start and do useful work. * Now this feature is coming to AWS Fargate, which will help your application deploy and scale out faster by enabling containers to start without waiting to download the entire Container Image. * As of launch, you can now use it for both Fargate ECS as well as Fargate Naturally and ECS Compute. * Note that supporting this capability does require you to build a SOCI index for the container image. + Amazon has made this part easier, however, with a SOCI index builder. + This is a serverless solution for indexing container images in AWS. + If you like you can also create the SOCI indexes manually via the SOCI CLI provided by the soci-snapshotter project.
06:27📢 Justin- “I suspect this is a big issue if you're doing data learning sets and containers, right? So you need to load up a large amount of data set into the container, to basically then be able to train the model, but you know, you can start training the model on a subset of the data; you don't need the full thing to be loaded. And so I suspect that's really where the use case of this comes into play - in big data training and AI training.”
07:56 Amazon FSx for NetApp ONTAP Now Supports WORM Protection for Regulatory Compliance and Ransomware Protection * FSX for Netapp OnTap now supports Snaplock, an ONTAP feature that gives you the power to create volumes that provide Write Once Read Many (WORM) functionality. + (Or as we refer to it… how to turn your SAN into a paperweight and use it with care). * Snaplock volumes prevent the modification or deletion of files within a specified retention period, and can be used to meet regulatory requirements and to protect business-critical data from ransomware attacks and other malicious attempts at alteration or deletion. * FSx for OnTAP is the only cloud-based file system that supports Snaplock, and the ability to move Snaplock data to lower costs cloud storage. For now.
08:38📢Jonathan - “This is kind of a can of worms really. I see the advantage of protecting against ransomware, but also customers or consumers have a right to have the data deleted. So what happens if your data is on a worm drive with a policy that says it can't be deleted, but the regulatory requirements say that you have to delete customer data.”
20:29 Announcing AWS Fault Injection Simulator new features for Amazon ECS workloads AWS Fault Injection Simulator supports chaos engineering experiments on Amazon EKS Pods * AWS Fault Injection Simulator now supports Chaos experiments for EKS and ECS workloads. * We’re not sure just how much ADDITIONAL chaos you want to add to your containers, but now you have options! * ECS Actions Supported + Task-cpu-stress + Task-io-stress + Task-kill-process + Task-network-blackhole-port + Task-network-latency + Task-network-packet-loss * EKS supports all of the same actions.
11:02 📢 Jonathan - “We don't need to inject defects. We have plenty of our own.”
12:42 📢 Ryan - “Yeah, other than the basics of fault injection when it first came out, I don't think I've really used it since because like you said - I wish I could get to a level where I maintain application to a level where I'm like, yeah, I'm gonna make it really hardened and resilient.”
13:39 The future of Amazon's Honeycode cloud service is not looking so sweet * Filed under news we’re not at all shocked about, Honeycode may be on its last legs. * Originally launched in 2020, Honeycode was supposed to be the answer to AWS “low-code” development, which uses a simple drag and drop interface to help users easily build apps without advanced software engineering skills. * Amazon is currently providing bare minimum support for Honeycode, with no active promotions or sales activities for the app, according to people familiar with the matter. * It's basically a KTLO product, joining other services like Workdocs, Workmail and SimpleDB. * Amazon has great infrastructure as code, but has struggled with SaaS apps (outside of Connect IMO). With competing products for things like Dropbox, Slack, Tableau with only marginal success. * Interestingly enough, Honeycode was a high profile project when it launched. * Honeycode is still listed in the Amazon Directory but appears to have been absorbed by the new Next Generation Developer Experience team, which is focused on Generative AI.
GCP 15:48 Document AI introduces powerful new Custom Document Splitter to automate document processing * Google is focusing a lot on documents this year, with the launch of Custom Document extractor in February, and Custom Document Classifier in March. * Now they are announcing the latest feature in Document AI Workbench: the Custom Document Splitter. This will help users automatically split and classify multiple documents in a single file. * CDS allows customers to sort and classify their documents. + For example, businesses can validate if they have all the needed documents for an applicant. + Furthermore, individually classified documents can help automate other downstream processes. + The goal is to help businesses lower their documenting time and costs.
17:52 📢 Ryan - “In the pre-show I was talking about my expense report, and having to basically give the top page that has the account summary, but I don't really want all my individual cell phone transactions. And so being able to do stuff like that - automatically pre-processing, where you're splitting that up and not storing ages and ages of ‘this page intentionally left blank’ in your cloud storage is probably a pretty good idea.” Azure 17:49 Hotpatch is now generally available on Windows Server VMs on Azure with the Desktop Experience installation mode * Hotpatch is now available for Windows Server Azure Edition VMs with Desktop Experience installation mode using the newly released image. * Hotpatch is a feature that allows you to patch and install OS security updates on Windows Server Azure Edition Virtual machines on Azure without requiring a reboot. + Justin has a problem with this assertion, however… * Apparently, previously available only for Server Core Installations (with no GUI), now, they can do it with a full GUI every month. * Benefits + Lower workload impact with fewer reboots (allegedly) + Faster deployments of updates as the packages are smaller, install faster, and have easier patch orchestration with Azure Update Manager (allegedly) + Better protection, as the Hotpatch update packages are scoped to Windows security updates that install faster without rebooting (allegedly)
19:09 📢 Matthew- “I prefer not to ever log into my servers, ever deal with them in any way, shape or form. If there is a patch, the windows auto OS update feature, I don't know what the official name is on Azure for it, but it literally just takes care of it for you in the scale sets. You don't have to deal with it. Works great. Why do I need to actually patch local servers? I prefer not to do this… That is why I pay Microsoft to write it for me.”
19:41 📢 Ryan - “Well, with improvements like this, like Azure is going to be the only place to host Windows workloads, right? Because it's all the gripes with Windows. You're like, well, why would I run this another cloud provider? I have to reboot it every five minutes.”
20:07 Always Serve for Azure Traffic Manager * So you hotpatched your server and now need a reboot. * Now you can now use Always Serve for Azure Traffic Manager! * You can disable endpoint health checks from an ATM profile and always serve traffic to that given endpoint. You can also now choose to use 3rd party health check tools to determine endpoint health, and ATM native health checks can be disabled, allowing flexible health check setups.
20:55 📢 Jonathan - “It’s a pretty decent feature, actually. It seems weird to remove health checks, but what they're providing is a way to plug in your own health check infrastructure. So if you need something more complex than just a REST call or a web call that gets 200 or 500 back, then you can build something a lot more complex that runs much better tests, and then plug that into the load balancer.”
21:24 📢 Justin - “It's a lot of heavy lifting for me to now pull this all into APIs where… why don't you just give me the ability to run a custom health check as the health check through serverless, and then based on the output of what I give you, you can then do different scale set operations. Why completely divorce yourself from the responsibility and say, now you have a third party that's responsible. We're off the hook, when you could have given me a system that allows me to run my own code to do health checks.”
23:56 Microsoft and Meta expand their AI partnership with Llama 2 on Azure and Windows * Microsoft is doing all the AI things, and now announced support for the Llama 2 family of LLMs on Azure and Windows. * LLama2 is designed to enable developers and organizations to build generative AI powered tools and experiences. * Meta and Microsot share a commitment to democratizing AI and its benefits, and they are excited that Meta is taking an open approach with Llama 2.
23:56 Furthering our AI ambitions – Announcing Bing Chat Enterprise and Microsoft 365 Copilot pricing * Microsoft Inspire has announced Bing Chat Enterprise and Microsoft 365 Copilot pricing. * Bing chat enterprise delivers an AI-powered chat for the workspace, rolling out in preview to over 160 million people. * Also, for budgeting, you should know that Copilot is going to cost you $30 per user per month on top of your MS365 E3, E5, Business Standard and Business Premium customers. * Timing will be shared soon. We’re on pins and needles over here.
24:46 UPDATE: Analysis of Storm-0558 techniques for unauthorized email access * Storm-0558 acquired an inactive MSA consumer signing key and used it to forge authentication tokens for Azure AD enterprise and MSA consumer to access OWA and Outlook.com. All MSA keys active prior to the incident – including the actor-acquired MSA signing key – have been invalidated. Azure AD keys were not impacted. * The method by which the actor acquired the key is a matter of ongoing investigation. * Though the key was intended only for MSA accounts, a validation issue allowed this key to be trusted for signing Azure AD tokens. * This issue has been corrected. (Allegedly) * The big questions remain: what did they steal and how did they steal it?
26:09 📢 Justin - “So they fixed the root, which is good, but they still don't actually know how they got the acquired the key or at least they've not publicly announced how the packer got the key that was used and the whole thing. So this is not great, but I appreciate the thoroughness of this writeup versus the original document. And I do hope they answer the final piece of the puzzle. So we all. feel maybe a little better or a little worse. I'm not sure how I feel.” Closing And that is the week in the cloud! We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome episode 219 of The Cloud Pod podcast - where the forecast is always cloudy! Today your hosts are Justin and Jonathan, and they discuss all things cloud, including clickstream analytics, databricks, Microsoft Entra, virtual machines, Outlook threats, and some major changes over at the Google Cloud team. Titles we almost went with this week: * TCP is not Entranced with Entra ID * The Cave you Fear to Entra, Holds the Treasure you Seek * Microsoft should rethink Entra rules for their Email
A big thanks to this week’s sponsor: Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰News this Week:📰 AWS 00:47 Clickstream Analytics on AWS for Mobile and Web Applications * Want some solutions? Don’t we all! Well, for clickstream analytics at least, Amazon has released an update that has pre built solutions using Amazon components. * Covers iOS and Android * You can now deploy an end-to-end solution to capture, ingest, store, analyze and visualize your customers' clickstreams inside your web and mobile applications. * This solution is built using standard AWS services to allow you to keep your data in the security and compliance perimeter of your AWS account and customize the processing and analytics as you require, giving you the full flexibility to extract value for your business. * The new solution leverages ECS+Kafka/Kineses/S3, EMR, Redshift and Quicksight * You can use plugins to transform the data during processing via EMR< AWS has provided you to build in ones for User Agent enrichment and IP address enrichment. + You can also export your source server inventory list to a CSV file and download it to your local disk. + You can always continue leveraging the previously launched import and export functionality to and from an S3 bucket if you're so inclined. + Additional Post launch actions, adds four predefined post launch actions. - Configure Time Sync - Validate Disk Space - Verify HTTP(S) response - Enable Amazon Inspector * If only this had been written 9 months ago when everyone was trying to run away from Google analytics…
02:45 📢 Justin- “I believe they have cloud cost optimization opportunities and solutions, but I would appreciate maybe some additional of those. More dashboards, more pretty pictures for dealing with your Amazon bill.”
02:58 Introducing the AWS .NET Distributed Cache Provider for DynamoDB * Have you ever had to set up DynamoDB as a distributed cache provider in .Net? Were you frustrated with the documentation and/or the complexity of what you have to do? Well, fear not, gentle listener! Amazon has your back. * Now in preview is AWS .NET Distributed Cache Provider for DynamoDB. This library enables Amazon DynamoDB to be used as the storage for ASP.NET Core’s distributed cache framework. * This avoids unnecessary heavy lifting to implement a common .net core platform.
03:26📢 Jonathan - “That's awesome. I mean, this is replacing things like memcache and other similar technologies that are pluggable, I assume.”
04:09📢 Justin - “One of the things I've done quite a few times is enable session state for ASP.net code. And you can actually even use this Dynamo TV table to cache that, which is kind of great, because the way you either do it is you use Redis, which is the right way to do it, or you use SQL Server, which is the wrong way to do it. And you cause yourself all kinds of grief when your application gets a few hundred connections as your SQL Server can't keep up with it. So, always good to have another option in addition to Redis that is not SQL Server.” GCP 04:44 Former Amazon Web Services data center leader Chris Vonderhaar joins Google Cloud * Chris Vonderhaar (who was the VP of AWS Data Center Community and left in the spring) has now joined Google as VP Demand and Supply Management. * This is part of a larger shakeup in Google Cloud’s management team. * The changes include longtime google executive Urs Holzle, shifting to an Individual Contributor Role. * In the past Amazon has been aggressive about pursuing legal action against former executives, we will see what happens in this case.
06:20 Set task timeout (jobs) * Have you been angry that Google Cloud Run only supports a timeout of 1 hour? * Are you also angry that they’ve pivoted to using things like Knative to solve that problem? * Well, release that anger - you can now have Google Cloud Run timeouts up to 24 hours. * This is great for those LONG running jobs. * We here at The Cloud Pod like to refer to this as “serverful for serverless” and it's a great feature.
06:48📢 Justin - “Do be careful on this one. The pricing can get a little out of control on long running transactions. So do your math and ROI calculation to see if maybe you should just run it in a container, if it was going to take that long. Just to put it out there.” Azure 08:44 Latest generation burstable VMs - Bsv2, Basv2, and Bpsv2 * Microsoft has announced the public preview of new burstable VMs, Bsv2, Basv2 and Bpsv2. * These VMs offer a more cost-effective way to run workloads that burst in and out of activity. * BSV2 VMs have a base performance level that is guaranteed, and they can burst to a higher performance level for short periods of time. * BASV2 VMs are designed for workloads that only need to run occasionally, and they offer a pay-as-you-go pricing model. * To learn more about the new burstable VMs, check the Azure Blog announcement and Burstable VM documentation.
09:35 📢 Jonathan- “You almost love this kind of thing because now they can charge for the full Windows license for all 8 cores But you actually only get 2 cores worth of performance.”
09:43 📢 Justin - “I hadn't thought of that perspective, but yes, you're completely right. Well done, Microsoft, well done.”
09:53 Microsoft Entra expands into Security Service Edge and Azure AD becomes Microsoft Entra ID * Azure AD is now known as Microsoft Entra ID. * The name change represents the evolution and unification of the entire Microsoft Entra family, and a commitment to simplify secure access. * Did you know there was a WHOLE Entra family? We didn’t. Must have missed that blog. * No action other than snickering at the name is required for you, the end user. * Entra ID is more than just the AD you “know and love,” - it also provides: + App Integrations via SSO, Passwordless and MFA + Conditional access + Identity protection + Privileged Identity Management + End-User Self Service + Unified Admin Center * This brings it in line with the rest of the Entra product family with includes ID Governance, External SSO, Verified ID, Permissions Management, Workload ID, Internet Access and Private App Access * More information on Entra will be available at the live Tech Accelerator event on July 20th, 2023.
09:43 📢 Justin - “So apparently the Entra product that was announced a year ago in July of 2022, we clearly were on vacation… It’s interesting, you know, how we've been doing the show for a couple of years. I would say that the last 15 months now have been just kind of slow in general terms. So I don't know if that's a sign of the maturing cloud market, I don't know if that's a sign of productivity issues and layoffs impacting things, but I am sort of curious to see what Google Next drops this year. I'm really curious to see what reInvent does this year because it definitely feels like big innovations are kind of slowing down. And I don't know if that's just a perception I have or if that's reality.”
14:36 Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email * Microsoft mitigated a China-based threat actor targeting customer email. * The threat actor used a variety of techniques to steal email credentials, including phishing emails, malicious websites, and watering hole attacks. * Microsoft blocked the threat actor's activity and notified customers who may have been affected. * Most concerning in the announcement is some of the details - or lack of details. + The actor exploited a token validation issue to impersonate Azure AD users and gain access to enterprise mail.
15:01 📢 Justin - “The most concerning part of the answer though, in my opinion, is that they talk about the quote here, is the actor exploited a token validation issue to impersonate Azure AD users and gain access to enterprise mail. And they don't really say how he got that token. Was it, you know, is it a token that everybody has access to in the web application, or is it a private token that he should never have been exposed that he got through insider threat model or from. you know, maybe a performer employee or I don't know how that got out there. I wish they would expand on this. The initial alert on it is pretty lightweight.”
15:43 📢 Jonathan - “Yeah being able to forge tokens to access Outlook web access is slightly concerning…”
16:09 Azure’s cross-region Load Balancer is now generally available * The Azure cross-region load balancer is a load balancer that distributes traffic across multiple regions. (We know, that seems obvious but you never want to assume.) * This provides high availability and disaster recovery, as if one region fails, the other regions can continue to serve traffic. * The load balancer uses a global network of Azure virtual network gateways to provide high-performance, low-latency connections to ensure that users in any region will have a good experience when accessing your application. * As you would expect, the load balancer also provides health checking to ensure that only healthy instances serve traffic.
16:59 📢 Justin - “If you're next to the server that's normally in Los Angeles and now you're being routed to India, that's not gonna be a great latency experience, I'm sure. So good on them.”
17:13 General availability: Azure Data Explorer adds support for PostgreSQL, MySQL, and CosmosDB SQL external tables * ADX External Tables is a new feature in Azure Databricks * This allows you to connect to external data sources and query them using Databricks SQL. * This can be useful for a variety of reasons, such as: + Accessing data that is not stored in Databricks, such as data in a data warehouse or on-premises file system. + Querying data in a more efficient way than is possible with Databricks' native connectors. + Using Databricks' powerful SQL engine to analyze data from a variety of sources. * To use ADX External Tables, you first need to create an external table definition. This definition specifies the location of the data source and the format of the data. * Once you have created an external table definition, you can query it using Databricks SQL. * ADX External Tables is currently in preview and is available for a limited number of customers. * Want to become one of those super special people with the super special limited access? Contact your sales rep.
19:13 📢 Justin - “It's interesting to me Databricks is still around because I was convinced this company would get bought by Microsoft when they created Azure Databricks. But I was just looking at them as we were talking, they've raised a lot of money, including like $1.6 billion in August 2021. So they have a long runway and they're probably very expensive to buy at a billion dollars in revenue. But I'm sure, I assume they're gonna IPO at some point. So then if they fall apart, then Microsoft can buy them for cheap on the stock market. So maybe it’s a good strategy!” Oracle Continuing our Cloud Journey Series Talks We’ll continue our Cloud Journey Series next week when Ryan and Matt join us again - so be sure to tune in next week.
Welcome to episode 218 of The Cloud Pod podcast - where the forecast is always cloudy! Today your hosts Justin, Ryan, and Matt discuss all things cloud - including migration services, AppFabric, state machines, and security updates, as well as the idea of shifting left versus (or in addition to) shifting down. Titles we almost went with this week: * The Cloud Pod Prefers to be Bought by Anyone but IBM * What Does the F(in)O(ps)X say? * The Cloud Pod Leverage appFabric for your SaaS Security
A big thanks to this week’s sponsor: Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰News this Week:📰 01:21 IBM acquires hybrid cloud software company Apptio for $4.6B * + IBM is acquiring software company Apptio Inc for 4.6B in cash. + THe move comes five years after Vista Equity bought the firm for 1.94B + Apptio was created in 2007, and was notable as the first company Andreeson Horowitz invested in. Apptio owns Cloudability, among other features. + Apptio offers cloud-based technology and hybrid business management software for managing business in the IT field. + IBM Chief Executive Arvind Krishna said in a statement “Technology is changing business at a rate and pace we’ve never seen before. To capitalize on these changes, it is essential to optimize investments which drive better business value, and Apptio does just that. Apptio’s offerings combined with IBM’s IT automation software and watsonx AI platform, gives clients the most comprehensive approach to optimize and manage all of their technology investments.”
2:30📢Ryan - “The last time I played with Apptio was very early in my cloud experience and Apptio was struggling to understand how to sort of port their methodologies into cloud. It worked really well in the data center and for IT shops, for tracking assets and managing visibility into cost and financials there, but it really struggled with stuff like dynamically changing instance groups and that sort of thing. It made sense when they bought Cloudability, and I haven’t played with it since.”
04:39 Justin goes to FinopsX!
06:10📢Justin - “I did have an opportunity to talk to some startups. they're on the floor and they're thinking about kind of the next generation and what that looks like and you're really talking about bringing AI and LLM technology into FinOps and how do you get beyond the basics of it. I think we're at this kind of cusp of the end of the Gen 1 era… I suspect that we're in for a bunch of FinOps and capabilities coming out of these vendors as they try to figure out what their v2 is, and potentially new startups that are going to come in and be disruptive to the Gen 1 players, because I think it's a commodity, which was my big takeaway from the conference in general. It was good. It was a nice time. I definitely recommend going if you're in the FinOps space.”
08:07 📢Ryan - “I’m waiting for the first one of these players to really get the data enrichments, like AI generated data enrichment of your resources. The first person who cracks that in a reliable, useful fashion. I think it's going to change the way we do business. Cause I think there's a lot of business decisions we make on incomplete data, and I think that once that data is more complete and you can turn something loose - to do it at a very large scale. I think it's gonna change a lot about what we think of our businesses, how they run, how healthy they are, what things cost.”
Join us at FinOps X next year, and tune into The Cloud Pod in the months leading up to June - we’ll be sure to keep you updated on everything you need to join the fun in San Diego. AWS 13:54 AWS Application Migration Service Major Updates: Global View, Import and Export from Local Disk, and Additional Post-launch Actions * AWS has three major updates to the Application Migration Service. + Global View - You can manage large-scale migrations across multiple accounts. This feature provides you both visibility and the ability to perform specific actions on source servers, apps and waves in different AWS accounts. - Some actions: Launching test and cutover instances across accounts - Monitoring migration and execution progress across accounts + Import and Export from Local Disk- You can use AMS to import your source environment inventory list to the service from a CSV file on your local disk. + You can also export your source server inventory list to a CSV file and download it to your local disk. + You can always continue leveraging the previously launched import and export functionality to and from an S3 bucket if you're so inclined. + Additional Post launch actions, adds four predefined post launch actions. - Configure Time Sync - Validate Disk Space - Verify HTTP(S) response - Enable Amazon Inspector
15:03📢 Ryan- “I think the reason why none of us have ever used this tool is because we don't actually like supporting cloud adoption in this way. This is a lift and shift methodology and this just isn't a problem I have with lift and shift methodology. There's a lot of tools available and generally when I'm looking at cloud adoption, even in a lift and shift scenario, I'm trying to encourage better CI and CD and deployment automation and those types of things. And I feel like this is sort of a cheat around those things where you don't have that. And so I get it, but I do worry about what happens day three after you use this tool.”
17:29📢Matt - “It can be good, I guess, for like, ‘Hey, we got 80% of our environment and we have this one legacy system that we just need to move.’”
18:22 Generative AI with Large Language Models — New Hands-on Course by DeepLearning.AI and AWS * Generative AI is a type of artificial intelligence that can create new content, such as text, images, and music. * Large language models (LLMs) are a type of generative AI that are trained on massive amounts of text data. * LLMs can be used to create a variety of different types of content, including: + Text: LLMs can be used to generate text for a variety of purposes, such as writing articles, creating marketing materials, and generating customer service responses. + Images: LLMs can be used to generate images, such as product photos, marketing images, and even art. + Music: LLMs can be used to generate music, such as songs, jingles, and even entire albums. * A new hands-on course by DeepLearning.AI and AWS will teach you how to use LLMs to create your own AI-generated content. * The course will cover topics such as: + How LLMs work + How to train an LLM + How to use an LLM to create content + How to evaluate the quality of AI-generated content * They also teach you how to use the new Amazon LLM API, but we haven’t used that so can’t really give an opinion on how it works. * Conversely, if you’re using Google Workspaces you just hit a button in Google Docs. So that’s always an option.
19:29📢 Ryan - “This is the type of course that, you know, would help to step in a career, right? As technology moves on, as the ecosystem is changing, if you don't keep up - like if we don't learn AI - we are gonna sort of not understand what goes on in a couple of years. It's just gonna be the nature of the business. It's gonna be everywhere and ubiquitous and have influence everywhere. And so I love these courses for getting into some of these things at the ground level.”
22:23 New AWS AppFabric Improves Application Observability for SaaS Applications * Many companies turn to SaaS applications to provide software to their employees. * As SaaS app usage expands, there is an increasing need for solutions that can identify and address potential security threats, in order to maintain uninterrupted business operations. * Integration of SaaS apps with existing security tools requires many teams to build, manage and maintain P2P integrations. * In response AWS is launching AWS AppFabric, a fully managed service that aggregates and normalizes security data across SaaS applications to improve observability and help reduce operational effort and cost with no integration work necessary. * When the SaaS apps are authorized and connected, AppFabric will ingest the data and normalize disparate security data such as user activity logs. * This is accomplished using Open Cybersecurity Schema Framework, an industry standard schema and open sourced project co-founded by AWS. * The data is then enriched with user identifiers such as corporate email addresses. + This reduces our Security incident response time because you gain full visibility to user information for each incident. You can ingest normalized and enriched data to your preferred security tools, which allows you to set common policies, standardize security alerts and easily manage user access across multiple applications. * Some apps supported at preview launch: + Asana, Jira, Dropbox, Google Workspaces, M365 and M365 Audit logs, Miro, Okta, Slack, Smartsheet, Webex, Zendesk and Zoom. * Available in N. Virginia, Ireland, Tokyo in additional AWS regions * AWS AppFabric has Generative AI Capabilities * AWS Appfabric will empower you to perform tasks across applications in a future release automatically. * Audit data can be integrated into security tools such as logz.io, netskope, netwitness, rapid7 and Splunk. * Additionally, they mention in the article that they’re going to be adding some generative AI capabilities in the future, which when (and if) it comes out will allow users to uatmoatically perform tasks across applications. * It’s really great to see Amazon getting in the Vapoware game - announcing software they don’t have and that may - or may not - materialize at all.
25:46📢Justin - “Yep, well, it's like everyone was into NFTs and crypto stuff and Web 3.0 and then that all failed and then it was meta and meta universe and all that. Now we're into the chat GPT will save the world and the economy world and so everyone's gotta have features in that space.”
28:58 Deploying state machines incrementally with versions and aliases in AWS Step Functions * AWS Step Functions now supports versions and aliases, which allow you to deploy state machines incrementally and manage multiple versions of your state machines. * With versions, you can create a new version of your state machine without overwriting the existing version. * With aliases, you can create an alias for a specific version of your state machine. * This allows you to test changes to your state machine without affecting production traffic. * You can also use aliases to point to different versions of your state machine for different environments, such as development, staging, and production.
29:32 📢 Ryan - “So my fellow podcast hosts were like, we can get rid of this one. This isn't it. And I'm like, no, this is super awesome, guys. And I realized how much of a nerd I sounded like.”
29:41 📢Justin- “I thought this already existed! I just thought this already existed because lambdas under the hood, which is kind of what I've always used step functions with, you know, already have that. So when we talked about it, I guess I was just surprised that it didn't exist.” GCP 14:26 Expanding 24/7 multilingual support: Now in Mandarin Chinese and Korean * Google decided they were taking an extended 4th of July holiday, so this is the only thing they had to report this week. * If you require multilingual support for GCP, you can find it at https://cloud.google.com/support.
Azure 33:41 Azure Virtual Network encryption - now in Public Preview! * With Virtual Network encryption, customers can enable encryption of traffic between Virtual Machines and Virtual Machine Scale Sets within the same virtual network and between regionally and globally peered virtual networks.
33:58 📢 Justin - “This is one of those features that you have for your application - that isn't owned by you - and you need to encrypt it for a security compliance reason. And now you have an option, so I appreciate that.”
34:07 📢 Ryan - “Or that one thing that's still running on like a 2012 server and you can't move it off because it's not supported on a more modern thing, but it comes up in the security audit every single time.”
34:34 📢 Matthew - “And in true Microsoft fashion, it’s in public preview, so you have a little while until it’s actually usable.”
35:37 📢 Ryan - “Yeah, I feel like the preview is really, especially in GCP and Azure is a way to sort of not be bound by SLA, right? it's more contractual than it is about the product and the functionality of the app.
36:26 📢 Ryan - “I mean, now in the Google space, though, we have to worry about something being in preview for years and then going general available and then get sold to Squarespace. So…” Oracle Continuing our Cloud Journey Series Talks 36:55 The Modernization Imperative: Shifting left is for suckers. Shift down instead * We’ve got a really interesting article for this week’s Cloud Journeys discussion! * Have you heard the term shift down? We hadn’t! + Essentially shifting down is the process of moving testing to earlier stages of the software development lifecycle. + Shifting left is the process of integrating testing into the software development process. * Both shifting down and shifting left can help to improve the quality of software. * Shifting down can help to identify and fix defects earlier, which can save time and money. * Shifting left can help to improve communication and collaboration between developers and testers. * Both shifting down and shifting left can help to improve the overall quality of software + *Allegedly * According to the article, shifting down is mostly just taking advantage of managed services, which is interesting - given the fact that Google doesn’t really have a lot of managed services… but we’ll just ignore that fact for the time being.
38:22📢 Justin - “ So there is an overall kind of thread that you'll see on Twitter occasionally, or other subreddits ( if you're still using that) that basically say, you know, shift left is failing us as an industry, and it's not getting the value we want, it's not increasing the productivity we want, and it's not really working. I don't agree with that, I think shift left is working if it's done right... I'm intrigued mostly in this article about the idea of shift down, which is something I advocate for all the time. Managed services are something I love, because it takes away toil from my teams, and allows us to focus on things that matter. And so I do encourage this capability of shifting down to your managed service to help ease your burden, but shifting left, I still think has value.”
42:05📢 Ryan- “One point of the article I don't agree with - I don't think anyone is expecting a single person to do all the things. But I think that the important part to remember - with a full stack engineer - and that is, don't define yourself in the boundaries. There's gonna be, just like any engineering team, if you're solely focused on the front end, there's people that are gonna understand frameworks and technologies. at different levels of experience. You're gonna have React experts and Rails experts and those things. So it's no different, but the differences between full-stack engineers is that you're not tossing anything over a wall. You may not know, but it's still on you to go figure it out. And so leverage your team, leverage your peers. I don't think we're expecting everyone to know these things and be experts in these things, but the idea that... You have to know every technology front to end is ridiculous.” After Show Closing And that is the week in the cloud! We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome to the newest episode of The Cloud Pod podcast - where the forecast is always cloudy! Today your hosts Justin, Jonathan, and Matt discuss all things cloud and AI, as well as some really interesting forays into quantum computing, changes to Google domains, Google accusing Microsoft of cloud monopoly shenanigans, and the fact that Azure wants all your industry secrets. Also, Finops and all the logs you could hope for. Are your secrets safe? Better tune in and find out! Titles we almost went with this week: * The Cloud Pod Adds Domains to the Killed by Google list * The Cloud Pod Whispers it’s Secrets to Azure OpenAI * The Cloud Pod Accuses the Cloud of Being a Monopoly * The Cloud Pod Does Not Pass Go and Does Not collect $200
A big thanks to this week’s sponsor: Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰News this Week:📰 01:27 Vault 1.14 brings ACME for PKI, AWS roles, and more improvements * HashiCorp recently announced the general availability of ACME for PKI. * Vault 1.14 focuses on Vault’s core secrets workflows as well as team workflows, integrations, and visibility. * This allows you to use Vault to manage your TLS certificates, using the ACME protocol. * This allows you to use Vault to manage your AWS IAM roles, making it easier to grant access to your applications. * Vault has also been optimized for better performance, especially for large deployments. * A number of bugs have been fixed, improving the stability and security of Vault. * The Vaults Secrets Operator connects Vault secrets directly into native Kubernetes secrets.
Overall, Vault 1.14 is a significant release with a number of new features and improvements. If you are using Vault, I recommend upgrading to the latest version. AWS 03:36 Announcing the AWS Amplify UI Builder Figma Plugin * Finally! A plugin that makes Amplify work natively with Figma! (Any UI builders out there in our audience? Bueller? Bueller?) * AWS Amplify now offers you the UI Builder Figma plugin * This new plugin makes it easier to empower your design and development teams to seamlessly collaborate within a Figma file. * With the Amplify UI kit, easily theme your components, upgrade to new UI Kit versions and generate and preview React code from your designs directly in Figma. * Go from design to code in seconds by generating clean React code inside Figma, and see a live preview of the code running before adding it to your application.
04:15📢 Justin- “I went in and set this up today because I had never actually used Figma although I heard lots about it. So I signed up for my free account. I signed in for the plugin for Amplify and then I remembered I don't know how to use Amplify. So it didn't go so well for me but I'm gonna keep tackling it because one thing I'm not very good at is front end development and anything that makes me better as a front end developer would be a plus.”
04:40📢Jonathan - “Figma works really nice; it’s great for prototyping.”
06:44 AWS Transfer Family announces structured JSON log format * AWS Transfer Family now delivers logs in a structured JSON format across all resources - including servers, connectors, and workflows and all protocols including SFTP, FTPS, FTP and AS2. * The new format allows you to easily parse and query your logs using Cloudwatch Log insights, which automatically discovers JSON formatted fields. * You’ll also benefit from improved monitoring with support for CloudWatch Contributor Insights, which requires a structured log format to track top users, total number of unique users, and their ongoing usage. * In addition to the new log format, you’re now able to combine log streams from multiple AWS Transfer Family servers into a single Cloudwatch log group of your choosing. This allows you to create consolidated log metrics and visualizations, which can be added to cloudwatch dashboards for tracking server usage and performance.
And that very exciting announcement is linked to this one…
07:14 AWS Transfer Family announces Drummond Group Applicability Statement 2 (AS2) Certification * If you know anything about the Drummond Group or AS2 you probably care about this. * AWS Transfer Family has earned the official Drummond Group AS2 cloud certification seal. Drummond * Group is an independent provider of testing and certification services for various industry standards and protocols.
07:52📢Matt- “I read this headline and I looked at it and I went, wow, I've set up TransferFamily at least two or three times, set up all the logs and never have actually looked at them to know that it was not in JSON format.”
08:31 AWS launches AWS AppSync abstraction * If you didn’t know what appSync was before, you can now know even less by abstracting it behind the AWS Serverless Application Model with the new AWS Serverless GraphQL API resource abstraction. Fun! * AWS AppSync is a managed service that makes it easier to build scalable APIs that connect applications to data with a GraphQL endpoint.
08:59 📢Matt- “So they added it to CloudFormation and to SAM?”
09:02 📢Justin- “Apparently that’s what they did. And wrote a blog post about it! So thanks, Amazon! We really appreciate that.”
09:20 AWS Announces Generative AI Innovation Center * Amazon, in the midst of many other existential threats (unionization, antitrust no biggie.) wants you to know that they REALLY care about Generative AI too. * To prove it we are going to commit 100 million to a new Generative AI Innovation program. * The new program will help customers successfully build and deploy generative AI solutions. This will help customers successfully envision, design and launch new generative AI products, services and processes. * Building on more than 25 years of deep investment in developing AI technologies for customers and is just one part of AWS’s overall generative AI strategy to bring this technology to customers and partners around the world. + “Amazon has more than 25 years of AI experience, and more than 100,000 customers have used AWS AI and ML services to address some of their biggest opportunities and challenges. Now, customers around the globe are hungry for guidance about how to get started quickly and securely with generative AI,” said Matt Garman, senior vice president of Sales, Marketing, and Global Services at AWS. “The Generative AI Innovation Center is part of our goal to help every organization leverage AI by providing flexible and cost-effective generative AI services for the enterprise, alongside our team of generative AI experts to take advantage of all this new technology has to offer. Together with our global community of partners, we’re working with business leaders across every industry to help them maximize the impact of generative AI in their organizations, creating value for their customers, employees, and bottom line.”
10:40 📢Justin - “…they had a lot of AI and ML features, but they didn't have anything as revolutionary as chat GPT. So generative AI is where all the hotness is right now, and they are definitely lagging behind just a little bit.” GCP 14:26 Google Domains is shutting down; assets sold and being migrated to Squarespace * Google domains is winding down and selling the business and assets to Squarespace. * Squarespace entered into a definitive asset purchase agreement with Google, whereby Squarespace will acquire the assets associated with the Google Domains Business. * This includes approximately 10 million domains hosted on Google Domains spread across millions of customers. * Google launched the registrar business in 2014 as a bit proponent of HTTPS and Top-Level domains. The service just exited beta in 2022. * It's better than shutting down the service without a guided migration path...but holy crap! * Can’t wait till they sell the GCP business to a third party….
14:59📢 Justin- “I mean, if you can’t make money on 10 million domains I don’t know what you’re doing wrong.”
16:10📢 Jonathan- “Something as fundamental as domain registration for cloud users seems really weird to me that they would sell that and basically resell through a partner.”
19:58 Google Formally Accuses Microsoft of Trapping People in the Cloud * In peak American style, Google has employed the “if you can’t beat ‘em, sue ‘em” mentality when it comes to Microsoft's cloud business. * Google is accusing Microsoft of anti-competitive practices * Google after being beat up by the FTC, and is now complaining that Microsoft uses software licensing restrictions to keep customers locked into its cloud computing services. * The letter specifically takes issue with MS using its Windows Server and Office products to keep clients on Azure, and that Microsoft’s control is a national security risk. * Google has raised similar concerns to EU regulators. * Essentially, MS charges third party cloud providers extra to run its software, a cost that customers do not bear if they run on the same software on MS Azure’s cloud platform. * This has led to an FTP RFC on how the business practices for cloud computing providers affect competition and data security. And it has not been the only submission to raise concerns about Cloud Platform Competition.
20:57📢 Jonathan- “It’s kind of a weird conversation, because the free market's the free market. The business should be free to set the prices they charge for any product, for any customer. I mean, if you think about enterprise discount agreements, anything like that is a mechanism to provide different pricing to different customers based on usage of either one resource or combinations of resources. So on one hand, I'm like ‘they should be able to charge whatever they like to whoever they like and the market will figure things out’. On the other hand, it is such a monopolistic position to be in.”
23:20 Trace Exemplars now available in Managed Services for Prometheus * Cross Signal Correlation where metrics, logs and traces work together in concert to provide a full view of your systems health -- is often cited as the “holy grail” of observability. * However, given the fundamental differences in their data models, these signals usually live in separate, isolated backends. Pivoting between signal types can be laborious, with no natural pointers or links between your different observability systems. * Trace Exemplars provide cross-signals correlation between your metrics and your traces, allowing you to identify and zoom in on individual users who experience abnormal application performance. * Storing trace information with metric data lets you quickly identify the traces associated with a sudden change in metric values; you don’t have to manually cross-reference trace information and metric data by using timestamps to identify what had happened in an application when the metric data was recorded. * Google is making this easier with the support for Prometheus Exemplars in Managed Service for Prometheus.
24:36📢 Matt- “As things become more serverless, everything kind of becomes in its own little areas, tracking everything and tracking requests and all the different pieces that go through your system, has been a problem. And that's why AWS came out with X-ray, and APIMs andall these other things exist. So it's just another way to do a lot of the same things. It's nice that it's integrated into Prometheus. If you're running your own stacks of Prometheus and Grafana, it'll be nice to be able to do it all in one place versus having to use different tools for different aspects of your monitoring solution.” Azure 26:01 Microsoft Azure OpenAI lets enterprises feed corporate secrets to ChatGPT
Microsoft wants to make it easier for enterprises to feed their proprietary data and queries into Open AI GTP-4 or ChatGPT within Azure and see the results. What could go wrong? * Available in preview with Azure OpenAI service, it eliminates the need for training or fine tuning your own generative AI models. * A user fires off a query to Azure, MS cloud figures out what internal corporate data is needed, and the data is combined with the public data set and returned to the user. * The models are managed by Microsoft in its cloud, preventing Open AI from having direct access to the customer data, queries and output. * It is alleged that this new skill is “useful.” Insert side eye gif of your choice here. * Your prompts (inputs) and completions (outputs), your embeddings, and your training data:
are NOT available to other customers.
are NOT available to OpenAI.
are NOT used to improve OpenAI models.
are NOT used to improve any Microsoft or 3rd party products or services.
27:31 📢 Jonathan - “We talked last week about Google telling their own employees not to use generative AI, especially barred for coding. I wonder if Microsoft will do the same thing.”
27:51 📢 Matt - “Microsoft doesn’t use any chat GPT - any anything along those lines. They disable all the code pilot plugins on all their integrations.”
28:34 📢 Justin - “ I can see the advantage of having an AI LLM model in place to help you do things. But data privacy is the biggest issue in all this. And I kind of agree with Matt, if it's secret, don't put it anywhere that you don't trust it or don't control the endpoints. And maybe cloud isn't right for you for that particular use case.”
Side note, any listeners who want to get Jonathan a birthday gift, his list is at 29:18
30:00 Accelerating Scientific Discovery with Azure Quantum * Azure is announcing 3 new innovations to Quantum computing + Azure Quantum Elements - Azure Quantum elements accelerates scientific discovery by integrating the latest breakthroughs in high performance computing (HPC), AI and Quantum computing. - Reduce time to impact and costs by accelerating the R&D pipeline - Dramatically increase the search space for new materials, with the potential to scale from thousands of candidates to tens of millions - Speed up certain chemistry simulations 500kx - Get ready for scaled quantum computing by addressing quantum chemistry problems with AI and HPC, while experimenting with existing quantum hardware + Copilot in Azure Quantum - Scientists can accomplish complex tasks on top of the fabric of cloud supercomputing, advanced AI and quantum, all integrated with the tools they use today. - It can generate the underlying calculations and simulations, query and visualize data and help get guided answers to complicated concepts. - Helllllllllo Skynet! + MS Roadmap to Quantum Supercomputer - MS has achieved the first milestone towards a quantum supercomputer. They can now create and control majorana quasiparticles.We don't know what these are, but they sound really cool! With this achievement, they are on the way to engineering a new hardware-protected qubit.
30:56 📢 Jonathan - “I hadn't really considered that we could use the generative AI tools to actually write code for quantum computers actually. That's very useful to know because it's such a weird and limited language… but getting from a business idea, to code, to actually something that actually runs on quantum computers is a massive step. And actually being able to extract that and have Copilot write that code for you is super interesting. ”
31:39 📢 Matt - “I would have gone with terrifying, but interesting also works.”
31:53 Public Preview: Network Observability add-on on AKS * And lastly this week from Azure… * Azure has a new network observability add-on for AKS that will scrape useful metrics from K8 workloads and emit actionable networking observability data into industry standard prometheus format, which can be visualized with Grafana. * Key Customer Benefits to YOU (the customer) + Get access to node-level network metrics like packet drops, connection stats and more + Support for all Azure CNI’s + Support fall AKS node types Linux and Windows + Easy deployment using native Azure Tools + Seamless integration with the Azure managed Prometheus and Azure-managed grafana offerings.
And with that, we’re all burned out on logs. Networking and otherwise. Oracle Continuing our Cloud Journey Series Talks 33:40 How to build a FinOps roadmap | Google Cloud Blog * Justin is going to be at the FinOpsX Conference later this week, but in the meantime…How do you create a roadmap to FinOps? How do you get Cloud costs under control? * Define your goals. What are you trying to achieve with FinOps? * Assess your current state. What are your current costs? Where are you wasting money? * Develop a plan. What changes do you need to make to reach your goals? * Implement the plan. This includes setting up budgets, monitoring costs, and making changes as needed. * Measure your progress. Are you on track to reach your goals? If not, make adjustments to your plan. * Continuously improve. FinOps is an ongoing process, so be sure to review your plan regularly and make changes as needed.
30:31📢 Jonathan - “I like thinking about not just where we're wasting money, but why we're wasting money and how we're wasting money and what is it that got to that place where the finance is knocking your door… So I think one of the things that I'd focus on, would be processes and tooling and figuring out, well, why do we end up with all these objects in an object store that we don't need or want anymore? Or why do we have all these instances stood up and that no one's responsible for?”
38:15📢 Justin - “In the Google model and their steps, they talk about first defining your stakeholders, which is your CCOE, which we talked about a lot, if you have one. Engineering team is a stakeholder, your platform team is a stakeholder, the business and of course your accountants and finance team, who are the people yelling at you probably that you need a finance practice because the costs are out of control. But that's really kind of step one.” Closing And that is the week in the cloud! We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome to the newest episode of The Cloud Pod podcast - where the forecast is always cloudy! Today your hosts are Jonathan and Matt as we discuss all things cloud and AI, including Temporary Elevated Access Management (or TEAM, since we REALLY like acronyms today) FTP servers, SQL servers and all the other servers, as well as pipelines, whether or not the government should regulate AI (spoiler alert: the AI companies don’t think so) and some updates to security at Amazon and Google. Titles we almost went with this week: * The Cloud Pod’s FTP server now with post-quantum keys support * The CloudPod can now Team into your account, but only temporarily * The CloudPod dusts off their old floppy drive * The CloudPod dusts off their old SQL server disks * The CloudPod is feeling temporarily elevated to do a podcast * The CloudPod promise that AI will not take over the world * The CloudPod duals with keys * The CloudPod is feeling temporarily elevated.
A big thanks to this week’s sponsor: Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰News this Week:📰 No general news this week! Probably because no one wanted to talk to us. AWS 00:49 Amazon EC2 Instance Connect supports SSH and RDP connectivity without public IP address * You can now connect via SSH and RDP to EC2 instances without using public IP addresses. With EIC endpoints, customers have remote connectivity to their instances in private subnets, eliminating the need to use public IPv4 addresses for connectivity. * Previously you would have needed to create bastion hosts to tunnel SSH/RDP connections to instances with private IP addresses, but that created its own set of problems because bastion hosts would have to be patched, managed and audited as well as incur additional costs. * EIC endpoint combines AWS IAM-based access controls to restrict access to trusted principles with network-based controls such as security group rules. * It provides an audit of all connections via AWS cloud trail, helping customers improve their security posture.
01:31📢 Matt- “It’s nice to see Amazon still coming up with more solutions to not have things be public; and really try to get their customers to not use all the older-school technology.”
03:02 RDS Custom for SQL Server Lets you Bring Your Own Media * RDS Custom for SQL Server now allows customers to use their own SQL server installation media when creating an instance. By using BYOM, customers may leverage their existing SQL server licenses with Amazon RDS for SQL Server. Amazon RDS custom is a managed database service that allows customization of the underlying operating system and database environment. Managed features include Multi-AZ, point in time recovery, and more. * Previously when using RDS custom for SQL Server, customers used a license that included hourly pay as you go model. With BYOM, customers can provide their own SQL server licenses on Amazon RDS Custom for SQL Server. This allows customers who have already purchased SQL server licenses to save on costs while offloading the undifferentiated heavy lifting of database management to RDS custom.
04:28📢Jonathan- “I think the advantage for me is that I've often heard, well, we can't use RDS because it doesn't support this, doesn't support this, doesn't support this. Whereas now you can deploy your own instances with your own controls and just use RDS as a management layer. Kind of cool.”
06:22 Temporary Elevated Access Management with IAM Identity Center * AWS is providing you a solution for Temporary Elevated Access Management (TEAM) that integrates with IAM Identity Center (formerly AWS SSO) and allows you to manage temporary elevated access to your multi-account AWS environment. You can download the TEAM solution from AWS samples, deploy it and customize it to your needs. * The team solution has the following features: + Workflow and approval + Invoke access using IAM identity center + View request details and session activity + Ability to use managed identities and group memberships + A rich authorization mode
A Note from the team with some Reinforce quick hits for you:
** If you're using AWS Transfer for your SFTP solution, and quantum computing breaking your SFTP and FTPs ciphers keeps you up at night, AWS now supports post-quantum keys for AWS transfer. I mean personally if you're leveraging SFTP… in 2023 and post quantum security is your priority i’m unsure you're using the right technology.
Post-quantum hybrid SFTP file transfers using AWS Transfer Family
Your SOC team rejoices as it allows you to take automated actions to update your findings. These rules make it easy to avoid alert fatigue and more quickly close out alerts and issues.**
07:02 📢Matt- “This whole solution looks great. I'll be more curious in about two years from now when they add it into Amazon SSO - or the rebranded Amazon IAM Identity Center - to actually see it all nicely integrated in and not, ‘Hey, there's a web portal over here that you run with Amplify and there's probably Step Functions and CloudWatch.’ It's a really good solution for build your own. And if you have a public cloud team that can help manage this, great. But if you're trying to do this for a one or two AWS account, probably not worth the overhead and complexity of it. But it's nice to see that they’re, again, providing solutions for people.”
08:15 📢Jonathan - “I guess you could integrate it with things like change handlers so you can only get admin access during pre-approved changes or to pre-approved instances and that kind of thing. I'm sure this is a problem that a lot of people have, like what do you do when you don't want admin all the time, but you do need admin rights when you need it? And I've seen people build all kinds of tooling around this, you know, well, we keep passwords in volt, but if we get the password out to use temporarily, then we have to go back and change the password later. It's all a lot of moving parts. And so having an off the shelf solution like this is pretty neat.”
09:34 re:Inforce 2023 Quick Hits * Our recording schedule has been a bit off so we didn’t cover it at the time, but re:Inforce has come and gone - and we have the Cliffsnotes version just for you. * Post-quantum hybrid SFTP file transfers using AWS Transfer Family
Quick note from Justin If you're using AWS Transfer for your SFTP solution, and quantum computing breaking your SFTP and FTPs ciphers keeps you up at night, AWS now supports post-quantum keys for AWS transfer. I mean personally if you're leveraging SFTP… in 2023 and post quantum security is your priority i’m unsure you're using the right technology. Your SOC team rejoices as it allows you to take automated actions to update your findings. These rules make it easy to avoid alert fatigue and more quickly close out alerts and issues. * AWS Security Hub launches a new capability for automating actions to update findings
For those who were excited about WAF Fraud Control for Account Takeover Prevent (ATP, they are adding Account Creation Fraud Protection to protect your applications sign up pages against fake account creation by detecting and blocking fake requests. * Prevent account creation fraud with AWS WAF Fraud Control – Account Creation Fraud Prevention + Screw up timestamp as requested: 11:24 + Let’s blame Justin
12:14 Launching - Amazon S3 Dual-Layer Server-Side Encryption with Keys Stored in AWS Key Management Service (DSSE-KMS) * Additional timestamp errors for your listening pleasure! This is what happens when AI DOESN’T do the work for you I guess. Moving on. (Language Warning!) * For those who need to meet NSA CNSSP 15 for FIPS Compliance and Data at Rest capability Package 5.0 guidance for two layers of CNSA encryption. The new S3 Dual Layer Server Side Encryption with Keys stored in KMS (DSSE-KMS) is available for objects when uploaded to an S3 bucket. S3 is the only cloud object storage service that allows customers to apply two layers of encryption at the object level and control data keys used for both layers. DSSE-KMS makes it easier for highly regulated customers to fulfill rigorous security standards, such as the DOD. * DSSE-KMS applies two layers of encryption to objects in Amazon S3, which can help protect sensitive data against the low probability of a vulnerability in a single layer of cryptographic implementation. * DSSE-KMS is designed to meet National Security Agency CNSSP 15 for FIPS compliance and Data-at-Rest Capability Package (DAR CP) Version 5.0 guidance for two layers of CNSA encryption. * Holy acronyms, Batman!
14:30 📢Matt - “I think for the average consumer, you're probably not gonna need or want this. I'd be curious of what the overhead is or if it's something that Amazon's just eating the overhead on the backend.”
15:49 A New Set of APIs for Amazon SQS Dead-Letter Queue Redrive * AWS is launching a new API for SQS. * These new API’s allow you to manage dead-letter queue (DLQ) redrive operations programmatically. * You can use the SDK or the CLI to programmatically move messages from the DLQ to their original queue, or to a custom queue destination to attempt to process them again.
16:13📢Matt - “This is kind of nice. I mean, I always feel like I've had a dead letter queue and then I just send a notification. It's all I've ever used it for. But, if you can actually now move that message to somewhere useful, do either retry or if you're doing failure driven development (which I would recommend against) you could in theory just cascade it down, but it's nice that they are actually enabling this with APIs.”
16:40📢Jonathan - “Yeah, I've definitely had a use case for this before when we used SQS for hundreds of thousands of log events. And when Elasticsearch was down regularly, things would eventually time out of the queue after three days of trying to rebuild the Elasticsearch cluster. So moving those things was a Python script back to the thing, as I said, ended up in the back of the queue again. So. Definitely nice.”
18:06 Simplify How You Manage Authorization in Your Applications with Amazon Verified Permissions * Now generally available! * Amazon Verified Permissions (AVP) is a new service that makes it easier to manage authorization in your applications. * AVP uses machine learning to verify that users have the permissions they need to access your resources. * AVP can be used with any AWS service that supports IAM policies. * AVP is easy to set up and use. * AVP can help you reduce the risk of unauthorized access to your resources. * AVP can help you improve compliance with security and regulatory requirements. * AVP is available in all AWS regions. * AVP is a free service. * For more information, see the AWS documentation.
Note from Jonathan - It say easy to deploy not easy to use. Listener beware. GCP 20:31 Announcing Dataform in General Availability: develop, version control, and deploy SQL pipelines in BigQuery * + Google is announcing the general availability of Dataform, which lets data teams develop, version control, and deploy SQL pipelines in BigQuery. + Dataform helps data engineers and data analysts of all skill levels build production-grade SQL pipelines in BigQuery while following software engineering best practices such as version control with Git, CI/CD, and code lifecycle management. + Dataform offers a single unified UI and API with which to build, version control and operationalize scalable SQL pipelines. + In this single environment, data practitioners can develop new tables faster, ensure data quality and operationalize their pipelines with minimal effort, making data more accessible across their organization. * “Before we started using Dataform, we used an in-house system to transform our data which was struggling to scale to meet our needs,” says Neil Schwalb, Data Engineering Manager at Intuit Mailchimp. “After adopting Dataform and more recently Dataform in Google Cloud we've been able to speed up and scale our data transformation layer to 300+ tables across large volumes of data. The Google Cloud-Dataform integration has also sped up our development workflow by enabling faster testing, clearer logging, and broader accessibility.”
22:02📢 Matt- “Hey, Jonathan. Help explain to me what they're doing here, because all I see is that we're building pipelines from SQL to BigQuery, and they put a UI around it.”
22:14📢 Jonathan- “I think the big thing is data engineers spend a lot of time in a console clicking through things, clicking through pipelines, a lot of data quality is managed by people. A lot of pipelines are built by people rather than as code and so I guess by forcing it to be defined as code and versioned as code… potentially you could build a new pipeline, compare the output of that with the output of a previous pipeline. If it looks good then promote it to the next environment.”
23:05 Introducing Google’s Secure AI Framework * Google's Secure AI Framework is a set of principles and practices that guide the development and deployment of secure AI systems. The framework is based on three pillars: + Responsible AI development: This pillar includes principles such as transparency, accountability, and fairness. + Robust AI systems: This pillar includes principles such as accuracy, reliability, and safety. + Secure AI systems: This pillar includes principles such as confidentiality, integrity, and availability. * The framework is designed to help Google build AI systems that are safe, reliable, and trustworthy. It is also intended to help Google comply with applicable laws and regulations. * The key data points from the article are: + Google's Secure AI Framework is a set of principles and practices that guide the development and deployment of secure AI systems. + The framework is based on three pillars: responsible AI development, robust AI systems, and secure AI systems. + The framework is designed to help Google build AI systems that are safe, reliable, and trustworthy. + It is also intended to help Google comply with applicable laws and regulations. * The article also includes a number of case studies that illustrate how Google has applied the framework to real-world projects.
24:13📢 Matt- “I feel like all the cloud providers and all the AI providers are just saying, hey, this is what we're gonna do. And, you know, I really would like to see what are the consequences if they break their own framework. You know, like what are they going to do? Because cool, they can say that they're gonna be responsible and robust and secure and ensure confidentiality and all these things, but it's very easy to put out a press release saying that. It's very hard to prove that you're doing that.”
26:35 Google Warns its Employees: Do Not Use Code Generated by Bard * Google has warned its employees not to disclose confidential information to BARD, this isn’t surprising as many other large firms have similarly voiced these concerns. * However, they also said that they should not use the code generated by Bard, which seems to counter the message that developers can become more productive using Bard. * Google told Reuters its internal ban was introduced because bard can output undesired code suggestions. Which could lead to buggy or complex, bloated software that will cost developers more time to fix than if they don’t use AI to code at all. * The article also mentions that Google’s DeepMind AI lab does not want the US government to set up an agency to focus on regulating AI. (WEIRD) * Google argues the role should be split across different departments. * They believe NIST could oversee and guide policies and issues.
27:40📢 Matt- “NIST is a framework though; It's not an regulating agency. It's not like NIST says you have to do this. It's not a, it's a standards agency.”
28:01📢 Jonathan- “Yeah, that's why they want nest involved, presumably, so that it's very unregulated.” Azure 18:31 Announcing Microsoft’s AI Customer Commitments * Microsoft is committing several things to its customers around AI: + To be transparent about how AI is used in Microsoft products and services. + To provide customers with control over how their data is used for AI. + To build AI systems that are fair, unbiased, and accountable. + To invest in research and development to ensure that AI is used for good. + To collaborate with governments and regulators to develop responsible AI policies. + To educate and empower people to use AI safely and responsibly. * These commitments are important because they show that Microsoft is committed to using AI in a way that benefits customers and society as a whole.
32:18 📢 Matt- “Repeat everything we just talked about for Google.”
Welcome to the newest episode of The Cloud Pod podcast - where the forecast is always cloudy! Ryan, Jonathan, and Matt are your hosts this week as we discuss all things cloud, including updates to Terraform, pricing updates in GCP SCC, AWS Blueprint, DMS Serverless, and Snowball - as well as all the discussion on Microsoft quantum safe computing and ethical AI you could possibly want! A big thanks to this week’s sponsor: Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. 📰News this Week:📰 00:57 Terraform AWS provider updates to V 5.0 * Announced this week from Hashicorp, Terraform AWS provider updates to version 5.0 * The updates include support that they say will help them “focus on improving the user experience.” * Support & improvements for general tags was added, which can now be set at the provider level - applying them across all resources. * Thanks to new features in Terraform plugin SDK and the Terraform plugin framework issues related to inconsistent final plans, identical tags, and perpetual diffs are now solved. * More information on the default tags can be found on the changelog.
04:11📢 Jonathan - “It’s kind of cool - it’s a neat hack as well as a way of AWS providing a really useful feature without having to do any work on the cloud platform itself. Just implement the tool that does the deploying rather than having a service which could do it for you.” AWS 05:28 NEW AWS DMS Serverless * Recognizing that many organizations were migrating to cloud platforms due to huge amounts of data, AWS has launched their cloud Database Migration Service back in 2016. * To make the migration even more seamless, AWS has now announced DMS Serverless. * AWS DMS Serverless will automatically set up, scale, and manage migration resources - all to make your migrations easier and (hopefully) more cost effective. * Supports a variety of databases and analytics services, including Amazon Aurora, RDS, S3, Redshift, and DynamoDB among others.
06:36📢 Matt- “I was thinking about it at the end of the migration - we finally got it all replicated; now we’re gonna wait a month before we actually cut over. We need this very small change rate, vs. lets go replicate everything at the very beginning. It just kind of keeps it in sync. So in theory, it goes up and down, and you’re not provisioning based on peak capacity.”
07:26 New Snowball Edge Storage Optimized Devices with MORE storage and bandwidth * AWS Snow family Devices help you move and process data in a cost effective way. * These new enhanced Snowball Edge Storage Optimized devices are designed for huge amounts of data; petabyte-scale data migration projects. * They include 210 terabytes of NVMe storage and the ability to transfer up to 1.5 gigabytes of data per second. * To make these migrations even more efficient, AWS has added a Large Data Migration Program, which will assist sites in making sure they are prepared for the rapid data transfers, as well as setting up a proof of concept migration. * The idea is to allow customers to set up and deploy migrations to and from Amazon easily.
07:52📢Matt - “I’m just wondering when Snowball Edge Devices are gonna catch up to the snow machine - you know, like the trucks. 100 TB - we gotta be getting close.”
08:03 📢Ryan -”Not until you can drive it. I don’t care how much storage it holds. But I want to be able to drive it around - like anything I order from Amazon.”
09:25 Amazon Security Lake - Now Generally Available * AWS recently announced the general availability of Security Lake. * Security Lake will automatically centralize data from AWS environments, SaaS providers, on-premise environments, and clou sources into a purpose-build data lake - all stored in your account. * AWS says the security lake will make it easier to analyze security data, as well as enabling users to get a more comprehensive view of their security across an entire organization. * Security Lake will also help organizations meet security requirements.
10:25 📢Ryan - “These are great things; a lot of time this data is being collected anyway, and it’s being stored across many different devices and S3 buckets and it’s all over the place; at least this will put it all in one place where hopefully it's a little more useable. But also, the main benefit is that it’s going to be easy to visualize the cost of this. Because a lot of security logging isn’t really utilized, but it’s stored - sometimes for a very long period of time - without actually providing any value. Sometimes you can’t even search it. You can’t even hydrate it into something until you have to for a security response. So I do like this tool - as much as I want to make fun of it.”
11:54 Announcing AWS Blueprint for Ransomware Defense * AWS announced AWS Blueprint for Ransomware Defense - available for both public and enterprise organizations, and can be customized to meet specific requirements. * Blueprint is a comprehensive framework that helps orgs protect themselves against ransomware attacks - an ongoing and serious issue if you read the news, well, EVER. * It includes best practices for security, compliance, and disaster recovery. * Based on AWS Security services (obviously…) * If you really need help falling asleep, there’s 29 pages of prescriptive guidance and lists of CIS controls. Because who doesn’t love lists of CIS controls? We sure do!
Does it interest anyone else that AWS is putting out all these announcements before Re:inforce coming up in June? It will be interesting to see what they release…
13:57📢Jonathan- “It’s nice to have a robust plan that your vendor also uses, because as I’m sure there are more and more high profile ransomware cases in the news vendor management questions are going to start including do you have a plan to deal with ransomware - and what is it? And the easy ‘well, this is what we use and Amazon uses the same thing’ is probably a huge time saver.” GCP 15:27 Security Command Center (SCC) Premium Pricing Gets a 25% Reduction * Google Cloud has introduced a 25% reduction in Security Command Center (SCC) Premium pricing for project-level activation. * SCC is a comprehensive risk management and security platform offered by GCP.
15:56 📢 Ryan- “So I’m probably biased because of my personal experience with SCC, but it’s priced VERY very high, and it is very hard to roll it out at scale with it’s pricing model. So this, I feel, is a necessary move to make it competitive.” Azure 18:31 Building a Quantum - Safe Future * Quantum computers are still in the early stages of development, but they DO have the potential to break current encryption standards. (Jonathan is going to keep adding this to his prediction list until it comes true.) * Microsoft is now working on developing quantum safe cryptography that would potentially be resistant to quantum computers. * These kinds of updates and developments will be essential in protecting sensitive data. * Microsoft is working with both private and public partners to develop new standards and get it deployed.
Quick reminder - Microsoft is also building the quantum computers that are going to crack the current encryption, so we have to make sure we have encryption that can beat the encryption beating machines. A “finger in both pies” situation. So that’s fun
20:20 📢 Matt- “But can you build a safety standard against something that doesn’t exist yet?”
20:25 📢 Ryan - “That’s the easiest safety standard to build, right?!”
20:40 📢 Jonathan - “It is a bit of a self-fulfilling prophecy about the whole thing though.”
21:58 Reflections on AI and the Future of Human Flourishing * No, this isn’t the newest concept ride over at EPCOT. It’s the latest blog from Microsoft! A blog - about AI - from Microsoft? How new and interesting! * Did you know that AI has the potential to be a powerful tool for good? We had no idea! * But of course, “it is important to use AI responsibly” and be developed in a way that benefits all of humanity - not just a select few. * The blog post talks about the need to be prepared for the negative consequences of AI, such as job displacement, and how Microsoft needs to have “a clear understanding” of the ethical implications of AI. * It also discusses the need to include diverse voices and research when it comes to developing AI in the future.
25:33 📢 Ryan - “Localization for AI is gonna be a thing, right? We’re just not there yet. It is a very difficult challenge, labeling and machine learning - that’s been around for awhile and I still don’t know a really good solution, other than what people do - which is mechanical trick it out; pay a lot of people a little money to go and just do a subset. I imagine with localization, and we”ll see how good that turns out.”
29:55 📢 Jonathan- “I will say something for Open AI though; in themselves, I like that they’re not publicly owned. There aren't shareholders to please. They’re not being pushed by investors to rush things out or monetize in a particular way.”
34:05 Microsoft Announced the Azure AI Content Safety Public Preview * Now available in public preview, this new suite of AI tools is available to help companies protect their users from harmful content. * Content Safety uses advanced AI to detect (and remove) offensive or inappropriate content in text and in images. * The tools are currently available to all Azure users, and Microsoft is partnering to make them more widely available.
34:36 📢 Ryan - “If you were wondering why Microsoft felt the need to publish a blog post with a deep thought experiment about being responsible with AI and Microsoft’s responsibility, now you know! They also now offer a service in public preview where you can give them money!”
35:08 Matt’s article from 2017 Non-Profit Hackathon “We Saw. We Hacked. We Conquered”
38:17 Azure Load Balancer per VM limit has been removed * All customers using the standard load balancer now have UNLIMITED power. Wait, no. Unlimited load balancers. Yeah, that’s it. You can now have as many load balancers per VM as you’d like, which is a pretty big increase from TWO (one public and one internal) - which used to be the limit.
38:56 📢 Matt- “I just want to know what caused it. Like, what was the technical limitation that was in place that caused this limit to have to occur?”
Either way - their announcement is now officially shorter than our notes about said announcement. Oracle Continuing our Cloud Journey Series Talks 40:53 Cloud Native MultiCloud * I know it feels like we already talk about this all the time. + 214 episodes, so the question is do we LIKE multicloud? + Should it be your first choice? Probably not. + Are there times where multicloud makes sense? Maybe. A really compelling service or you inherit someone else’s cloud - but otherwise there doesn’t really seem to be a good enough reason. Especially given the potential cost. * Is it even POSSIBLE to do multi cloud correctly? It’s hard enough to do ONE cloud right. + The best course of action is probably to choose the one that best fits your organization, and then just deal with its limitations - rather than trying to manage a multi cloud environment. * Our opinion: there’s almost no reason anyone should voluntarily choose a multicloud situation. * There’s an argument to be made that you actually lose time, money, and efficiency by losing out on some of the pros of your first environment - you lose the benefits of using the cloud. * One of the important things to remember is that the cloud - by default - is NOT cheaper than on prem. + Using the included services, and the correct tools, can definitely increase the value for money * Issue where multi cloud might make sense: data center location (read: latency, downtimes, etc) but even then it really only applies to the “last mile” talking to devices or customers. + Data sovereignty is going to be a key issue for regions and, in turn, multi cloud * Issue where multi cloud is not ideal - vendor lock. Do you want to be locked into a relationship with one vendor or three? + Does cost really influence moving from one cloud provider to another? Or is it just too complicated? If you’ve seen an entity actually completely move clouds over cost please let us know! + Pricing is definitely prohibitive for multicloud, including compliance, the number of people required, etc.
Welcome to the newest episode of The Cloud Pod podcast! Justin, Ryan, Jonathan, Matthew are your hosts this week as we discuss all things cloud and AI, as well as Amazon Detective, SageMaker, AWS Documentation, and Google Workstation. Titles we almost went with (and there’s a lot this week)📃The Cloud Pod becomes the cloud docs🎩The Cloud Pod loves inspector gadget📄The Cloud Pod documents the documentation🌍The Cloud Pod bangs its shin, since geospatial abilities are lacking🌎The Cloud Pod bangs its shin, since we lack geospatial abilities🌏The Cloud Pod bangs its shin, if only we had geospatial abilities🧞Unlike the Cloud Pod, Alibaba Cloud exits the stage🧨Retiring AWS Documents on Github… or how we laid off too many people in ourdocument team and can’t support this albatross anymore🏗️Microsoft Builds AI tools at its Build Conference and Wants you to Build MoreA big thanks to this week’s sponsor:Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.📰News this Week:📰01:29 Alibaba to Exit Cloud Business After Beijing Undercuts Potential Alibaba is apparently planning to spin out its $12 Billion dollar cloud business. * It’s unclear if Alibaba is bowing to market pressures or political pressures; in 2020 Beijing became increasingly suspicious of cloud services operated by private firms, and started cracking down on internet services. * Alibaba Cloud drew regulatory ire in 2021 for discovering and sharing a flaw before informing authorities (there goes their citizenship score), and was investigated for its role in China’s largest cybersecurity leak. * Analysts value it at 30B, and was a once thriving operation that harbored the potential to AWS level of market control in China. * “This full spinoff plan involving AliCloud is both bold and puzzling, “Nomura Holdings Inc analysts Jialong Shi and Thomas Shen wrote in a note. "Their current valuation for the unit stands at about $31 billion. AliCloud is BABA’s organic business and is still deemed as one of the long-term drivers for the group even though its growth temporarily slowed down in recent quarters due to macro headwinds. That is why we find it puzzling that BABA has decided to fully spin off this business instead of retaining a minority stake at least*.
04:30📢 Justin - “We're basically entering a very Cold War period between the US and Chinese. And so that's gonna be interesting to see how that continues to shake out. I saw some articles this week as well, like in the information about VC firms trying to exit their investments in China and just realizing that it's not gonna be the growth engine they expect it to be. I mean, we talked about here on the show even some of the supply chain issues with China, with the cloud providers and how it's impacted them. And now, I just saw this week, Apple just announced that they were making chips with Broadcom on US soil for some things. So, there's definitely an undercurrent in our politics about China in general.”05:46📢 Matt - “On the flip side, I'm kind of curious to see how taking this business unit out of the general Alibaba is going to work, especially with everyone starting to yell that the big tech companies are growing too large and everything. If this could be an interesting test balloon to see how AWS could spin out of Amazon, GCP could spin out of Google, Azure out of Microsoft, it could be an interesting playbook to see how they start to divide up the business units.06:15📢 Justin - “I really don't see anyone doing that unless they're forced to by the government.”AWS06:29 Amazon SageMaker Geospatial Capabilities Now Generally Available with Security Updates and More Use Case Samples* Amazon Sagemaker Geospatial capabilities were originally previewed at AWS re:Invent 2022. They are new Generally available with some security updates and additional sample use cases. * This service makes it easy to build, train, and deploy machine learning models using Geospatial data. * As part of the general availability announcement, they are integrating this capability with KMS and VPC networks. * AWS is touting several real world use cases for this technology (check out the article linked for more in depth discussion of these topics.) + Maximize Harvest Yield for Food Security + Damage Assessment + Climate Change Monitoring + Predict Retail Demands + Support Sustainable Urban Development * Are you excited to try out this new feature? Are you in US West 2? Great! Oh, you’re not? Sad tears - it isn’t available for you yet. * Time for the $$$ - the free tier is available for 30 days and includes 10 free ml geospatial compute hours, up to 10gb of free storage and no $150 monthly user fee - for one user. Everything after that will cost you money. Potentially lots of it. So be careful.
7:15📢 Jonathan - “My first thought was, well how can those poor farmers afford technology like this? And I'm thinking, ahhhh no, we're talking about like Monsantos.”We’ll be interested to see how AWS uses this tech over time, potentially for PR purposes.10:07 New – Simplify the Investigation of AWS Security Findings with Amazon Detective* Detective should have been called inspector, but they already called something else Inspector, so that’s a lost opportunity. Should have asked us first. * The detective now offers investigation support for findings in AWS Security Hub in addition to those things detected by Guard Duty. * It’s now easier than ever before to determine the cause and impact of findings coming from new sources such as AWS Identity and Access Management. * Justin got an abuse report just this morning, and it gave him an opportunity to try out Detective and was pretty good - except when he actually needed to contact support. So that’s always fun.
12:21 Retiring the AWS Documentation on GitHub* Do you remember this blog post from 5 years? Randomly we do - 5 years ago Jeff Bar told us about the fact that AWS documentation was open source and available on github. * Now, after a prolonged period of experimentation AWS will archive most of the repos starting the week of June 5th, and will devote all of their resources to directly improve the AWS documentation and website. * According to their newest update, the issue was that the primary source for most AWS documentation is an internal system that had to be manually synced with Github Repos. * Despite the efforts of their documentation team, keeping the public repos in sync has proven to be very difficult and time consuming, with several manual steps and some parallel editing. * This effort was high and consumed time that could have been used in ways that more directly improved the quality of the documentation - they honestly just decided it wasn’t worth it. AKA they laid too many people off and couldn’t keep up. * Repos containing code samples, sample apps, cloudformation templates, configuration files and supplementary resources will remain as-is since those repos are primary sources and get high levels of engagement. Do definitely use the thumbs up / thumbs down feature; they say they’re monitoring that.
14:33 📢Matt - “I'm just more curious of why it was so hard to sync them.”15:58 📢Jonathan -”If they can build out ES and orchestrate SQL server clusters, you'd think they could orchestrate copying some docs up to GitHub. Seems a little odd.”16:37 📢Jonathan - “I’m sure it has nothing to do with the fact that they don't want Microsoft using all the contents of github to train AI models or anything else…”17:00 Welcome to AWS Documentation Have you seen this portal? Come check out the weird page with us! Maybe you can also send in a complaint about the weird graphic design. We are not fans.
19:23 AWS partners bring choice of temporary elevated access capabilities to IAM Identity Center* Customers of AWS IAM Identity Center can use CyberArk Secure Cloud Access, Ermetic, and Okta Access Requests for temporary elevated access, or just in time access. * This ongoing collaboration with partners; AWS Identity validated that these solutions integrate with Identity Center and address common customer requirements, such as the ability to request and approve time-bound access and to audit action logs. * Temporary elevated access allows a workforce user who does not have standing permission to perform a task, such as changing the configuration of a production environment, to request permission, receive approval, and perform the task during a specified time.
20:09📢 Ryan- “As someone who's working towards developing this very same solution for a different project, this is fantastic. I think that the ability to have temporary access to cloud resources is a big key. And then especially if you're already leveraging an identity provider, being able to couple those together within IAM Identity Center is fantastic. So I like this.”GCP27:28 Cloud Workstations is now Generally Available! * Work Stations (not Spaces. Just FYI.) * Last year at Google Cloud Next, they introduced cloud workstations in public preview as a vital part of the Software Delivery Shield offering, to help address this challenge. Now they are thrilled to announce GA of Cloud Workstations with a list of enhanced features, providing fully managed integrated development environments (IDE) on Google Cloud. * Cloud workstations enables faster developer onboarding and increased developer productivity while helping support your compliance requirements with an enhanced security posture. The goals are to speed up developer onboarding, provide consistent dev environments and security hardened systems. * If you would like to force all of your developers to go use a virtual workstation to do all their developer work, this is available to you now! Woohoo!
30:49 📢 Jonathan - “I like the idea of having a standardized desktop with all the tools already installed because it just really sucks to see - especially new employees - spending a month getting things set up. However, I do value my ‘not connected to the internet’ time and I can sit on the plane and do some work locally. There's plenty of opportunities that will be lost, I think, by forcing people to only use this.”31:12 📢 Ryan- “It's a good option, right? When I think about some of the struggles with data science and access to data, this sort of offering can make that real easier, but I don't think it replaces my local workstation.”Azure34:53 Microsoft Build brings AI tools to the forefront for developers* Microsoft Build was this week, and boy they announced a ton of AI stuff! ALL. THE. STUFF. * If you have upgraded to Windows 11 or Windows 365 you're about to get a lot of AI - in the form of copilot; which is also opening up Copilot plugins to developers. * Microsoft will use the same plugin standard as ChatGPT to allow easy interoperability between Azure AI, GitHub AI, and Microsoft Copilot. * New Azure AI studio, which will make it simple to integrate external data sources into Azure Open AI services. * They are introducing Azure Machine Learning Prompt Flow to make it easier for developers to construct prompts while taking advantage of popular open-source prompt orchestration solutions like Semantic Kernel. * Azure Open AI service is bringing advanced models to integrate external data sources into Azure OpenAI Service. In addition, we’re excited to introduce Azure Machine Learning prompt Flow to make it easier for developers to construct prompts while taking advantage of popular open source prompt. * Justin’s personal favorite - Microsoft Fabric is a new unified platform for analytics that includes data engineering, data integration, data warehousing, data science, real-time analytics, applied observability and business intelligence, all connected to a single data repo called OneLake. * Copilot in Fabric in every data experience, customers can use conversational language to create dataflows and data pipelines, generate code and entire functions, build machine learning modes or visualize results - real language for the win! Can’t wait to see this one in use. * Azure Dev Box received new capabilities including customization using configuration as code and new start developer images; you can get a whole new developer experience.
37:30 📢 Jonathan - “So we were right about low code being a non-starter. I just don't think we quite saw these AI tools coming quite as fast as they have.”37:40 📢 Ryan - “Drag and drop we knew wasn't gonna work, but if I could just say it… ok! There's nothing worse than trying to figure out, you know, the fields of a data and, and, you know, dimension it the right way. And then screwing it all up and not knowing how to get back to the three changes that go when it was sort of what you wanted, but not quite. And I do really like this. I've been playing around with more and more solutions that are similar… I’m lazier for it, which is great.”38:28 📢 Jonathan - “I think the race is officially on now between Google getting Bard or whatever integrations and personal assistants set up on Android phones and maybe Chromebooks. We don't really hear much about Chromebooks anymore.” (Says the guys who have spent a quarter of the podcast talking about Chromebooks.)OracleNo new news.
Continuing our Cloud Journey Series Talks39:54 Security in Cloud Native * This week in cloud journeys we’re discussing all things security! We know you’ve been waiting patiently for this one. There’s quite a bit to unpack, including connectivity capabilities, dynamic environments, and autoscaling, among other issues. Also on the agenda today: + Encryption - Encrypt everything EVERYWHERE. All of it. Run the encryption. Make your compliance and security departments happy. - How do you then manage all the keys? Single key? Per customer? Per environment? Managed provider? There’s a lot of technologies; a lot of things that need to come into play when making decisions. + Zero Trust Access - Can be a big part of your security story + Managed Security Services - DLP, Config, Security Hub, Guard Duty - Ability to use tokens - Most cloud providers don't have this as an option for users; so it’s usually 3rd party software or writing your own. + Secure connectivity between distributed APIs + Newer Technologies require newer security methods + Dynamic environments require contextual information about workloads
45:32 📢 Ryan - “we've had decades of managing security in our environments and data centers and we've built tooling to match. And it's always my favorite cloud experience when the security team comes up and says, oh, we've got a vulnerability at this IP. Like, that's not a thing. Like that IP is gone. It's been gone for a long time. Like it's, you know, it's... It is an ephemeral construct and a lot of the tools are built to identify those sorts of things by stuff that's very static in a data center, but it's not very static in a cloud environment.”
48:45📢 Jonathan- “I think the problem is just that everyone had their own very siloed areas of responsibility. So you'd have the virtualization team and the network team and the, you know, release team, security team, they all have their own separate sets of tools with no access to each of those tools. And so it's really kind of like this is the only way that those machines could be scanned was by feeding it a massive subnet and just pinging everything until they got some response from something. or installing agents everywhere. And it really isn't a model that translates well to the cloud and auto scaling groups or managed instance groups.”
After Show50:43 “The Need to Visualize a Cloud Infrastructure” aka Justin Does a Thingwww.cloudockit.com
www.lucidchart.com
www.hava.io
Spotted on the HorizonNext week on the Cloud Pod Podcast…ClosingAnd that is another week in the cloud! We would like to thank our sponsors Foghorn Consulting, who is definitely NOT AI generated. Check out our website, the home of The Cloud Pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome to the newest episode of The Cloud Pod podcast! Justin, Ryan, Jonathan, Matthew are your hosts this week. Join us as we discuss all things cloud, AI, the upcoming Google AI Conference, AWS Console, and Duet AI for Google cloud. Titles we almost went with this week:* 🔒You can finally lock yourself out of the AWS Console! * 🤝Google IO delivers the AI… hopefully soon to be renamed Google AI Conference * 🖥️Azure announces major MySQL upgrade! * 😢Azure can now update mysql without taking itself offline
A big thanks to this week’s sponsor:Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.📰News this Week:📰01:10 - Terraform is in the news! * Terraform Cloud updates plans with an enhanced Free tier and more flexibility * A bunch of new updates are coming to Terraform Cloud * These update will provide access to premium features, up to 500 resources in the free tier * There are also new paid offerings for management capabilities, scaling currency, and enterprise support. * Consistent billing metrics based on managed resources, scaling concurrency, and enterprise support area available across all tiers. But let’s be honest - who needs consistent billing metrics? Half the fun is in the guessing! * New Features Include: + Premium security features such as SSO and Policy as Code on all tiers (yes, even the free ones for the poors like us.) + Make it “easy and frictionless” for smaller teams and organizations to get started with their first use cases. + And -finally- updated paid tiers provide easy upgrade paths for organizations as their usage scales, and they have more advanced use cases. * Consumer Advice Time! The updated pricing models include a “per resource” charge. That has the potential to get REAL messy over 500 devices. * Of course, it’s an option to stay on the legacy models, but the “carrots” - like SSO and Sentinel/OPA support - are pretty good, so you really just need to do a cost benefit analysis for your particular situation.
02:35 📢Ryan - “Yeah, I mean, the licensing for Terraform products for cloud and both enterprises always been rough, right? Like starting off per users for cloud makes sense. And at some point for enterprise, they had switched to per project, not users, because they figured out very quickly that what everyone did was just sort of link it together behind automation pane.”04:48 📢”Justin - the devil's in the details of what they consider a resource, right? And it's every single thing. I mean, 10 cents per EC2 instance, hmm. Like, yeah, I get 10 cents worth of value out of Terraform, not having to manually do that stuff. So, like, yeah, but then like you get into S3 buckets and like, I'm definitely not gonna get 10 cents of value out of an S3 bucket every month.”* Our only big question from this announcement is just what they consider a billable resource vs. a supportive resource. Example pricing could potentially be really helpful here. * Does anyone in the audience have a PhD in finance? We could use some help with some cost calculation.
AWS11:00 Amazon Aurora I/O-Optimized Cluster Configuration with Up to 40% Cost Savings for I/O-Intensive Applications * Announcing! The general availability of Amazon Aurora I/O Optimized! * This new cluster configuration offers improved price performance and predictable pricing for customers with I/O intensive apps (like e-commerce, payment processing systems, pretty much anything with SAP) * As much as we like the “everybody loves a surprise bill” method, you can now more confidently predict your costs for I/O intensive workloads - and get up to 40% cost savings when your I/O exceeds 25 percent for your current Aurora Spend. * If you use reserved instances for Aurora, you could potentially see even greater savings. Rad!
13:10 📢Jonathan - “The predictability of the workload means that they can, that Amazon themselves can better kind of put customers in buckets for IOPS. And so they can manage capacity better, whereas customers with very bursty workloads, they always have to make sure that capacity's available when they need it.”14:13 Private Access to the AWS Management Console is generally available * Now generally available in AWS Management Console - Private Access! * Private access allows access to your AWS Management Console from on-premise networks using a secure, private connection. * AWS touts the new access as easy to set up, and a good way to help improve costs, security, and compliance. And who doesn’t love improvements to cost, security, and compliance? * Some of the benefits of using Private Access to the AWS Management Console: + Improved security: Private Access to the AWS Management Console provides a more secure way to access AWS resources, instead of using a public internet connection. + Increased compliance: Private Access to the AWS Management Console can help you meet compliance requirements by providing a secure, controlled way to access AWS resources. + Reduced costs: Private Access to the AWS Management Console can reduce costs by eliminating the need for a VPN or other expensive connectivity solutions. + Improved performance: Private Access to the AWS Management Console can improve performance by providing a direct, private connection to AWS resources. + Increased flexibility: Private Access to the AWS Management Console can provide increased flexibility by allowing you to access AWS resources from your on-premises network. * Want to start utilizing Private Access? Us too! It is currently available in US East (Ohio), US East (N. Virginia), US West (Oregon), Europe (Ireland), and Asia Pacific (Singapore). * Looking for a more secure, compliant, and cost effective way to access your AWS resources? Private Access might just be the answer. Allegedly.
insert a classic Matthew horror story about some weird tech niche17:14 Using Open Source Cedar to Write and Enforce Custom Authorization Policies* Amazon has released support for Cedar * Cedar provides a simple and intuitive API that makes it easy to write policies for all your applications. * Cedar supports a variety of authorization models, including role-based access control (RBAC), attribute-based access control (ABAC), and capability-based access control (CBAC). * Cedar is highly extensible, allowing you to customize it to meet your specific needs. * Cedar is well-documented and has an active community of users and contributors. * Cedar has a pretty website.
17:52 📢Matt - “This is the first I'm hearing of this kind of concept and I'm loving it. Cause this is one of those things where if you're building your own app, I dread sort of the authentication flow, and so I'm always trying to leverage some other party for this.”18:26 📢Justin - “The examples they gave, this tiny to-do user policy thing, it's pretty great. It's a cute little app, and it gives you a very simple way to use it in a client, like a Python client or a Rust server. It's not a bad little example of how to do it. So yeah, I love all this. Ever since CDK, everybody's rushing to make all these things as code, but not restricted by CloudFormation. So I'll take it as a win anytime, it's not CloudFormation.”19:14 Announcing Provisioned Concurrency for Amazon SageMaker Serverless Inference* More exciting news from Amazon! SageMaker Inference now offers provisioned concurrency. This will allow you to set a specific number of concurrent requests that your model can handle. * This can help you to ensure that your model is always available to serve requests, even during periods of high demand. * Provisioned concurrency is available for both batch and real-time inference. * To use provisioned concurrency, you need to create a SageMaker endpoint with the "provisioned" concurrency mode.You can then specify the number of concurrent requests that you want your endpoint to handle. * What are the costs for this new Provisioned Concurrency for Amazon SageMaker Serverless Inference magic we hear you asking? Well, dear listener, wonder no more. + Pricing is based on the number of concurrent requests that you provision, and if you choose to provision one or multiple models. + The cost for provisioned concurrency is per hour, and you are billed for the hours that your concurrency is provisioned. For example, if you provision 10 concurrent requests for a model that costs $0.01 per hour, you will be billed $0.10 per hour for the provisioned concurrency. If you only use 5 concurrent requests for that model, you will only be billed $0.05 per hour. * Savings Plan is available for provisioned concurrency; and can offer a lower per-hour price than the on-demand price. * Users can choose between 1 or 3 year Savings Plan. * The bulk buying rule applies here - the more concurrency you commit to, the lower your price per hour will be.
20:08 📢Jonathan - “Seems to be becoming quite a pattern, doesn't it? They've moved away from servers, have serverless, it's on demand, you pay for what you use, but also now you can have provisioning capacity because you realize that that didn't actually work for people.”20:08 📢Ryan - “Well, it's not that it didn't work. It's that the people having to pay for this do not like spiky, unpredictable workbooks. Right? Like a lot of the provision capacity isn't because you run out of capacity. It's for consistency. And so like if you're going to use this, use it, right. And then we'll baseline the provision part so that we have a consistent cost model. Because otherwise we have no idea what our costs are doing. We don't know when it's out of control or we don't know when it's normal. And it's, so a lot of this I think is, is less about actually having the capacity to execute than it is actually just standardizing and removing those big spikes.”GCP22:56 At Google I/O, generative AI gets to work * Lots of news coming out of Google I/O this year, and surprise surprise - most of it centers around AI! Who would have guessed? Not us… * According to Google CEO, easy and scalable AI is going to drive innovation at all levels of business. * Google Cloud announced a number of new AI and machine learning products and features at Google I/O 2023. These include: + Cloud AutoML Natural Language, which makes it easier to build natural language processing models without any machine learning expertise. (Justin is excited for this one. Natural language for the win.) + Cloud AutoML Vision Edge, which enables developers to build and deploy custom vision models on edge devices. + Cloud TPUv4 Pods, which are powerful machine learning accelerators that can be used to train larger and more complex models. + Cloud ML Engine Pipelines, which make it easier to manage and monitor machine learning pipelines. * Cloud AI Platform, which is a unified platform for building, training, and deploying machine learning models. * These new products and features are designed to make it easier for developers and businesses to build and deploy AI and machine learning solutions. They also “demonstrate Google's commitment to AI and machine learning, which are two of the most important technologies of our time.” * And that’s a recap on Google AI, er, I mean Google I/O for 2023.
26:15 Introducing Duet AI for Google Cloud – an AI-powered collaborator * A few weeks ago we discussed BARD, and how Google had added some new programming languages and capabilities. * At Google I/O they have now presented Duet AI for Google Cloud. * Duet AI, which is on a limited access (much to Jonathan’s dismay) will help create a cloud experience that’s more personalized and intent-driven. * Duet AI will understand your environments, and assist users in building secure and scalable applications - all with expert guidance. * New capabilities powered by Duet AI + Code Assistance which provides AI-driven code assistance for cloud users such as application developers and data engineers. It provides code recommendations as they type in real time, generates full functions and code blocks, and identifies vulnerabilities and errors in the code, while suggesting fixes. + Chat assistance to get answers on specific development or cloud-related questions. Users can engage with chat assistance to get real-time guidance on various topics, such as how to use certain cloud services or functions, or get detailed implementation plans for their cloud projects. + Duet AI for Appsheet will help you create intelligent business applications, connect their data and build workflows into Google Workspace via natural language.
28:28 📢 Justin - “So one of the things they announced at Google I.O., that I don't have a story here for us, but they announced integration of BARD and stuff into Google Apps, and you could subscribe for the beta. And so I got the CloudPod Google Workspace into the beta. So most of the show notes today were written by AI.” (Insert tears from the show note writer.) ☎️Listener poll: What sorts of interesting, non-WGA line busting uses does Chat GT have in your day job (beyond dad jokes and basic chat)? Let us know! Azure34:21 New and upcoming capabilities with Elastic Cloud (Elasticsearch)—An Azure Native ISV Service * Moving on to Azure and services we hate with Elastic Cloud (missed title opportunity.) * Elastic Cloud Elasticsearch is now an Azure native ISV service. It’s now fully integrated with Azure services and can infect, I mean manage, using Azure tools. * There are a number of new and upcoming capabilities in Elastic Cloud Elasticsearch, including: + Support for Azure Kubernetes Service (AKS) + Integration with Azure Synapse Analytics + Support for Azure Active Directory (Azure AD) authentication + Improved performance and scalability
36:33 📢 Jonathan - “You know, when people are addicted to drugs, we don't just say well here's a drug dealer that's got a better deal we say maybe you should move off that and try doing something else.”And that pretty much sums up the guys’ thoughts on Elastic Cloud. Moving on. 37:25 What’s new with Azure Files * Azure Files is a fully managed file storage service that provides SMB and NFS file shares. It is a highly available, scalable, and durable service that can be used to store any type of data, including application data, user data, and backups. * There is currently no premium tier, but let's be real - it’s coming. Just wait and see. * Azure Files offers a number of features, including: + Durability: Azure Files is designed to be highly durable. Data is replicated across multiple data centers to protect against data loss. + Scalability: Azure Files can be easily scaled up or down to meet your needs. + Performance: Azure Files offers high performance for both reads and writes. + Availability: Azure Files is available in all Azure regions. + Security: Azure Files offers a number of security features, including encryption and access control. * New features include + Azure Files now supports Azure Files Sync, which allows you to sync files between Azure Files and your on-premises file servers. + Azure Files now supports Azure Files Premium, which offers higher performance and scalability. + Azure Files now supports Azure Files Edge, which allows you to deploy Azure Files to your edge locations. * The cost of Azure Files will depend on the following factors: * The type of storage account you choose. * The amount of storage you need. * The performance level you need. * The region you choose. * For example, a Standard storage account with 1 TB of storage in the US East region would cost \$12.50 per month. * Just know this doesn’t include network data transfer costs - which will most likely be high.
40:10 📢Ryan - “The Cloud. Full of sharp edges.” (Yet another missed title opportunity.)40:41 General Availability: Azure Database for MySQL - Flexible Server major version upgrade * Azure Database for MySQL Flexible Server now supports major version upgrades. * This means that you can now upgrade your database from one major version to another without having to rebuild your database - THANK GOODNESS! * The upgrade process is fully automated and takes care of all the necessary steps, including data migration and schema changes. * To use the major version upgrader, you must have a subscription to Azure Database for MySQL Flexible Server. * You can also find more information about the upgrade in the Azure docs if you want to learn more about this. + We don’t.
41:22 📢 Jonathan - “I mean, if you can roll back, that's nice. If there's less downtime, that's nice. If it syncs ahead of time before it does it, that'd be kind of cool. But saying that it does all the necessary steps? Yeah, I don't think so. There's a whole lot of testing involved in major upgrades for MySQL.”41:42 📢 Ryan - “ALL THE UPGRADES. It said ALL the upgrades! I’m just gonna click the button.”41:48 📢 Matt - “What could possibly go wrong?”OracleNo new news. Sad face. Continuing our Cloud Journey Series Talks47:27 Managed Services* Welcome back to Cloud Journeys! We’re still talking cloud native, and this week we’re focusing on managed services. In cloud native, there are 5 things managed services should be providing you with - and those include: 1. Reduces costs. Managed services can help you reduce costs by offloading the responsibility of managing and maintaining infrastructure to the cloud provider. This can free up your team to focus on other tasks, such as developing and deploying applications. 2. Increases agility. Managed services can help you increase agility by providing you with access to the latest technologies and features. This can help you quickly develop and deploy new applications and services. 3. Improves reliability. (Unless you’re in France. Too soon?) Managed services can help you improve reliability by providing you with a high level of uptime and availability. This can help you ensure that your applications and services are always available to your users. 4. Reduces complexity. Managed services can help you reduce complexity by providing you with a single point of contact for all of your cloud needs. This can help you avoid the hassle of managing multiple vendors and platforms. 5. Improves security. Managed services can help you improve security by providing you with a secure environment for your applications and data. This can help you protect your business from cyberattacks.
47:58 📢 Jonathan - “Reduce cost is interesting because I think they can enable better architectures, thinking about serverless and event driven architectures which don't cost anything. That could reduce costs versus running something 24-7. However, managed services in general are really not cheaper than running them yourself. It's just a matter of where you spend the money, I think.”48:24 📢 Justin - “Well, you have to calculate the ROI differently. Like an RDS database, for example, you know, yes, you're offloading SQL Server Management or MySQL Management or Postgres or whatever flavor of database you're using to the cloud provider. So maybe you have 10 DBAs, and now maybe you only need six DBAs. So you have an ROI there, because you were able to do less DBAs, or have the DBAs do a more valuable thing, you don't have to fire them necessarily… And if you can focus on just your app, then you save money. But that ROI is not a direct ROI because that database costs 20% more than that database would have cost you on EC2. But you have less headcount required to support it.”☎️Listener Poll - what sorts of things can you think of that are advertised as a managed service but it really isn’t? Matt’s example - having to tell Azure the number of servers that run your load balancers. 55:33 📢 Ryan - “That's my biggest gripe with Composer; is that it's pretending to be a managed Airflow service and it's not. It's a deployment template.”Keep listening for some after show convos with Justin and the boys - especially if you’re interested in learning about when Yahoo was cool. (It was! It really was!)After Show1:00:01 Can Marissa Mayer Eclipse Herself? * Marissa Mayer was the CEO of Yahoo! from 2012 to 2017. * She is now the CEO of Lumi Labs, a company that develops augmented reality technology. * The article discusses whether Mayer can "eclipse herself" at Lumi Labs, as she did at Yahoo!. * The article argues that Mayer's success at Yahoo! was due to a number of factors, including her experience at Google, her strong leadership skills, and her ability to attract top talent. * The article also argues that Mayer's success at Lumi Labs will depend on a number of factors, including the company's ability to develop successful products, the market for augmented reality technology, and Mayer's ability to lead the company. * The article concludes that it is too early to say whether Mayer will be successful at Lumi Labs, but that she has the potential to be a successful entrepreneur.
1:01:56 📢 Ryan - What I've been waiting for from Lumi Labs is sort of like… give me something to play with because their application availability and stuff is very early and not generally available. I kind of want to see what they'll do. I think that one of the things that she spearheaded while I was at Yahoo was a lot of the weather app stuff and her views on mobile - for a company at the time that was really trying to figure out whether it was a content company or a technology company - her views on mobile were very different from what we were used to for the last few years since the previous CEOs. She was very opinionated, very data driven, and had introduced some really cool mobile experiences during that time. So I think that she's got a good track record of that kind of delivery. So I look forward to what they're doing.”Spotted on the HorizonNext week on the Cloud Pod Podcast…ClosingAnd that is another week in the cloud! We would like to thank our sponsors Foghorn Consulting, who is definitely NOT AI generated. Check out our website, the home of The Cloud Pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome to the newest episode of The Cloud Pod podcast! Justin, Ryan, Jonathan, Matthew and Peter are your hosts this week as we discuss all things cloud and AI, Titles we almost went with this week:* The Cloud Pod is better than Bob’s Used Books * The Cloud Pod sets up AWS notifications for all * The Cloud Pod is non-differential about privacy in BigQuery * The Cloud Pod finds Windows Bob * The Cloud Pod starts preparing for its Azure Emergency today
A big thanks to this week’s sponsor:Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.📰News this Week:📰00:40 - News this week starts out with TCP’s own news - Peter’s podcasting career is riding off into the sunset. He claims he’ll actually start listening, but we’ll see…we’re always happy for more listeners though, no matter how we get them. 02:18 - FinOps Foundation debuts new specification to ease cloud cost management* Have we mentioned the FinOps User Conference? I can’t remember if we’ve mentioned that at all… In any event, join the fun June 27th through the 30th in beautiful and sunny San Diego, and be immersed in all things FinOps. It’s a dream vacation opportunity! * In the meantime, the Finops foundation has announced FOCUS, an open-source initiative designed to help companies more easily track their cloud costs, which will initially launch at the conference. * The goal of the initiative is to develop a standard specification for organizing cloud spending and usage data. * According to FinOps, FOCUS will also provide a number of related data management capabilities, MS and Google will join the steering committee tasked with managing the project. * “FOCUS will solve problems that organizations maturing their cloud adoption now face,” said Udam Dewaraja, the chair of the FinOps Foundation’s FOCUS working group. “Today, there’s no clear way to unify cost and usage data sets across different vendors.” * FOCUS introduces standardized terminology for describing cloud expenses and usage metrics, provides a standardized schema, or a data format in which financial information can be organized. A schema specifies technical details such as the maximum number of expenses that should be included in each database row.
AWS04:18 New Storage-Optimized Amazon EC2 I4g Instances: Graviton Processors and AWS Nitro SSDs* AWS is launching the new I4g instances powered by Graviton2 processors - delivering up to 15% better performance than their storage-optimized instances. Whoo! * Shapes come in 2 VCPU, 16gb Memory and 468gb of Storage up to 64 vcpu, 512gb of ram, and 15 tb of storage. * The instances leverage the AWS Nitro SSD’s for NVMe storage. Each storage volume can handle up to 800k random write iops, 1 million random reads, 4600mb/s of sequential writes and 8000mb of sequential reads - more reads and writes than a Scholastic Book Fair! * “What region is this available?” We hear you asking. Fear not, dear listener! We have that info too. The new features are available in select regions including US-East-1, US-West-2 and Ireland in OD, Spot, RI and Savings Plan Form.
05:08 📢Ryan - “some of these numbers are just staggering for workloads when, you know, the traditional sort of standard app is hundreds of megabytes maybe like at peak. So this is - it's a lot. I'm glad I don't have to pay for this.”05:28 📢Justin - “Yeah, 800,000 random write ops, IOPS. I mean, that's just crazy. And then they can support a million random reads. That's, you know, you'd buy a whole sand just to do that in prior lives. You know, and that'd be your entire workload. Now you're talking about a single server with that kind of throughput. It's just, it's incredible.”06:06 - Introducing Bob’s Used Books—a New, Real-World, .NET Sample Application* For folks who need to support .net apps, up until this point there’s really just been some sample code or a need to go search GitHub for your standardized patterns and methods. * That is - until now! AWS has a new open-source sample application, a fictitious used book eCommerce store they’re calling “Bob’s Used Books” - a boon for .net developers working AWS. * The sample app is built using ASP.Net core version 6, and represents an initial modernization of typical on-premises custom applications. Representing the first stage of modernization, the application uses modern cross-platform .net, enabling it to run on Windows and Linux systems in the cloud. * The .net app is based on a monolithic MVC (Model-view-controller) design. T * Typical of the .net framework era, it also uses a single MS SQL Server database to contain inventory, shopping cart, user data and more. * Bob’s Used Books leverages several AWS native services, including Cognito, RDS, S3, AWS SSM, Secrets Manager, Cloudfront and Rekognition
07:12📢Ryan - “I mean, they want to build a bridge for .NET into the cloud, right? And so they can't start off with stored procedures because it's so hard to make that work in a cloud native environment.”07:24 📢Justin - “it would be nice though if they gave you a pattern to, hey, move your stored procedure out of a SQL database and move it into server lists or into some other thing like that. That'd be super nice.”09:54 New – Set Up Your AWS Notifications in One Place* Have you ever had to go set up notifications? It’s a lot of clicks through multiple areas of applications. It’s an unnecessary pain. We’re glad to see AWS finally caught up with the other cloud providers in this area. * AWS is launching AWS User notifications a single place in the AWS Console to setup and view AWS notifications across multiple AWS accounts, Regions and Services * You can centrally set up and view notifications from over 100 AWS services such as S3, Ec2, Health Dashboard, CLoudwatch Alarms or AWS Support case updates in a consistent, human friendly format. You can also configure delivery channels -- email, chat and push notifications to the AWS console mobile app, where you can receive the notifications. * Alternatively you can view notifications in the AWS Management Console
11:04📢Matt - “It looks like from deep in the notes that there's a whole bunch of stuff you have to do in order to get the event bridge events to kind of flow between the accounts. So it doesn't look like it's press a button, get all your accounts in the organization. It looks like it's going to require some setup for multiple accounts.”GCP14:05 Chronicle Security Operations Q1 Feature Roundup * Chronicle has several new features this week to make securing the google cloud easier than ever. + New Looker Based Advanced Report modules to create strong BI Capabilities and have them completely embedded + Customers can now grant access to Google Support to help address issues + New case list view - easier to find those cases raised by Chronicle + Integration between Chronicle Alerts and Soar + Enhanced UDM search + Scheduled Reports - don’t need to log into the console * Australian listeners rejoice - there's now expanded regional support in Australia for iRap protection. We don’t know what that is. Some sort of murderous Australian spider spray maybe? We assume our Australian listeners know, so we’ll just leave it there.
15:41 BigQuery Differential Privacy There are SO MANY* laws in regards to privacy. And we don’t want to be in charge of that. * Thankfully, now in Public Preview is BQ differential privacy, which is SQL building blocks that analysts and data scientists can use to anonymize their data. In the future, they will integrate differential privacy with BigQuery data clean rooms to help organizations anonymize and share sensitive data, all while preserving privacy. * This builds on the Differential Privacy library that is used by the ads data hub and the covid-19 community mobility report. * They are also partnering with Tumult labs, a leader in differential privacy for companies and government agencies. Tumult labs offers technology and professional services to help google cloud customers with privacy implementations. * Differential privacy is an anonymization technique that limits the personal information that is revealed by an output. It is commonly used to allow inference and to share data while preventing someone from learning information about an entity in that dataset.
17:27 📢Peter - “It'll be interesting to see how much easier this makes it. But this has always been a big ask for people moving to the cloud who then want an easy way to have test data and their test environments and other use cases. So if it does make it easier and it's not just a tool that does it on BigQuery, then I can imagine some people are going to be pretty happy.”Azure18:04- Preparing for future health emergencies with Azure HPC * We’re crossing our fingers that this is a waste of money and that there will NEVER BE another major health emergency. NEVER AGAIN. * Essentially the GPU’s can be utilized to help prevent that next pandemic. * Azure HPC enables researchers to unleash the next generation of healthcare breakthroughs. The computational capabilities offered by HPC HB-Series VM, powered by AMD EPYCTM CPU Cores, allows researchers to accelerate insights and advances into genomics, precision medicine and clinical trials, with near infinite high performance bioinformatics infrastructure capabilities.
19:48📢Jonathan - “I think near infinite high performance is probably a bit of a marketing stretch.”20:30- Cloud-based chip design for national security achieves key milestone * Continued US leadership in emerging technology requires a sustainable supply of advanced chips to power innovation from AI to Quantum computing. The CHIPS and Science act passed last year aims to boost domestic research and manufacturing capacity for critical microelectronics. To support this the DOD launched the Rapid Assured Microelectronics Prototypes using Advanced Commercial Capabilities Program (RAMP), an effort to Accelerate the secure, sustainable development of microelectronics for defense technologies. * As part of this effort, Azure has developed three new state-of-the-art chips to benefit Azure Government Cloud customers and to ensure compliance with DoD supply chain requirements + This essentially means the chips can’t be manufactured in China in any way.
Oracle23:45 Microsoft and Oracle Discussed Sharing AI Servers to Solve Shortage * Oracle and Microsoft have reportedly discussed an unusual agreement to rent servers from each other if either company runs out of computing power for cloud customers that use large-scale artificial intelligence, according to a person with knowledge. * The proposed deal discussions have been happening as Oracle Chairman Larry Ellison and other senior executives firm up broader AI strategy, including how to use AI software to improve the company's core software products. * Who bought a lot of A100 Tensor Core CPUs that are most likely just sitting around? And then who also happens to have a direct connection between their cloud and the other cloud, you know, for things like ordering Oracle databases that could take advantage of selling AI chips to Azure for a profit. We don’t know. Really weird. Ok, moving on.
Continuing our Cloud Journey Series Talks26:54 We were going to continue with our Cloud Journey Series, but DHH stirred up a bunch of drama, and now we have to address it. * From the opinionated creator of Ruby on Rails, and Cloud Repatriation, DHH brings us “Amazon can’t even make Microservices or serverless work” * His latest poke in the eye at cloud computing starts from a pretty innocent post by the Amazon Prime team where they moved from a microservices architecture to a monolith * DHH basically sums up his entire opinion that microservices are crazy. And that the real word results of all the Microservices “theory” is that in practice, microservices pose perhaps the biggest siren song for needlessly complicating your systems. And Serverless only makes it worse. * DHH equates Microservices to “Zombie Architecture”. Another strain of intellectual contagion that refuses to die, and has been eating brains since the dark days of J2EE (remote server beans) through the WS-Deathstar Nonsense. * And he particularly points out that Amazon was the one who started all of this with their huge move to SOA and API calls. * Is Amazon Eating Crow here?
Scaling up the Prime Video audio/video monitoring service and reducing costs by 90% * Don’t be confused - it’s really just the microservices of Prime, not Prime itself. * Going to the source material… what you realize pretty quickly is that this particular thing is not ALL OF AMAZON PRIME.. It's a microservice of Prime. And in this case they deal with big video files and long-running processes. * They point out that what they built worked, but wasn’t meeting their service SLI/SLO’s and so the re-architecture to a monolith addresses that issue. * These patterns are all tools and methods, and there is never one correct answer; it depends on many factors. But we all know that microservices should be omnipotent and immutable, and if you break them down too much, you end up in microservice dependency logic hell. Microservice inception sounds like a great idea, right?
30:18 📢Jonathan - I think the problem they had really is that they took the software architecture and kind of projected that onto the infrastructure services they could use to fill those particular functions in the service they were delivering. I mean, and yes, it worked. And yes, it made sense logically. The diagram is the same regardless of whether it's in a monolith or whether it's user-managed services, but they realized they made a mistake and they need to bring those back to be more tightly coupled again. It makes sense. I mean, there's monoliths and there's monoliths. It's huge monoliths that are manageable. And there's small monoliths like this, which make total sense just as there's microservices deployments, which are completely out of control. It's a huge sliding scale, but to me, this just kind of seems like a little overzealous sort of turning what should be a software architecture into an infrastructure deployment type architecture.”How to recover from microservices * If you agree Microservices are the devil and want to stop the insanity DHH gives you 5 tips on how to get back on track: + Stop Digging - Can’t clean it up if you keep making a mess at the same time + Consolidate critical, dependent paths first + Leave isolated performance hotspots for last + Prioritize dropping the most esoteric implementations + Learn to partition large systems with modules rather than networks
Monoliths are not dinosaurs * After DHH’s post went viral, Werner Vogels had to weigh in on his All Things Distributed blog * He points out that software architecture is not like the architectures of bridges and houses. After a bridge is constructed it is hard, if not impossible to change. Software allows you to make changes and as you evolve the architecture you may change components. * He highlights how if you hire the best engineers, you should trust them to make the best decisions * There is not one architectural pattern to rule them all!
33:12 📢Peter - “Yeah, I want to disagree with David Hansen here, but Ruby on Rails, come on. He made Ruby on Rails. How can I disagree with someone who created Ruby on Rails and raced in the 24 hours of Le Mans?”35:16 📢Justin - “we're down to one Ruby on Rails person, which is me, and I'm not even that much of a Ruby on Rails fanboy anymore. I used to be, but I found my way out of that hole, unlike Vader.”News From the Clouds That Didn’t Make the Main ShowAWS* https://aws.amazon.com/about-aws/whats-new/2023/05/aws-cloudtrail-lake-query-presto-sql-select-functions/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-iot-sitewise-15-minute-intervals/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-glue-large-instance-types-generally-available/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-iot-sitewise-optimized-storage-hot-path-data/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-managed-services-prometheus-4-regions/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-quicksight-scatterplot-options-additional-use-cases/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-athena-apache-hudi/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-quicksight-state-persistence-bookmarks-embedded-dashboards/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-quicksight-vpc-public-apis-multi-az-support/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-memorydb-redis-creating-clusters-management-console/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-cloudwatch-synthetics-synthetics-nodejs-runtime-version-4-0/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-device-farm-rooted-android-private-devices/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-aurora-serverless-v2-additional-regions/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-rekognition-face-occlusion-identity-verification-accuracy/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-backup-cross-region-backups-four-regions/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-cloudwatch-metric-streams-filtering-name/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-quicksight-dataset-parameters-slicing-dicing-experiences/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-network-firewall-reject-action-stream-exception-policy/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-vpc-ipam-additional-aws-regions/ * https://aws.amazon.com/about-aws/whats-new/2023/05/sagemaker-ml-inf2-ml-trn1-instances-model-deployment/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-vss-application-backups-powershell-logging/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-codepipeline-govcloud-us-east/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-emr-eks-self-hosted-notebooks-managed-endpoints/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-kinesis-data-analytics-melbourne-region/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-security-hub-tracking-changes-finding-history-feature/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-emr-eks-vertical-auto-scaling/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-elemental-mediaconvert-video-pass-through/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-resilience-hub-trust-advisor-dynamodb-support/ * https://aws.amazon.com/about-aws/whats-new/2023/05/zonal-shift-amazon-route-53-recovery-controller-18-regions/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-batch-dashboard-customization-console/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-msk-apache-kafka-version-3-4-0/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-directory-service-smart-card-authentication-govcloud-us-east-region/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-appsync-graphql-apis-private-api-support/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-multi-az-standby-amazon-opensearch-service/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-rekognition-content-moderation-images-videos/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-network-firewall-suricata-home-net-variable-override/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-well-architected-tool-integration-service-catalog-appregistry/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-rds-postgresql-pgvector-ml-model-integration/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-user-notifications-available/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-console-mobile-application-launches-push-notifications/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-kendra-content-based-query-suggestions/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-direct-connect-location-phoenix/
GCPAzure* https://azure.microsoft.com/en-us/updates/general-availability-inbound-icmpv4-pings-are-now-supported-on-azure-load-balancer/ * https://azure.microsoft.com/en-us/updates/generally-available-azure-dns-private-resolver-is-available-in-8-additional-regions/ * https://azure.microsoft.com/en-us/updates/alwaysserve/ * https://azure.microsoft.com/en-us/updates/preview-automatic-scaling-for-app-service-web-apps/ * https://azure.microsoft.com/en-us/updates/retirement-of-sql-server-native-client-snac-ole-db-provider-for-linked-servers-in-azure-sql-managed-instance/ * https://azure.microsoft.com/en-us/updates/general-availability-azure-iot-edge-supports-rhel-9/ * https://azure.microsoft.com/en-us/updates/public-preview-azure-cold-storage/ * https://azure.microsoft.com/en-us/updates/public-preview-palo-alto-networks-saas-cloud-ngfw-integration-with-virtual-wan/ * https://azure.microsoft.com/en-us/updates/generally-available-ebsv5-and-ebdsv5-nvmeenabled-vm-sizes/ * https://azure.microsoft.com/en-us/updates/mabsv4/ * https://azure.microsoft.com/en-us/updates/generally-available-serverless-sql-for-azure-databricks/
Oracle * https://blogs.oracle.com/cloud-infrastructure/post/oracle-cloud-vmware-solution-flexible-standard-shapes * https://blogs.oracle.com/cloud-infrastructure/post/launch-oracle-linux-8-stig-profile-instances-easy * https://blogs.oracle.com/cloud-infrastructure/post/vcn-cidr-range-requirement-odsa * https://blogs.oracle.com/cloud-infrastructure/post/3rd-party-apps-multicloud-multiregion * https://blogs.oracle.com/cloud-infrastructure/post/tryg-insurance-save-50-percent-k8-cloud-costs https://blogs.oracle.com/cloud-infrastructure/post/secure-oracle-cloud-vmware-solutions-workloads-oci-network-firewall * https://blogs.oracle.com/cloud-infrastructure/post/node-cycling-container-engine-kubernetes-oke
ClosingAnd that is the week in the cloud, we would like to thank our sponsors Foghorn Consulting. Check out our website, the home of The Cloud Pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome to the newest episode of The Cloud Pod podcast! Justin, Ryan, Jonathan, and Matthew are all here this week to discuss the latest news and announcements in the world of cloud and AI - including New Relic Grok, Athena Provisioned Capacity from AWS, and updates to the Azure Virtual Desktop.Titles we almost went with this week:None! This week’s title was SO GOOD we didn’t bother with any alternates. Sometimes it’s just like that, you know? A big thanks to this week’s sponsor:Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.📰News this Week:📰01:27 - Quick reminder - Finops X Foundation Conference is almost here! * This is the annual FinOps Foundation Annual User Conference, and it is taking place June 29th through the 31st in Beautiful San Diego, California. * Hundreds of your fellow practitioners will be sharing their FinOps knowledge, collaborating in chalk talks and networking together. * Why should you attend? Great question. Let me tell you. 1) There’s a party on an aircraft carrier. Need more? You got it. 2) You can learn best practices when it comes to FinOps and save your company lots of money - you’ll be a hero! (Look at the economy and current interest rates. Heroic is an understatement.) Need another reason? Look no further! Justin will be there! We know you’ve always wanted to chat with him in person. No? How about free stickers? Free stuff is good. Everyone loves stickers.
02:47 New Relic is back on the pod - and they’ve got something new * New Relic just launched Grok, their new AI observability assistant * + If you remember a few weeks ago, we had someone from New Relic on the pod, and they told us something was coming, but weren’t quite ready to tell us what it was - and now, it’s here! + New Relic is throwing their hat into the AI ring - Grok. + Grok will allow engineers to use large language models to help utilize natural language when performing many of the routine tasks in New Relic, like setting up instrumentation, building reports, or managing accounts. + Engineers can sift through the data more easily and come through their unified telemetry data without having to write complex queries. + From New Relic: “Observability tools exist to serve the DevOps and DevSecOps movements. Engineers use observability tools to get the data they need to operate and secure the software they build,” said New Relic Chief Product Officer Manav Khurana. “The reality, howeve r, is that it’s hard for every engineer to translate a question they have into a data model, sift through their tools to find the right data, and then translate data back to an insight in natural language. That’s why DevSecOps practices are lagging behind all the innovation in Observability tooling. Now with Generative AI, there will be an explosion of new software developed in a completely different way, creating even more complexity to operate and secure software.”
04:28 📢Jonathan - “It's funny they called out specifically the DevSecOps, though, as a team that needed this kind of assistance.”04:40 📢Justin - “Well, I mean, I think DevSecOps as a practice is really still pretty immature. I think the DevOps movement was a little bit more active because it was also the time we were doing web scale. We were doing a bunch of things. And so there was a lot more momentum behind DevOps.”AWS8:10 Introducing Athena Provisioned Capacity* AWS is not launching the ability to provision capacity when running your Athena Queries. As many of you know, Athena is a query service - based on presto - that allows you to analyze data in S3. * Data sources include on-premise and other cloud systems, and use standard SQL queries; and Athena is serverless, so there is no infrastructure to manage. * Until today, you only paid for the queries you ran, but the times, they are a changin’. * Now you can get dedicated queries and use a new workload management feature to prioritize, control and scale your most important queries, paying only for the capacity you provision. AWS says customers have been asking for this feature for some time, as Athena costs can get out of hand right quick, and it was difficult to forecast those costs. * To solve this, they are introducing the capability to provision dedicated query processing capacity at scale, and with provision capacity, you can provision a dedicated set of compute resources to run your queries, and this always-on capacity can serve your business critical queries with near-zero latency and no queuing. such as cost, concurrency, and query prioritization. + Users now have control over workload performance characteristics such as cost, concurrency and query prioritization. + Users only pay for the capacity provisioned - not for the actual usage. This will help bills stay predictable. + You reserve the capacity in Data Processing Unit (DPU). A single DPU is equivalent to four vCPU and 16gb RAM. The minimum capacity you may provision is 24 DPU for 8 hours. This new provisioned capacity for Athena is ideal for those of you running any volume of queries, but the sweet spot to start using provisioned capacity is when you spend $100 or more per month on Athena, which is a pretty low break even point. + It seems to be built with an 8 hour workday in mind; you can turn it on in the morning and turn it off at night, then just pay for on demand queries outside of those hours.
10:30 📢Jonathan - “$100 is pretty easy to reach with Athena…I think I’d kind of like to find a middle ground where you can just literally set a maximum maximum concurrency for Athena without paying for provision capacity upfront to say, okay, don't let me spend more than this, but I still want to use it from the serverless pool.”12:28 📢Justin - “I can see how this makes a lot of sense in a SaaS app, especially one that's potentially querying different data sources that aren't owned by a company, because what would prevent you from embedding a thing into your product? Customer goes and points it at their S3 bucket has 25 petabytes of data in it and runs this tool and gets data out of it, but now all of a sudden you have a bill that's very large based on all that data consumption that could be probably problematic.”14:25 - AWS Compute Optimizer identifies and filters Microsoft SQL Server workloads* Did anyone else read this announcement from AWS and initially assume it meant Compute Optimizer is telling us we need to kill all of our SQL server workloads? No? Just us? Ok - moving on. * AWS Compute Optimizer now supports inferred workload types by filtering on the Amazon EC2 instance recommendations. * This inferred workload type features ML, and automatically detects the applications that might be running on your AWS resources.
14:52📢Justin - “When they say ML here, I assume they mean we had a regex that basically said, oh, hey, your EC2 instance is using a Microsoft with SQL Server license included, or that it's an EC2 instance that potentially has an inbound port on port 1433, which would be Microsoft SQL Server. So I'm not really sure how much ML is actually there. But it’s a nice idea.”16:09 📢Ryan - “I really did just read this as optimizers just no longer going to target Microsoft SQL workloads. It's just going to exclude them from any optimization.”GCP17:06 It’s EXTREMELY important for all of you to know that Google’s #1 priority is optimizing your costs. Let’s just get that out of the way first thing. * It’s so important to them they’re now offering discounts! Specifically, they’re offering committed use discounts for RHEL and RHEL for SAP on Compute Engine. These new CUDs can save you up to 24% when compared to on-demand PAYG prices. * Once your commitment is created with your RHEL (Red Hat Enterprise Linux) based systems, you will now automatically receive the discount and when your commitment runs out you’ll just revert to on-demand pricing. Once you are in an active commit, you cannot cancel or edit it.
18:49 Cloud Storage FUSE and CSI driver now available for GKE* Interestingly, Amazon had recently announced the same thing… * GCP has said many of their customers are leveraging Kubernetes with stateful workloads and data on Kubernetes, but customers are looking for more integrated solutions across compute and storage. * Enter Cloud Storage FUSE - objects in cloud storage buckets can be accessed as files mounted as local file systems, providing a frictionless experience for applications that need file system semantics (as long as you don’t actually try to do file things on them.) * Cloud Storage FUSE is available today in Preview, with official Google Support. * Fuse capability supports GCS, providing portability, massive scale, streaming data support, built-in support for GKE Standard and Autopilot, non-privileged access, and authenticating out of the box and extensive support for accelerators to make your life easier.
20:36 📢Ryan “This is another thing that's going to blow up in my face when you make me run SQL servers on Kubernetes.”22:45 📢Justin - “So if any of our listeners have done SQL Server on Kubernetes at any level of scale and either failed horribly or were successful, I'd love to hear from you.”(Jonathan would like to request that everyone only send their horror stories.)Azure24:17 - New Azure Virtual Desktop features to answer our customers’ top needs* Lots of new features for the Azure virtual desktop this week * Updates include FSLogix profiles for Azure AD, which joined VMs in Azure Virtual Desktop. * If you’re not familiar with FSLogix ( like we weren’t) it’s apparently a more fancy version of your desktop experience on an RDP thing. And yes, “thing” is the technical term. * Additionally, there's a fix for the FSLogix 2210 bug - and they’re REALLY excited about this. * Azure Virtual Deskop Insights at Scale - Reporting of key information across resources in one view * RDP Shortpath for public networks using the STUN protocol; which improves the transport reliability of Azure VD connections over public networks by establishing a direct UDP-based data flow between the remote desktop client and session hosts. * Symmetric Nat support for Azure Shortpath * Watermarking on Azure VD * Private link for Azure Virtual Desktop * Microsoft Teams Application Windows Sharing - Which begs the question, what OTHER bugs live in Azure VD that this was a bug that needing fixing?
26:10📢Justin - “Every screenshot you get has Microsoft Azure in the background, so everyone knows you're using Azure."30:52 Next up, for those of you who like to burn money using firewalls on Azure, they now support the virtual WAN with their first SaaS offering* + The offering is coming from Palo Alto networks, where you can subscribe to the “next generation firewall” which is an Azure native ISV service. * “At Microsoft, we are dedicated to ensuring that Microsoft Azure is the most trusted and secure cloud platform. With the preview release of the Palo Alto Networks Cloud NGFW for Azure, we are pleased to expand our ecosystem of native ISV solutions and provide customers and developers with more options to meet their security needs. This collaboration between Palo Alto Networks and Microsoft combines the scalability and reliability of Azure with Palo Alto Networks expertise to help safeguard our customers against the latest threats.”—Julia Liuson President, Microsoft Developer Division at Microsoft. * "More and more of our customers are running their business critical applications in Azure and are looking to us to help keep those workloads secure. With Cloud NGFW for Azure we are excited to combine Palo Alto Networks best-in-class security with the scalability and reliability of Azure to provide our mutual customers the ability to run their applications with confidence. As a managed Azure Native ISV service, we are proud to deliver the ease of use customers expect from a cloud native experience.”—Lee Klarich, Chief Product Officer, Palo Alto Networks.
27:55📢Matt - “This is the opposite of cloud native.”27:57📢Ryan - “Well, it's at least not a virtual device, plugged into your network and just sort of duct taped to the outside saying ‘look, security!’ You know, so if you're going to use Palo Alto for these services, and maybe you've already got a whole bunch of investment for an on-prem work site; like at least this is a path forward that I can do. It's got some scalability. I'm hoping it's got a deep integration that's beyond the virtualization presentation layer.”Continuing our Cloud Journey Series Talks31:52 Taking a little side step today - instead of talking about cloud native, we’re taking a look at an article recently put out by HashiCorp. * + Why you should run your platform team like a product team (hashicorp.com) + Ryan, Jonathan and Justin discuss this very issue often times when they talk about building services. The article is a great recap of some of their most recent content regarding CCOE.
33:50 📢Ryan - “ These infrastructure focused teams are were becoming platform teams, whether they knew it or not, right? Cause that's how complex the business has become, and how fast things need to move. That's really the only answer. You're gonna have too many customers to sort of just run infrastructure in a traditional way.”34:27📢Jonathan - “I think those SLAs are the important thing for me because there's always the assumption if you're an infrastructure team or operations team that you'll provide 100% uptime, you'll always be on call, you'll always jump on the current need of the day. And I think the move to the mindset that actually we're building platforms and development teams are our customers sort of helps formalize the idea that actually this is a service and we do have an SLA and you are a customer and we have to take your needs into consideration, but also the needs of the rest of the business.”38:09 📢 Jonathan - “I think even having a product manager for the platform itself would be interesting because typically that's a very customer-facing role in the business's customers, rather than internal customer-facing role. I think the person who takes on that role would probably have to be somebody who's very familiar with the platform itself.”46:34 📢 Justin - “Definitely check it out. If you're looking to build a platform team or you're running a cloud platform team that is trying to move to DevOps and DevSecOps, and make your team better, this is a great article for food for thought and to kind of get you thinking in the right direction about IT as a service.”Spotted on the HorizonNext week on the Cloud Pod Podcast…News From the Clouds That Didn’t Make the Main ShowAWS* Amazon GuardDuty Malware Protection adds on-demand scanning * AWS SimSpace Weaver Snapshots are now generally available * AWS Config now supports 23 new resource types * Amazon EC2 now supports AMD SEV-SNP * Amazon RDS now supports M7g and R7g database instances * Amazon EC2 C6id, M6id, R6id instances are now available in additional regions * Amazon MSK now offers multi-VPC private connectivity and cross-account access * AWS Fault Injection Simulator now supports Amazon EC2 Instance disk fill * Amazon Managed Grafana now supports workspace configuration with version 9.4 option * AWS Verified Access is now generally available * Amazon S3 now applies two security best practices to all new buckets by default * Amazon Route 53 Resolver endpoints for hybrid cloud are now available in three new AWS Regions * Amazon CloudWatch adds new console capabilities and data visualizations * Amazon Location Service adds support for long distance matrix routing * Amazon QuickSight launches two suites of data ingestion APIs * AWS Lambda adds support for Java 17 * Contact Lens for Amazon Connect evaluation capabilities are now generally available * AWS IoT Core Device Advisor announces support for MQTT over WebSocket * Amazon SageMaker accelerates local ML code conversion to remote jobs * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-sagemaker-data-wrangler-image-data-preparation/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-compute-optimizer-filtering-tags/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-security-hub-four-integration-partners/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-aurora-serverless-v1-postgresql-13/ * https://aws.amazon.com/about-aws/whats-new/2023/05/aws-health-publishes-events-eventbridge-primary-backup-regions/ https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-sns-message-data-protection-additional-regions/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-sns-fifo-topics-five-regions/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-inspector-vulnerability-intelligence-database/ * https://aws.amazon.com/about-aws/whats-new/2023/05/amazon-efs-replication-aws-regions/
GCPAzure* Azure Event Hubs Dedicated self-serve scalable clusters for mission critical Kafka, AMQP and HTTPs workloads * Azure Cosmos DB for PostgreSQL Data Encryption with Customer Managed Keys * General Availability: Centrally Managed Azure Hybrid Benefit for SQL Server * Public Preview: Azure API Management and Microsoft Defender for APIs integration * Public Preview: Azure Monitor Metrics Dataplane API released * Generally available: Azure Monitor alerts now suggests signals to alert on * Generally Available: Operation Abort in AKS * Generally Available: Inbound IP restrictions for Azure Container Apps * Public preview: Session affinity for Azure Container Apps * Generally Available: TCP support for Azure Container Apps * Generally available: Synthetic GraphQL * Generally available: API Management Authorizations * Public Preview: Support for Azure VMs using Premium SSD v2 in Azure Backup
Oracle * Experience the power of stable diffusion and NVIDIA Live Portrait at Open Data Science Conference 2023 * Using OCI Network Firewall for SSL decryption * Creating a disaster recovery solution and migrating SQL Server databases with reduced downtime using log shipping on OCI * https://blogs.oracle.com/cloud-infrastructure/post/dr-migration-sql-server-database-log-shipping
ClosingAnd that is the week in the cloud, we would like to thank our sponsors Foghorn Consulting. Check out our website, the home of The Cloud Pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome to the newest episode of The Cloud Pod podcast! Justin, Ryan and Matthew are your hosts this week as we discuss all the latest news and announcements in the world of the cloud and AI - including what’s new with Google Deepmind, as well as goings on over at the Finops X Conference. Join us! Titles we almost went with this week:* 🧠The Cloud Pod DeepMinds bring you the Cloud News * 📻The Cloud Sounds Better When Tuned Properly * ☁️The Cloud Pod Delegates Itself to Multiple Organizations * 🌧️The Cloud is Flush with Cash but Still Raining on Employees.
A big thanks to this week’s sponsor: Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.📰News this Week:📰00:43 - Finops X Foundation Conference is just around the corner * This is a great opportunity to meet with other Finops users and share knowledge, collaborate on Chalk Talk, and network in beautiful San Diego, CA. There will even be an awards ceremony on an aircraft carrier, and you KNOW you want to be there for that. * Do you like stickers? Of course you do. Everyone likes stickers! Be on the lookout for Justin - he’ll be there! And if you ask nicely (or even just sort of nicely) he’ll give you a TCP sticker, so that right there is a great reason to attend. * The conference is June 29th - 31st, and registration can be found on the Finops Foundation website. See you there!
02:51 It’s earning season. Listener discretion is advised. * Let’s start with Microsoft * + At their earnings report on Tuesday, Microsoft is reporting $52.9 billion revenue, up 7% from the previous year. Expectations were set at $51 billion. Much of this is driven by AI (because what isn’t driven by AI these days.) + Overall profits were up 9% from last year, coming in at $18.3 billion. + Microsoft Azure helped with these numbers by recording a 22% increase, vs. a 34% increase seen last year.
03:51 📢Ryan- I’m surprised with some of the numbers, just because I wasn’t expecting - after so many years of growth - that it would continue to rise despite the economic dip.”* Moving on to Google Earnings… * + Google earnings were recorded at $69.79 billion, which was higher than analysts expected, thanks partly due to Google cloud revenue and an increase in Youtube advertising (all of it aimed at my kid, apparently.) + Google cloud (GCI) revenue came in at $7.45 billion, which was slightly lower than expectations, but the good news is that Google finally recorded a profit in their cloud computing sector! This means everyone using GCI won’t be left in the dust, since we all know Google loves to kill off anything that isn’t profitable.
05:30 📢Ryan- “I imagine there’s a lot of people who have worked really hard to turn this profitable; it’s been up and down the last couple of years.”05:45 📢Matt- “I’m wondering if now they’ve kind of stabilized some of the capital expenditures, that they've kind of done with all the data center build outs and stuff like that. So now it's a little bit more maintenance and more incremental improvements, but I guess it also depends on how many new regions they open every year.”06:15 Side Note in regards to those data center maintenance issues - Have you heard about the shutdown of Europe West 9 in Paris? Starting on April 25th at 7pm PST, water damage from the fire suppression system caused a multi cluster failure, leading to the shutdown of multiple zones. Thankfully the shutdown is now limited to West 9a, which is good news for everyone - except those using West 9a. As of this morning, May 2nd, the outage is still being reported, and there’s no ETA for recovery. Our final thoughts on this… maybe just avoid France? 09:20 - Ok - back into earnings with Amazon** Amazon recorded revenue of $127.4 billion, vs. expectations that were set at $124.5 billion. So that’s good, right Wall Street? Right? Bueller? * Amazon Web Services also did a little better than expected, $21.3 billion vs. $21.22 billion. That’s a 16% growth in the first quarter, which seems good on the surface, but the good ole’ analysts over on the street still aren’t happy, since the previous quarter’s growth was a nice, round 20%. * Amazon’s CEO, Andy Jassy, was quoted as saying “There’s a lot to like about how our teams are delivering for customers, particularly amidst an uncertain economy. Our Stores business is continuing to improve the cost to serve in our fulfillment network while increasing the speed with which we get products into the hands of customers (we expect to have our fastest Prime delivery speeds ever in 2023). Our Advertising business continues to deliver robust growth, largely due to our ongoing machine learning investments that help customers see relevant information when they engage with us, which in turn delivers unusually strong results for brands. And, while our AWS business navigates companies spending more cautiously in this macro environment, we continue to prioritize building long-term customer relationships both by helping customers save money and enabling them to more easily leverage technologies like Large Language Models and Generative AI with our uniquely cost-effective machine learning chips (“Trainium” and “Inferentia”), managed Large Language Models (“Bedrock”), and AI code companion CodeWhisperer. We like the fundamentals we’re seeing in AWS, and believe there’s much growth ahead.”
11:08📢Matt - “I was about to say BINGO! At the end of that because I feel like I just heard 17 buzzwords all in a row.”11:08📢Justin - “It's a tough market, and it's tough for everybody - it's not just the cloud providers. But does that mean the gravy train of AWS is over? I don't think so… I did see some posts recently on sysadmin forums, such about moving workloads from cloud back to on-prem; and there are workloads that should never have been moved to cloud that are very static and they don't have economical advantages of using the cloud. So those decisions will be made - and those decisions should be made all the time - when you look at your workloads. But is it a big trend? I don't think it's a trend yet.” AWS15:27 There’s already a new feature for CodeCatalyst!* AWS announced a new Dev Environment dashboard for CodeCatalyst. * The dashboard enables users with the space administrator role to centrally view and manage dev environments across projects; and when using the new dashboard you can view, stop and delete dev environments belonging to your space * We are 100% taking credit for this, even though our idea for it in last week’s show was published after they made the announcement. We all have Alexa devices. We know what happened. You’re welcome. * This new feature helps justify the $20/month price tag, and we definitely expect to see more over the next few months.
17:17 - Amazon announced that S3 Compatible Storage on AWS Snowball Edge Compute Optimized Device is now generally available. * Joining a whole collection of purpose-built services to AWS Snow, customers now have access to S3 compatible storage. This will eliminate any need to re-architect applications for each deployment. * This also makes it easy for you to store data and run applications requiring Amazon S3 compatible storage across the cloud, on-premises, and at the edge in connected and disconnected environments with a consistent experience. * In addition, users can now utilize AWS OpsHub to manage Snow Family Services, as well as Amazon S3 compatible storage on the devices at the edge or remotely from a central location. This provides a unified view of the AWS services that are running on Snow devices, and automates tasks operational tasks through AWS Systems Manager * AWS OpsHub is available at no additional cost to users. * You can also use this as an intermediate storage location and allow the snow device to handle the replication; * We anticipate that this may ease your migration from traditional file systems to object storage.
20:13 📢Justin - “I do hope someday in my career I get to do a very massive storage migration, not to the point that I need the truck, but … where the point is that you have to order like a hundred of these things. Then I can build like mazes in my data center of snowball edge devices. I think it would be fun.”20:25 📢Matt - “I kinda want the truck - and get the two armored police cars to drive with it.”21:05 Amazon Inspector now supports deep inspection of EC2 instances Amazon Inspector now supports deep inspection of EC2 instances when the continual EC2 scanning feature is activated. With this expanded capability, Inspector now identifies software vulnerabilities in application programming packages including Python, Java and node.js packages and OS packages. * Go go gadget vulnerability management tool! Amazon Inspector continually scans your AWS workloads for vulnerabilities and unintended network exposures. * The AWS Regional Services list will let you know where Inspector is currently available. * Like AWS OpsHub, Inspector is available at no additional cost to users. * Note* Legacy accounts can turn this on; for new customers it’s on by default.
22:43 AWS Firewall Manager adds support for multiple administrators* Customers with multiple organizational units (OU’s) can now create up to 10 administrator accounts for your AWS Firewall managers.
22:32 📢Matt “Yeah, and the reason why I kind of thought this was interesting was lot of the stuff you could always only delegate to a single account. So things like config admin, the firewall manager, which also includes WAF, and a lot of the other ones, you can only go to one location. So this is kind of nice that you can start to subdivide stuff out, especially if you're an organization that has potentially multiple acquisitions that you're merging in; you still have your own security teams. You can kind of let them kind of manage their own aspects of it. So it's kind of just interesting to see that they are doing this. I'm curious to see if they expand it to all the other services that have delegated administrators.”Google25:17 - Google DeepMind: Bringing Together Two World Class AI Teams * Sundar Pichai himself released a letter to Google employees in regards to some changes happening with their AI organization. * He says they have created two completely state of the art and world-class research times “Leading the industry forward” but AI is moving faster than either of the teams can handle, so they’re combining the DeepMind and Google Research teams. * The new team, Google DeepMind, is poised to really accelerate Google’s AI progress.
27:30 - Bard can now help you learn to code! * Bard is still just for personal use, but it can personally help you with quite a few tasks! * As of now, Google says Bard can help you code, as well as with software development tasks, like code generation, debugging, and code explanation, something Justin specifically is excited about, because reasons. (Ryan is the reason.) * The new capability is available in 20 different programming languages, including C++, Java, Python, and Typescript - among others. You can even export your Python code without copy and pasting, making collaborative projects even easier than that diorama in 6th grade. * For users new to coding (or working with Ryan) Bard can explain pieces of code. * One of the more interesting aspects of this announcement is that this new feature of Bard is still early in its development, so they warn it may provide inaccurate, misleading, or false information. So essentially Bard has turned into Cable News. Awesome. Additionally, it may provide users with incomplete code, or code that isn’t optimal for your use. Interestingly enough, you can then ask Bard to fix that code or make it faster. The moral of the story: make sure you check Bard’s work.
28:45📢Ryan - “It is at this point that I want to remind our listeners that I am also capable of providing inaccurate misleading or false information and definitely provide code that's not optimal or non-functional.” 30:52 Next Gen Confidential VM is now available in private preview * Confidential Compute technology called AMD Secure Encrypted Virtualization-Secured Nesting Paging (AMD SEV-SNP) on general purpose N2D machines. * These new instances build upon memory encryption and adds new hardware-based security protections such as strong memory integrity, encrypted register state (Thanks to encrypted SEV-ES) and hardware-rooted remote attestation. * Brand new to you! * We offer our sincere apologies that Jonathan isn’t here to better explain this stuff to you all (and us, if we’re being honest.)
33:29📢Justin - “I think the other big lift is that most dev teams are already buried trying to get features out and then say, oh, you had to go modify your code to use this confidential computing thing. I think that's also becomes a problem for a lot of companies. And again, it goes back to the business driver. If you have the driver to do it, then you're gonna make the investment. But if you don't, it's sort of like, I'll get to it eventually. And you never, just never do.”Azure34:20 Preview: Introducing DCesv5 and ECesv5-series Confidential VMs with Intel TDX * If the AMD Confidential VMs on Google were nice, but you really wanted Intel, then Azure has you covered with the new DCesv5-series and ECesv5-series in preview. * They feature the 4th Gen Intel Xeon Scalable processors; these VMs are backed by an all-new hardware-based trusted execution environment called Intel Trust Domain Extensions (TDX). * The selling feature is that organizations can use these VMs to seamlessly bring confidential workloads to the cloud without any code changes to their applications. * DC variant up to 96vcpu and 385GB of memory; EC variant up to 64vcpu and 512GB of memory * Since you may want to attest to the environment, Azure can retrieve hardware evidence for cryptographic verification (just like Google could) of the TEE state and third-party root of trust. * Organizations will have native support for attestation with Microsoft Azure Attestation. They have worked closely with intel on support for project Amber, Intel's upcoming trust services, to help enterprises that want to enforce operator independence and separation of duties in deploying confidential computing.
35:26📢Ryan - “I like that the add test station service that I mean, I want to see that pattern grow across cloud as well. Like that's, I love the idea of being able to attest your state and verify compliance by API request. Fantastic.”35:43📢Justin - “As a person who has had to collect evidence for many audits, anything to automate that stuff and and to get confidence is always a big deal.”35:57 A little more on Project Amber * Amber is new to us so Justin researched it a bit. It’s an Intel project, and from their website “Project Amber is the code name for Intel’s groundbreaking service/SaaS-based implementation of an independent trust authority that provides attestation of workloads in a public/private multi-cloud environment.” * Don’t trust Amazon, Azure, or Google? Trust Intel! It’s an option. That’s all we’re saying. * We’ll be interested in watching where this one goes!
37:34 Cloud Cost optimization strategies with Microsoft Azure * There are many benefits to optimization of your cloud costs, including understanding your bill (I mean, who needs to understand what you’re paying, right?) Reducing carbon emissions, and improving the performance of applications. + #1 - RIght Sizing (where everyone should start) + #2 - Clean up unused resources + #3 - Buying reservations and savings plans (commit MORE money to Microsoft!) + #4 - Database and application tuning (especially if you are trying to get bigger boxes.)
39:33📢Matt - “I always feel like #2 I really feel like number two here, clean up, is always ridiculously hard because everyone's like, oh, it's in the cloud. It's only like two cents a gigabyte or three cents a gigabyte. Who cares? But people forget that if you're doing two, 200, 2000, gigabytes approaching terabytes per day, and all you're doing is aggregating and you're never cleaning up, that starts to add up to real money real fast.”Oracle40:02 Build your skills with the OCI Multicloud Architect Certification and Course * “Multicloud is the new normal” (especially if you're using Oracle databases and want to save a ton of money on licensing!) OCI is here with a new Multicloud Architect Course and Certification, so you can build up some necessary skills, have a neat little badge, and probably not make any more money. Awesome! * This certification is ideal for cloud architects interested in designing and building multi-cloud solutions utilizing Oracle services. * The Oracle learning platform is your one stop shop to get ready for your multi-cloud certification test with video courses, skill checks, exam preps, practice exams, online certification exams, credentials and more. * Public Service Announcement: this is mostly just an OCI to Azure exam. You’re welcome.
Continuing our Cloud Journey Series Talks42:44 Episode 4: All About State* Look, I know you’ve all been preached to in regards to building stateless…and we know state isn’t webscale. But hang with us a minute. + In many cases, stateless is still the best way to go, but it’s not ALWAYS the best option in regards to cloud native architecture.
43:30 📢Ryan - “I would argue that we've always built state. We've been building towards stateless to understand how to manage our state and not rely and make assumptions about our state. But very little that I've worked on doesn't have a state somewhere.”44:00 📢Matt - There's always state somewhere. Whether it's in your SQL or your caching layer or somewhere, like if you're using session caches or anything like that, there's still always state.”* Now in cloud native, a stateful approach has some advantages; the most obvious benefit is the reduction in the overhead of retrieving remote state on every request. But maintaining state may also have increased complexity. + This is tied to the fact that our perception is that we are doing things in the current way. * But now in an event-based state persistence, the stateful alternative shares an events-first way of processing and persisting state changes. Using classic shopping cart scenarios, each change to the state of the shopping cart is persisted as a sequence of events.
28:35 📢Justin - “And so this is again, thinking differently about your apps as you think about cloud native, is that where does eventing make sense? And then how do you think about state with that regard to that eventing?”* Justin and Ryan then argue about consensus protocols. (Not to be confused with the much more interesting protocol droids.) + Zookeeper vs EtcD - Ryan tries to defend it, but EtcD is behind Kubernetes, and as we’ve pointed out before Kubernetes is the new hotness, so… winning.
50:01 📢Ryan - “the argument we always have is just, is it the tool or is it how the tool is used, right? And so my argument is that if you cram too much into EtcD, you're gonna have the same problems as you do in ZooKeeper.”51:41 📢Justin - “At the end of the day, anytime you're dealing with a distributed state management system that has to get to quorum, you know, you can't overload it. And that's probably the biggest mistake people make with using EtcD and Zookeeper is they try to shove everything into it.”Spotted on the HorizonNext week on the Cloud Pod Podcast…News From the Clouds That Didn’t Make the Main ShowAWS* Choose Korean in AWS Support as Your Preferred Language * AWS Amplify supports Push Notifications for mobile and cross platform apps * AWS Lake Formation and Glue Data Catalog now manage Apache Hive Metastore resources * AWS Systems Manager now supports AWS Cloud Development Kit (CDK) applications * AWS License Manager now supports upgrading of EC2 Instances from Ubuntu to Ubuntu Pro operating system * AWS Glue Crawlers now support creating partition indexes * Apache Kafka support now available in AWS Distro for OpenTelemetry * Amazon Personalize now supports Kafka Sink connector to ingest real-time data with ease * AWS WAF Captcha launches JavaScript API support * Redesigned opportunity management experience in AWS Partner Central * AWS SAM CLI announces local testing support for API Gateway Lambda authorizers * Announcing Amazon GuardDuty support for AWS Lambda * Amazon Redshift announces general availability of Dynamic Data Masking * Introducing AWS WAF Ready Partner Offerings * Amazon Redshift announces general availability of MERGE SQL command * AWS Snowball Edge Compute Optimized now supports Amazon S3 compatible storage * AWS Amplify Flutter announces general availability for web and desktop support * Amazon Redshift announces centralized access control for data sharing with AWS Lake Formation * Amazon Comprehend improves accuracy of document classification using layout data * AWS Resource Access Manager supports fine-grained customer managed permissions * AWS Elemental Link UHD now supports Dolby Digital and Digital Plus * Amazon Keyspaces (for Apache Cassandra) supports IN operator for SELECT queries * Announcing AWS DataSync Discovery general availability (GA)
GCPAzure* Azure Service Fabric 9.1 Third Refresh Release * Generally available: Cross-region service endpoints for Azure Storage * General Availability: Support for Linux clients to use identity-based access to Azure file shares over SMB * Azure CycleCloud 8.4.0 release * The era of AI: How the Microsoft Cloud is accelerating AI transformation across industries
Oracle * Simplify IT with Oracle Cloud VMware Solution and Dell Data Protection Suite
ClosingAnd that is the week in the cloud, we would like to thank our sponsors Foghorn Consulting. Check out our website, the home of The Cloud Pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome to the newest episode of The Cloud Pod podcast! Justin, Ryan and Jonathan are your hosts this week as we discuss all the latest news and announcements in the world of the cloud and AI - including Amazon’s new AI, Bedrock, as well as new AI tools from other developers. We also address the new updates to AWS’s CodeWhisperer, and return to our Cloud Journey Series where we discuss insert dramatic music - Kubernetes! Titles we almost went with this week:* ⭐I’m always Whispering to My Code as an Individual * 🤖Azure gets an AI, Google gets an AI… and Amazon finally gets an AI * 🧑💻You can now creep out your copilot by whispering to your code * ✍️AI fails to generate an interesting show title this week
A big thanks to this week’s sponsor: Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.📰News this Week:📰AWS News@01:36 - Codewhisperer is now generally available - and includes a free tier! * -Besides just the availability, this new real-time AI coding companion also includes a FREE individual tier open to all developers. This is a (good!) surprise to us. * -The free tier works with many popular IDEs, including VS Code and Intellij IDEA among others. * -Codewhisperer can assist in productivity by creating code for repetitive or routine tasks * - Cost wise, Codewhisperer is pretty much in line with other products like GitHub Copilot. * - Python, Java, Javascript, Typescript, C#, Go, Rust, PHP, Ruby, Kotlin, C, C++, Shell Scripting, SQL and Scala * -The downside: security is fairly limited (Python and Java, for instance) * 02:50 📢Jonathan: “I’m super happy that they’ve launched with so many languages supported, and so much support for different IDE’s. It’s a great launch. It’s definitely a time saver, and I’d pay the $20 a month for the service even if there wasn’t a free tier.” * (But maybe we don’t say that too loudly, or the free tier will disappear…) * And speaking of that free tier - * 04:49 📢Jonathan: “I expect the reason there’s a free tier is so that they get much more data from user experiences, and can retrain the model based on people’s feedback.” * 05:24 📢Ryan: “It’s edging us closer to code writing code.” * -One of the things that is important to point out from our discussion today is that you can get a bit more for your money from Copilot, which also has a free tier for individuals.
@09:10 Amazon is excited to announce the Simple Database Archival Solution* -SDAS is an open source solution, available under the Apache License, and can be deployed directly from your AWS account * -Do you have a problem with being able to safely archive data from your databases? According to Amazon this is a wide ranging problem for many folks, and since storing data on-premises can be extremely costly, this may be a great alternative. * -It automates a lot of the logistics of archiving data and leverages Step Functions, Glue, S3 and Athena. * -What is supported, you may be asking? Fear not, dear reader; we have that information too! Oracle, Mysql or Microsoft SQL Server. * -SDAS, right out of the box, will also give you detailed information on the status of your data, so you always know what’s going on. Well, when it comes to archived data, anyway. * 12:00 📢Ryan - It’s clear from the write up that the purpose is not really to make that data useable, it’s to store it for compliance and regulatory reasons, right, so can you get it out when the lawsuit is filed is the success criteria.
@12:28 Amazon is getting into the AI business!* AI is going to be completely reinvented! Wait, no not really. 3rd in market maybe? Sure. * Amazon says that AI and machine learning have been a focus for Amazon for over 20 years, and that seems pretty obvious given the size of the company, and the complexities of things from their online services to robotics in their fulfillment centers. * The new tool, called Amazon Bedrock, aims to “democratize” ML and make it available for everyone to utilize and give users an easy way to build and scale generative AI. * Bedrock will give users access to multiple powerful Foundation Models for texts and images. The FMs are from AI21 labs, anthropic, stability AI, and Amazon’s Titan FMs and are accessible via an API. * Utilizing a serverless experience, users will be able to figure out what model is right for them, get started customizing their FM with their own data, and then deploy them into their own applications. Neat! * 14:05📢Ryan - I remember just lamenting about how AI seemed to be a tagline of every security or operations software that was being pitched to me, and there’s no way it could possible get worse - but what a fool I was. Because it is - you can’t open a news article without it being related to AI these days, and I can’t even keep up.” * 14:57📢Jonathan- I don’t think were in a position to predict what this space is going to look like in 6 months or 12 from now; I think the rate of innovation in this area is going to be absolutely exponential.” * 🔪Quick poll: (1) Are you saying please and thank you to Echo, Alexa, etc? (2) Will that keep us from getting murdered by AI? Nevermind. Let’s stop thinking about it.
GCP@16:48 Google has announced a new AI model for healthcare * -There’s a new cloud automation toolkit and cloud based claims acceleration suite * -They also previewed the Med-PaLM 2, described as a neural network capable of answering all of your most pressing medical questions. * -Our takeaway from this one - PLEASE someone convince WebMd to adopt this new tech. We’re tired of always being diagnosed with cancer.
@ 17:25 - Google announced the public preview of BigQuery change data capture -Joins their existing datastream for Bigquery solution which helps you seamlessly replicate data from relational databases such as MySQL, PostgreSQL, AlloyDB, and Oracle, directly in Big Query. * -Thanks to BigQuery’s native CDC support, customers can directly replicate insert, update and/or delete changes from source systems into BigQuery without complex DML Merge-based ETL pipelines, cutting out the middleman. As Jonathan pointed out, it’s not new* technology, so we’re a little surprised it wasn’t already a feature, although that may have been due to costs, and now it’s just a bit more cost effective. * 18:07 📢Ryan - This really feels like the BigQuery team is just challenging customer requests at this point; like, FINE. We’ll incorporate every database functionality into this.”
Azure@20:08 - It’s Kubernetes news from Azure today! Announcing the general availability of Azure CNI Overlay in Azure Kubernetes Service* -customers have been pushing the scales and boundaries of existing network solutions in Azure Kubernetes Services, so the new overlay will go a long way in addressing performance and scaling needs.
@22:35 Continuing our Cloud Journey Series Talks Great segues mean great content, and boy do we have some of that for you all today. And just what is great content? Kubernetes, of course! * Episode 3 of the Cloud Journey discusses - * What is Kubernetes and how does it support cloud native architecture? + The first thing you do to build a cloud native app is to put it in Kubernetes. Right? RIGHT? + The tech world revolves around Kubernetes these days. Maybe a lot of that is due to it being open source? * 24:17 📢Ryan - “I really think the Kubernetes wave has done a disservice to cloud native.” * 24:26 📢Jonathan - “I m still not entirely sure why Kubernetes as won the hearts and minds the way it has…I think part of it has to do with the prestige of companies like Google, and everyone wants to do things the Google way.” * What are the benefits of using Kubernetes for container orchestration? + There’s lots of great ways to orchestrate containers, and Kubernetes is one, but it’s really complex. + Great if you’ve got a team / support infrastructure, but it’s not simple. You really do need a team. + Did Kubernetes stifle some of the cloud native innovation in Serverless. Although, at least to Justin, Serverless is still the long term winner. + Kubernetes can add a lot of value to legacy platforms. * 28:35 📢Justin - “I hope someday we get to the end of Kubernetes as this end all, be all tool and say look we need something, simpler and easier that just works*.” * What is a service mesh and how does it help with microservice communication and management? + How does mesh ultimately help with this cloud native architecture? + Service mesh is a network infrastructure layer in the communication model. + It intercepts traffic leaving a service, applies rules, manages moving the request / data to an egress point and facilitates the flow. + Can service mesh replace networking? * 30:42 📢Justin - “If regular networking is role based access control, service mesh is the attribute based access control…It’s a way to simplify communication, because then it allows access to allow communication in a safe, prescriptive way.”
What are some popular service mesh technologies?* Are all of them based on Istio? * You definitely can do things in Console, but it’s more of a gateway proxy, but it’s not really a service mesh. * Jonathan would also like you to know about Console Connect, which Justin totally didn’t just mention.
News That Didn’t Make the Main ShowAWS* Amazon EC2 Inf2 Instances for Low-Cost, High-Performance Generative AI Inference are Now * Generally Available * Introducing AWS Libcrypto for Rust, an Open Source Cryptographic Library for Rust * Supabase Makes Extensions Easier for Developers with Trusted Language Extensions for PostgreSQL * Investigate security events by using AWS CloudTrail Lake advanced queries * Scale your authorization needs for Secrets Manager using ABAC with IAM Identity Center * Amazon EMR Serverless adds job-level billed resources for efficient cost management * AWS Lambda adds support for Python 3.10 * AWS Backup announces support for SAP HANA databases on Amazon EC2 * Amazon RDS events now include tags for filtering and routing * Prepare data easily with Amazon Personalize and Amazon SageMaker Data Wrangler integration * Amazon DocumentDB (with MongoDB compatibility) provides ODBC driver to connect from BI tools * Amazon EFS now supports up to 10 GiB/s of throughput * Amazon DynamoDB now supports up to 50 concurrent table restores * Introducing the AWS CloudFormation Template Sync Controller for Flux * AWS Elastic Disaster Recovery now simplifies launch settings management * AWS Glue launches new capability to monitor usage of Glue resources * Amazon SageMaker Collections is a new capability to organize models in the Model Registry * AWS Systems Manager Incident Manager now supports Microsoft Teams for Collaboration * Announcing availability of AL2023 and gMSA support on Amazon ECS Linux containers * Amazon ECS on AWS Fargate supports extensible ephemeral storage for Windows Tasks * Announcing updated video background blur and replacement in Amazon Chime SDK * Amazon Redshift enhances string query performance by up to 63x * Announcing AWS Elemental MediaConnect Gateway * AWS Service Management Connector introduces AWS Support and Automation integrations in Jira Cloud * Amazon EC2 Trn1n instances, optimized for network-intensive generative AI models, are now generally available * Amazon EC2 Inf2 instances, optimized for generative AI, are now generally available * AWS launches Split Cost Allocation Data for Amazon ECS and AWS Batch * EC2 Image Builder supports vulnerability detection with Amazon Inspector for custom images * AWS Ground Station now supports Wideband Digital Intermediate Frequency * Amazon EKS now supports Kubernetes version 1.26
GCP* New to Chronicle: Building Rules with Your Own Threat Intel Part 2
Azure* Generally Available: Kubernetes 1.26 support in AKS * Public preview: AKS service mesh addon for Istio * Generally Available: Long term support version in AKS * Public preview: Fail Fast Upgrade on API Breaking change detection * Generally Available: Azure CNI Overlay for Linux * OpenCost for AKS cost visibility * GA: Azure Active Directory workload identity with AKS * Azure Service Operator stable release version 2.0 now available * Hotpatch is now available on preview images of Windows Server VMs on Azure with the Desktop Experience installation mode * Generally Available: Azure App Service - New Premium v3 Offerings * Public Preview: Isovalent Cilium Enterprise through Azure Marketplace * Regional expansion: Azure Elastic SAN Public Preview is now available in more regions. * Azure Storage Mover is now Generally Available * General Availability: Azure CNI Overlay * Use Stream Analytics to process exported data from Application Insights * Connect Azure Stream Analytics to Azure Data Explorer using managed private endpoint. * Generally available: Azure Cosmos DB for PostgreSQL REST APIs * Azure SQL—General availability updates for mid-April 2023 * Generally available: Azure Cosmos DB for PostgreSQL cluster compute start and stop * Public preview: Node Resource Group (NRG) lockdown * Azure Machine Learning - General Availability for April * General Availability: Azure App Health Extension - Rich Health States * General availability: Azure DevOps 2023 Q1 * General availability: Improved scaling model for Azure Functions with Target Based Scaling * Azure SQL—Public preview updates for mid-April 2023 * General availability: Read replicas for Azure Database for PostgreSQL Flexible Server * Generally Available: New burstable SKUs for Azure Database for PostgreSQL - Flexible Server * Generally Available: Azure Database for PostgreSQL - Flexible Server in the Australia Central region. * Public preview: Azure Container Apps offers new plan and pricing structure * Generally available: Static Web Apps support for Python 3.10 * Public preview: Azure Container Apps supports user defined routes (UDR) and smaller subnets * Public preview: Azure Functions V4 programming model for Node.js * General Availability: App Configuration geo-replication * Manage your APIs with Azure API Management’s self-hosted gateway v2
Oracle * Achieve up to 50% better price-performance for big data workloads on OCI Ampere A1 Compute * Introducing the user tutorial for Cloud Shell * FastConnect integration with Megaport Cloud Router * Oracle unveils record breaking genomic analysis benchmark * New Oracle Cloud Infrastructure and Oracle Database capabilities, ready for CloudWorld Tour 2023
After ShowMass Layoffs and Absentee Bosses Create a Morale Crisis at Meta* The year of efficiency has some side effects * Employees are joking about being fired on internal slack teams and a rampant gallows humor exists * Employees are complaining though where Meta’s top executives have moved away from Silicon valley resulting in IC’s and now no middle managers as they’ve been laid off wandering around. And Zuckerberg is on Paternity leave. * Overall between the layoffs, absentee leadership and concerns about the future strategic direction by Zuckerberg has just hurt employee morale.
ClosingAnd that is the week in the cloud, we would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, slack team, send feedback or ask questions at thecloudpod.net or tweet at us with hashtag #thecloudpod
Welcome to the newest episode of The Cloud Pod podcast! Justin, Ryan and Matthew are your hosts this week as we discuss all the latest news and announcements in the world of the cloud and AI. Do people really love Matt’s Azure know-how? Can Google make Bard fit into literally everything they make? What’s the latest with Azure AI and their space collaborations? Let’s find out!Titles we almost went with this week:* Clouds in Space, Fictional Realms of Oracles, Oh My. * The cloudpod streams lambda to the cloud
A big thanks to this week’s sponsor: Foghorn Consulting, provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you have trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.📰News this Week:📰General News@00:57 - Interesting article - What is Open AI doing that Google Isn’t * (Besides making a usable product, obviously.) * -Google AI lab is separate, meaning researchers are separate from the engineers, versus Open AI where they are one combined team, which - go figure - works out better. -The article goes on to question whether Google is “losing their edge” which, as the number 3 player in the AI industry, is pretty evident. The guys discuss the two services, as well as how Bard can be crammed into every product Google makes. * 02:49 📢Ryan: “I find it kind of fascinating that Open AI, because they were first to market, gets to dictate what AI is.”
@07:01 Are you an AI developer? Are you looking to build out your own models? -Good luck. Finding the hardware to do that continues to be an issue. * The Information put out an article about a shortage of servers at all the major cloud companies, including AWS, Azure, GPC, and OCI. The biggest issue is a shortage of GPUs and GPU processors, which was one of the first and main resources to have supply chain issues. * Desktop computer GPUs are having less issues with supply. Some of that is thanks to the bottom falling out of the Bitcoin market (no need for mining anymore.) * 07:57 📢Ryan - “It’s a run on a limited resource, and GPU’s - they were the first to hit supply chain issue… it’s always been sort of a scarce resource. When I first heard of GPU’s being used for machine learning and those types of workloads, there weren’t enough of them, and it wasn’t really embedded in the type of hardware you need to run in a data center. * 09:07📢Justin - “A lot of GPU returns and GPU availability in the desktop market, which those GPU’s are better suited for doing high computational work of 3D and things that are required for getting to bitcoin… so you could use desktop GPUs but your experience won’t go as far.” * Unfortunately the smart British guy isn’t here to tell us all the ins and outs of the differences between types of GPUs, so do tune in for that next week!
@10:37 FinOps slack channels had some chatter in regards to the Amazon spot market pricing increases. * For the past couple weeks prices have continued to grow in US East 1, US AP Southeast 1A, and European servers (which are always more expensive anyway) among others. Justin discusses his ideas for why this is the case. Surprisingly (or not surprisingly at all) most of his theoretical reasons for these prices increases are pretty cynical - but they include capacity constraints in the supply chain, Amazon limiting additional buying because they’re going into earnings, and (most cynically) theorizing that Amazon is artificially increasing the prices in the spot market to boost sales and topline growth. * 12:35📢Justin - “I used to run spot instances for The Cloud Pod in US West 2 which is in Oregon, and it worked really great until re:Invent week. Then all the labs said ‘use US West 2!’ and guess what? They’re all hitting capacity that I was using in a spot market. So all my servers go down - which is a terrible scenario.”
AWS@16:56 AWS Lambda announces support for payload streaming* -Response payloads can be progressively streamed back to the client, which should help improve performance for both web and mobile apps, since functions can send partial responses as they become ready. The streaming responses will cost more in network transfer costs; billing is based on the number of bytes generated and streamed after the first 6mb, with an initial maximum response size of 20mb. The guys agree this is a useful function, but is at an early stage, since it only supports Node.js currently. We’re excited to see how this one evolves as they develop it further. * 18:09📢Ryan - “That is pretty cool actually, because that does open up Lambda for a lot more workloads that have been traditionally stuck on big servers with big beefy network connections.”
@ 21:36 - Any Proton users out there? They just announced an integration with Git for service sync. * Essentially customers can sync Proton service configurations directly from GitHub. Cool, huh? * Justin especially is interested in this one, and is excited to play with it a bit, even if Matt was a little surprised it wasn’t already in place. * We also think this one may be a really good intro for some dev teams when it comes to simple CI/CD pipelines.
@ 23:43 - You can now add an Elasticache cache to Amazon RDS databases in the RDS console. * While you could definitely do this before, you had to do your own plumbing, configurations, and configure security groups. * This new update should help accelerate application performance, and potentially lower costs, since when using caching you have to pay data transfer costs if it’s going across zones. * We’d love to give you more information, and a quick note about our experience with this, but neither our RDS servers in Oregon or RDS servers in Ohio have this option, so that’s helpful. * 26:46📢Justin: “It’s the most basic, low level integration they could have possibly done to make this work.” * 27:08📢Ryan: “It's a console enablement of the existing service” * 27:27📢Justin: “The promise of this headline is amazing - and the detail implementation is not.” * If you’re looking for “the button” - it’s DEEP and hidden in the actions menu. (Don’t search in the DBS instances menu where Justin was looking. That would make too much sense.) * Bottom line: This isn’t what we were hoping it would be. Sad face.
GCP @31:50 - No new announcements, but they added some new things to their blog. -Google Cloud deploy now supports canary deployment strategy The new deployment will support all target types, including Google Kubernetes Engine, Cloud Run, and Anthos. @ 35:39 Google also announced General Availability of Cloud Run services as backends to Internal HTTP(S) Load Balancers and Regional External HTTP(S) Load Balancers. * -Internal load balancers allow you to establish private connectivity between Cloud Run services and other services and clients on Google Cloud, on-premises, or on other clouds. Additionally, you can get custom domains, migration tools from legacy servers, identity aware proxy support. Internal load balancers are something many companies overlook, so we’re excited to see this coming out with the external load balancers. * 37:27📢Matt: “I feel like the internal load balancer is one of the harder things; a lot of times they use whatever their external tools are, and the internal load balancer is really what trip up a lot of the cloud providers and always is a later feature. So it’s nice to see that they’re doing it all at once.”
@ 38:41 - The Observability tab in the Compute Engine console has reached general availability. * -The new visualization tool for Compute Engine Fleets, which Google says is an easy way to monitor and troubleshoot the health of your fleet VMs. Cool! We like pretty graphs. * -Sorry Google. We don't mean to be mean. Next week give us some press releases so we’re less salty.
Azure @ 40:33 - Microsoft is excited to continue sucking up all the oxygen on AI with a new Azure connected learning experience (or CLX)* Do you want to learn all about AI? Of course you do! Become a data scientist today (and earn more money too!) by taking part in three new courses centered around AI data and skills. Now you too can become an Azure certified AI solutions engineer. Fancy!
@ 42:36 - AZURE IN SPACE - Azure announced advancements in technologies across multiple government agencies with multiple new features. * Are you ready for some acronyms? Because the Fed LOVES their acronyms. Ok. Here we go: advancements include: * Viasat RTE integration with Azure Orbital Ground Station, bringing high rate, low latency data streaming downlink from spacecraft directly to Azure. * A partnership with Ball Aerospace and Loft Federal on the Space Development Agency’s (SDA) National Defense Space Architecture Experimental Testbed (NeXT) program, which will bring 10 satellites with experimental payloads into orbit and provide the associated ground infrastructure. * Advancements on the Hybrid Space Architecture for the Defense Innovation Unit, U.S. Space Force and Air Force Research Lab, with new partners and demonstrations that showcase the power, flexibility, and agility of commercial hybrid systems that work across multi-path, multi-orbit, and multi-vendor cloud enabled resilient capabilities. * Seriously though, how much do we all love the name Space Force? * Azure powers Space Information Sharing and Analysis Center (ISAC) to deliver Space cybersecurity and threat intelligence operating capabilities. The watch center’s collaborative environment provides visualization of environmental conditions and threat information to rapidly detect, assess and respond to space weather events, vulnerabilities, incidents, and threats to space systems. * @43:46 📢Ryan: “Space is cool.” * That really about sums it up, doesn’t it?
@47:39 - new Azure App Service plans - will they bring greater choice and cost savings? There are two new offerings, and they’re super exciting and not confusing at all. * -We’re so happy to have Matt here to explain ALL of this stuff for us. Are you ready for this? Microsoft names for instances always make a ton of sense, so pay attention. * -“In uncertain economic times, you need more flexible options to achieve your business outcomes. To meet the need, Microsoft is excited to announce new plans for Azure App Service customers with two new offerings in the Premium V3 (Pv3) tier and expansion in the isolated v2 tier, which powers the high-security app service environment 3. The cost-effective P0v3 plan and a new series of memory-optimized (P*mv3) plans are designed to help more customers thrive and grow with Azure platform as a service (PaaS).” * Got that? Don’t say we didn’t warn you. Don’t worry. Matt is going to be able to explain it EVEN BETTER next week. Probably. Maybe. * @52:51 📢Matt: “You can’t do anything less than ultra premium - this is what I’ve learned. Everything has to be the highest end, because that’s the only way they nicely give you the security stuff that you need to make it past all your compliance.”
Oracle @ 56:28 Oracle sovereign cloud solutions are now making realms available for enhanced cloud isolation* Realms help with data sovereignty requirements by creating logical collections of cloud regions that are isolated from each other, and they don’t allow customer content to leave a region outside that realm. * Oracle’s EU Sovereign Cloud will be launching in 2023 * The EU sovereign cloud will initially be made of two regions in Germany and Spain. * TLDR; regions that are linked keep data in one governance area. Thanks Oracle. We’re super grateful to know what terrible things you’re doing on the backend. 👍
Continuing our Cloud Journey Series TalksSkipping the cloud journey. Again. We’ve been talking a bit too long already, so we should probably end here. You’re welcome. News That Didn’t Make the Main ShowAWS* Announcing media metrics for AWS Elemental MediaConvert * AWS Well-Architected Framework strengthens prescriptive guidance * Amazon SageMaker Inference Recommender improves usability and launches new features * AWS Firewall Manager adds support for six additional AWS WAF features * Amazon Connect now enables agents to handle voice calls, chats, and tasks concurrently * AWS Glue visual ETL now supports new native Amazon Redshift capabilities * Amazon Connect Voice ID now supports multiple fraudster watchlists per Voice ID domain * Amazon RDS Optimized Reads now offers up to 2X faster queries on RDS for PostgreSQL * Amazon QuickSight now supports Row Level Security tags with OR condition * Amazon GuardDuty Adds Three New Threat Detections to Alert Customers on Suspicious DNS Traffic * NICE DCV announces the general availability of the DCV Extension SDK * Amazon RDS for MySQL supports inbound replication for RDS Multi-AZ deployment option with two readable standby DB instances * Amazon RDS for MySQL now supports up to 15 read replicas for RDS Multi-AZ deployment option with two readable standby database instances * EMR on EKS now supports Apache Spark with Java 11 * RDS Custom for SQL Server now supports Multi-AZ deployments * Amazon Aurora now supports PostgreSQL 15 * AWS Trusted Advisor introduces Engage for AWS Enterprise On-Ramp Support customers (Preview) * Amazon SageMaker now supports sharing predictions with Amazon QuickSight * Amazon WorkSpaces Core introduces Microsoft Office 2019 Professional Plus bundle * AWS Security Hub launches 4 new security best practice controls * Introducing AWS Cloud Operations Competency Partners * AWS Proton introduces Git management of service configurations * Amazon CodeCatalyst Dev Environments now supports GitHub repositories * Amazon Monitron extends data stream with closure codes and status from sensors * AWS Controllers for Kubernetes (ACK) for Amazon MemoryDB is now generally available * Amazon CloudFront supports S3 Object Lambda Access Point origin * AWS Network Firewall now supports IPv6-only subnets * AWS App Runner adds 7 new compute configurations * Amazon S3 adds new visibility into object replication status * Announcing CSV Export for AWS Resource Explorer Search Results * AWS Systems Manager Distributor supports New Relic Infrastructure Monitoring agent * Amazon AppFlow announces 6 new connectors * AWS AppSync now supports publishing events to Amazon EventBridge * Amazon Rekognition launches Face Liveness to deter fraud in facial verification * Amazon EC2 Serial Console is now available on EC2 bare metal instances * Amazon Pinpoint now supports AWS PrivateLink * AWS WAF supports larger request body inspections for Amazon CloudFront distributions * AWS WAF increases web ACL capacity units limits
Azure* Enable Trusted launch on your existing Azure Gen2 VMs * NGINXaaS - Azure Native ISV Service * Azure Monitor managed service for Prometheus has updated our AKS add-on to support Windows nodes * Read replicas for Azure Database for PostgreSQL Flexible Server
Oracle * Create and manage OKE Clusters using Cluster API
AWS Puts Up a New VPC Lattice to Ease the Growth of Your ConnectivityAKA Welcome to April (how is it April already?) This week, Justin, Jonathan, and Matt are your guides through all the latest and greatest in Cloud news; including VPC Lattice from AWS, the one and only time we’ll talk about Service Catalog, and an ultra premium DDoS experience. All this week on The Cloud Pod. This week’s alternate title(s):* AWS Finally makes service catalogs good with Terraform * Amazon continues to believe retailers with supply chain will give all their data to them * Azure copies your data from S3… AWS copies your data from Azure Blobs… or how I set money on fire with data egress charges
📰News this Week:📰AWS@00:56 - Lots from AWS – Terraform and Service Catalog, Supply Chain and its crazy pricing, and VPC Lattice -Self-service provisioning of Terraform open source configured with AWS Service Catalog. This means you can define your service catalog resources with either cloud formation or Terraform. And yes, Service Catalog inception is potentially a viable thing. 📢Matt: “It’s useful when you want to give people who don’t know what they’re doing very specific things; if you’re in a large organization, really just defining exactly what people can do…but to me it really starts to remove a lot of the innovation… but if you really want your teams to leverage the cloud and innovate I feel like it does start to limit some of the different aspects of the cloud.”📢Justin: “Don’t drink the ITSM kool-aid on Service Catalog.”@ 04:32 - AWS Supply Chain is now generally available; and yes, this is the same Supply Chain that was introduced at re:Invent. AWS says it will help mitigate risks, lower costs, increase visibility and help give actual insights on the supply chain.-Honestly, we’re talking about Supply Chain because the pricing is all over the place. For example, the first 100,000 Supply Chain insights are .40/each; the next 900,000 are .13/each, and over 900,000 its .065/each. @ 09:26 - VPC Lattice is finally here! Also announced at re:Invent, this gives you the ability to connect, secure, & monitor communications between services. It also gives the ability to refine policies for both traffic management and network access. -Since the announcement, a few new capabilities have been added, including the ability to use custom domains, deploy open source AWS gateway API controllers to use Lattice with a Kubernetes-native experience, as well as giving the ability to configure SSL/TLS certificates when using HTTPS that matches the custom domain. You can also:* use the Kubernetes gateway API to connect services across multiple clusters * use an ALB or an NLB as a target for service * support IPv6 connectivity with IP address target type * -be confused by pricing
📢Justin: “Their examples of Lattice pricing hurts my brain just a little bit.”@ 13:36 - Guard Duty now supports Amazon EKS Runtime monitoring, which lets you detect Runtime threats from over 30 security findings via an EKS add on, which gives increased visibility on individual container Runtime activity. Guard Duty can tell you which potential containers are compromised, and it can be combined with audit logs. It’s kind of nice to see AWS growing the Guard Duty platform.@ 18:40 - AWS Data Sync now supports copying data from Azure Blob in a moment of “us too” when compared to Blob’s data sync. 📢Justin: “Now you can set up a really cool loop, where you can have your AWS data sync take your Blob data and then your Blob sync take the data back from S3 and that’s how you can burn a lot of money really quickly.”GCP @20:23 - Nothing of interest from GCP this week, just like last week. They had two things in their “what's new this week” but neither of those things were really new. One of them centered around the Looker Modeler for BI metrics. So that happened. Azure @ 21:24 - Announcing! Firewall enhancements for Azure! Now you have the ability to troubleshoot network performance and traffic visibility. The announcement included enhancements to logging and metrics, and offered a preview of three new tools for network administrators, including latency probe metrics, a flow trace log, and the unfortunately named fat flows (or top flows) log. It’s fine if you want to prove it’s not your firewall causing the problems, but otherwise, is it too much to ask for this all to just work? 📢Justin: “Of course Azure firewall is a cloud native firewall, so I don't want any of those things; just provide those to me in a dashboard or a security tool that would tell me these things are broken…instead you’re going to charge me a bunch of money for those other three tools, so thanks for that… but I prefer not worrying about this in my cloud.”📢Jonathan: “I like the visibility, but I don’t want to have to worry about this stuff.”@ 24:44 - DDos IP protection is entering general availability - a whole new skew on DDoS protection! This is geared towards small businesses, although the guys agree that you must be a REALLY small business to make this make sense monetarily, since Rapid Response Support, cost protection, and Azure Firewall Manager, and AWAF discounts are all missing from the base package. As a group, we’re just really looking forward to that ultra-premium DDos experience from Azure. Oracle * No Oracle news today. Not even any mud slinging.
Continuing our Cloud Journey Series Talks We WERE going to talk about Kubernetes, because let’s be real. Who isn’t* talking about Kubernetes. But Ryan decided he didn’t want to get out of bed this week, so we’re skipping our Cloud Journey series for this week, until he can rejoin us.
Spotted on the Horizon* Next week on the podcast we’re hopeful Ryan will grace us with his presence. Then we’ll get back into our Cloud Journey series.
News That Didn’t Make the Main ShowAWS* Amazon Kendra releases Microsoft OneDrive Connector * Announcing general availability for macOS Support on Amplify Library for Swift * Amazon Athena adds view support for external data sources * AWS Migration Hub now supports High Availability SAP HANA systems * Amazon SageMaker Feature Store now supports hard deletion in online store * AWS Service Catalog announces support for Terraform open source * Announcing Utilization Notifications for EC2 On-Demand Capacity Reservations * AWS Billing Conductor pricing change * Amazon Textract announces Bulk Document Uploader to test Textract on multiple documents * Amazon MWAA now supports Shell Launch Scripts * Announcing policies validations during synthesis time with AWS Cloud Development Kit (CDK) * Import data from 45+ sources for no-code ML with Amazon SageMaker Canvas * The sixth generation of Amazon EC2 instances powered by AMD processors now support faster Amazon EBS-optimized instance performance * Amazon ElastiCache for Redis simplifies creating new clusters in the AWS Management Console * Amazon SWF now supports AWS PrivateLink * AWS Trusted Advisor now includes fault tolerance checks for Amazon ECS * Amazon Textract announces updates to the AnalyzeDocument - Tables feature * AWS License Manager now offers improved license visibility and distribution across your organization * Amazon Simple Email Service now detects gaps in BIMI configuration * Amazon Simple Email Service now supports delivery and engagement graphs * AWS Cloud Map enables service editing in AWS Console * Console Toolbar is now generally available for AWS CloudShell * AWS Glue Studio visual ETL adds 10 new visual transforms * AWS Blu Insights enhances user access with single sign-on * AWS Site-to-Site VPN adds support for better visibility and control of VPN tunnel maintenance updates * Amazon GuardDuty now monitors runtime activity from containers running on Amazon EKS * Amazon Kendra launches Featured Results * AWS Compute Optimizer now supports HDD and io2 Block Express EBS volume types * Amazon SageMaker Canvas now supports NLP and CV use cases * EC2 Image Builder adds real-time build tracking and improves build speeds for image pipelines * AWS Compute Optimizer now supports EC2 instances with non-consecutive utilization data * Amazon DevOps Guru for RDS supports RDS for PostgreSQL * AWS Network Firewall announces support for ingress TLS inspection * AWS Chatbot now supports search of AWS resources and AWS content * AWS Compute Optimizer now supports 61 new EC2 instance types * AWS Well-Architected Tool Announces Consolidated Report and Enhanced Search functionality * Announcing the ACK Controllers for Amazon EventBridge and Pipes * AWS Batch now supports user-defined pod labels on Amazon EKS * Amazon SNS launches the Extended Client Library for Python to support payloads up to 2GB * AWS Elastic Disaster Recovery supports automated replication of new disks * Amazon RDS Custom now supports new General Purpose gp3 storage volumes * Amazon Omics now enables batch variant store imports * Amazon CloudFront announces support for HTTP status and response generation using CloudFront Functions * AWS re:Post now includes AWS Knowledge Center articles * AWS Toolkits for JetBrains and VS Code now support AWS SAM Accelerate to speed up application iteration * Amazon SageMaker Python SDK now supports setting default values for parameters * AWS announces Amazon DataZone (Preview) * New – Ready-to-use Models and Support for Custom Text and Image Classification Models in Amazon SageMaker Canvas
GCPAzure* Generally available: Large disk support for disaster recovery of Hyper-V VMs using Site Recovery * Public Preview: Support for Azure VMs using Ultra disks in Azure Backup * Public preview: Private Application Gateway v2 * Public preview update: Azure Automation supports PowerShell 7.2 and Python 3.10 runbooks * General Availability: New General-Purpose VMs - Dlsv5 and Dldsv5 * The “managed” IoT Edge solution on Azure stack Edge will be retired on March 31, 2024. Transition your IoT Edge workloads to an IoT Edge solution running on a Linux VM on Azure Stack Edge. * Azure Image Builder Portal Functionality now available * Azure Service Fabric 9.1 Second Refresh Release * Generally available: Mount Azure Files and ephemeral storage in Azure Container Apps * Azure Maps is now HIPAA (Health Insurance Portability and Accountability Act) compliant * Public Preview: Simplified flush operation for caches using active geo-replication * Public Preview: In-place scaling for enterprise caches * Public preview: AKS support for Kubernetes 1.26 release * Public Preview: Storage in-place sharing in Microsoft Purview in additional regions * Public Preview: Connection audit logs for Enterprise tier caches * Generally Available: Larger SKUs for App Service Environment v3 * Preview: customer managed key encryption for Enterprise tier caches * Generally available: Azure Premium SSD v2 Disk Storage in East US 2, North Europe and West US 2 * Generally available: Azure Monitor Alerts now support duplicating alert rules * Multi-Column Distribution for Dedicated SQL pools is now available! * General availability: IP Protection SKU for Azure DDoS Protection * Public Preview: Azure Migrate - Discover ASP.NET & Java web apps and assess ASP.NET in all environments * General availability: Microsoft Purview DevOps policies for Azure SQL Database * Enhanced Azure Arc integration with Datadog simplifies hybrid and multicloud observability
Oracle * Hands-on experimenting with Oracle Cloud Infrastructure and Roving Edge * OCI Domain Name System (DNS) service: More than public names * Disaster recovery at scale with OCI Full Stack Disaster Recovery * GraalVM for Java microservices in the cloud * Access OCI compliance reports on-demand in the Oracle Cloud Console
Andrew Krug from DatadogIn this episode, Andrew Krug talks about Datadog as a security observability tool, shedding light on some of its applications as well as its benefits to engineers.Andrew is the lead in Datadog Security Advocacy and Datadog Security Labs. Also a Cloud Security consultant, he started the Threat Response Project, a toolkit for Amazon Web Services first responders. Andrew has also spoken at Black Hat USA, DEFCON, re:Invent, and other platforms..DataDog Product OverviewDatadog is focused on bringing security to engineering teams, not just security people. One of the biggest advantages of Datadog or other vendors is how they ingest and normalize various log sources. It can be very challenging to maintain a reasonable data structure for logs ingested from cloud providers. Vendors try to provide customers with enough signals that they feel they are getting value while trying not to flood them with unactionable alerts. Also, considering the cloud friendliness for the stack is crucial for clients evaluating a new product. Datadog is active in the open-source community and gives back to groups like the Cloud native computing foundation. One of their popular open-source security tools created is Stratus-red-team which simulates the techniques of attackers in a clean room environment. The criticality of findings is becoming a major topic. It is necessary when evaluating that criticality is based on how much risk applies to the business, and what can be done. One of the things that teams struggle with as high maturity DevOps is trying to automate incident handling or response to critical alerts as this can cause Configuration Drift which is why there is a lot of hesitation to fully automate things. Having someone to make hard choices is at the heart of incident handling processes. Datadog Cloud SIEM was created to help customers who were already customers of logs. Datadog SIEM is also very easy to use such that without being a security expert, the UI is simple. It is quite difficult to deploy a SIEM on completely unstructured logs, hence being able to extract and normalize data to a set of security attributes is highly beneficial. Interestingly, the typical boring hygienic issues that are easy to detect still cause major problems for very large companies. This is where posture management comes in to address issues on time and prevent large breaches. Generally, Datadog is inclined towards moving these detections closer to the data that they are securing, and examining the application run time in real-time to verify that there are no issues. Datadog would be helpful to solve IAM challenges through CSPM which evaluates policies. For engineering teams, the benefit is seen in how information surfaces in areas where they normally look, especially with Datadog Security products where Issues are sorted in order of importance. Security Observability Day is coming up on the 18th of April when Datadog products will be highlighted; the link to sign up is available on the Datadog Twitter page and* Datadog community Slack*. To find out more, reach out to *Andrew on Twitter @andrewkrug and on the Datadog Security Labs website*.Top Quotes * 💡 "I think that great security solutions…start with alerts that you are hundred percent confident as a customer that you would act on" * 💡 "When we talk about the context of 'how critical is an alert?’ It is always nice to put that risk lens on it for the business" * 💡 "Humans are awesome unless you want really consistent results, and that's where automating part of the process comes into play" * 💡 "More standardization always lends itself to better detection"
This week on the podcast, Justin, Jonathan and Ryan are joined by Matt Kohn and can be found chatting about all things microservices and containers - including new Security Copilot features. In our cloud journeys, we discuss just what defines a microservice (spoiler: the guys actually agree for once) and whether or not those microservices require containers. Also on the agenda, IS Kubernetes the new Monolith? 📰News this Week:📰@4:00 - HashiCorp has announced quite a few updates for Terraform, including a number of innovations for the cloud version. This includes:-A new version of the UI (not actually new if you use the cloud version) and a new cross organizational provider, which will allow users to share via a private registry across an organization. -They introduced Projects, which will give the ability to organize workspaces and ownership boundaries within Terraform. -An Auth update will give enhanced integration between Terraform and GitHub.com-But wait, there’s more from HashiCorp! Among the updates is a new and improved pipeline model called the TFE Taskworker. This will let Terraform offer features like OPA support, dynamic provider credentials, and drift detection. 📢From Justin: “And OPA is exactly what you thought - they’re getting rid of Sentinel. No. They’re not. They’re giving you OPA AND Sentinel so you can use either/or or both of them.”AWS@7:57 AWS News - We discussed a few weeks ago the new app migration service from AWS; well, they’ve added three new features! -Import/Export: You can use the App Migration Service to import source environment inventory list from a CSV file (snazzy!) as well as exporting that same data for reporting purposes, offline reviews, and update integration. - New dashboard for server migration metrics and added 8 additional predefined actions, such as converting licenses to Amazon licensing. - ALB’s now support TLS 1.3 (Did anyone else realize they hadn’t already offered that update?)📢Matt: “I think what scares me more is the Windows update version; they have a runbook that will just do the upgrade for you. I feel like that definitely will never end well.”@14:04 - GCP: Nothing of interest this week! Still trying to get Bard to work, go figure. Google recently discussed their “shared agenda for sensible AI progress” which is essentially an “if you can’t beat ‘em regulate ‘em” ideology.SIDENOTE: Weird Amazon returns policies SIDENOTE: AI Startup Replika - it goes where you think it does. (Hint: Where the internet ALWAYS goes.) Azure@ 20:19 - Moving on to Azure - Microsoft’s inaugural secure event says they are “bringing the power of AI to security” but are they? The announcement doesn’t tell us much, but it marries GPT to Security Copilot. But is this a product they need to be selling? The guys discuss what GOOD AI integration would look like for InfoSec. 📢Ryan: “I can’t get the image out of my head of Clippy wearing a badge saying ‘Would you like to open a Sev1 incident’?”📢Justin: “Just because you have the big partnership with Open AI for billions of dollars doesn’t mean every one of your products has to get AI in a bad way.”📢Jonathan: “I wish it well, I really hope that it gets developed and we no longer have to work with real InfoSec people.” (No offense to InfoSec people, even though none of them are listening to this.)@29:10 - Even more Azure News! Azure AI is now available for ISV’s! Did Microsoft announce Azure AI last week? Yes. Are they announcing it again? Yes. Just to make sure you don’t forget they exist. But they also announced their Azure Virtual Network Manager; a solution for producing, configuring, deploying & grouping network resources. So that’s nice, right? Oracle@34:56 Oracle is in the news and they’re slinging more mud - this time in the direction of AWS. They have compared serverless and determined that Oracle can save money over serverless on AWS. A lot of the focus was on AWS’s Lambda which is proprietary, whereas OCI’s FN Project (which, spoiler alert, Oracle owns) is open source.📢Jonathan (re: AWS Lambda) “I don’t personally care that it’s not open source; it’s a service that I consume through an API, it does a thing, that I pay for. If it breaks they fix it.” The end result, can you save money with OCI? Sure. Or you could just sign up for AWS Savings Plan. Continuing our Cloud Journey Series Talks:@40:37 - Last week we talked about Cloud Native, and this week we’re taking a deep dive on microservices and containers - what are they? Is there a true definition of a microservice that we can all agree on? What we agree on: an architectural style that are small applications, have a very specific purpose and can be scaled independently of each other. 📢Justin: “I think, as an industry, we’ve sort of forgotten that containers were really made to make it easier to package and deliver software; they’re not really necessary for anything else.” Is it a microservice if it’s just an extension of a monolith? We can agree that in order to be cloud native the microservice doesn’t necessarily need to be in containers; as long as it continues to be independent of everything else. The guys discuss all things microservice, monoliths, and containers, and the benefits of using them in cloud native architecture. Also: Kubernetes. Since it’s the new monolith. Also, how do you think about CI/CD in cloud native architecture? A lot of it probably comes down to just what you’re trying to achieve for the business. Make sure to tune into next week’s podcast where the guys hold an intervention for Justin so he’ll stop suggesting running SQL Server on top of Kubernetes.Coming Up Next Week:More on the “new hotness” that is Kubernetes Links to Additional Reading and Articles Mentioned:Cheating is All You Need by Steve Yegge
On this episode of The Cloud Pod, the team discusses the new Amazon Linux 2023, Google Bard, new features of Google Chronicle Security Operations, GPT-4 from Azure Open AI, and Oracle's Kubernetes platform comparison. They also talk about cloud-native architecture as a way to adapt applications for a pivot to the cloud.A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.This week’s highlights* 🚨 AWS: Amazon announces General Availability of Amazon Linux 2023. * 🚨 GCP: New capabilities available on Google Chronicle Security Operations * 🚨 Azure: Azure announces preview of GPT-4 in Azure Open AI Service. * 🚨 Oracle: Oracle compares its Kubernetes platform with that of Hyperscalers.
Top Quotes * 💡 "The goal of Cloud Native architecture is to develop scalable resilient ports of applications that you can easily deploy and manage in a modern Cloud environment" * 💡 "You maximize the benefits of the platform you're on and you minimize the weaknesses of it when you design for that platform" * 💡 "There's nothing that prevents you from going to the cloud if you're not cloud-native, I just think you don't get the advantages of the cloud native and what the cloud brings to you"
AWS: Amazon announces General Availability of Amazon Linux 2023.* 👤 Amazon Linux 2023, a Cloud-Optimized Linux Distribution with Long-Term Support * ️🕵️ This third generation of Amazon Linux Distributions includes security policies to apply the common industry guidelines.
GCP: New capabilities available on Google Chronicle Security Operations.* 0️⃣ Chronicle Security Operations Feature Roundup * These New features enable a speedy response to threats.
Azure: Azure announces preview of GPT-4 in Azure Open AI Service.* 0️⃣ Introducing GPT-4 in Azure OpenAI Service * As billing starts on the 1st of April, customers can begin harnessing Open AI's most advanced model.
Oracle: Oracle compares its Kubernetes platform with that of Hyperscalers.* 0️⃣ Kubernetes cloud cost comparison: Who provides the best value? * They highlight both serverless and managed K8 services and compare some specific services offered by both.
The Cloud Journey Series; Cloud Native Architecture.* Cloud-Native architecture is an approach to building and running applications that use Cloud computing principles and technologies. * Some benefits are scalability, reduced time to market, better utilization of resources, integrated management and monitoring as well as efficiency with large or small-scale work. * While it is possible to move to the cloud without being cloud-native, the benefits may be reduced and there are no provisions for the typical challenges in the cloud space.
Other Headlines Mentioned:* Amazon to lay off 9,000 more workers, including at AWS, as cost-cutting effort continues * Amazon Takes Its Time Delivering Second Round of Job Cuts * AWS Chatbot Now Integrates With Microsoft Teams * Try Bard and share your feedback * AWS announces new AWS Direct Connect location in Muscat, Oman * Application Auto Scaling now supports resource tagging * AWS now allows you to bring your Windows 11 licenses to Amazon WorkSpaces * Amazon VPC Reachability Analyzer now supports 3 additional AWS networking services * Amazon Corretto 20 is now generally available * Amazon EMR now supports Amazon EC2 C7g (Graviton3) instances * Amazon Connect launches support for multiple SAML 2.0 identity providers * AWS Backup now supports VMware vSphere 8 and multiple virtual NICs * AWS Database Migration Service now generates an AWS Glue Data Catalog when migrating to Amazon S3 * AWS Migration Hub Strategy Recommendations adds support for binary analysis * AWS Database Migration Service now supports S3 data validation * Amazon CloudWatch Logs adds support for new Amazon VPC Flow Logs metadata * AWS CodeBuild now supports a small GPU machine type * Amazon GuardDuty RDS Protection for Amazon Aurora is now generally available * Amazon Kendra releases Microsoft SharePoint Cloud Connector * Amazon EC2 C6in, M6in, M6idn, R6in, and R6idn metal instances are now available * AWS Clean Rooms Now Generally Available — Collaborate with Your Partners without Sharing Raw Data * Google Cloud targets multiplayer game developers with GKE Autopilot * Pub/Sub schema evolution is now GA * Introducing time-bound Session Length defaults to improve your security posture * Announcement: Azure Active Directory backed authentication for JMS 2.0 API on Azure Service Bus * General Availability: ASP. NET web app migration to Azure App Service using PowerShell Scripts * Generally available: Encryption scopes on hierarchical namespace enabled storage accounts * Azure Maps is now HIPAA (Health Insurance Portability and Accountability Act) compliant * Public preview: Listener TLS certificates management available in the Azure portal * Public Preview: PgBouncer monitoring metrics for Azure Database for PostgreSQL - Flexible Server * Preview: JSON support for Active Geo-Replication on Azure Cache for Redis * Azure SQL—General availability updates for mid-March 2023 * General Availability: Performance workbooks for Azure PostgreSQL - Flexible Server * Azure Load Testing support for JMeter 5.5 * Now available: Azure Kubernetes Service Edge Essentials * Azure Machine Learning - Generally availability updates for March 2023 * Generally available: Azure Monitor integration with Azure Container Apps * Generally available: Azure SQL Database offline migrations in Azure SQL Migration extension * Public preview: Azure Database for MySQL connector for Power Apps, Logic Apps * Azure Red Hat OpenShift version 4.11 now available * Generally Available: Durable Functions support of managed identity for Azure Storage * Public preview: Data API builder instantly creates modern REST and GraphQL endpoints for modern databases * Public Preview: Collect Syslog from AKS nodes using Azure Monitor container insights * Public Preview: Performance Plus for Azure Disk Storage * Azure Red Hat OpenShift March Updates * Generally available: Azure Ultra Disk Storage in Brazil Southeast, South Africa North and UAE North * Azure SQL—Public preview updates for mid-March 2023 * Public Preview: Change data capture for Azure Cosmos DB analytical store * Generally available: ContainerLogV2 Schema in Azure Monitor container insights * Generally available: Metric charts support for split-by operations on multiple dimensions * Generally available: Azure Firewall Basic * Public Preview - Backup for Azure Kubernetes Service (AKS) * Public preview: Database connections support in Azure Static Web Apps * Public preview: Azure Static Web Apps support for A Record * General Availability: Support for pg_hint_plan and server extensions in Azure Database for PostgreSQL – Flexible Server * General Availability of Azure Hybrid Benefit for SQL Server on Azure VMware Solution * Azure Machine Learning - Public Preview updates for March 2023 * Azure Machine Learning – March 2023 Region Expansion Announcement * Public Preview: Selective Disk Backup and Restore in Enhanced Policy for Azure VM Backup * Generally available: Azure Digital Twins Data history supports Graph updates * Kubernetes at scale just got easier with new Oracle Container Engine for Kubernetes enhancements * OKE virtual nodes deliver a serverless Kubernetes experience * Kubernetes cluster add-on lifecycle management * First principles: Making Kubernetes serverless with OCI Virtual Nodes * Breakthrough computational analysis of grate discharge flow performed by Ansys Rocky DEM-SPH on OCI bare metal GPU shape
After show: Mark Zuckerberg will be laying off 10,000 Facebook employees.* 0️⃣ Update on Meta’s Year of Efficiency. * This comes with a manifesto highlighting his key points for making Meta a formidable tech company.
In this episode, Ravi Mayuram highlights the functionality of Couchbase as an evolutionary database platform, citing several simple day-to-day use cases and particular advantages of Couchbase.Ravi Mayuram is CTO of Couchbase. He is an accomplished engineering executive with a passion for creating and delivering game-changing products for startups as well as Fortune-500 industry-leading companies.Notes Couchbase set out to build a next-generation database. Data has evolved greatly with IT advancements. The goal was to build a database that will connect people to the newer technologies, addressing problems that relational systems did not have to solve. The fundamental shift is that earlier systems were internally focused, built for trained users but now the systems are built directly for consumers. This shift also plays out in the vast difference in the number of consumers now interacting with these systems compared to the fewer trained users previously interacting with the systems. One of the key factors that sets Couchbase apart is the No-SQL Database. It is a database that has evolved by combining five systems; a Cache and Key-value store, a Document store, a Relational document store, a Search system, and an Analytical system. Secondly, Couchbase performs well in the geo-distributed manner such that with one click, data is made available across availability zones. Lastly, all of this can be done at a large scale in seconds. Regarding the global database concept that Google talks about, a globally consistent database may not be needed by most companies. The performance will be the biggest problem as transaction speed will be considerably low. Couchbase does these transactions locally within the data center and replicates them on the other side. The main issue of relational systems is that they make you pay the price of every transaction no matter how minor, but with Couchbase, it is possible to pay only the cost only with certain crucial transactions. Edge has become a part of the enterprise architecture even such that people now have edge-based solutions. Two edges are emerging; the Network edge and the Tool edge where people are interfacing. Couchbase has built a mobile database available on devices, with sync capability.As a consumer, the primary advantage of bringing data closer to the consumer is the latency issue. Often, data has to go through firewalls and multiple steps which delays it but this is the benefit of Couchbase. The user simply continues to have access to the data while Couchbase synchronizes the data in the back. One of the applications of Couchbase in healthcare is insulin tracking. With many devices that monitor insulin which must work everywhere you go, Couchbase Lite does the insulin tracking, keeps the data even in the absence of a network, and later syncs it for review by healthcare professionals. This is also useful in operating rooms where the network is not accessible. The real benefit is seen when the data eventually gets back to the server and can be interpreted to make decisions on patient care. The Couchbase Capella Service runs in the cloud and allows clients to specify what data should be sent to the edge and what should not be. This offers privacy and security measures, such that even in the loss or damage of a device, the data is secure and can be recovered. To effectively manage edge in devices, a lot of problems must be addressed to make it easier. One of the concerns for anyone coming into Couchbase Capella is the expense of data extraction from the cloud, however, Couchbase is available on all three cloud providers. Also, with Couchbase, there is no need to keep replicating data as you can work on the data without moving it, which largely saves costs. Other use cases for Couchbase include information for flight bookings, flight crew management systems, hotel reservations, and credit card payments. To learn more, visit the Couchbase website. There is also a free trial for the Couchbase Capella Service. Top Quotes** * 💡 "The modern database has to do more than what the old database did” * 💡 "Managing edge in devices is not an easy thing, and so you have to solve a lot of problems so it becomes easier"
On this episode of The Cloud Pod, the team discusses Amazon Pi Day, Google's upcoming I/O conference, the agricultural data manager by Microsoft, and the downturn in net profits of Oracle. They also round up cloud migrations by highlighting tools from different cloud service providers that are useful for the process.A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.This week’s highlights* 🚨 AWS: Amazon celebrates Pi Day with live twitch streams. * 🚨 GCP: Google announces their I/O conference to take place near their headquarters in Mountain View. * 🚨 Azure:To increase global food production, Microsoft has created an agricultural data manager. * 🚨 Oracle: Net income for Oracle this quarter dropped to 1.9 billion.
Top Quotes * 💡 "It's been the thorn in the side of every migration I've been a part of… 'how are we going to operate FTP securely in the cloud?" * 💡 "It is not about where you are in the future to Amazon, it's about where you are today… that's why Google and Azure have some success seen as Amazon because they come in and they realize the true long-term value of the customer not the immediate short-term value of the Amazon approach"
AWS: Amazon celebrates Pi Day with live twitch streams.* 👤 Celebrate Amazon S3’s 17th birthday at AWS Pi Day 2023 * ️🕵️ They also announced 7 new capabilities across their data services.
GCP: Google announces their I/O conference to take place near their headquarters in Mountain View.* 0️⃣ Google I/O 2023 developer conference to kick off on May 10 * The full agenda will be published in the next few weeks.
Azure: To increase global food production, Microsoft has created an agricultural data manager.* 0️⃣ Announcing Microsoft Azure Data Manager for Agriculture: Accelerating innovation across the agriculture value chain * With the rising rate of hunger, this manager will provide solutions by maximizing agricultural data.
Oracle: Net income for Oracle this quarter dropped to 1.9 billion.* 0️⃣ Oracle’s stock heads south on revenue shortfall * Despite the drop, and the gap from other cloud providers, they only slightly missed Wall Street expectations.
The Cloud Journey Series; Cloud Migration Tools.* The final part of Cloud Migrations Migrations; cloud tools to help with your migration. * AWS has the highest amount of tools for cloud migrations; GCP and Azure also have some useful tools, but the least is OCI * Foghorn Consulting can help clients with planning out their migration program.
Other Headlines Mentioned:* The inside story on Mountpoint for Amazon S3, a high-performance open source file client * https://aws.amazon.com/blogs/aws/new-use-amazon-s3-object-lambda-with-amazon-cloudfront-to-tailor-content-for-end-users/ * The next generation of AI for developers and Google Workspace * Azure previews powerful and scalable virtual machine series to accelerate generative AI * ChatGPT is now available in Azure OpenAI Service * Amazon MemoryDB for Redis Announces 99.99% Availability Service Level Agreement * Application Auto Scaling now supports Metric Math for Target Tracking policies * Introducing fine-grained access controls with AWS Lake Formation and Apache Hive on Amazon EMR * Amazon EC2 M1 Mac instances now support in-place operating system updates * Amazon Keyspaces (for Apache Cassandra) now supports client-side timestamps * Announcing an updated console experience for Amazon GameLift * Amazon Kendra releases Confluence Server Connector * Amazon Kendra releases Confluence Cloud Connector * Amazon Kendra releases SharePoint OnPrem Connectors * Amazon Neptune introduces graph summary API * Announcing R6i instances for Amazon Neptune * Amazon Neptune announces support for Slow Query Logs * Amazon Connect Wisdom now supports Microsoft SharePoint Online * Amazon QuickSight adds hide collapsed columns control for Pivot table * Amazon OpenSearch Service now supports OpenSearch version 2.5 * Amazon Route 53 Resolver endpoints for hybrid cloud announces IPv6 support * Amazon EMR on EKS adds support for emitting customer metrics for managed endpoints * Amazon SageMaker Data Wrangler now supports Amazon EMR Hive as a big query engine * Amazon SES adds email receiving metrics for better visibility and control * Amazon Connect launches a new API for customers to access historical metrics * Announcing Favorites feature to organize AWS Systems Manager documents and runbooks * Announcing lower data warehouse base capacity configuration for Amazon Redshift Serverless * Amazon Aurora MySQL-Compatible Edition now supports Microsoft Active Directory authentication * Public preview: Azure Cognitive Service for Vision Powers State-of-the-Art Computer Vision Development * Public preview: Illumio for Azure Firewall * Public Preview: Azure Chaos Studio now available in * General availability: Ephemeral OS disks supports encryption at host using customer managed keys * Public preview: Accelerated Connections for Network Virtual Appliances now in Azure Marketplace * Private Preview: Azure Backup enables vaulted backups for Azure Files for comprehensive data protection. * GA: Spot Priority Mix * General availability: Yocto Kirkstone recipes for IoT Edge 1.4 LTS * Public Preview: Azure Backup enables vaulted backups for Azure Blob for comprehensive data protection. * Oracle Cloud VMware Solution with OCI block volumes * First principles: Using redundancy and recovery to achieve high durability in OCI Object Storage * OCI Object Storage is certified as Veeam Ready - Object
After show* 0️⃣ Silicon Valley Bank failed last week, alongside a few other banks. * This was a result of changes in banking regulations made by the last administration.
On this episode of The Cloud Pod, the team talks about the possible replacement of CEO Sundar Pichai after Alphabet stock went up by just 1.9%, the new support feature of Amazon EKS for Kubernetes, three partner specializations just released by Google, and how clients have responded to the AI Powered Bing and Microsoft Edge.A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.This week’s highlights* 🚨 AWS: The new Amazon EKS release: the "combiner". * 🚨 GCP: Google rolls out new partner specializations * 🚨 Azure: Microsoft releases AI-Powered Bing and Microsoft Edge.
Top Quotes * 💡 "It's always going to be a race for these cloud providers to manage every software, in general, to stay up to date because it's challenging"
AWS: The new Amazon EKS release: the "combiner"..* 👤 Amazon EKS now supports Kubernetes version 1.25 * ️🕵️ The most notable change in version 1.25 is the removal of Pod Security Policies PSPs.
GCP: Google rolls out new partner specializations.* 0️⃣ Three new Specializations help partners digitally transform customers * These new specializations are Datacenter modernization services, DevOps services and Contact Center AI services.
Azure: Microsoft releases AI-Powered Bing and Microsoft Edge.* 0️⃣ The new Bing preview experience arrives on Bing and Edge Mobile apps; introducing Bing now in Skype * With positive feedback, they will be launching the Bing and Edge mobile apps.
Other Headlines Mentioned:* Alphabet Needs to Replace Sundar Pichai * Announcing Amazon ECS Task Definition Deletion * New – Amazon Lightsail for Research with All-in-One Research Environments * Microsoft Azure innovation powers leading price-performance for SQL Server * AWS Security Hub launches 7 new security best practice controls * AWS App Runner introduces web application firewall (WAF) support for enhanced security * AWS SAM connectors now supports multiple destinations * Announcing Consolidated Control Findings and a Consolidated Controls View for AWS Security Hub * Amazon EC2 C7g instances are now available in additional regions * AWS Glue Crawlers now support integration with Lake Formation * Vertical specific bot templates in Lex Console * AWS Systems Manager for SAP is now generally available, with initial support for backing up SAP HANA databases using AWS Backup * Amazon RDS for MariaDB adds new disaster recovery (DR) capabilities with Cross-Region Automated Backups * Amazon RDS for MySQL adds new disaster recovery (DR) capabilities with Cross-Region Automated Backups * Amazon CloudWatch RUM now supports customer defined metrics for troubleshooting and monitoring * Amazon Forecast now supports built-in holiday data for 251 countries to improve your forecasting accuracy * AWS Resilience Hub adds application change capabilities and simplified APIs * AWS Transfer Family announces support for sending AS2 messages over HTTPS * Amazon QuickSight enables role-based access control to data sources that connect to Amazon S3 and Athena * AWS Transfer Family announces AWS CloudFormation support and enhanced monitoring capabilities for AS2 * Amazon Detective adds the ability to export data from Summary page panels and search results * AWS App Runner now supports HTTP to HTTPS redirect * Amazon EKS and Amazon EKS Distro now support Kubernetes version 1.25 * Amazon ECS increases the number of provisioning tasks quota to deliver faster Cluster Auto Scaling * Announcing Smart Data Validation for Amazon Fraud Detector * Amazon CloudWatch Synthetics announces new Synthetics NodeJS runtime version 3.9 * Amazon Aurora Serverless v1 now supports customer configurable maintenance windows * AWS Service Catalog now supports the ability to disassociate and delete products in one-action * SageMaker Autopilot now offers the ability to select algorithms while launching a machine learning training experiment * Amazon CloudWatch Internet Monitor is now generally available * AWS Lake Formation extends Data Filters to all regions for supported services * Amazon Redshift announces general availability of ROLLUP, CUBE, and GROUPING SETS in GROUP BY clause * AWS SimSpace Weaver now supports AWS IAM Identity Center * AWS Lambda now supports Amazon DocumentDB change streams as an event source * Autocomplete suggestions are now available on AWS Marketplace search * AWS SAM CLI announces preview of Rust build support * AWS Private CA releases open source samples to help create Matter compliant certificate authorities * Code scans for Lambda functions within Amazon Inspector now in preview * Our progress toward quantum error correction * Azure NetApp Files volume user and group quotas * Public Preview: Azure NetApp Files now support large volumes up to 500TiB in size * Public preview: Incremental snapshots for Premium SSD v2 Disk Storage * GA: Create disks from CMK-encrypted snapshots across subscriptions and in the same tenant * Public preview: Azure Managed Lustre * General availability: Azure Sphere OS version 23.02 * Public Preview: Azure NetApp Files support for 2TiB capacity pools * 3 Microsoft Azure AI product features that accelerate language learning * Exploring mTLS setup to send a client certificate to the backend and OCSP validation * Empowering operators and enterprises with the next wave of Azure for Operators services shaping the future of cloud * Azure private MEC delivers modern connected applications for industries * General availability: Scale improvements and metrics enhancements on Azure’s regional WAF * What's new in Azure Data & AI: Azure is the best place to build and run AI workloads * Microsoft commercial marketplace: Spend smarter, move faster Facebook Twitter LinkedIn * Upgrade your OCI Site-to-Site VPN tunnels to the next generation OCI VPN service * ODSA versus the OCI-Azure Interconnect * MLPerf: Benchmark multinode ML training on OCI
Revolutionizing Observability with New RelicIn this episode, Daniel explains a new strategy towards observability aimed at contextualizing large volumes of data to make it easier for users to identify the root cause of problems with their systems.Daniel Kim is a Principal Developer Relations Engineer at New Relic and the founder of Bit Project, a 501(c)(3) nonprofit dedicated to making tech accessible to under-served communities. His job is basically to get developers excited about Observability, and he hopes to inspire students to maximize their potential in tech through inclusive, accessible developer education. He is passionate about diversity and inclusion in tech, good food, and dad jokes. Show NotesFirst, it is important to differentiate between monitoring and observability. Monitoring is basically when a code is instrumented to send data to a backend, to give answers to preconceived questions. With Observability, the goal is to monitor your system so as to later ask questions that were not in mind during the instrumentation of the system. Hence, if something new comes up you can find the root cause without modifying the code. There are so many levels of things to check when troubleshooting to find the cause of a problem, and this is where observability comes in. There are different use cases for logs, metrics, and traces; Logs are files that record events, warnings, or errors however logs are ephemeral which means there is increased risk of losing a lot of data. A system needs to be in place to move logs to a central source. Another issue with logs is that it is poorly structured data. Logs are good to have as the last step of observability. Metrics and traces can however help to narrow down where to search in the logs to solve an issue. Metrics are measurements that reflect the performance or health of your applications. They give an overview of how the systems are doing but tend to not be very specific in finding the root cause of a problem; other forms of data have to be adopted to get a clear picture. This is where Traces come in. Traces are pieces of data that track a request as it goes through the system. Because of this, they can identify the root cause of an error or bottlenecks slowing down the system. However, they are very expensive and as such sampling is used when tracing but this reduces the accuracy of traces. Correlating information from logs, metrics, and traces gives a full clear picture for debugging to be carried out successfully. A lot of New Relic customers strive to get more pieces of data to get errors faster. To balance the right data at the right time with the right cost, the first step when collecting large amounts of data is to find out how your organization is leveraging the data. A quick audit of the data to identify useful data is helpful. This can be done monthly or quarterly. Unstructured logs are difficult to aggregate In the cloud native space, being able to be compatible with as many people as possible will determine the winners because there are many projects people use in production. Projects that are compatible with many other projects are the way forward. APM is still very useful to understand application performance and in the future, data from all sources will be correlated to figure out the cause of a problem. Getting value very early from the system involves having a solid infrastructure and installing APM. The real power of full stack observability is getting data from different parts of your stack so you can diagnose what part of your system is going wrong. Leveraging AI to make sense of large amounts of data for engineers is going to be a huge plus. A lot of vendors claim that their alert systems will automatically generate all alerts for you but this is not true because they would not know your team's needs. It is ultimately up to your team to set up alerts that create an observability strategy. Those who invest time into setting this up get the most ROI from New Relic. Engineers need to figure out what metrics are important to them. About New Relic One:This was made to be a singular observability platform where people can correlate various pieces of data to get more context making the work easy for engineers. The goal was to help engineers to find the information they need as fast as possible, especially during a crisis. This kind of third-party solution is much more applicable for processing millions of logs or larger data, compared to native tools. It also provides a large amount of expertise around observability and curated experiences around machine-generated data. The future seems to have customers tilting towards open-source observability solutions. OpenTelemetry is one example of this, as it brings together all observability offerings in open source in a whole stack observability experience. Visit the New Relic website to learn more about it. To learn more about ways to use New Relic, check out the New Relic Blogs. Top Quotes * 💡 "Having so much data and information about your system, you're able to quickly figure and rule out issues that you may be having that's causing the issue" * 💡 "A really good practice when we think about controlling cost is getting a really good idea of how you're actually using the data that you're collecting" * 💡 "Having structured logs is really helpful when we're talking about observability" * 💡 "Something that I've realized in the tenure that I've been working in observability is that when something sounds too good to be true, it probably is"
On this episode of The Cloud Pod, the team discusses the AWS systems manager default enablement option for all EC2 instances in an account, different ideas from leveraging innovators plus subscription using $500 Google credits, the Azure Open Source Day, the new theme for the Oracle OCI Console, and lastly, different ways to migrate to a cloud provider.A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.This week’s highlights* 🚨 AWS: AWS systems manager has a new default enablement option for all EC2 instances. * 🚨 GCP: Leveraging the innovators plus subscription to create ideas on how to use Google cloud credits. * 🚨 Azure: About Azure Open Source Day * 🚨 Oracle: Oracle redesigns OCI Console UI
Top Quotes * 💡 "There's a lot to understand about your product and the way it works before you can even think about a cloud migration" * 💡 "In the cloud, we always tell to plan for failure" * 💡 "If you're selling to your business the need to innovate… and you're going to move on a cloud journey, then you need to actually deliver on those things"
AWS: AWS systems manager has a new default enablement option for all EC2 instances* 👤 Announcing the ability to enable AWS Systems Manager by default across all EC2 instances in an account * ️🕵️ Using DHMC, core system manager capabilities are now available to all EC2 instances in an account.
GCP: Leveraging the innovators plus subscription to create ideas on how to use Google cloud credits* 0️⃣ What would you build with $500 in Google Cloud credits included with Innovators Plus * The innovators plus subscription offers $500 in credits and vouchers for certification.
Azure: About Azure Open Source Day* 0️⃣ 7 reasons to join us at Azure Open Source Day * This virtual event will take place on the 7th of March from 9 to 10:30. * Join the Azure Collective on Stack Overflow
Oracle: Oracle redesigns OCI Console UI* 0️⃣ Introducing Redwood Theming for Oracle Cloud * Although the changes are cosmetic, usability enhancements are expected. .
The Cloud Journey Series; Cloud Migrations* Cloud migration means moving your workload to a cloud provider, and the first part of this journey is the discovery phase. * After inventory and assessment, the next step is to decide exactly how to move to the cloud which can be any one of five methods. * It is imperative to consider your products and existing operational processes when migrating to a cloud provider..
Other Headlines Mentioned:* https://awsteele.com/blog/2023/02/20/a-role-for-all-your-ec2-instances.html * New: AWS Telco Network Builder – Deploy and Manage Telco Networks * Announcing AWS ParallelCluster 3.5 with a new UI for AWS ParallelCluster * Amazon Connect Cases now supports AWS PrivateLink * Amazon Detective launches an interactive workshop for investigating potential security issues * Amazon OpenSearch Service now lets you schedule service software updates during off-peak hours * AWS App Runner adds service level concurrency, CPU and Memory utilization metrics * Amazon Connect launches granular access controls for real-time metrics * AWS Incident Detection and Response now supports New Relic integration * AWS Step Functions adds integration for 35 services including EMR Serverless * Amazon CloudWatch announces increased quotas for Logs Insights * Amazon MQ adds AWS Key Management Service (AWS KMS) support for RabbitMQ brokers * Request tracing for customizations now available for AWS Control Tower Account Factory for Terraform * Amazon Managed Grafana now supports network access control * Amazon Kinesis Data Streams for Amazon DynamoDB now supports AWS CloudFormation for Global Tables * Amazon Cognito identity pool data events are now available in AWS CloudTrail * Amazon Pinpoint now supports SMS and voice spending metrics in Amazon CloudWatch * AWS WAF Captcha adds support for ten additional languages * AWS WAF Fraud Control - Account Takeover Protection now allows inspection of origin responses * Amazon Fraud Detector(AFD) launched AFD-Lists to optimize fraud prevention strategies * Amazon EC2 Dedicated Hosts now support automated maintenance on rare degradation * AWS Expands Torn Write Prevention to EC2 Im4gn, Is4gen instances and additional EBS regions * Amazon RDS for Oracle now supports early notifications of Auto minor Version Upgrades (AmVU) * Behind the Scenes at AWS – DynamoDB UpdateTable Speedup * Building your own private knowledge graph on Google Cloud * Read-write premium caching now in public preview * Public preview: Serverless Hyperscale in Azure SQL Database * Generally Available: Azure Functions Linux Elastic Premium plan increased maximum scale-out limits * Generally Available: Availability zones support for Azure Functions in new regions * Generally Available: Durable Functions support for .NET isolated model * Public Preview: Azure Communication Services Chat for Bot Framework * Public preview: Major version upgrade in Azure Database for PostgreSQL – Flexible Server * General availability: Encryption using CMK for Azure Database for PostgreSQL – Flexible Server * GA: 50K relationships per twin support in Azure Digital Twins * Public preview: VBS enclaves for Always Encrypted in Azure SQL Database * Public Preview: Jobs API to support bulk import in Azure Digital Twins * Public preview: Cluster key index in Azure Cosmos DB for Apache Cassandra * Azure SQL—General availability updates for mid-February 2023 * General availability: Azure Active Directory for Azure Database for PostgreSQL – Flexible Server * General availability: Improved geo-replication for Azure Cache for Redis * Public Preview: SDK type bindings * Generally available: Azure Functions support for Python 3.10 * Public preview: Python 3.10 Support * Public preview: Upgrade scheduler * Public preview: New General-Purpose VMs - Dlsv5 and Dldsv5 * Public Preview: Import Jobs API Support in Azure Digital Twins * General availability: Azure IoT Edge supports Ubuntu 22.04 * General availability: Azure Data Explorer Dashboards * Now Available: Azure Monitor Query client module for Go * Public Preview: Customer-managed keys for Azure NetApp Files volume encryption * Azure Backup: Enhanced experience for creating and managing private endpoints for Recovery Services vaults is now available * 6 ways to improve accessibility with Azure AI * DDoS Mitigation with Microsoft Azure Front Door * Deploy Oracle FLEXCUBE with Oracle Kubernetes Engine * Boost profitability with full flexibility: Automated DevOps on Oracle Cloud A1 compute * Announcing native OCI Object Storage provider backend support in rclone * Behind the scenes: Too slow, workflow! How OCI services use controllers to coordinate background processes
After show* 0️⃣ Northern Va. is the heart of the internet. Not everyone is happy about that. * This is due to the constant humming noise from the machines particularly disturbing those living close to it.
AI Products & EarningsOn this episode of The Cloud Pod, the team talks about the announcement of Amazon VPC resource map, Google's new AI product, the new Bing AI-powered search engine, and why multiple accounts are necessary for data centers to carry out work seamlessly in the cloud.A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.This week’s highlights* 🚨 AWS: AWS announces Amazon VPC resource map * 🚨 GCP: Sundar introduces Google's new AI product, Google Bard. * 🚨 Azure: Microsoft announces the resurgence of Bing now powered by Open AI and Edge browser.
Top Quotes * 💡 "How was Google the first one to start looking into AI and still be late to the market?" * 💡 "That's why you have a center of excellence; they're positioned centrally to be able to orchestrate all the different moving parts and be able to facilitate the communication between all the different projects and parts of not only your business but also your cloud provider's business as well" * 💡 "I think it's important to not try to answer the next ten years of problems but also to try to build in circuit breakers or flexibility into your designs so that you can quickly adapt"
AWS: AWS announces Amazon VPC resource map.* 👤 New – Visualize Your VPC Resources from Amazon VPC Creation Experience * ️🕵️ This feature shows users their existing VPC resources and routing on a single page in order to simplify VPC creation on AWS.
GCP: Sundar introduces Google's new AI product, Google Bard.* 0️⃣ An important next step on our AI journey * It is a conversational AI service, powered by LaMDA, being made available to trusted testers before the public.
Azure: Microsoft announces the resurgence of Bing now powered by Open AI and Edge browser.* 0️⃣ Reinventing search with a new AI-powered Microsoft Bing and Edge, your copilot for the web * The new Bing search engine will include a new chat experience and better search with complete answers, as well as other features.
The Cloud Journey Series; The Cloud Center of Excellence (CCOE)* The complexity of the workload being managed at data centers makes multiple accounts imperative for ease of processing. * Despite the evolution in projects and accounts, there are some poorly thought out aspects, for example, shared VPC. * The onus is on cloud users to identify what they need to communicate intrasystem and what they can have in complete isolation.
Other Headlines Mentioned: Google suffered ‘pullback’ in ad spending over holidays, Alphabet stock falls after earnings * Amazon stock falls as least profitable holiday quarter since 2014 leads to its worst annual loss on record * Amazon: Airing Out The Financial Laundry * Amazon EC2 C7g metal instances are now available * In development: New planned datacenter region in Saudi Arabia (Saudi Arabia Central) * Microsoft Azure Load Testing is now generally available * Azure Native NGINXaas makes traffic management secure and simple—now generally available * The anatomy of ransomware event targeting data residing in Amazon S3 * Optimizing your Kubernetes compute costs with Karpenter consolidation * AWS Service Management Connector for Jira Service Management customer portal * AWS announces new AWS Direct Connect location in Kolkata, India * Amazon Fraud Detector introduces Cold Start model training for customers with limited historical data * Amazon CloudWatch now supports high-resolution metric extraction from structured logs * AWS SimSpace Weaver now supports CloudFormation * AWS Glue Crawlers now support MongoDB Atlas * AWS Systems Manager Change Manager now supports a more flexible way of approving change requests * AWS Systems Manager Change Calendar now provides a more comprehensive calendar view of operational events * Amazon RDS for PostgreSQL now supports seg extension * Amazon Chime SDK now offers a Windows client library * Amazon EC2 Mac instances now support replacing root volumes for quick instance restoration * AWS SAM CLI introduces ‘sam list’ command to inspect AWS SAM resources * AWS AppConfig expands encryption capabilities, integrating with AWS Secrets Manager and AWS KMS * Amazon Connect launches AWS CloudFormation support for instance management APIs * Amazon OpenSearch Service now supports enabling SAML during domain creation * Use your own training image in a private Docker registry with Amazon SageMaker * Amazon increases NAT Gateway’s capacity to support concurrent connections to a unique destination * Amazon Omics Supports PrivateLink & CloudFormation * AWS App Runner now supports HTTP 1.0 protocol * AWS CloudFormation StackSets gives quick access to list of Regions for stack instances of a stack set * New to Chronicle: Contextual Awareness * How to migrate Cloud Storage data from multi-region to regional * How to use advance feature engineering to preprocess data in BigQuery ML * Submit your entry now for our new* Talent Transformation Google Cloud Customer Award * Demystifying BigQuery BI Engine * Advancing cancer research with public imaging datasets from the National Cancer Institute Imaging Data Commons * What Data Pipeline Architecture should I use? * Azure Red Hat OpenShift for Microsoft Azure Government—now generally available * Now available: "Find my partner" for Azure Data Explorer * Generally Available: Serverless Real-Time Inference in Azure Databricks * Azure Digital Twins Control-Plane Preview API Retirement (2021-06-31) * General Availability: Managed Run Command – Execute PowerShell or shell scripts on Virtual Machines and Scale Sets * Public Preview: Azure Digital Twins * Generally available: New storage backend for Durable Functions — Microsoft Netherite & MSSQL * Generally Available: Azure Functions support for Node.js 18 * General availability: Trusted launch for Azure VMs in Azure for US Government regions * Azure SQL Gen 4 hardware approaching end of life 31 March 2023 * Generally Available: Azure Kubernetes Service introduces two pricing tiers: Free and Standard * Meta Declares ‘Year of Efficiency’ as Revenue Stagnates
Spatial Simulations with AWS SimSpace WeaverIn this episode, Peter sits with Rahul Thakkar to discuss the revolutionary AWS SimSpace Weaver, highlighting its unique function and applications across several industries.Rahul Thakkar is the Director and General Manager of Simulation Technologies at Amazon Web Services. Before AWS, he held multiple executive roles at Boeing, Brivo, PIXIA, and DreamWorks Animation. He is an inventor, and global technology executive with a background in cloud computing, distributed and high-performance computing, media and entertainment, film, television, defense and intelligence, aerospace, and access control.His film credits include Shrek, Antz, and Legend of Bagger Vance. In 2002, he was part of the team that won an Academy Award for Shrek as the Best Animated Feature. Again in 2016, at the 88th Annual Academy Awards, Thakkar received a Technical Achievement Award.NotesAWS SimSpace Weaver enables customers to run extremely large-scale spatial simulations without having to manage any of the underlying infrastructure. It also removes the complexity of state management of entities as they move about the simulation. Previously, carrying out such simulations would be done sequentially, in a cumbersome manner over years but now it can be done in parallel in weeks. Different organizations have tried out this functionality for several scenarios and the results have been amazing. This value was largely made possible due to the approach of working with customer feedback.Rahul's interest in the cloud came much later in his career which started initially in the R&D department of the Motion Picture industry where he created many of the complex graphics in movies. He later moved into a small start-up that was developing technologies for satellite imagery and mapping, and from here he moved to aerospace. Generally, he observed the problem that it is very expensive for companies to maintain their infrastructure when dealing with simulations. It also would drain resources and distract from the main focus of the company. Eventually, knew he had to use AWS, and now he works with them.All the other primitive tools within AWS are being consumed to build the service. There is also the ability to write to S3 so that customers can write the simulations out. This helps customers to remember how the simulation played out.Relating this new service to the metaverse, Rahul believes that when it comes to the metaverse, each organization has its vision of what it should be. However, AWS built the tools to empower these organizations to build their metaverses. Despite the possibility of having competition from Azure or GCP, the focus of AWS would remain on the customer and their needs, innovation on their behalf.Identifying new problems that the service would be very applicable for is a great challenge that AWS relies on customers for, to help AWS envision where they want to go with the service. There are definitely many companies running simulations but it is hard to predict how many would migrate to the AWS SimSpace Weaver because it is still a new product. Nonetheless, a lot of industries are interested in this new service. These include smart cities, organizations ranging from local to federal or international, logistics and supply chains, large-scale event planning, or any situation where there is a need to simulate a large problem with digital replicas of the real world.Top Quotes * 💡 "The fact that we worked from the customer backwards is something that allowed us to deliver the kind of value that they're getting right now with AWS SimSpace Weaver" * 💡 "Each one of these organizations have their own vision of a metaverse"
Applying and Maximizing ObservabilityIn this episode, Christine talks about her company, Honeycomb which runs on AWS, with the goal of promoting observability for clients interested in the performance of their code or those trying to identify problem areas that need to be corrected.Christine Yen is the Co-Founder and CEO of Honeycomb. Before founding Honeycomb, she built analytics products at Parse/Facebook and loved writing software to separate signals from noise. Christine delights in being a developer in a room full of ops folks. Outside of work, Christine is kept busy by her two dogs and wants your sci-fi & fantasy book recommendations.Notes Honeycomb is an observability platform that helps customers understand why their code is behaving differently from what they expected. The inspiration behind this software came after Christine’s previous company was acquired by Facebook and they realized how software made it very easy to identify problems in large code data within a short time. This encouraged them to build the tool and make it available to all engineers.If the first wave of DevOps was Ops-people learning how to automate their working code, the second wave would be helping developers learn to operate their code. Honeycomb is designed intentionally to ensure that all types of engineers can make sense of the tool.Honeycomb has always come up with ways for customers to use AWS products and get the data reflected in Honeycomb to be manipulated. Over the last few months, they have ensured that it is possible for clients to plug into CloudWatch Log and CloudWatch metrics, and redirect data directly from AWS products into Honeycomb instead. Clients can also use Honeycomb to extract data based on what their applications are doing. This applies to performance optimization, experimentation, or any situation where a company wants to try a code to see how it performs on production. The focus remains on the application layer. Before Honeycomb, no one was using observability in this context.The pricing of Honeycomb is based on the volume of data, which makes it predictable and understandable. Unlike when the pricing scale is based on the fidelity of the data, which can be quite expensive.Challenges within the observability space: The question is how to help new engineers learn from the seasoned engineers on the team through paper trails left by the seasoned engineers. This is a problem that can only be solved by enabling teams to orient new engineers on their systems without having to create another question as part of the code.Building an AI Approach in Honeycomb may not be suitable because of the context involved, since training effective machine learning models relies on a vast amount of easily classifiable data and this does not apply in the world of software; every engineering team's systems are different from every other engineering team's systems. Honeycomb is interested in using Al to build these models in order to help users know what questions to ask.With Honeycomb, usage patterns are much more dependent on the curiosity and proficiency of the engineering team; while some engineers who are used to getting answers directly may just leave the software, those who have a culture of asking questions will benefit more from it.Top Quotes * 💡 "Not having to predict ahead of time what matters, is making such a difference in our ability as engineers to get ahead of issues, identify them quickly, resolve them" * 💡 "We're out of a world where any individual engineer holds the entire system in their head" * 💡 "Observability is the only way forward as we make our worlds ever less predictable"
On this episode of The Cloud Pod, the team discusses the upcoming 2023 in-person Google Cloud conference, the accessibility of AWS CloudTrail Lake for non-AWS activity events, the new updates from Azure Chaos studio, and the comparison between Oracle Cloud service and other Cloud providers. They also highlight the application and importance of VPCs in CCOE.A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.This week’s highlights* 🚨 AWS: AWS CloudTrail Lake now allows users to consolidate, immutably store, and analyze activity events from non-AWS sources. * 🚨 GCP: Google Cloud 2023 Next conference will be in-person. * 🚨 Azure: New updates are available in the Azure Chaos studio. * 🚨 Oracle: Oracle creates a page comparing its cloud services with AWS and others.
Top Quotes * 💡 "A transit gateway effectively is saying we're going to let you make multiple VPCs into one VPC, which is awesome" * 💡 "When you're designing VPC networking, make sure you're aware of the cost involved in cross-zone communication because it's not free and it can be quite significant"
AWS: AWS CloudTrail Lake now allows users to analyze activity events from non-AWS sources.* 👤 New – AWS CloudTrail Lake Supports Ingesting Activity Events From Non-AWS Sources * ️🕵️ Initially, AWS cloud lake was a service to access, analyze and store user and API activity from AWS as a source, but now users can set up custom events or integrate with other providers.
GCP: Google Cloud 2023 Next conference will be in-person.* 0️⃣ Google Cloud Next * This will be the first in-person Next conference since 2019.
Azure: New updates are available in the Azure Chaos studio.* 0️⃣ Chaos studio - Public preview updates for January 2023 * These updates include the availability of dynamic targeting, enabling service tags, VMSS SHutdown 2.0, and others.
Oracle: Oracle creates a page comparing its cloud services with AWS and others.* 0️⃣ Compare cloud services across OCI and other cloud providers, highlighting its equivalents to AWS, Azure and GCP
The Cloud Journey Series; The Cloud Center of Excellence (CCOE)* VPC means Virtual Private Cloud and is a service tied to almost every aspect of the cloud, especially in AWS. * Security requirements are crucial to consider with VPCs which would include ACLs and VPC Flow Logs. * Another consideration for VPCs is connectivity back to your private data center which may be through a VPN connection or a direct connect point-to-point from a third party or your data center into the cloud provider itself.
Other Headlines Mentioned:* Native OPA Support in Terraform Cloud Is Now Generally Available * Introducing Hermes, An Open Source Document Management System * New – Deployment Pipelines Reference Architecture and Reference Implementations * AWS announces Amazon-provided contiguous IPv6 CIDR blocks * Lessons learned optimizing Microsoft’s internal use of Azure * Latest OCI Blockchain Platform update enables blockchain interoperability and brings Web3 capabilities to OCI * OpenAI-backed motion to dismiss * AWS achieves ISO 20000-1:2018 certification for 109 services * Visualize AWS WAF logs with an Amazon CloudWatch dashboard * SageMaker Automatic Model Tuning now adds three new completion criteria for tuning jobs * Amazon OpenSearch Service simplifies remote reindex for VPC domains * Amazon CloudWatch now simplifies metric extraction from structured logs * Amazon Athena releases data source connector for Google Cloud Storage * AWS CloudTrail Lake now supports ingestion of activity events from non-AWS sources * AWS Systems Manager announces integration of Automation with Change Calendar * Amazon AppFlow announces 4 new data connectors * AWS announces Credential Guard support for Windows instances on Amazon EC2 * Amazon QuickSight launches Radar chart * AWS Snow Family now supports Ubuntu 20 and 22 operating systems * AWS Outposts rack local gateway now supports VPC prefix lists to simplify routing policy management * AWS Snow Family now supports software updates on AWS Snowcone * Amazon Kendra Expanded Data Formats Support * Bottlerocket now supports network bonding and VLAN tagging * Amazon RDS now supports increasing storage size when creating read replicas and restoring databases from snapshots * AWS Glue Studio Visual ETL now supports 5 new transforms * AWS announces access of Simple Monthly Calculator estimates in the AWS Pricing Calculator * AWS Fault Injection Simulator announces Pause I/O action for Amazon Elastic Block Store volumes * AWS announces three new AWS Direct Connect locations * AWS Conversational AI Competency Partner's implement high-quality chatbot solutions * Amazon Personalize simplifies onboarding with data insights * Generally available: Apply Azure storage access tiers to append blobs and page blobs with blob type conversion * General Availability: 5 GB Put Blob * Microsoft Cost Management updates—January 2023
After show* 0️⃣ Microsoft, GitHub, OpenAI urge judge to bin Copilot code rip-off case. * This request is based on grounds that the case lacks standing as there is no evidence that the plaintiff suffered harm that can be addressed by the court.
On The Cloud Pod the team reviews the multi-billion-dollar DOD contract formerly known as Jedi awarded to big tech companies; Microsoft buys a stake in LSE, raising questions; Werner shares his 2023 tech predictions and posts the Distributed Computing manifesto to his blog; and lastly, at Azure, Bell hits bumps while trying to make Microsoft safer. A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.This week’s highlights* 🚨 The Pentagon awards a cloud-computing contract that can reach up to $9 billion in total through 2028 to Amazon, Google, Microsoft, and Oracle. * 🚨 Microsoft buys 4% stake in the London Stock Exchange * 🚨 AWS: Werner posts the Distributed Computing Manifesto to his blog All Things Distributed and shares his 2023 tech predictions. * 🚨 GCP: Break down data silos with the new cross-cloud transfer feature of BigQuery Omni * 🚨 Azure: Bell hits obstacles in his push to make Microsoft more secure as feedback suggests the bar is being set too high.
Top Quotes * 💡 "The long and the short of it is that slowly over time, the ship date when buying something on Amazon or anywhere else gets closer to real-time and the cost to get it to you gets lower" * 💡 “All software has defects since it’s created and configured by humans, [But] the pattern of security incidents [and] defects in Azure reported by third parties and the related severity suggests that even Microsoft is challenged in adopting proper security controls in cloud-native development pipelines, like many enterprises.”
AWS: ALL THINGS DISTRIBUTED – WERNER VOGELS’ BLOG* 💂 Werner posted the Distributed Computing Manifesto to his blog “All Things Distributed”. * ️🕵️ The manifesto highlights the challenges Amazon was facing at the end of the 20th century, and hints at where it was headed. * 👤 He also shared his 2023 tech predictions on the blog involving cloud technology, simulated worlds, silicone chips supply chain transformation, and smart energy..
GCP: Break down data silos with the new cross-cloud transfer feature of BigQuery Omni* 0️⃣ GCP launched big query Omni in 2021 to help customers break down data silos. * 🚤 They have now added support for SQL-supported Load Statements that allowed AWS/Azure Blob data to be brought into big query as a managed table for advanced analysis. * 🚤 Feedback confirms improvements in usability, security, latency, and cost audibility.
Azure: Bell hits obstacles in his push to make Microsoft more secure.* ⬆️ After spending 23 years at Amazon, Charlie Bell, the most senior cybersecurity executive now at Microsoft, faces resistance to preventing and responding to software vulnerabilities believing that he was setting the bar too high. * 📦 If there are flaws in the software they write that leads to vulnerabilities for downtime, developers in bell’s unit can expect to be paged and asked to fix it. This is long-standing practice at AWS but a new concept at Microsoft.
Oracle: Oracle announces the availability of OCI * 🤝OCI is a serverless computer service that enables you to run containers instantly without managing any servers. * 🚤 OCI Container Instances enables you to run containerized applications without operational complexity or managing infrastructure.
TCP Lightning Round⚡ Scores are now at TCP Lightning Round Justin (9), Ryan (8), Jonathan (5), Peter (0), Joe (1).Other Headlines Mentioned:* Amazon DevOps Guru for RDS detects SQL load changes * AWS fixes vulnerability affecting container image repository * The Cloud Pub/Sub team has announced the general availability of the exactly-once-delivery feature. * Azure has launched new role-based training courses to help you tailor your azure learning * Azure Storage Mover–A managed migration service for Azure Storage. * OCI or Azure: Which offers the best value for serverless container instances? * Oracle clouds never go down, says Oracle's Larry Ellison
The Cloud Pod recaps all of the positives and negatives of Amazon ReInvent 2022, the annual conference in Las Vegas, bringing together 50,000 cloud computing professionals. This year's keynote speakers include Adam Selpisky, CEO of Amazon Web Services, Swami Sivasubramanian, Vice President of Data and Machine Learning at AWS and Werner Vogels, Amazon's CTO. Attendees and web viewers were treated to new features and products, such as AWS Lambda Snapstart for Java Functions, New Quicksight capabilities and quality-of-life improvements to hundreds of services. Justin, Jonathan, Ryan, Peter and Special guest Joe Daly from the Finops foundation talk about the show and the announcements.Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.Episode Highlights ⏰ AWS Pricing Calculator now supports modernization cost estimates for Microsoft workloads*. * ⏰ AWS Re:Invent 2022 announcements and keynote updates.
Top Quote💎 “But if I'm putting my business data into another data lake, and I want to use the business data to inform my security data, I now have to cross the lakes to even make this connection to get that data set. So I agree with you on a pure security basis in the open schema for security data is really great. My issue is that you're putting borders around these lakes, when you really want to bring the data together and be able to hydrate across. That's why we have enterprise data, we analyze data warehouses, where we have all these things to bring this data together, add context to data. And I feel like this is just more removing context.” [37:20]AWS: Amazon Goes to India AWS Pricing Calculator now supports modernization cost estimates for Microsoft workloads. [1:39]* * Introducing Finch: An open source client for container development*. [3:19]* * AWS opens its 30th region in India*. [4:51]* * New for AWS backup: Protect and restore CloudFormation stacks*. [5:57]* * Amazon ECS Service Connect enabling easy communication between microservices**. [7:31]
REINVENT RECAPDAY 1 KEYNOTE: Peter DeSantis [19:11]Compute [19:42] Announcing AWS Lambda SnapStart for Java functions. * Amazon EC2 C7gn instances is now in preview. * Introducing Elastic Network Adapter (ENA) Express for Amazon EC2 instances*.
DAY 2 KEYNOTE: Adam Selipsky [24:52]Advertising & Marketing [25:34] Announcing AWS Clean Rooms*.
Compute [26:29] New AWS SimSpace Weaver allows you to run large-scale spatial simulations in the cloud*.
Databases & Analytics [27:31] Amazon OpenSearch Serverless – Run Search and Analytics Workloads without Managing Clusters–now in preview. * AWS Announces two new capabilities to move toward a zero-ETL future on AWS. + AWS announces Amazon Aurora zero-ETL integration with Amazon Redshift. + Amazon Redshift Integration with Apache Spark. * AWS Announces Amazon DataZone. * AWS Announces Five New Capabilities for Amazon QuickSight. + Support for forecast and "why" questions in Amazon QuickSight Q. + Automated data preparation for Amazon QuickSight Q. + Paginated reporting built for the cloud. + Simple and fast analysis for large datasets. + Faster, programmatic migration to the cloud.*
Security [35:12] Amazon Security Lake – A purpose-built customer-owned data lake service*–now in preview.
DAY 1 & 2 ANNOUNCEMENTS [:]:AI/Machine Learning [41:02] AWS unveils new AI service features and enhancements at re:Invent 2022. + Amazon Textract launches analyze lending to accelerate loan document processing. + Announcing real-time capabilities in Amazon Transcribe Call Analytics API to improve customer experience. - New Search Capabilities on Amazon Kendra: * Amazon Kendra launches tabular search for HTML documents. * Amazon Kendra launches expanded language support for semantic search. - New Capabilities for Amazon HealthLake. - Amazon CodeWhisperer adds Enterprise administrative controls, simple sign-up, and support for new languages*.
Compute [42:15] New general purpose, compute optimized, and memory-optimized Amazon EC2 instances with higher packet-processing performance.* + Amazon EC2 M6in / M6idn Instances. + Amazon EC2 C6in Instances*.* * AWS Nitro Enclaves now supports Amazon EKS and Kubernetes*.* * AWS Compute Optimizer now supports external metrics from observability partners**.
Network & Content Delivery [44:18] Elastic Load Balancing capabilities for application availability.* + Announcing preview for Amazon Route 53 Application Recovery Controller zonal shift*.* + Application Load Balancer (ALB) Cross Zone Off. + Network Load Balancer (NLB) Health Check Improvements. + ALB and NLB Minimum Healthy Targets.**
Security [45:32] Amazon Inspector Now Scans AWS Lambda Functions for Vulnerabilities. * Announcing AWS KMS External Key Store (XKS)*.
Storage [46:40] Announcing a new generation of Amazon FSx for OpenZFS file systems. * Amazon FSx for NetApp ONTAP simplifies access to Multi-AZ file systems from on-premises and peered networks. * Amazon FSx for NetApp ONTAP doubles the maximum throughput capacity and SSD IOPS per file system. * AWS announces lower latencies for Amazon Elastic File System*.
DAY 3 KEYNOTE: Swami Sivasubramanian [48:36]Artificial Intelligence & Machine Learning [48:36] AWS machine learning university new educator enablement program to build diverse talent for ML/AI Jobs. * Amazon SageMaker Data Wrangler Supports SaaS Applications as Data Sources. * AWS Announces Eight New Amazon SageMaker Capabilities. + New ML governance tools for Amazon SageMaker – Simplify access control and enhance transparency over your ML projects. + Next Generation SageMaker Notebooks – Now with built-in data preparation, real-time collaboration, and notebook automation. + Preview: Use Amazon SageMaker to build, train, and deploy ML models using geospatial data*.
Database & Analytics [50:46] AWS Announces Five New Database and Analytics Capabilities. + Amazon DocumentDB Elastic Clusters. + Amazon OpenSearch Serverless – Run Search and Analytics Workloads without Managing Clusters. + Amazon Athena for Apache Spark. + AWS Glue Data Quality. + Amazon Redshift now supports Multi-AZ (Preview) for RA3 clusters. * Amazon GuardDuty RDS Protection now in preview. * Amazon Redshift now supports auto-copy from Amazon S3. * Now in preview: Amazon Redshift data sharing now supports centralized access control with AWS Lake formation*.
DAY 3 ANNOUNCEMENTS:Artificial Intelligence & Machine Learning [54:11] Introducing AWS AI Service Cards: A new resource to enhance transparency and advance responsible AI*.
Database & Analytics [54:28] Amazon Redshift announces support for dynamic data masking (preview). * Amazon Kinesis Data Firehose adds support for data stream delivery to Amazon OpenSearch Serverless*.
Networking [56:50] VPC Lattice – Simplify networking for service-to-service communication*–now in preview..
Security [58:58] AWS Verified Access Preview — VPN-less secure network access to corporate applications*.
Storage [1:00:30] AWS Announces Torn Write Prevention for EC2 I4i instances, EBS, and Amazon RDS. * Amazon S3 Access Points can now be used to securely delegate access permissions for shared datasets to other AWS accounts*.
DAY 4 KEYNOTE: Werner Vogels [1:01:43]Developer Tools [1:01:59] Announcing Amazon CodeCatalyst (preview), a unified software development service*.
Serverless [1:04:17] Step Functions Distributed Map – A Serverless Solution for Large-Scale Parallel Data Processing. * Create point-to-point integrations between event producers and consumers with Amazon EventBridge Pipes. * AWS Application Composer* is now in preview.
DAY 4 ANNOUNCEMENTS [1:05:37]Gaming [1:05:37] Introducing Amazon GameLift Anywhere – Run your game servers on your own infrastructure*.
Re:Invent Predictions 2022 (Ryan 22, Justin 15, Peter 23) [1:06:03]Peter1. Adding RDS To Savings Plan 2. GPU for Fargate 3. New mi6.xlarge family of EC2 only used by british spies
Justin1. New Graviton/Arm Based Pick - YES 2. Cognito 2.0 3. Meh Conference, only niche announcements nothing for the general market. And no additional cost savings for customers due to profitability needs at AWS
Ryan1. Significant Step Flow increases - Andrew Fitzgerald - OG 2. Salesforce Killer for CRM Ryan Lucas - CloudPod 3. SLSA solution and/or enablement/visualization/existing code family products
Jonathan1. ARM Chip Factory
⚡ TCP Lightning Round (Justin 9, Ryan 8, Jonathan 4, Peter 0, Joe 1)Amazon Textract launches the ability to detect signatures on any documentAWS Secrets Manager now supports rotation of secrets as often as every four hoursAmazon QuickSight adds line and marker customization options for line charts, Small Multiples for line, bar and pie charts and the ever popular TextboxAmazon Managed Workflows for Apache Airflow (MWAA) now offers container, queue, and database metricsAWS Service Catalog now supports syncing products with Infrastructure as Code template files from GitHub, GitHub Enterprise, or BitbucketAmazon CloudFront launches continuous deployment supportIntroducing Amazon Omics
RE:INVENT NOTICE Jonathan, Ryan and Justin will be live streaming the major keynotes starting Monday Night, followed by Adam's keynote on Tuesday, Swami's keynote on Wednesday and Wrap up our Re:Invent coverage with Werner's keynote on Thursday. Tune into our live stream here on the site or via Twitch/Twitter, etc. On The Cloud Pod this week, a new AWS region is open in Spain and NBA and Microsoft team up to transform fan experiences with cloud application modernization.
Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. General News [0:04] * 🥳 CDK for Terraform 0.14 Makes it Easier to Use Providers
Episode Highlights * ⏰ New AWS region open in Spain. * ⏰ NBA and Microsoft team up to transform fan experiences with cloud application modernization.
Top Quote 💎 “When we set this up, they still called you by voice and you had to validate when it took up to an hour to support case. And yeah, it would take forever. Like, not only did it take you to an hour, there's like 10 things you needed to do with a root account that you couldn't do with an im account. Yeah, it was brutal back then.” [9:27] AWS: Amazon Goes to Spain * 🇪🇸 New AWS region open in Spain. [2:00] * 💻 You can now assign multiple MFA devices in IAM. [2:32] * 🔈 Announcing AWS CDK Support and CodeBuild Provisioning for AWS Proton. [6:16] * 💿 Introducing the AWS Proton dashboard. [6:16] * 🧑💻 Incident Manager from AWS Systems Manager launches incident coordination capabilities for Incident Response. [7:00] * 💾 Announcing enhanced operational incident response capabilities with AWS Systems Manager and PagerDuty. [7:21] * 📀 AWS announces Amazon WorkSpaces Multi-Region Resilience. [7:56] * 📜 Announcing certificate-based authentication for Amazon WorkSpaces. [7:56] * 😌 Announcing General Availability for Amazon WorkSpaces Integration with SAML 2.0. [8:10]
Reinvent 2022 Predictions [9:27] Peter 1. Adding RDS To Savings Plan - Thanks Kap, Steve Bisson and Eric Mulatrick 2. GPU for Fargate - Defel on Reddit 3. New mi6.xlarge family of EC2 only used by british spies - Robert Martin - Finops Slack
Justin 1. New Graviton/Arm Based Pick - Thanks Akustic646 from reddit 2. Cognito 2.0 - Thanks Syphoon from Reddit 3. Meh Conference, only niche announcement its nothing for the general market. And no additional cost savings for customers due to profitability needs at AWS - Glenn - OG AWS
Ryan 1. Significant Step Flow increases - Andrew Fitzgerald - OG 2. Salesforce Killer for CRM Ryan Lucas 3. SLSA solution and/or enablement/visualization/existing code family products
Jonathan 1. ARM Chip Factory
Tie Breaker Number Ryan: 22
Justin: 15
Peter: 23 Azure: The NBA Drafts Microsoft * 😀 Azure Synapse Link for SQL is now generally available. [26:37] * 💻 DR secondary free with SQL Server on Azure Virtual Machines is now generally available. [26:58] * 🤝 NBA and Microsoft team up to transform fan experiences with cloud application modernization. [27:22]
⚡ TCP Lightning Round (Justin 9, Ryan 8, Jonathan 4, Peter 0) [28:22] * Amazon WorkSpaces announces version 2.0 of WorkSpaces Streaming Protocol. * AWS Service Management Connector now supports provisioning AWS Service Catalog products in Atlassian’s Jira Service Management Cloud * AWS Security Hub now supports bidirectional integration via AWS Service Management Connector for Atlassian’s Jira Service Management Cloud * Amazon NAT Gateway Now Allows You to Select Private IP Address for Network Address Translation * Announcing the new Applications widget on AWS Console Home * Announcing preview of the AWS SDK for SAP ABAP
And that is the week in the cloud. We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, Slack team, send feedback or ask questions at thecloudpod.net or Tcweet at us with hashtag #thecloudpod
RE:INVENT NOTICE Jonathan, Ryan and Justin will be live streaming the major keynotes starting Monday Night, followed by Adam's keynote on Tuesday, Swami's keynote on Wednesday and Wrap up our Re:Invent coverage with Werner's keynote on Thursday. Tune into our live stream here on the site or via Twitch/Twitter, etc. On The Cloud Pod this week, Amazon Time Sync is now available over the internet as a public NTP service, Amazon announces ECS Task Scale-in protection, and Private Marketplace is now in preview.
Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. Episode Highlights * ⏰ Amazon Time Sync is now available over the internet as a public NTP service. * ⏰ Amazon announces ECS Task Scale-in protection. * ⏰ Private Marketplace is now in preview.
Top Quote 💎 “And then those companies say, ‘Well, I don't have time to performance tests and regression tests and load tests.’ Or, or, ‘It's not broken, I don't want to fix it.’ You know, and so they just sit there paying more money because it's not worth the risk.” [10:37] AWS: Time for Amazon * ⚖️ Amazon announces ECS Task Scale-in protection. [2:05] * ⏳ Amazon Time Sync is now available over the internet as a public NTP service. [4:54] * 🍎 Amazon EC2 Mac instances now support Apple macOS Ventura. [6:14] * 📦 Amazon RDS now supports General Purpose gp3 storage volumes. [7:49] * 📀 Amazon EKS supports Kubernetes version 1.24. [10:53] * 🪟 New centralized Logging for Windows Containers on Amazon EKS using Fluent Bit. [15:50] * 🔊 Amazon EC2 announces new price and capacity-optimized allocation strategy for provisioning Amazon EC2 Spot Instances. [16:28] * 💻 AWS Backup now supports restore of VMware workloads to Amazon EC2. [18:37]
GCP: Privately GCP * 🔈 Private Marketplace is now in preview. [20:05] * 🧘 Google Public Sector announces continuity-of-operations offering for government entities under cyberattack. [21:48]
Azure: Empowered Azure * ❗Project Flash Update: Advancing Azure Virtual Machine availability monitoring. [23:37] * ☁️ Empowering ISVs to build and sell with the Microsoft Cloud. [25:47] * 👩🏼🤝👨🏽 More inclusive workplaces: Independent Review prompts Microsoft to release an action plan. [27:35]
⚡ TCP Lightning Round (Justin 8, Ryan 7, Jonathan 4, Peter 0) [29:00] Amazon S3 Glacier improves restore throughput by up to 10x when retrieving large volumes of archived data Amazon RDS for SQL Server now supports a linked server to Oracle Amazon RDS for Oracle now supports Amazon Elastic File System (EFS) integration AWS Secrets Manager increases the API Requests per Second limits General availability: Multivariate Anomaly Detection General availability: Retryable writes in Azure Cosmos DB for MongoDB Generally available: Static Web Apps support for preview environments in Azure DevOps Amazon EventBridge Launches New Scheduler Things Coming Up: AWS Reinvent - November 28th-Dec-2
And that is the week in the cloud. We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, Slack team, send feedback or ask questions at thecloudpod.net or Tcweet at us with hashtag #thecloudpod
On a slow news week, we talk about the new AWS Switzerland region, Googles 2022 State of Devops report and GCP gets those flexible committed use discounts!
Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. General News [4:02] * 👮 Announcing the 2022 Accelerate State of DevOps Report: A deep dive into security.
Episode Highlights * ⏰ Announcing the 2022 Accelerate State of DevOps Report: A deep dive into security. * ⏰ AWS opens a new region–its 28th– in Switzerland * ⏰ GCP unveils flexible committed use discounts.
Top Quote 💎 “Back when you only had the option of on demand or reserved instances, and you do the math… And if you run the thing, basically more than 40 hours a week, you might as well buy the Ri. You're not getting any benefit of scaling anyway, at that point. So this is this is so much better, you get the benefit of committing to an aggregate use and the discount to that with the benefit of turning stuff off when you're not using it.” [32:24] AWS: Amazon Isn’t Neutral About Switzerland * 🇨🇭 AWS opens a new region–its 28th– in Switzerland. [19:29] * 🔎 Quickly find resources in your AWS account with new Resource Explorer. [21:55]
GCP: Google Is Committed To Their Flexibility * 🔈 Announcing MongoDB connector for Apigee Integration. [24:40] * 🧘 GCP unveils flexible committed use discounts. [28:15]
Azure: Azure Needs No Downtime * 0️⃣ Zero downtime migration for Azure Front Door—now in preview. [33:57]
⚡ TCP Lightning Round (Justin 8, Ryan 7, Jonathan 4, Peter 0) [35:09] * AWS Certificate Manager now supports Elliptic Curve Digital Signature Algorithm TLS certificates * Amazon ElastiCache adds support for Redis 7 * AWS Private 5G service now includes support for multiple radio-units * Amazon ElastiCache now supports Internet Protocol Version 6 (IPv6) * GA: Encrypt Azure storage account with cross-tenant customer-managed keys
After Show: * 👖 Amazon is tightening its belt and Alexa could face cutbacks.
Things Coming Up: AWS Reinvent - November 28th-Dec-2
And that is the week in the cloud. We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, Slack team, send feedback or ask questions at thecloudpod.net or Tweet at us with hashtag #thecloudpod
On The Cloud Pod this week, Amazon announces Neptune Serverless, Google introduces Google Blockchain Node Engine, and we get some cost management updates from Microsoft.
Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. General News [1:24] * 😯 Microsoft surprises with first quarter results * 📉 Microsoft drops 6% after revealing weak guidance on its earnings call * 3️⃣ Alphabet announces Q3 results * ✂️ YouTube shrinks Alphabet; company will cut headcount growth by half in Q4 * ⚓ Amazon stock sinks 16% on weak Q4 guidance * 3️⃣ Amazon announces Q3 results * 🦥 Amazon CFO says tech giant is preparing for ‘what could be a slower growth period’ * 😞 AWS just recorded its weakest growth to date * 🏅 AWS named as a leader in the 2022 Gartner CIPS Magic Quadrant for the 12th consecutive year
Episode Highlights * ⏰ Amazon announces Neptune Serverless. * ⏰ Google introduces Blockchain Node Engine * ⏰ Cost management updates from Microsoft.
Top Quote 💎 “Google Cloud is an important partner to HashiCorp, and our enterprise customers use HashiCorp Terraform and Google Cloud to deploy mission critical infrastructure at scale. With 70 million downloads of the Terraform Google Provider this year and growing, we’re excited to collaborate closely with Google Cloud to offer our joint customers a seamless experience which we believe will significantly enhance their experience on Google Cloud.” - Burzin Patel, HashiCorp VP, Global Partner Alliances. [39:38] AWS: Amazon Goes to Neptune * 🪐 Announcing Amazon Neptune Serverless – A fully managed graph database that adjusts capacity for your workloads. [13:15] * 🖥 AWS Batch for Amazon EKS. [17:08] * ☁️ AWS Console mobile application adds support for AWS CloudShell. [20:13] * 💉 AWS Fault Injection Simulator now supports network connectivity disruption. [21:57] * 📜 AWS Private Certificate Authority introduces a mode for short-lived certificates. [24:01] * 🔈 AWS announces Amazon EKS Anywhere on Apache CloudStack. [24:51] * 🎩 Amazon EKS Anywhere now includes support for Red Hat Enterprise Linux. [26:32] * 🕶️ Announcing dark mode support in the AWS Management Console. [28:01] * 🪛 Amazon EC2 enables easier patching of guest operating system and applications with Replace Root Volume. [29:24] * ✨ Amazon Aurora supports cluster export to S3. [30:50] * 💵 Amazon MSK now offers a low-cost storage tier that scales to virtually unlimited storage. [32:02]
GCP: Google Goes Blockchain? * 🌍 Introducing assured workloads in Canada and Australia. [33:37] * 🪙 Introducing Blockchain Node Engine: fully managed node-hosting for Web3 development. [34:57] * ☁️ Google Cloud and HashiCorp deliver a more efficient approach for cloud support services. [38:59] * 💪 Introducing Sensitive Actions, a new way to help keep accounts secure. [41:20] * 💻 Join the Google Cloud BI Hackathon. [45:26] * 📀 Skaffold v2 GA: Further enhancing developer productivity. [46:41]
Azure: Microsoft’s Got that Money (Update), Honey! * 💸 Microsoft Cost Management updates—October 2022. [48:03] * 👋 General availability: Azure Cosmos DB for MongoDB data plane RBAC. [50:12]
After Show: * 😧 Why we're leaving the cloud * ⁉️Why we’re leaving the electric grid
⚡ TCP Lightning Round (Justin 8, Ryan 6, Jonathan 4, Peter 0) [50:53] * Amazon Cognito now provides user pool deletion protection * AWS Nitro Enclaves is now supported on AWS Graviton * AWS Service Management Connector now streamlines display of AWS Service Catalog products by Account and Region in ServiceNow Service Portal * Amazon SES now offers new model to simplify provisioning and managing dedicated IPs * Announcing new AWS Amplify Library for Swift, now with support for both iOS and macOS * Announcing Red Hat Enterprise Linux (RHEL) Workstation on AWS * Amazon RDS now supports events for operating system updates * Amazon Virtual Private Cloud (VPC) now supports the transfer of Elastic IP addresses between AWS accounts * AWS CloudTrail Lake now supports export of signed query results to Amazon S3 * Improve your Azure SQL Managed Instance performance with new TempDB configurations. * Auto-scale compute to higher limits with up to 80 vCores in selected regions using Azure SQL Database serverless.
Things Coming Up: AWS Reinvent - November 28th-Dec-2
And that is the week in the cloud. We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, Slack team, send feedback or ask questions at thecloudpod.net or Tweet at us with hashtag #thecloudpod
On The Cloud Pod this week, Amazon EC2 Trn1 instances for high-performance model training are now available, 123 new things were announced at Google Cloud Next ‘22, Several new Azure capabilities were announced at Microsoft Ignite, and many new announcements were made at Oracle CloudWorld.
Thank you to our sponsor, Foghorn Consulting, which provides top-notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. Episode Highlights * ⏰ Amazon EC2 Trn1 instances for high-performance model training are now available. * ⏰ 123 new things were announced at Google Cloud Next ‘22. * ⏰ Several new Azure capabilities were announced at Microsoft Ignite. * ⏰ Many new announcements from Oracle CloudWorld.
Top Quote 💎 “We are pleased to have co-designed the first ASIC Infrastructure Processing Unit with Google Cloud, which has now launched in the new C3 machine series. A first of its kind in any public cloud, C3 VMs will run workloads on 4th Gen Intel Xeon Scalable processors while they free up programmable packet processing to the IPUs securely at line rates of 200Gb/s. This Intel and Google collaboration enables customers through infrastructure that is more secure, flexible, and performant.” – Nick McKeown, Senior Vice President, Intel Fellow and General Manager of Network and Edge Group. [35:26] AWS: Increasing Your Large-Scale Distribution * 🏃 Amazon EC2 Trn1 instances for high-performance model training are now available. [1:55] * 🖥 AWS launches new local zones in Taipei and Delhi. [3:29] * 🔈 A new cost explorer console experience was just announced, and it’s Justin approved. [4:26] * ➕ Amazon Connect Cases is now generally available. [6:40]
GCP: What Will They Announce Next? * 💸 You can now manage storage costs by automatically deleting expired data using Firestore Time-To-Live (TTL). [9:23] * 📢 123 new things were announced at Google Cloud Next ‘22. [11:04] * 👮 Google introduced new capabilities for secure transformations at Next '22. [15:14] * 💳 You can now learn with an annual subscription to Google Cloud. [20:10] * 👓 Introducing the next evolution of Looker, your unified business intelligence platform. [22:49] * ☁️ Google announces 20+ cloud networking innovations at Google Next.. [24:58] * ⛑️ New Google Workspace innovations to aid in hybrid work. [28:37] * 💽 Google is unifying data across multiple sources and platforms. [33:30] * 💾 New C3 VM and Hyperdisk for Google Cloud. [35:00] * 💲 Google Cloud offers up to 11% off on Spot VM. [37:12] * 👀 Cloud Monitoring now supports PromQL. [38:23] * 🤝 Google Cloud inks cloud and payments partnership with Coinbase. [38:46] * 🇮🇱 Google Cloud opens a new region in Israel. [40:54]
Azure: Igniting the Competition * 💪 Increase productivity with Microsoft Cloud. [44:14] * 🔥 Several new Azure capabilities were announced at Microsoft Ignite. [47:08] * 👋 Introducing Microsoft Syntex: Content AI integrated with the flow of work in Microsoft Cloud. [52:15] * 🧱 Azure Firewall Basic now in preview. [53:05] * 🎲 Introducing AiDice, advanced anomaly detection with AIOps. [54:38] * ❤️🔥 From Places to Edge Workspaces, more news from Microsoft Ignite. [55:12] * 📀 You can now leverage SFTP support for Azure Blob Storage to build a unified data lake. [1:02:12] * 💻 Enterprise-grade DDoS protection for SMBs is now available in preview. [1:03:39]
Oracle: CloudWorld 2022 Announcements * 1️⃣ Oracle CloudWorld day one: Announcing Oracle Database 23c. [1:05:36] * 2️⃣ Oracle CloudWorld day two: Serverless Kubernetes, coming soon. [1:07:24]
Things Coming Up: * Kubecon US - October 24-28th * AWS Reinvent - November 28th-Dec-2
Episode 185: The Cloud Pod is flush with Cache! On The Cloud Pod this week, Amazon introduces their new file cache for on premises systems, Google introduces GKE Autopilot, and Azure helps you strengthen your security even more.
Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.
Episode Highlights * ⏰ Introducing Amazon File Cache, the new AWS cache for on-premises file systems. * ⏰ Google introduces support for GPU workloads and more in GKE Autopilot. * ⏰ Strengthen your security with Policy Analytics for Azure Firewall.
Top Quote 💎 “I get the feeling that the multiple tenancy, in a way is probably the selling point here. That as you acquire new companies, or as you bring on new partners dynamically, it's easier to integrate those IDPs. Whereas previously, it's been pretty difficult to to have multiple sources of identity, I guess it sort of abstracts those and provides a single layer to the Google identity service.” [22:07” General News: * 😨 We will not be recording during the week of Google Cloud Next, so our episodes will be slightly delayed–fear not, we’re recording an episode immediately after Next so we can deliver your weekly dose of cloud news ASAP.
AWS: All About the Cache
GCP: Put Your Work on Autopilot?
Azure: Budget Updates on the Go! * 💪 Strengthen your security with Policy Analytics for Azure Firewall. [25:18] * 💰 Cost Management updates for September, including the ability to track budgets from the Azure mobile app! [28:17] * 👋 Azure SQL Database Hyperscale reverse migration to general purpose tier is now generally available.. [30:06] * 🔊 Generally available: Azure Functions .NET Framework support in the isolated worker model. [32:05]
Oracle: Is it Halloween or April Fool’s Day?
TCP Lightning Lightning Round [37:01]
⚡️ With Justin out this week, Ryan looks to take over as champion:
Justin (8), Ryan (6), Jonathan (4), Peter (1).
AWS Service Catalog console makes improvements on usability AWS announces updated Support Plans Console with new IAM controls AWS Systems Manager adds CloudWatch Alarms to control tasks Bottlerocket is now supported by Amazon Inspector AWS Certificate Manager Private Certificate Authority is now AWS Private Certificate Authority
(Lets hope this starts a trend… looking at you Simple Systems Manager)
Things Coming Up:
Google Cloud Next - October 11th - 13th Oracle Cloud World - October 17-20th Devops Enterprise Summit US Flagship - October 18th-20th - Las Vegas Kubecon US - October 24-28th AWS Reinvent - November 28th-Dec-2 (assumed)
And that is the week in the cloud. We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, Slack team, send feedback or ask questions at thecloudpod.net or Tcweet at us with hashtag #thecloudpod
On The Cloud Pod this week, AWS announces an update to IAM role trust policy behavior, Easily Collect Vehicle Data and Send to the Cloud with new AWS IoT FleetWise, now generally available, Get a head start with no-cost learning challenges before Google Next ‘22.
Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.
Episode Highlights * ⏰ AWS announces an update to IAM role trust policy behavior. * ⏰ Easily Collect Vehicle Data and Send to the Cloud with new AWS IoT FleetWise, now generally available. * ⏰ Get a head start with no-cost learning challenges before Google Next ‘22.
General News: * 📱 Google Next is coming up in two weeks. [0:56] * 😨 Next week’s show will be sans Justin. [1:02]
AWS: More like “Announcement” Web Services
GCP: Google Next Is Almost Here!
Azure: Read This if You’re Running PostgreSQL 11?
TCP Lightning Round [30:06]
⚡️ Ryan, Jonathan, and Peter are making it a little too easy at this point:
Justin (8), Ryan (5), Jonathan (4), Peter (1).
Azure unmanaged disks will be retired on 30 September 2025 Continuous delivery setting of Azure VM will be retired on 31 March 2023 – Use Azure DevOps to create pipelines Deployment Center setting of Azure Kubernetes service (AKS) will be retired on 31 March 2023 – Use Automated Deployments to create pipelines Announcing availability of AWS Outposts rack in Kazakhstan and Serbia Amazon Kendra releases Dropbox connector AWS Cost Categories now support retroactive rules application AWS Copilot, a CLI for the containerized apps, adds IAM permission boundaries and more
Things Coming Up: Google Cloud Next - October 11th - 13th Oracle Cloud World - October 17-20th Devops Enterprise Summit US Flagship - October 18th-20th - Las Vegas Kubecon US - October 24-28th AWS Reinvent - November 28th-Dec-2 (assumed)
And that is the week in the cloud. We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, Slack team, send feedback or ask questions at thecloudpod.net or Tcweet at us with hashtag #thecloudpod
On The Cloud Pod this week, AWS Enterprise Support adds incident detection and response, the announcement of Google Cloud Spanner, and Oracle expands to Spain.
Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. Episode Highlights * ⏰ AWS Enterprise Support adds incident detection and response * ⏰ You can now get a 90-day free trial of Google Cloud Spanner * ⏰ Oracle opens its newest cloud infrastructure region in Spain
Top Quote 💎 “A very large percentage of MySQL HeatWave customers are AWS users who are migrating off Aurora. However, there are still some AWS customers who are not able to migrate to OCI. This is a service where the data plane, control plane and console are natively running on AWS. We have taken the MySQL HeatWave code and optimized it for AWS infrastructure.”
-Nipun Agarwal, senior vice president of MySQL, Database and HeatWave at Oracle. General News: 🆕 Moving from Ruby to Go, Vagrant 2.3 Introduces Go Runtime. [0:58] AWS: New Proactive Monitoring from AWS * 🚨 AWS Enterprise Support adds incident detection and response. [2:01] * 🙂 Helping to vastly reduce failover times, Amazon RDS Proxy adds support for Amazon RDS for SQL Server. [3:59] * 📑 Beginning October 11th, ACM public certificates will be issued by one of the Intermediate CA’s that AWS manages. [7:46] * 💽 AWS has announced direct VPC routing for AWS outposts. [10:23] * 🖥️ You can now deploy your Amazon EKS Clusters Locally on AWS Outposts. [12:12]
GCP: Free Trial Here! Get Your Free Trial Here! * 🤑 You can now get a 90-day free trial of Google Cloud Spanner. [14:04] * 👮 If you need a new way to protect your data, try Google introduced fine-grained access control for Cloud Spanner. [14:58] * 📀 Googles Database Migration service now supports Google Alloy DB in preview. [16:30] * 🧑💻 Revelations from Storage Innovation Day [17:36] * 🍻 Hold our collective beers… you can now Sign up for the Google Cloud Fly Cup Challenge. [20:31] * 🗣️ Google has announced Pub/Sub metrics dashboards for improved observability. [22:52] * 💻 Virtual Machine support in Anthos is now generally available. [25:14] * 🖱️ Beginning this month, Vertex AI matching engine and feature store will support real-time streaming ingestion as preview features. [26:54]
Azure: Low-latency Streaming… What Is It Good For? * 🔋 Azure Media Services low-latency live streaming is now generally available. [27:51] * 📈 The ability to resize peered virtual networks is now generally available. [30:56]
Oracle: Oracle goes abroad * 💰 Oracle’s total revenue increases by 23% in the first fiscal quarter. [32:44] * 🇪🇸 Oracle opens its newest cloud infrastructure region in Spain [34:53] * ☁️ Only two years later, Oracle finally brings MySQL heatwave to the Amazon Cloud. [35:56]
TCP Lightning Lightning Round [30:06] ⚡️ Another week goes by and Justin’s reign remains unthreatened:
Justin (7), Ryan (5), Jonathan (4), Peter (1). * AWS Transfer Family now supports multiple host keys and key types per server * AWS Cloud Development Kit (CDK) announces CDK Construct tree view in the AWS CloudFormation console * Introducing Visual Conversation builder for Amazon Lex * AppFlow now supports deleting records in Salesforce * AWS Systems Manager now supports patching newer versions of SUSE Linux Enterprise Server, Oracle Linux, and Red Hat Enterprise Linux * On 1 October 2025, the Log Analytics alert API in Azure Monitor will be retired * Sign Amazon SNS messages with SHA256 hashing for HTTP subscriptions
Things Coming Up: * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 17-20th * Devops Enterprise Summit US Flagship - October 18th-20th - Las Vegas * Kubecon US - October 24-28th * AWS Reinvent - November 28th-Dec-2 (assumed)
On The Cloud Pod this week, Amazon SWF launches a new console experience, Google acquires Mandiant, and Azure Space has some new products coming your way soon.
Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week.
Episode Highlights * ⏰ Amazon SWF just launched a new console experience for building distributed applications. * ⏰ The Google acquisition of Mandiant (Mandoogle!) is finished. * ⏰ Azure Space announced their next wave of products.
Top Quote
💎 “The new certification is sort of interesting, because it's a little bit more like the, the content isn't new, right? But the certification is new. And so it's an interesting metric. Like how do you, how do you ensure people are reviewing the content? You have these certifications that you measure on the completion of that? So like, it's, I can see how it's a little bit of like, weaponizing, you know, those metrics in order to like drive culture change, maybe within an org where there's division over private cloud or public cloud? Or, you know, it just depends on what you want to do. But very interesting.” [17:04] General News: * 😳 Hashi Corp announced that Consul Terraform Sync is generally available at the 0.7 release. [1:12]
AWS: More Like Amazon SWTF? * 🤔 You’ve never heard of it, but Amazon SWF just launched a new console experience for building distributed applications. [4:20] * 😷 Amazon SNS launches a public preview of message data protection. [6:53] * 🏃♂️ Your containers will now be launching faster, thanks to Seekable OCI for lazy loading container images. [10:00]
GCP: Hey Siri, What Is a Mandoogle? * 🙊 Google Cloud Next is less than one month away. Have you registered yet? [12:16] * 🤷🏻♀️ The Cloud Digital Leader certification is bringing Cloud training to those of us who aren’t technically inclined. [14:56] * 🚨BeyondCorp Enterprise is giving you more ways to protect your corporate applications. [18:45] * 🧑💻The Google acquisition of Mandiant (Mandoogle!) is finished, finally bringing the two cybersecurity giants together. [19:34] * ☁️ Google introduces cloud backup and DR. [21:56]
Azure: Even More Products From Azure * 👋 Built-in Azure Monitor lerts for Azure Backup is now generally available. [25:45] * 📀 Two years after launch, Azure Space announced their next wave of products. [28:54]
TCP Lightning Lightning Round [30:06] ⚡️ The scores stayed the same this week… will Justin ever be de-throwned?:
Justin (7), Ryan (5), Jonathan (4), Peter (1). * Multi-instance GPU support in AKS * AWS Backup adds Amazon CloudWatch metrics to its console dashboard * Amazon RDS Performance Insights now supports displaying top 25 SQL queries * SageMaker Studio now supports Glue Interactive Sessions * AWS Firewall Manager adds support for AWS WAF custom requests and responses * Azure Dedicated Host support for Ultra Disk Storage * AWS Fargate announces migration of service quotas to vCPU-based quotas * Standard network features for Azure NetApp Files
Aftershow: * 👑 Queen Elizabeth II dies at 96
Things Coming Up: * Elasticon San Francisco - October 4th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 17-20th * Devops Enterprise Summit US Flagship - October 18th-20th - Las Vegas * Kubecon US - October 24-28th * AWS Reinvent - November 28th-Dec-2 (assumed)
On The Cloud Pod this week, Amazon announces Amazon Inspector’s new support of Windows OS for continual software vulnerability scanning of EC2 workloads, Google has several exciting announcements regarding Chronicle, Azure is announcing pretty much everything under the sun, and Oracle announces OCI Lake in beta.
Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. Episode Highlights ⏰ Amazon Inspector now supports Windows operating system (OS) for continual software vulnerability scanning of EC2 workloads.
⏰ Google makes 3 announcements about Chronicle.
⏰ Azure has three–yes, three–new releases this week.
⏰ Oracle announces OCI Lake in beta. Top Quote 💎 “The picture is still opaque of what the real value of this is going to be. But the fact that it's out there is good or, you know… it's the classic. “I'm leaving Amazon and I have worked on this code for five years and I like doing open source. So I can keep using it. It can be that classic move.” General News: * 🤑 Gartner published an article indicating that SaaS vendors will be using sustainability as a basis to raise their prices. [0:34] * 🤪 The news out of VMWare this week can basically be summed up as: Tanzu, Tanzu, and more Tanzu. [2:38]
AWS: Scanning, scanning, scanning…. * 📏 Amazon Event Ruler is becoming open source. [10:50] * 🔍 Amazon Inspector now supports Windows operating system (OS) for continual software vulnerability scanning of EC2 workloads. [14:12]
GCP: Dear Diary, today I… 🖊️ A Chronicle blog post diary, Google made several announcements [17:09]:
📈 There are new ingestion metrics coming to Chronicle.
⏳ New YARA-L functionalities are coming that will allow you to apply more fine grained time based criteria into your detections.
🦠 The Chronicle native-VirusTotal augment widget is now available. Azure: New Releases, New Releases Everywhere… * 🔋 Azure Managed Grafana is now generally available. [19:39] * 👋 Enterprise-ready Azure Monitor change analysis capability released–say that five times fast. [22:03] * 🖥️ Enterprise-grade edge for Azure Static Web Apps is now generally available. [25:16]
Oracle: * 💾 Oracle has announced OCI Lake (beta), which provides fine-grained access control to all resources in a data lake's object storage. [26:48]
TCP Lightning Lightning Round [30:06] ⚡️ This week, Ryan inches closer to dethroning Justin as the scores move to:
Justin (7), Ryan (5), Jonathan (4), Peter (1). * Unity Catalog for Azure Databricks is now GA * Azure Cosmos DB integrated cache is now GA * You can now authenticate to Azure Service Bus using Managed Identities * AWS announces open-sourced credentials-fetcher to simplify Microsoft AD access from Linux containers * AWS Fargate announces availability of Microsoft Windows Server 2022 images for Amazon ECS * AWS Config conformance pack templates can now be stored in AWS Systems Manager * Amazon Managed Service for Prometheus Alert Manager & Ruler logs now available in Amazon CloudWatch Logs * Announcing new AWS Console Home widgets for recent AWS blog posts and launch announcements
Aftershow: 🍎 The Top 9 Announcements from Apple's iPhone 14 Event
Things Coming Up: * Sectember - CSA Conference - September 26-30th - Bellevue WA * Elasticon San Francisco - October 4th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 17-20th * Devops Enterprise Summit US Flagship - October 18th-20th - Las Vegas * Kubecon US - October 24-28th * AWS Reinvent - November 28th-Dec-2 (assumed)
And that is the week in the cloud. We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, Slack team, send feedback or ask questions at thecloudpod.net or Tweet at us with hashtag #thecloudpod
On The Cloud Pod this week, Amazon adds the ability to embed fine-grained visualizations directly onto web pages, Google offers pay-as-you-go pricing for Apigee customers, and Microsoft launches Arm-based Azure VMs that are powered by ampere chips.
Thank you to our sponsor, Foghorn Consulting, which provides top notch cloud and DevOps engineers to the world’s most innovative companies. Initiatives stalled because you’re having trouble hiring? Foghorn can be burning down your DevOps and Cloud backlogs as soon as next week. Episode Highlights ⏰ Fine-grained visualizations can now be embedded directly into your webpages and applications
⏰ Google is now offering pay-as-you-go pricing for its Apigee API customers
⏰ Microsoft launches Arm-based Azure VMs powered by ampere chips Top Quote 💎 “I think I feel like SimCity 2000 lied to me. By now we should have had satellites in space collecting solar power and beaming microwave energy down to us.” General News: * 😐 Due to concerns about power shortages and availability of supplies, Microsoft and Amazon cancel several new planned data centers in Ireland. [1:18]
AWS: Adding Visuals to Your Apps Is Getting Even Easier… * 📊 Fine-grained visualizations can now be embedded directly into your webpages and applications thanks to Amazon QuickSight. [4:44] * ⚙️ Amazon’s announcement of the new AWS Support App for Slack is going to streamline management of technical, billing, and account support cases. [6:24] * 🗣️ AWS Security Hub is now publish announcements through Amazon SNS, and anyone can submit via the console or CLI. [8:37] * ✉️ Amazon RDS for SQL Server now supports email subscription for SQL Server Reporting Services (SSRS). [10:37] * ☁️ Amazon CloudFront launches Origin Access Control (OAC), which helps more easily secure S3 origins. [11:08] * 🔐 Your account login pages are becoming even more secure, thanks to AWS WAF Fraud Control. [12:38] * 📦 Amazon EKS Anywhere Curated Packages now generally available. [13:20] * 📈 AWS and VMware Announce VMware Cloud on AWS integration with Amazon FSx for NetApp ONTAP, allowing customers to scale storage independently. [14:33] * 🇦🇪 AWS now has regions open in the United Arab Emirates (UAE). [16:06]
GCP: Get What You Pay For * 🧩 Managed AD from Google now supports on-demand backups, schema extension support, and requires zero hardware management or patching. [18:02] * ⚔️ Six months after it was launched in preview, virtual Machine Threat Detection is now generally available to Cloud customers [20:30] * 🌥️ Google Cloud Certificate Manager is also generally available. [21:31] * 💳 Google is now offering pay-as-you-go pricing for its Apigee API customers, allowing them to unlock all of the benefits with no upfront commitment. [23:03]
Azure: Arms in the Cloud * 🦾 Ampere Altra Arm-based processors are now generally available on the Azure cloud. [24:28] * 🖥️ Azure Data Explorer now supports native ingestion from Amazon S3, one of the most popular object storage services. [27:00] * 🧑💻 IoT Edge 1.4 is now generally available. [28:34]
TCP Lightning Lightning Round [30:06]
⚡️ This week, Peter struggles to keep up, as everyone else’s scores increase to: Justin (7), Ryan (4), Jonathan (4), Peter (1). * A new sign-in experience is now generally available for Amazon QuickSight * Announcing the Oracle Cloud VMware Solution summer release * Amazon AppFlow now supports Jira Cloud as a source * Announcing support for Crawler history in AWS Glue * Prevent a lifecycle management policy from archiving recently rehydrated blobs on Azure * Announcing dynamic performance scaling with autotuning for OCI Block Storage
Aftershow: * 🪫 Silicon Valley Startup Sparks Controversy Over What Critics Call ‘Racist Software'
Things Coming Up: * Sectember - CSA Conference - September 26-30th - Bellevue WA * Elasticon San Francisco - October 4th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 17-20th * Devops Enterprise Summit US Flagship - October 18th-20th - Las Vegas * Kubecon US - October 24-28th * AWS Reinvent - November 28th-Dec-2 (assumed)
And that is the week in the cloud. We would like to thank our sponsors Foghorn Consulting. Check out our website, the home of the cloud pod where you can join our newsletter, Slack team, send feedback or ask questions at thecloudpod.net or Tcweet at us with hashtag #thecloudpod
On The Cloud Pod this week, the team weighs the merits of bitcoin mining versus hacking. Plus: AWS Trusted Advisor prioritizes Support customers, Google provides impenetrable protection from a major DDoS attack, and Oracle Linux 9 is truly unbreakable.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 AWS Trusted Advisor offers a new Priority capability for Enterprise Support, offering a prioritized view of critical risks. * 🚨 Nothing’s touching Google, as it blocks the largest Layer 7 DDoS attack to date, with a whopping 46 million requests per second (RPS). * 🚨 The new Oracle Linux 9 comes with Unbreakable Enterprise Kernel Release 7 (UEK R7) and Red Hat Compatible Kernel (RHCK).
Top Quotes * 💡 “This is really just institutionalizing the knowledge that the Enterprise customers are already getting from their account team. And it probably really helps — in the event that the AWS account team experiences churn for those customers — not to be negatively impacted. It probably makes it really easy for new people on that AWS account team to come in and know where the other team left off. I don't think it's really a new feature — just a new way to access data that customers are already getting.” * 💡 “Ignoring those Tor nodes — which didn't make a whole lot of traffic — that's 12,000 requests a second per source IP, on average. That's enormous.”
AWS: A Trusty Advisor’s Priorities * 🧑🔧 Finally, AWS has found a use for Mechanical Turk, with its new Priority capability for Trust Advisor. * 🔭 If you've been curious about what's happening during domain updates of the OpenSearch Service, you now get more visibility into validation errors during blue/green deployments. * 📜 Great news for license-holders and clearly by popular demand: RDS for Oracle now supports managed Oracle Data Guard Switchover and Automated Backups for read replicas.
GCP: Heavily Armored Cloud * 🥝 Google Cloud is saying goodbye to its IoT Core service in 2023. How about instead of turning it off, just stop selling it? * ✂️ You can benefit from operating system Committed Use Discounts (CUD) with workload predictability. Now, get some cuts on your SUSE Linux Enterprise Server (SLES) — with savings of up to 79%. * 🛡️ There’s much fanfare at Google, as it blocks the largest Layer 7 DDoS attack to date. It didn’t last long though, because the attackers gave up — probably deciding there was no value in continuing. * 🔍 Chronicle SecOps Suite now offers curated detections for SOC teams. Now you’ve got them, what do you do with them? Well, be on the lookout out for a follow-on service from Google, probably coming soon.
Azure: It Must Be Kubernetes Week at Azure * 🤔 In a strange announcement that doesn’t make a whole lot of sense, Public IP Capability for Azure VMware Solution is now generally available. What does “the ability to receive up to 1000 or more Public IPs” actually mean? Come on, Azure. * 🤝 If you’re in the Kubernetes camp, you get a big change with the general availability of Kubernetes 1.24 support. (For most people this isn’t a big deal and you don’t care.) * 🤗 It sounds expensive, but it’s dedicated: Azure Dedicated Host Support is now general available. * ⌨️ It’s mind blowing that key management system integration with AKS wasn’t already a thing, but there we go.
Oracle: Surviving a Train Wreck * 🚆 If you were super excited about the general availability of Oracle Linux 9, you get cloud-ready platform images now available in OCI, with the Unbreakable Enterprise Kernel Release 7 (UEK R7) and Red Hat Compatible Kernel (RHCK).
TCP Lightning Round ⚡ Jonathan makes the dad joke of the century, but fails to snag the point from Justin. The scores stand at: Justin (7), Ryan (4), Jonathan (3), Peter (1). Other Headlines Mentioned: * Amazon RDS now supports setting up connectivity between your RDS database and EC2 compute instance in 1-click * Now capture AWS Site-to-Site VPN connection logs using Amazon CloudWatch * AWS Cost Categories now support Out of Cycle cost categorization * Amazon EKS announces cluster-level cost allocation tagging * Azure UAE North Availability Zones
Things Coming Up: * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th-13th * Oracle Cloud World - October 16th-20th * Kubecon US - October 24th-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBD * Microsoft events - TBD Check for status
After Show: Elon Musk’s lawyers are bringing in a Twitter whistleblower as part of the ongoing plan to back away from buying the social media giant.
On The Cloud Pod this week, the team chats cloud region wars to establish the true victor. Plus: AWS Storage Day offers a blockhead badge, all the fun of the Microsoft Dev Box, and Google sends people back to sleep with its Cloud Monitoring snooze alert policy.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 AWS Storage Day 2022 marks the fourth annual event streamed live on Twitch, with its File Cache service announcement and five new available learning badges. * 🚨Google now offers alert policy snoozing in Cloud Monitoring for maintenance or non-business hours. * 🚨Microsoft previews its Dev Box, a managed service enabling developers to create cloud workstations.
Top Quotes * 💡 “I found it completely shocking that this didn't exist in AWS — that you only had enable/disable — when first moving over there. So this is a fantastic feature for Google Monitoring. I love it.” * 💡 “This seems like one of those things I'd like, but half the fun of starting a new project is installing a new version of Python or something that completely hoses my local laptop. And I spend the next three or four days frantically trying to undo what I've done that breaks six other things.”
AWS: It’s Storage Day! * 🗃️ AWS livestreamed its fourth annual Storage Day on Twitch, and Ryan is rather excited about getting his hands on that blockhead badge for core storage competency. Plus, the new File Cache service promises to accelerate and simplify hybrid cloud workloads. * 🤔 Continue to be blown away by the theory of HTTP/3 (and if you’re like Ryan, dread the day you have to troubleshoot it), as Amazon CloudFront now supports it. * 📱 Now available in US regions (with a likely quick extension with increased adoption and understanding of the service): AWS Private 5G. * 👐 Amazon and Splunk co-announce the release of the Open Cybersecurity Schema Framework (OCSF) project with a lot of partners… but (interestingly) no Elastic. * 🤝 If you've been holding off on that move from Dockershim to the new launcher, now’s the time to do it before it’s too late: Amazon EKS and Amazon EKS Distro now support Kubernetes version 1.23. * 🤔 Apparently Amazon Cognito enables native support for AWS WAF, but we’re not entirely sure what they're enabling here — it feels like something they should have already been doing.
GCP: Hitting the Snooze Button * ❓ Query Library offers new tools for increasing developer productivity. You should eventually be able to actually save your queries into a custom Query Library, but we’re still waiting on this. * 😴 A snooze, not a pause: Google Cloud Monitoring can now send alerts to sleep, which is perfect for maintenance and non-business hours. * ☁️ Google Cloud Deploy gets several awesome new features this week, including faster onboarding with Skaffold, delivery pipeline management and expanded enterprise features.
Azure: Microsoft Dev Box Treats * 🇶🇦 Microsoft announced its new cloud region in 2019. Two and a half years later, Qatar is finally here. * 🧑💻 Microsoft previews its Dev Box, a managed service that enables developers to create cloud workstations and focus on writing their code instead of building environments to run it.
TCP Lightning Round * ⚡ The lightning lightning round this week (sans Peter) keeps the scores at: Justin (6), Ryan (4), Jonathan (3), Peter (1).
Other Headlines Mentioned: * Optimize resources across your organization using AWS Compute Optimizer from a designated account * The Amazon Chime SDK announces elastic channels * Amazon EBS adds the ability to take crash-consistent snapshots of a subset of EBS volumes attached to an Amazon EC2 instance
Things Coming Up: * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th-13th * Oracle Cloud World - October 16th-20th * Kubecon US - October 24th-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBD * Microsoft events - TBD Check for status
After Show: Post-pandemic remote working, Apple’s enforcing three days a week in the office with a new deadline in place.
On The Cloud Pod this week, the team gets judicial on the Microsoft-Unity partnership. Plus: Amazon acquires iRobot, BigQuery boasts Zero-ETL for Bigtable data, and Serverless SQL for Azure Databricks is in public preview.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 iRobot signs an agreement with Amazon for its acquisition. To what end remains known to Amazon and Amazon alone. * 🚨 Google offers a Zero-ETL approach for Bigtable data analytics using BigQuery. * 🚨 Serverless SQL for Azure Databricks is now in public preview.
Top Quotes * 💡 “Almost all of Amazon's big acquisitions have always been about something indirect. The Whole Foods acquisition was really about the logistics supply chain behind the scenes of moving that around — they kept the brand … and they have the same footprint for stores … but now they have a lot more infrastructure for AmazonFresh. And I suspect for iRobot it's the same thing.” * 💡 “This is super handy for huge datasets where you want to track trends over a long time. It's always really difficult and you always end up compromising somewhere — by not loading or querying your full dataset, because you can’t get it from A to B, or trying to run the query against two separate data sets and combining the results. So this is a nice thing to have for those users who have data across these multiple places.”
AWS: We, Robots * 🤖 Those who hate working in Amazon warehouses might not have to have anything to complain about anymore, as Amazon agrees to acquire iRobot. * 🏁 If you need to get up to speed with Graviton, you’ve now got Graviton Fast Start, which helps move workloads over to AWS. * 🛡️ VMware’s interesting cloud workload protection feels like a continued diversification away from virtualization as your main revenue stream. * ☁️ CloudWatch Evidently, Amazon's second product to help with feature flagging, adds support for creating target customer segments for feature launches and experiments. Neat! * 💸 In what seems like a cost-saving announcement, Lambda gets tiered pricing (but most enterprise customers already have this pricing experience).
GCP: It’s A Big World Out There * ❓ You can now benefit from a Zero-ETL approach for Bigtable data analytics using BigQuery. * 🧑💼An on-premises Windows workload nice-to-have offers support with Certificate Authority Service. * ☁️ Second generation Cloud Functions is now generally available. So are they moving to Knative or away from it? * 🌏 Great news if you’re in the Asia Pacific region outside of Singapore and Australia, with more Google Cloud regions on the way.
Azure: Unity is Strength * 🤝 Microsoft and Unity buddy up for the sake of digital creators, 3D artists and game developers across the world. Whether it’s all-in on Azure or just a simple partnership is a topic of hot debate. * 🕹️ VMware VMs get a modernization boost with Site Recovery, now generally available. See how many times it mentions “experience” in one announcement. * 🧱 If you were skeptical about that one, Serverless SQL for Azure Databricks is now in public preview. They’ll charge you when you use it (because they know you're always going to use it). * 🔮 VM insights with Azure Monitor agent are also in public preview. Hopefully they do this a little better than Amazon did. * 3️⃣ As all things come in threes, the third public preview is Azure Dedicated Host support for Ultra SSD. Next in line is Ultra premium, Ultra Premium Ultra, and Ultron discs, before we move to crystal storage or something biological. * ✨ Either it’s Gartner Magic Quadrant update season or Azure thinks they have something to brag about, because Microsoft is apparently a leader in Gartner’s 2022 edition.
Oracle: Peter’s Back! Bring Out the Oracle Story * 🤝 OCI Code Editor makes developing with Oracle Cloud Infrastructure a whole lot easier. Is this top of the list for all the cloud features you could develop and release? You decide.
TCP Lightning Round ⚡ Ryan edges a touch closer to Justin this week, making the scores: Justin (6), Ryan (4), Jonathan (3), Peter (1). Other Headlines Mentioned: * Public preview: Azure Dedicated Host restart * AWS Data Exchange increases the asset size limit to 100GB * Amazon Aurora Serverless v1 now supports PostgreSQL 11 and In-Place upgrade from PostgreSQL 10 * Amazon SageMaker Pipelines now supports sharing of pipeline entities across accounts * Amazon S3 adds a new policy condition key to require or restrict server-side encryption with customer-provided keys (SSE-C) * AWS Direct Connect expands AWS Transit Gateway support at more connection speeds * Introducing Google Cloud and Google Workspace support for multiple Identity providers with Single Sign-On
Things Coming Up: * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th-13th * Oracle Cloud World - October 16th-20th * Kubecon US - October 24th-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-December 2nd (assumed) * Oracle OpenWorld - TBD * Microsoft events - TBD Check for status
On The Cloud Pod this week, the team discusses why Ryan’s yelling all day (hint: he’s learning). Plus: Peter misses the all-important cloud earnings, AWS Skill Builder subscriptions are now available, and Google Eventarc connects SaaS platforms.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Earnings time is upon us once again, and it’s apparently doom and gloom all around as tears of loss are wiped away with $100 bills. * 🚨 AWS makes its Skill Builder subscriptions available with more than 500 courses and four new learning experiences. (The Cloud Pod is now registering signups for a virtual proctor while you take the test.) * 🚨Google Eventarc for events enthusiasts unifies and integrates supported SaaS platforms.
Top Quotes * 💡 “Teams is a huge focus. The last two years have been companies figuring out how to remote work for the first time ever. That's not a sustainable thing — those two years’ growth is all just pandemic.” * 💡 “I do like the way that they're presenting a lot of this training. I don't learn well in the classroom setting — I learn by doing, so any kind of hands-on labs or the jams which I've done in person at re:Invent are better for me to learn the internet intricacies of different services. So I love this.”
General News: Earnings, Damned Earnings, and Negative Analysts * 💵 First up for reported earnings is Microsoft, where no one’s really hurting. (Wait until you see the other guys.) * 😢Sadly, Google still hasn’t figured out how to make money on GCP. Ad revenue is down. * 🤦 Amazon suffers slower demand amid another net loss. Rivian takes a big hit, so if you were hoping to see it turn around, it hasn’t. * 🙅 Of course, all of this bad news means Google and Microsoft have scaled back hiring efforts. Coupled with high inflation and bad interest rates, an economic bloodbath in the next 12 months looms. * 🪓 Oracle axes U.S. staff as part of a plan to lay off thousands — mainly in marketing and customer experience. This could signal a step back from opening so many new data centers.
AWS: Building Skills One Course at a Time * 🌐 Handy new IPv6 support appears for AWS Global Accelerator. * 🌎 Already five years too late, CDK for Terraform is now (finally) generally available. * 👐 Amazon OpenSearch Service gets a trifecta of boosts in the form of advanced log and application analytics, OpenSearch version 1.3 support, and support for EBS gp3 volume type. * 🧿 For those who need Neptune at scale, the Amazon Neptune Global Database is the perfect solution. As a growing service, it’s a great thing to have. * 👷 Giving problems to solve instead of document-based learning is what AWS Skill Builder Subscriptions sets out to do with its 500+ courses and four new learning experiences. Pretty cool! * 🛡️ You can now build AWS Config rules with AWS CloudFormation Guard — perfect for those who aren’t full-time developers who can still lend a hand in security. * 👓 So long as you don’t leave it on all the time, running Visual Studio software on Amazon EC2 could save money. At the same time, it looks like no-code isn't going to be a thing that soon.
GCP: Let’s All Come Together Now * 👌 To avoid heavy lifting, stream data with Pub/Sub direct to BigQuery. (No pipelines needed!) It’s like an ETL without the “T.” * 👷 If you were super excited about AWS Skill Builder and wanted certification but via GCP, your calls have been answered: Meet the new Professional Cloud Database Engineer certification. * 🔒 Keep it secret, keep it safe: Cloud SQL for PostgreSQL and MySQL local user password policies pop up for protection. * 🙌 Eventarc promises to connect, unify, and integrate supported SaaS platforms for event management and infrastructure.
Azure: Well on the Way to That Government Contract * 🤔 In a one-sentence press release, US West 3 sees a price drop. For what, and why, remains a mystery. * 🎅 Microsoft threat intelligence solutions leverage its acquisition of RiskIQ in its bid to up security posture and hunt for bad guys. * 📈 If you needed that certification to do government work, you're good to go with the newly ICSA Labs-certified Azure Firewall Premium.
TCP Lightning Round ⚡ With scorer Peter still absent, this week sees the round robin once again. The scores remain: Justin (6), Jonathan (3), Ryan (3), Peter (1). Other Headlines Mentioned: * General availability: Next hop IP support for Azure Route Server * Generally available: Azure Public IPv6 offerings are free as of July 31 * AWS Support launches a new AWS Support Center console domain * General availability: Reservation administrator and reader roles in the Azure Portal * Now in Preview - Amazon WorkSpaces Integration with SAML 2.0 * Amazon RDS for MySQL now supports enforcing SSL/TLS connections * AWS Microservice Extractor for .NET now provides automated refactoring recommendations * VM Import/Export now supports Windows 11 * AWS Ground Station announces a new antenna location in the Asia Pacific (Singapore) Region * AWS Secrets Manager connections now support the latest hybrid post-quantum TLS with Kyber
Things Coming Up: * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th-13th * Oracle Cloud World - October 16th-20th * Kubecon US - October 24th-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBD * Microsoft events - TBD Check for status\
After Show: * If earnings weren’t disappointing enough, it could be time for Google employees to fix their resumes: Their CEO emphasizes productivity, focus and efficiency with a ‘Simplicity Sprint.’
On The Cloud Pod this week, the team gets skeptical on Prime Day numbers. Plus: AWS re:Inforce brings GuardDuty, Detective and Identity Center updates and announcements; Google Cloud says hola to Mexico with a new Latin American region; and Azure introduces its new cost API for EC and MCA customers.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 AWS re:Inforce brings us Amazon GuardDuty, Amazon Detective and IAM Identity Center releases, updates and name-changes for additional protection and headache. * 🚨 Google Cloud adds a third Latin American data region to its collection — this time, in Mexico. * 🚨 EA and MCA customers now benefit from Azure’s new Cost Details API for better HR and finance management.
Top Quotes * 💡 “This must always have been their plan. Amazon did not build that block Inspection Service just so that Orca could serve their own customers. They must have had an eye on the huge customer base of people using EBS Volumes to do this exact same thing. So it's no surprise [as they’ve] had almost two years of sole ownership of the service to deliver this to customers. I'm not surprised at all to see an enhancement like this. And it's awesome. Really.” * 💡 “Microsoft is in a lucky position, because the Windows ecosystem has been very services heavy for a long time. … They've got this unique position where they can deprecate … they can pivot to new APIs more quickly than AWS, who are stuck with so many customers [and it’s] very painful for them to deprecate … It’s lucky that [Microsoft] don't have customers that would push back against this, because they're used to constant change.”
AWS: re:Inforcing Prime Numbers * #️⃣ There may well be some spin in Jeff Barr’s latest brag on behalf of Amazon for its Prime Day 2022. Impressive numbers nonetheless! * 💂 New malware detection for EBS Volumes with GuardDuty is the first of three announcements hot out of AWS re:Inforce — very similar to Orca Security malware snapshot and restore functions. * 🕵️ The second offering is Amazon Detective’s support for Kubernetes Workloads on EKS, for improved security investigations. There’s nothing not to like here, and it shows exactly why we use managed services. * 👤 Finally, the terribly named AWS IAM Identity Center — which you may remember was previously called AWS SSO — promises to scale your workforce access management. They could’ve called it “AWS Centaur,” but instead opted for two words that mean absolutely nothing.
GCP: Making US Automakers Happy One Latin American Region at a Time * 🇲🇽 Google Cloud says hola to Mexico, as it adds a third Latin American data region following Santiago, Chile, and Sao Paulo, Brazil. If there are further updates within the next three to four years, Ryan has kindly volunteered to be The Cloud Pod’s reporter on the ground. * 0️⃣ Not “no code,” just… “low code:” Next-gen Dataflow covering Prime, Go and ML is here. See if you can get as excited as your hosts. * 🚤 Pretty neat with nice integrations across it, the generally available BigLake allows you to unify data lakes and warehouses.
Azure: The Buzzword Is Deprecate * 💸 HR and finance rejoice: Both Enterprise Agreement (EA) and Microsoft Customer Agreement (MCA) customers benefit from the Microsoft Cost Details API, now generally available. * ⬆️ If you're doing patch management — which you will be if you're running Windows on Azure — you’ve got the public preview of Update Management Center to get hyped about. More importantly, it's a very nice and easy graphic dashboard to say that you're in patch compliance. * 📦 And if you're unhappy with MSIs, you’ll love the general availability of VM Applications, designed to manage and deploy applications to VMs and VMSS. Another package manager? Great! Just what we need.
Oracle: Taking a Walk on the Wild Side * 🤝Oracle decides that if you can't beat them, you should join them, as it announces its database service for Azure. Multicloud for managed services? This level of integration at the UX level is kind of nuts. If you make a website that looks like somebody else's website, it’s usually called a scam, right?
TCP Lightning Round ⚡ Justin would’ve awarded the point to Ryan if points were being awarded, but they’re not. As such, the scores remain at: Justin (6), Jonathan (3), Ryan (3), Peter (1). Other Headlines Mentioned: * AWS Fault Injection Simulator now supports ChaosMesh and Litmus experiments * AWS Backup adds support for Amazon RDS Multi-AZ clusters * AWS WAF adds sensitivity levels for SQL injection rule statements * Amazon Macie introduces new capability to securely review and validate sensitive data found in an Amazon S3 object * Amazon DocumentDB (with MongoDB compatibility) now supports fast database cloning * Now programmatically manage primary contact information on AWS accounts * Enable post-quantum key exchange in QUIC with the s2n-quic library
Things Coming Up: * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th-13th * Oracle Cloud World - October 16th-20th * Kubecon US - October 24th-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBD * Microsoft events - TBD Check for status
After Show: * Google fires the engineer who claimed its AI was sentient. Obviously revealing company secrets is a big no-no, but it does raise interesting questions about how we’ll test sentience in the future.
On The Cloud Pod this week, the team discusses facial recognition avoidance tactics. Plus: Waving farewell to CentOS 7 with the rise of Rocky Linux, Amazon traverses the new Cloudscape, and the U.K. heatwave spells disaster for Oracle and Google data centers.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 As CentOS is put out to pasture, say hello to Rocky Linux, named in honor of CentOS late co-founder Rocky McGaugh. * 🚨 Cloudscape Design System is the latest AWS open source wonder for web application building. * 🚨 The great British heatwave of 2022 burns Oracle and Google data centers to a crisp.
Top Quotes * 💡 “It answers the question of who we shout at if there's a bug at zero day and the community doesn’t get around to fixing it. Now we can shout at Google.” * 💡 “It's probably a sign of further issues to come unless they do some productive work. Because it's one thing to … build a data center in Utah [where] it gets up to 45 degrees C and the sun's heating the air under some land. And that's a completely different situation than heating up Europe, which is … much less expected to have those kinds of temperatures so far north. … So it's going to be time to invest in HVAC business.”
General News: The Best Data Lake Is the One With Your Boat on It * 🛥️ VentureBeat offers up its top 10 data lake solution vendors this year. If you also don’t know what a data lake is, fear not (it tells you).
AWS: Open Source Because They Can’t Sell It? * 🪐 AWS suits up for battle against Microsoft and Google with its server chip. Fire up the Graviton! * 👐 Cost-saving automated and easily modifiable EBS Elastic Volumes are here. (Just watch out for a pesky potential price increase.) * 🌁 The very cool VPC Flow Logs for Transit Gateway will make things much more efficient. * 💰 AWS announces neat new AppConfig Extensions. Step one: Enable feature. Step two: Figure it out yourself. Step three: Profit, profit, profit. * ☁️ AWS goes open source with Cloudscape Design System for building web applications. * 🏔️ More epic work from Amazon as EC2 R6a Instances join the M6a and C6a club, now rolled out across all three primary node types. You're welcome!
GCP: The Rise of Rocky * 🤯 Stunned reactions all around here at The Cloud Pod: Model co-hosting enables resource sharing among multiple model deployments on Vertex AI. A great use case, with the next step being making it entirely serverless. * 🥊 For those of you who live in the Linux world like your hosts, you’ll be waving goodbye to CentOS 7, as Rocky Linux (named in honor of one of the late CentOS co-founders) makes its debut. * 💪 Welcome the Arm-based Tau T2A to the VM family. Will Google start selling the Graviton Three to the other cloud providers making it a $12 billion business? * 📚 Batch is ostensibly a new managed service for scheduling batch jobs at any scale, but let us know if you see what’s managed about this. You’ll be managing everything else, so there’s no value add. Good luck if you do use it!
Azure: Sovereignty Is the Buzzword * 💎 If you were already confused about Premium and Ultra Premium storage, we have a new flavor to add to your nightmares: Azure Premium SSD v2 Disk Storage, which is now in preview. * 😐 Azure’s facial recognition approach has changed, and the engineers among you may be feeling as conflicted as Ryan about it. On the other hand, demand facial sovereignty! Tell Azure (and AWS) that you refuse to be identified — an interesting use case and neat business model. * ⚖️ Gateway Load Balancer is now generally available in all regions. A feature we’re all glad exists that we don’t need to take advantage of. * 🤝 Microsoft and Netflix buddy up, and all we’re wondering is if Microsoft is trying to poach some of that sweet, sweet cloud revenue Netflix pays AWS. * 👑 Microsoft Cloud for Sovereignty is its answer to Oracle. Nothing new here, just a rebrand — some lipstick on a pig. * 💡 What’s new for Azure Stack HCI at Microsoft Inspire 2022? Find out all the latest therein. * ₿ If you're into Bitcoin, Azure’s confidential ledger is now generally available, and is apparently a better solution to banks’ compliance and technology requirements than what they’ve been using for so long already. Why care now about the distributed immutability of a ledger? (Unless it’s not a better solution.) * 💸 For those of you who aren’t cutting costs and need a new way to burn your money faster, Azure SQL Managed Instance hosts premium-series hardware which is now generally available.
Oracle: The Data Centers Are Burning * 🔥 Both Oracle and Google experienced data center knockouts in London due to the U.K. heatwave. We want to know the hows and whys: Did external dependency fail? Power delivery to the data centers? Or was it the data center itself and the HVAC system inside?
TCP Lightning Round ⚡ Ryan snags the point this week, creeping up to equalize with Jonathan and making the scores Justin (5), Jonathan (3), Ryan (3), Peter (1). Other Headlines Mentioned: * Amazon Timestream announces improved cost-effectiveness with updates to metadata metering * AWS Lambda Powertools for TypeScript is now generally available * AWS Firewall Manager now supports AWS Network Firewall strict rule order with alert and drop configurations * OCI Queue limited availability program * Australian Government certifies Oracle Cloud Infrastructure under the Hosting Certification Framework * Moving data from the mainframe to the Google cloud made easy
Things Coming Up: * SCALE 19X - July 28th-31st
After Show: * Slack is making some free plan changes (Business+ or custom enterprise plans aren’t affected). Live from Sept. 1, 2022, there’ll be a small price increase, and free users get 90 days of messages and uploads instead of the 10,000 message and 5GB limit of yore.
On The Cloud Pod this week, the team discusses shorting Jim Chanos amid the great cloud giant vs. colo standoff. Plus: Google prepares for a post-quantum world, Amazon EC2 M1 Mac instances are now generally available, and master of marketing Oracle introduces sovereign cloud regions for the European Union.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Future forward Google prepares for a post-quantum world, while most corporations won’t catch up for a long time. * 🚨 Amazon EC2 M1 Mac instances are now generally available (so the hidden Mac Mini under that developer’s desk can finally be replaced). * 🚨 Master of marketing Oracle introduces sovereign cloud regions for the European Union.
Top Quotes
💡 “Quantum computing has been taken very seriously from a security perspective. Conservative estimates [are] 10 to 20 years before we have quantum computers large enough and reliable enough to run short algorithms to factor these large primes. But we're starting ... It’s going to take a long time for businesses to actually catch on and realize and modernize and adopt this before the bad things start to happen. If they ever do.”
💡 “The big issue is from a federal government perspective: In a world where quantum computing can actually go through those primes fast enough and decrypt all this data … it's a huge national security risk [and] a huge problem for the world. … Does it follow into the corporate world as quickly? No. Will it become a big issue when it happens? Hell yeah. There'll be a Y2K-level disaster that we'll have to be dealing with.” General News: Walmart Muscles In * 🏞️ Will cloud giants really drive colos off a financial cliff? Big leagues short-seller and Enron prophesier Jim Chanos seems to think so… or maybe that’s all part of his plan. * 🛒 Walmart saw that and said, Well, we're doing it too: Their CTO claims they’re now the largest hybrid cloud in existence. Having 10,000 massive buildings at their disposal must be convenient.
AWS: New York, New York * 🖥️ EC2 M1 Mac instances are now generally available. Thanks to Apple’s licensing agreement, they have to be turned on for 24 hours minimum. * 🗺️ Identity and Access Management gets IAM Roles Anywhere for workloads outside of AWS, removing a huge and clunky obstacle to adoption. Awesome. * 📏 EC2 Auto Scaling customers can monitor their predictive scaling policy with Amazon CloudWatch, but we’re left wondering how to close the loop on having to monitor the monitoring service to make sure it’s doing what it’s supposed to be doing. * 🥅 If you're a .NET developer leveraging AWS for all your compute needs, you’re in luck — there’s a streamlined deployment experience for .NET applications in .NET CLI and Visual Studio. Huge sales ahoy. * 3️⃣ In the first of three New York summit announcements, three new serverless analytics offerings are generally available. * 💭 In preview at re:Invent, the Cloud WAN managed service is now generally available. But beware of inter-region data transfer charges, which could get very expensive. * 📘 First you partner, then you kill them: DevOps Guru offers recommendations and log anomaly detection to quickly detect and resolve issues.
GCP: The Future Is Scary * 🕵️♀️ Google is preparing for a post-quantum world, as mathematicians and cryptographers from all over the world race to develop algorithms before disaster strikes.
Azure: Why, Microsoft, Why!? * 🚀 The legacy agent callback config from log analytics workspaces rejoices at the public preview of Monitor Agent’s new migration tools, and we’re super happy for you. For everyone else, this is crazy — why not just build the migration tool into the actual agent itself? * 🗄️ 30’s a strange limit for supported window server containers, but there we go. Obviously the support team is happy — just decrease the number of containers until it works.
Oracle: The Sometime-Master of Marketing Returns * 🇪🇺 A story to die for: Oracle introduces its new sovereign cloud regions for the European Union. Spare a thought for poor Accenture, who have to build products around this.
TCP Lightning Round ⚡ Justin (6) jumps ahead again with the rest of the team trailing behind — Jonathan (3), Ryan (2), Peter (1). Other Headlines Mentioned: * AWS re:Post introduces profile pictures and inline images * Amazon WorkMail now supports invoking Lambda to fetch availability (free/busy) * AWS Security Hub launches 36 new security best practice controls * Amazon QuickSight launches APIs for account create * Amazon Athena enhances console and API support for parameterized queries * Amazon GuardDuty introduces new machine learning capabilities to more accurately detect potentially malicious access to data stored in S3 buckets * Multicloud reporting and analytics using Google Cloud SQL and Power BI * General availability: Azure Database for PostgreSQL—Hyperscale (Citus) supports PostgreSQL minor versions * General availability: Azure Active Directory authentication for Application Insights * General availability: Azure Application Insights standard test for synthetic monitoring * IN, NOT_IN and NOT EQUAL query operators for Google Firestore in Datastore Mode
Things Coming Up: * AWS re:Inforce - July 26th-27th → Now Moved to Boston * SCALE 19X - July 28th-31st
Postgres @ SCALE
DevOps Enterprise Summit Virtual - US - August 2nd-4th
After Show: * Apple spent eight years trying to build a self-driving car. The team chatted about this and self-driving cars in general after the show.
On The Cloud Pod this week, the team discusses data sovereignty for future space-customers. Plus: There’s a global cloud shortage, Google announces Apigee advanced API security, and GKE Autopilot gets new networking features.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Microsoft is the latest victim in a global cloud shortage, spinning it as a temporary issue fueled by surging Teams demand and rapid Azure growth. * 🚨 Google announces Apigee Advanced API Security in a bid to defend against increased attacks and traffic volumes. * 🚨 GKE Autopilot gets new network features in the form of IP masquerading and eBPF, now generally available.
Top Quotes * 💡 “The supply chain has been huge on a lot of people. You don't hear so much from Amazon, and I don't know if that's related to the commerce site Amazon.com and the overprovisioning they did … If AWS went the same route and has a bunch of stock, cluster manufacturing their own chips, maybe they have a little bit more control. But everyone else is screwed.” * 💡 “In the article, it just says what you can do to detect bots. But some bots are the use case [you’re] selling to the world. ... On the surface, it sounds logical, but there are some ‘gotchas’ that you need to be careful of if you're doing B2B or doing things that look bot-ish.”
General News: All the Joy of the Crypto Crash * 💢 Apparently the tech talent crunch (not because we suck at running Kafka) is to blame for a 68% reliance on AWS managed services. Come on, VentureBeat, you can do better than this! * 🌤️ Microsoft is in the yellow zone because of a global cloud shortage, which it’s attributing to rapid Azure growth and increased Teams demand.
GCP: The Very Apigee of Security * 🛡️ Google announces Apigee Advanced API Security to help protect against increased attacks and traffic volumes. Seems more like a WAF function than a misconfiguration issue, though. * 📓 Go go go, Google: get more support for structured logs in the latest version of Go logging library. * ☁️ Monitor your cloud metrics now in Managed Service for Prometheus. Allegedly, Cloud Native community members have an 86% chance of using Prometheus (we’re not so sure about that number.) * 🇫🇷 Say bonjour to the new Paris region, as the French government aims to make the nation cloud native. * 🎭 GKE Autopilot’s new IP masquerading and eBPF network features are now generally available. * 🛠️ Query Insights for Cloud Spanner promises to troubleshoot performance issues with pre-built dashboards. When latency is high, it’s your fault. When it’s low, it’s because we’re awesome.
Azure: Head in the Clouds * 😖 Get ready to cringe hard: Which Azure service should you use to run your applications? Op sides are very angry about how this article is written. * 💵 NVads A10 v5 virtual machines are now generally available, offering to help choose the right size for your workload. Why choose one when you can have both?
TCP Lightning Round ⚡ With a full house this week, Jonathan (3) edges closer to Justin (5), with Ryan (2) and Peter (1) tailing slightly behind. Other Headlines Mentioned: * Public preview: Azure Ephemeral OS disk support for confidential virtual machines * Announcing availability of AWS Outposts rack in Panama * AWS Database Migration Service now supports IBM Db2 z/OS as a source * AWS Database Migration Service now supports Babelfish for Aurora PostgreSQL as a target
Things Coming Up: * AWS re:Inforce - July 26th-27th → Now Moved to Boston * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th-13th * Oracle Cloud World - October 16th-20th * Kubecon US - October 24th-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC
On The Cloud Pod this week, Peter finally returns with some beer-based bets about Amazon extending its TLS deadline. Plus: Terraform drift detection for managing infrastructure, chilling tales of Amazon’s CodeWhisperer ML advances, and Anthos on-premise options finally arrive for your platform of choice. Plus the cloud talks about AWS SNOWCONES in SPACE!!!!!!
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Terraform Cloud finally adds drift detection to help manage infrastructure, now generally available after its 2020 preview. * 🚨 Amazon’s crazy “ML-powered coding companion,” CodeWhisperer, is here for our jobs. * 🚨 Google expands its Distributed Cloud platform with Anthos on-premises options.
Top Quotes * 💡 “I'm surprised it's taken so long. Because I mean, the reality is if you're in a plan, and the plan doesn't require any changes, then there's been no drift. So what was the obstacle in delivering this as a feature sooner?” * 💡 “Not only they're training their own machine learning models, but they're also generating code. Not concerned at all.”
General News: Drifting in the Right Direction * 🏁 While everyone’s been a little afraid to pull the trigger, HashiCorp announced drift detection in Terraform cloud, which is in a public beta. Pretty exciting! * 🗺️ HashiCorp also announced the launch and free public beta of HCP Boundary, but what's their long-term vision?
AWS: Whispering Sweet Somethings to the Machine * 🌿 SageMaker Ground Truth now supports synthetic data generation, promising to reduce time and training costs for model operations. Getting enough data to actually train a model could be hard… (fake it til you make it?) * 🤖 Your new “ML-powered coding companion” CodeWhisperer now writes code for you. We’ve joked about it before, but Alexa really is one step away from upskilling to coding. * 📆 Peter’s betting two beers at his local pub on Amazon extending the deadline on this one: TLS 1.2 is to become the minimum TLS protocol level for all AWS API endpoints. There’s currently just under a year to get yourself sorted. Good luck! * 🍨 Apparently, even space has (AWS) Snowcones: Amazon sends one to the International Space Station * 🛫 As EKS improves control plane scaling and update speed by up to 4x, get ready for a lot of step function workload. * 🤫 Imagine waiting 10 years for private IP VPNs… well, we did, and here they are, introduced by AWS Site-to-Site VPN.
GCP: Anthos Attracts * 🏢 Google expands Distributed Cloud platform with Anthos on-premises options running on your virtual platform of choice. Very neat. * 💵 Apparently the Google Cloud product manager listens to the show, because we now have billing info at our fingertips in the latest Cloud Console mobile app to show it’s not costing you $100 million a day. * 🛡️ Neat new Cloud Armor edge security policies and proxy load balancer support is now generally available. * 🛡️ And if that wasn’t exciting enough, Cloud Armor also announced even more features including rate limiting, adaptive protection, and bot defense. * 🌦️ Public sector agencies are getting new sustainability offerings to improve climate resilience… so, they have a new insurance company as a customer, right?
Azure: Dispatches From the Space Race * 🛰️ Azure’s Orbital Ground Station as Service (GSaaS) aims to reduce costs for satellite operators while extending their mission life.
Oracle: The Story of All Stories * 🌐 Oracle’s got your back this week, with a dedicated region allowing you to run your stack wherever you like (although it's a stretch to call it a region).
TCP Lightning Round
⚡ After all the desperate talk of crowdsourcing points last week, Peter finally returns to host the lightning round. Jonathan manages to snag the point this week, making the scores Justin (5), Jonathan (3), Ryan (1), and Peter (1). Other Headlines Mentioned: * AWS Support announces an improved create case experience * Public preview: Create an additional 5000 Azure Storage accounts within your subscription * Amazon has a plan to make Alexa mimic anyone's voice * AWS Fargate now fully supports multiline logging powered by AWS for Fluent Bit
Things Coming Up: * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * Microsoft events - TBD Check for status
On The Cloud Pod this week, the team discusses Jonathan’s penance for his failures. Plus: Microsoft makes moves on non-competes, NDAs, salary disclosures, and a civil rights audit; AWS modernizes mainframe applications for cloud deployment; and AWS CEO Adam Selipsky chooses to be intentionally paranoid.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 The Balmer era is officially dead: Microsoft curbs non-competes, drops NDAs from worker settlements, disclose salary ranges, and even launches a civil rights audit. * 🚨 AWS launches their new modernization service for mainframe applications, now deployable in fully managed AWS runtime environments. * 🚨 AWS CEO Adam Selipsky “choose[s] to be intentionally paranoid,” as he leads the company through turbulence.
Top Quotes * 💡 “We've talked about how garbage those [noncompetes] are, the problems they've had with them, executives leaving, Amazon going to Microsoft, then getting sued and all the mess of that. So I'm super glad they're finally starting to see a tide swell change in technology where that's no longer a thing.” * 💡 “I always felt like Amazon was going to just create a mainframe as a service offering — buy a bunch of IBM mainframes that they sell out to you — because that's been a model of mainframe for a long time: CPU slicing, rentals and that kind of thing. But it seems like now they're going to go down this other path where the answer is [that] you convert to a more modern architecture, which is interesting.”
General News: It’s a New Era * 💵 The times they are a-changin’, as Microsoft revises its position on non-competes, NDAs, and salary range disclosure, while launching a civil rights audit. Take that, Amazon! * 💨 Target CIO Mike McNamara jumps away from AWS with a scaled move toward multicloud architecture. Target allegedly has 4,000 engineers, which seems like a lot. * 👎 Archera vents via Venturebeat about the unmanageability of cloud costs, calling for standardized billing. While it might be helpful and even valuable, this seems a road too far traveled.
AWS: Modernized Mainframes and Intentional Paranoia * 🕰️ You can now take advantage of AWS’ new modernization service for mainframe applications, deployable in fully managed AWS runtime environments. * ♻️ There are some nice enhancements for MGN, including DR configuration and Linux to Rocky Linux and SUSE Linux Subscription conversions. * 👀 AWS CEO Adam Selipsky admits, “I choose to be intentionally paranoid,” as he leads the company into a turbulent world. * ☎️ A nice feature so long as you don’t use it for bad things, Amazon Connect now offers high volume outbound campaign capabilities. This clearly exists because customers only answer around 10% of the automated calls they receive. Why? Because it’s all spam. * 🔕 With AWS Managed Microsoft AD, you can finally you can finally disable ciphers, amongst other things. Amazon, what took you so long? * 👌 Justin doesn’t actually hate the new AWS Bills page experience. Not exactly high praise, but in a world where all billing pages are terrible, it’s surely something.
GCP: Big and Powerful * 🥧 Bad scheduling in the press corps led to the very late release of this announcement about 100 trillion digits of pi on Google Cloud. Pi Day was March 14. * 🤖 Google reimagines AutoML and announces Vertex AI Tabular Workflows. * 🤷 For those in ML teams who don't really know what they're doing and want to just take advantage of marketplaces of prebuilt ML AI code, they now can thanks to Google and NVIDIA. * 🔐 To help secure sensitive data, Google announces two new BigQuery capabilities: Column level encryption functions are general available, and there’s a preview of Dynamic masking. * ☹️ If you know the Obama “not bad” meme, you’ll know the reaction Justin had to gcpdiag, the new open source troubleshooting tool. * 🇮🇹 Like all regional announcements, the new cloud region in Milan provides Ryan with the perfect opportunity to add it to his travel list.
Azure: Facial Recognition Is Coming for Us All * 🏎️ Azure SDK for Go is now generally available. Why not? * 📄 There’s now a 16MB limit per document in API for MongoDB, which is in public preview. (That’s an 8x increase for those who want math.) * 🕹️ And if you want to play with that new feature, you can do it locally via the Linux emulator with Azure Cosmos DB API for MongoDB, now in public preview. * 🔥 Learn what’s new in Azure Firewall, and there’s a lot: Intrusion Detection and Prevention System (IDPS) signatures, TLS inspection (TLSi) Certification Auto-Generation, and web categories lookup are all now generally available. Additionally, Structured Firewall Logs and IDPS Private IP ranges are both now in preview. * 🤔 Azure Cognitive Services promises to be responsible with its AI investments and facial recognition safeguards. Only time will tell… * Hot on the trails of AWS and Google, Azure hops on the firewall manager bandwagon with Azure Firewall Manager promising simplified, centralized network security management.
Oracle: Breaking News: Oracle has Finally Fixed its RSS Feed * 🤝 Someone working at Oracle must listen to The Cloud Pod, because Justin is now receiving Oracle news! Oracle announces that more startups are choosing Oracle Cloud Infrastructure (OCI) over other cloud platforms, citing customers that no one has ever heard of like Aleph Alpha and Aindra Systems. * 🗣️ While on an Oracle earnings call after the AWS outage, Oracle Chairman Larry Ellison took the opportunity to quote a (definitely real) anonymous customer who told him “Oracle never ever goes down” — never mind the five incidents that have happened since December 8th. * 💻 Oracle releases OCI DevOps Service, an end-to-end CI/CD platform where developers can commit their own source code to a repository, build and test software artifacts, and run deployments to OCI platforms.
TCP Lightning Round ⚡ New ideas abound as Peter’s disappearance becomes yesterday’s news. Now you can vote for the winner each week via The Cloud Pod Slack Channel. Until those votes come in, the scores stand at Justin (5), Ryan (1), Jonathan (2), Peter (1, although we’re not sure how). Other Headlines Mentioned: * Reduce read I/O cost of your Amazon Aurora PostgreSQL database with range partitioning * Introducing managed zone permissions for Cloud DNS * Announcing private network solutions on Google Distributed Cloud Edge * New – Amazon EC2 R6id Instances with NVMe Local Instance Storage of up to 7.6 TB * Azure API Management reusable policy fragments * Public preview: Azure Cosmos DB serverless container storage limit increase to 1TB
Things Coming Up: * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * Microsoft events - TBD Check for status
On The Cloud Pod this week, half the team whizzes through the news in record time. Plus: AWS Elastic Disaster Recovery, Google Distributed Cloud adds AI, ML and Database Solutions, and there’s another win for NetApp with Azure VMware Solution.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 AWS Elastic Disaster Recovery now supports up to 300 staging and target accounts, which seems like a small number for some enterprises with thousands. * 🚨With the power of Anthos, Google Distributed Cloud adds AI, ML and Database Solutions — continuing the trend of service monetization regardless of host location. * 🚨 Another win for NetApp, the home of choice for Azure VMware solutions optimization.
Top Quotes * 💡 “If you're really doing auto scaling [and] traditional cloud native, you don't use the service because you’ve already built it into your app. So this is for legacy IT operations like SAP, Oracle, and others. Three hundred or 3,000 covers small and medium business, but large enterprise has way more than that.” * 💡 “When Anthos first was announced, and Outpost for AWS, we talked about how likely it was that more and more cloud-native services were going to be made available anywhere, on any cloud, in any data center. It's definitely a pattern of monetizing the services regardless of where they're hosted.”
AWS: Bouncing Back From Disaster * 🗃️ Amazon EMR Serverless is now generally available, a cool feature running big data applications (and Outpost too). But it’s interesting that it’s been branded “serverless” when it’s clearly a managed service. * ⛑️ Elastic Disaster Recovery now supports 300 staging and target accounts, but we can’t help wondering how this helps the largest enterprises. * 📋 Step Functions launches a workflow-based interactive application workshop, and it looks like a golden age for developer experience is close at hand. * 🦖 Amazon Route 53 announces IP-based routing for DNS queries, which is going to make things complicated. So preoccupied with whether or not they could integrate, they didn't stop to think if they should.
GCP: Complexity on Top of Complexity * 📜 Google Chronicle offers context-aware detections, alert prioritization and risk scoring for its Security Operations. But wouldn't you want to protect everybody from everything? * ✅ A boon for customer choice and flexibility: Google Distributed Cloud adds AI, ML and database solutions. On prem, running Kubernetes and Anthos? Justin loves this. * 🤠 Yeehaw! Time to grab that 10-gallon hat and run your server, because the new Google Cloud region in Dallas, Texas, is now open.
Azure: It’s All About the Datastores * 🗄️ Azure VMs get a performance boost for data intensive workloads. You never can get enough storage optimization. * 🔷 Azure introduces comprehensive new skilling guides. Microsoft has been running training programs for more than three decades, so they've got their pattern down by now. * 💻 NetApp does it again as the datastore of choice for Azure VMware Solution, now available in preview.
TCP Lightning Round ⚡ Justin (5) tells Jonathan (2) to try his best to win 0 points, safe from Ryan (1) and Peter (1) in the dungeon. Other Headlines Mentioned: * Amazon EC2 Dedicated Hosts are now available on AWS Outposts * Amazon Kendra releases GitHub SaaS & On-Prem Connector * AWS Security Hub now receives AWS Config managed and custom rule evaluation results * Amazon CloudFront now supports TLS 1.3 session resumption for viewer connections * AWS IoT Device Management announces an 80% price reduction for Secure Tunneling
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
Sustainability Summit - June 28th * AWS Reinforce - June 28th-29th → Now Moved to Boston * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * Microsoft events - TBD Check for status
On The Cloud Pod this week, the team discusses the new Madrid region’s midday siesta shutdown. Plus: Broadcom acquires VMWare for $61 billion, Azure gets paradigmatic with 5G, and you can now take the 2022 Google-DORA DevOps survey.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Broadcom acquires VMWare for $61 billion, in one of the largest-ever acquisitions. * 🚨 Google Cloud and DORA team up to bring us the 2022 Accelerate State of DevOps Survey. * 🚨 Azure calls 5G a “paradigm,” but is it just hype?
Top Quotes * 💡 “This is an interesting reverse on the large cloud providers getting into the silicon business, which makes sense to me — that they want to control their supply chain and optimize. … Is Broadcom going to start becoming like a cloud provider? That's interesting. I wouldn't suspect that.” * 💡 “What [is Azure] trying to do? Are they trying to sell us on [5G]? Are they trying to change the way we develop? Because we're just going to waste our time developing stuff that requires some of these things, and then the infrastructure is not going to be there to support it.”
General News: Diversifying the Portfolio * 💰 In one of the largest acquisitions ever (just shy of Dell’s EMC takeover at $67 billion and Microsoft’s Blizzard acquisition at $69 billion), Broadcom acquires VMware for $61 billion. This could have big implications for enterprise.
AWS: Need for Speed * 💾 If you need a lot of disk space to log transactions, you’re in luck: Amazon EC2 M6id and C6id instances buff up their storage by up to 7.6TB. * 📸 Ryan’s usually doing whatever he can to avoid this, but if you need Elastic Volumes and Fast Snapshot Restore (FSR) support for io2 Block Express, you’ve now got it.
GCP: the State of DevOps in 2022 * ✅ Why do IT leaders choose Google Cloud certification for their teams? In case you were wondering, here’s a puff piece with the answer. * 🏞️ If you need to change streams with Cloud Spanner, you can now do so. A cool feature, but it does need to be by email (there’s no homing pigeon option… yet). * 💫 If you want to learn a whole bunch of irrelevant HPC jargon, this is the blog post for you. * 📋 You can now take the 2022 Accelerate State of DevOps Survey, launched by Google and DORA. * 💥 Eliminate hotspots in Cloud Bigtable, but remember just as “no good plan survives first contact with the enemy,” no data structure plan survives general availability. * 🤔 The super useful Network Analyzer detects service and network issues. Always on and always free to use — very nice! * 🕵️ Like Ryan, you might want more out of Confidential Computing, which is now generally available. * 🇪🇸 The team considers a field trip to Madrid as Google opens a new region there. * 💳 Granular instance sizing for Cloud Spanner could prove very useful for startups and early projects on a budget, with production workloads running for as low as $40/month.
Azure: Getting a Little Meta * 🤝 In a somewhat puzzling move, Meta selects Azure as its strategic cloud provider for AI and PyTorch purposes. Maybe they don’t want to support their own data science teams? * 🔋 Azure calls 5G a “paradigm” instead of an “upgrade”. But is it really even required? * 🤫 Now you’ve got more places to hide your money as Switzerland adds two extra regions to its existing one.
TCP Lightning Round ⚡ Justin (5) continues resting on his laurels, with Jonathan (2) and Ryan (1) tailing behind and Peter (1) still in the dungeon. Other Headlines Mentioned: * Amazon Lightsail containers now supports deploying images from Amazon ECR private repositories * AWS Launch Wizard now supports SQL Server deployments using Amazon FSx for NetApp ONTAP * Amazon ElastiCache for Memcached now supports encryption of data in transit * AWS IAM now supports WebAuthn and Safari browser for multi-factor authentication with security keys
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
Sustainability Summit - June 28th * Amazon Re:Mars - June 21st - 24th * AWS Reinforce - June 28th-29th → Now Moved to Boston * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * Microsoft events - TBD Check for status
On The Cloud Pod this week, the team talks tactics for infiltrating the new Google Cloud center in Ohio. Plus: AWS goes sci-fi with the new Graviton3 processors, the new GKE cost estimator calculates the value of your soul, and Microsoft builds the metaverse.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 AWS fires up the Graviton3 processors for some big energy savings. * 🚨 Google develops the new GKE cost estimator for people who aren’t curious about cost. * 🚨 Microsoft Build comes out of nowhere to deliver awesome, scary AI-driven tools with much mention of metaverse (yuck).
Top Quotes * 💡 “This feature isn't developed for you because you're curious about the cost. This is developed specifically for the people who are not curious about the cost. It's a big red number. When they're doing the deployment, it’s like, oh, I should probably not do that.” * 💡 “I cannot wait for the robot overlords to completely school me at code. This is gonna be hilarious… and frightening.”
General News: HashiCorp Extends Its Reach * 👁️ Ryan is slightly embarrassed by how much he’s excited about the new HCL Extension for Visual Studio Code 0.1 announcement.
AWS: Abiding by the Laws of Graviton3 * 🚰 Storage company NetApp continues to buck industry trends with Backup and FSx support for ONTAP. Don’t forget to check out the TCP Talks interview with Anthony Lye, Executive VP and General Manager of NetApp. * ⚡ New AWS-designed Graviton3 Processors power Amazon EC2 C7g Instances, now generally available. * 🏢 Control Tower now supports concurrent operations for preventive guardrails. Awesome if you’re just starting, tougher if you’ve been at it for a while. * 🔍 If you’ve been waiting for Kendra to give you something you actually cared about in dev, here you go: Jira connector enables document search on Jira repository. * 🤝 Great news: Incident Manager expands support for runbook automation. We love announcements like these. * 💪 Ryan now has even less excuse for not trying Resilience Hub, after it adds support for Terraform, Amazon ECS and more. * 🌩️ Once again, AWS admits that multicloud is a real thing, with DataSync’s flexible file movements across Google Cloud and Azure.
GCP: Changing Behavior One Cost Estimate at a Time * 💸 The new GKE cost estimator seems designed to ward off expensive new deployments. * 🕵️ Unless you’re a total data nerd you won’t likely use PSP's new open source cryptographic hardware offloading. Interesting nonetheless, and could be great technology to try at scale. * 📕 Ryan thinks policy guardrails for Terraform on Google Cloud CLI preview is a huge announcement and readily acknowledges he needs to get out more. * 🌎 Finally for GCP this week, Ohio’s very own Columbus houses a brand new data region.
Azure: Unleashing the Terrifying Power of AI-written Code * 🗃️ It’s what we wanted all along: HostProcess Containers is now in public preview. Great when you need it, but you should try really hard to not need it — it’s last resort territory. * 👷 Neither Microsoft nor our listeners told us about this, but Microsoft Build delivers a dazzling array of tools for builders: AI now writes your code, something something metaverse. * 💵 Don’t you just love paying the market for the marketplace? NGINX is in public preview. * 📒 Jonathan really doesn’t understand the need for Ledger in Azure SQL Database. (A database is meant to be dynamic — it makes no sense for static data.)
TCP Lightning Round ⚡ Because Peter is still in the dungeon and the team is looking out for him, the scores remain the same: Justin (5), Jonathan (2), Ryan (1), and Peter (1). Other Headlines Mentioned: * Amazon Chime SDK now supports video background replacement and blur on iOS and Android * Public preview: Azure Digital Twins 3D Scenes Studio * General availability: Azure Backup supports backup of Write Accelerator enabled disks * Amazon EC2 enables customers to protect instances from unintentional stop actions * Scale your cloud-native apps and accelerate app modernization with Azure, the best cloud for your apps * Announcing Multi-Account Support for AWS Transit Gateway Network Manager * Google Cloud establishes European Advisory Board * Run your fault-tolerant workloads cost-effectively with Google Cloud Spot VMs, now GA * GKE workload rightsizing — from recommendations to action * Unlock real-time insights from your Oracle data in BigQuery * Draft 2: An open-source project for developers building apps on Kubernetes * General availability: Azure Backup support for trusted launch Azure Virtual Machines * Public preview: Azure Stream Analytics no code editor * Introducing the Microsoft Intelligent Data Platform
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
Applied ML Summit - June 9th
Sustainability Summit - June 28th * Google Next - June 6th-8th * RSA Conference - June 6-9th * Amazon Re:Mars - June 21st - 24th * AWS Reinforce - June 28th-29th → Now Moved to Boston * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * Microsoft events - TBD Check for status
On The Cloud Pod this week, the team struggles with scheduling to get everyone in the same room for just one week. Plus, Microsoft increases pay for talent retention while changing licensing for European Cloud Providers, Google Cloud introduces AlloyDB for PostgreSQL, and AWS announces EC2 support for NitroTPM.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Big changes are afoot with Microsoft on both pay and European licensing fronts. * 🚨 A very busy Google finds time to release AlloyDB for PostgreSQL. * 🚨 NitroTPM gets Amazon EC2 support.
Top Quotes * 💡 “I hope that it's the exact opposite of TK and Google Cloud — that they’re really focused on the values and the culture and providing meaningful work. Especially during the last year in the pandemic, a lot of people have realized there's a lot of different priorities; that money is good — it doesn't buy happiness, but it buys a lot of things that can make me happy — but it's getting that fulfillment, and enrichment is also super important. Not just a slog.” * 💡 “The problem is they're not building power plants fast enough to support all of the power demand they have in this country. So there's a possibility that these cloud providers may get pushback on building data centers in the region, which can have a huge detrimental impact. So keep an eye on that.”
AWS: Some Dynamite Announcements * 🤝 AWS teams up with IBM in a SaaS-based partnership. Interesting that it’s IBM, but money talks, and there’s no better time to do it. * 💥 EC2 now supports NitroTPM and UEFI Secure Boot, which is an interesting pivot for the security-minded. * 🛡️ Open source supply chain security gets a nice big $10 million investment from AWS. * ⚙️ If you need the functionality, you’ve got some nice EKS Anywhere curated software packages to choose from, which are now in public preview. * 🕹️ CloudWatch improves the console experience, which no one really wants. There’s a lot more Amazon can be doing.
GCP: Busy Little Bees * 🗄️ AlloyDB for PostgreSQL promises freedom from expensive legacy databases. Here’s to hoping it works. * 😠 Google Cloud employees are seemingly at loggerheads with management on the subject of growth. Is it really a representative sample, though? * 🤖 The U.S. public sector gets Autonomic Security Operations (ASO). Great news if you can’t hire an army of security analysts. * 🎹 The Cloud Pod is all for what furthers the use of temporary ended keys, which SAML’s federated workloads do. Increased flexibility… but probably a step backwards for actual directory. * 🥈 Google saw Amazon’s $10 million investment and raised it with the introduction of its new Assured Open Source Software (OSS) service. * 🏛️ Anthos Multi-Cloud promises standardization, security, and governance across environments. * 🇪🇺 Google Cloud at KubeCon EU announces new projects, updated services, and ways to connect. (KubeCon’s been a little dark for Ryan the last few years.)
Azure: It’s All About the Money * 🤑 Microsoft has jacked up its pay in an attempt to retain talent. Great if you’re money-hungry! * 🔒 Nice job copying Amazon, Azure: The new DNS Private Resolver is now in public preview. * 🎛️ In the shortest announcement ever, Container Apps now support log streaming and console connect. After Justin read the documentation four times and only understood about 40% of it, he decided it wasn’t worth it. * 💚 What’s not to love about going green? Microsoft Cloud for Sustainability accelerates sustainability progress and business growth from June 1. * ⚖️ Microsoft responds to European Cloud Provider feedback with specifically vague and non-binding principles and programs for maximum plausible deniability.
TCP Lightning Round ⚡ The scores remain unchanged with Justin in the lead (5), followed by Jonathan (2), Ryan (1), and Peter (1). Other Headlines Mentioned: * AWS Control Tower can now use customer provided core accounts * Amazon VPC now supports multiple IPv6 CIDR blocks * Amazon CloudWatch Synthetics adds support for canary resources deletion when a canary is deleted * Amazon VPC Traffic Mirroring now supports sending mirrored traffic to Gateway Load Balancer backed monitoring appliances * Administer AWS Single Sign-On from a delegated member account in your organization * AWS PrivateLink announces support for IPv6 * Maintenance made flexible: Google Cloud SQL launches self-service maintenance * Extending BigQuery Functions beyond SQL with Remote Functions, now in preview * Google Cloud is forming a dedicated Web3 team
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
Startup Summit - June 2nd
Applied ML Summit - June 9th
Sustainability Summit - June 28th * Google Next - June 6th-8th * RSA Conference - June 6-9th * Amazon Re:Mars - June 21st - 24th * AWS Reinforce - June 28th-29th → Now Moved to Boston * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * Microsoft events - TBD Check for status
On The Cloud Pod this week, the team discusses wholesome local Oakland toast for breakfast. Plus: Hybrid infrastructure is unsustainable, the AWS Proton template library expands, and Amazon angers the team by describing Step Functions as “low-code.”
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Against the trend of popular opinion, it turns out that hybrid infrastructure is a bad idea in the long term, with a few significant drawbacks. * 🚨 The AWS Proton template library just got bigger, so now people can find something else to complain about. * 🚨 Amazon annoyingly describes Step Functions as low-code, which is definitely not true.
Top Quotes * 💡 “Proton was only developed as an answer for, how should we deploy onto Amazon? It's setting yourself up just so someone can armchair-quarterback and poke holes in it. Now they're saying, well, how would you do this? [Answer:] You have the templates. And then they're gonna be like, the templates are cool, except it doesn't meet my pretty edge case, so they'll complain about that. We'll see templates for the templates next.” * 💡 “I just love the assumption that you could low-code a solution with Step Functions, just because I've created many a step function and state machine flow. And all it is is coding and then figuring out why the code isn't doing what I want — because I'm not passing things correctly between the different functions. The ability for someone who can't write code to be able to to accomplish anything is a little far fetched.”
General News: Don’t Plan on Hybrid for Long... * ⛈️ In the cloud court of public opinion, dissent is infrequent. Yet here’s Michael Bathon of Rimini Street claiming that hybrid is actually bad in the long-term.
AWS: What Is Low-Code, Anyway? * 📚 The AWS Proton template library expands — as does people’s list of things to complain about. * ✍️ Amazon very irritatingly calls Step Functions low-code, with new workflow observability features. * 👯 Can the annoying customer with the single use case please stand up? Amazon RDS for PostgreSQL now supports a lot more read replicas. Driven by the business side, perhaps?
GCP: Something’s Got To Give With BigQuery * 🏃 Cloud TPU VMs are now generally available, with faster speeds and lower costs for training. * ❓ BigQuery BI Engine now supports more tools and custom applications. All we heard is that the analysts want to learn BigQuery, so they made it work for them. * ⛅ It’s one thing to provide a good service and another thing to develop an open source tool that anyone can use for their own workloads in their own clouds: namely, CIS hardening support in Container-Optimized OS. Nice going, Google. * 🎼 Great for those who need it (and a “meh” for those who don’t): You can now orchestrate Looker data transformations with Cloud Composer.
Azure: Red Hat and Azure: Friends With Hybrid Benefits * ⛑️ Azure continues cosying up to Red Hat with seamless workload management. * 🎅 The time when we don’t have to do podcast anymore is near at hand, with new voices and emotions via Azure’s Neural Text to Speech (TTS) * 🛡️ Three new managed services come from Microsoft’s bid to boost its cybersecurity business. Professional services with a security angle?
Oracle: The Search Is On * 🔮 Oracle Cloud Infrastructure (OCI) Search Service with OpenSearch is now available. We’re wondering if they realize this is an open source project largely contributed to by Amazon.
TCP Lightning Round ⚡ The scores remain Justin (5), Jonathan (2), Ryan (1), Peter (1) until the team lets Peter out of the dungeon (maybe next week). Other Headlines Mentioned: * AWS Secrets Manager now publishes secrets usage metrics to Amazon CloudWatch * Amazon EFS now supports a larger number of concurrent file locks * Monitor your Amazon Managed Service for Prometheus usage with Amazon CloudWatch usage metrics * Amazon Connect now supports up to six participants on a customer service call * The New Amazon ElastiCache console is now available
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
June 2nd - Startup Summit
June 9th - Applied ML Summit
June 28th - Sustainability Summit * AWS Summits
May 23-25th - Washington DC * Google Next - June 6th-8th * RSA Conference - June 6-9th * Amazon Re:Mars - June 21st - 24th * AWS Reinforce - June 28th-29th → Now Moved to Boston * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * Microsoft events - TBD Check for status
On The Cloud Pod this week, Peter’s been suspended without pay for two weeks for not filing his vacation requests in triplicate. Plus it’s earnings season once again, there’s a major Google and SWIFT collaboration afoot, and MSK Serverless is now generally available, making Kafka management fairly hassle-free.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Earnings season is upon us once again, with billions earned and lost. Who are the winners? * 🚨 MSK Serverless is now generally available as a boon for Kafka management. * 🚨 Google and SWIFT uproot the financial world in announcing a huge cloud-based collaboration.
Top Quotes * 💡 “It's hard to call a 32% increase for Azure earnings a slowdown, but it is definitely slower than what they saw in 2021 and the boom of the pandemic. But the overall trend is everyone's gonna keep adopting cloud hyperscalers to host their infrastructure.” * 💡 “The important thing about this is that it's signaling a change in compliance controls; all these financial organizations with very traditionally physical hardware in Iraq in the data center [had] no way to move to the cloud. So whether it's through advocacy or proof of process, being able to virtualize all these things is going to be huge and will open up a massive market for new customers.”
General News: Earnings Are In, and It’s Looking... Good? * 🏞️ Imagine earning $116.4 billion and then still losing money. But fear not after such a rough quarter, Amazon: AWS revenue is here to save the day at 37%. * ⭕ Meanwhile, Google revenue increased slightly below expectations, and GCP is still losing money — but $43 million less than last year. * 🚀 Finally, Microsoft has Azure to thank for its 32% growth.
AWS: A Truly Kafkaesque Affair * 🌤️ MSK Serverless is now generally available, offering a reduction in the overhead of managing Kafka. * ⛸️ Amazon EC2 instances get some storage-optimizing icy processing power. (You just know there's still a whole team of DBAs that doesn't think this is good enough.) * 🔑 Last on the AWS front: There are new management features for EC2 key pairs. We’re ecstatic!
GCP: Last Chance to Register for the Google Cloud Security Summit * 🤔 GCP offers some CISO perspectives on security updates, as well as a reminder to register for the upcoming summit. * 😱 No-code solutions provide some nightmare fuel, as SAP BTP announces five new capabilities. What could go wrong? * ☁️ Build and flaunt your cloud skills with a nice new certificate, available from Google’s Coursera training course. * 🏎️ SWIFT and Google are looking to revolutionize the world of finance as they announce a major cloud-based collaboration.
Azure: Premium Class Warfare * 🤗 In what seems a little underhanded, Azure announces new investments to help accelerate a move to them. We’re still not sure about creating a ‘premium class' of Microsoft users (especially since its security updates). * 👾 We’re also not sure if the general availability of object replication on premium blob storage and the increase of the rule limit is a joke or not. * 🤓 You know a nerd wrote this article about the Azure Web Application Firewall (WAF) by the way it opens: “Threat intelligence at scale!”
TCP Lightning Round ⚡ The team agrees that no one earns the point this week, with the scores remaining at Justin (5), Ryan (1), Jonathan (2), Peter (1). Other Headlines Mentioned: * Amazon RDS Data API now supports returning SQL results as a simplified JSON string * Public preview: Static Web Apps support for preview environments in Azure DevOps * Amazon Relational Database Service on AWS Outposts now supports storage autoscaling * Amazon RDS now supports Internet Protocol Version 6 (IPv6) * AWS Snow Family now enables you to remotely monitor and operate your connected Snowball Edge devices * Amazon CodeGuru Reviewer now supports suppression of files and folders in code reviews * AWS AppConfig Feature Flag Lambda Extension announces support for Arm/Graviton2 processors * Amazon RDS Performance Insights now allows you to more easily see metrics for any time interval
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
May 17th - Google Security Summit
June 2nd - Startup Summit
June 9th - Applied ML Summit
June 28th - Sustainability Summit * AWS Summits
May 18th - Tel Aviv
May 23-25th - Washington DC * Microsoft Security Summit - May 12th * Kubecon EU - May 16th-20th * Google Next - June 6th-8th * RSA Conference - June 6-9th * Amazon Re:Mars - June 21st - 24th * AWS Reinforce - June 28th-29th → Now Moved to Boston * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * Microsoft events - TBD Check for status
On The Cloud Pod this week, the team establishes that Justin may be immune to COVID. Plus all the latest from the AWS Summit, Azure Red Button team up on DDOS defense, and engines are revving in the great VMware showdown.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 The AWS San Francisco Summit kicks off with a ton of new generally available stuff, but not-so-impressive attendance (looking at you, COVID). * 🚨 Microsoft and Red Button buddy up on DDOS defense testing initiative. * 🚨 AWS, Google and Oracle rev their engines for the VMware top spot.
Top Quotes * 💡 “Really shows you the power of partnership … There’s finally some easy button for testing these things. Because you always dream: Maybe I could create my own DDoS situation, which seemingly I do occasionally by accident, but intentionally would be nice this time.” * 💡 “I don't necessarily trust their math, but assuming that it’s reasonably correct, it seems like a good market for Oracle to go after if you're gonna try to compete with those three platforms — I don't see a ton of people moving straight to the cloud on VMware. But that's a pretty compelling argument and potentially a way of getting VMware customers to the cloud quicker: let's just do it now if we don't have to get off of VMware.”
General News: Great Expectations * 📈 Gartner anticipates big growth (20.4%) in public cloud spending for 2022!
AWS: Everything Generally Available * 🎛️ Finally, you can use IAM to control access to a resource based on the account, OU or organization that contains the resource — just how it used to be, and makes a whole lot more sense. * 🌈 You might be excited for the confusingly named Amazon CloudWatch for Ray — if you can work out what it is (we couldn’t). Something to do with machine learning? * 🗄️ One for the data scientists: Announcing the Amazon SageMaker Serverless Inference, which should prove a boon for infrastructure management. * 👎 Now the guru can tell you your code sucks, too: Introducing the power of operational issue automatic detection in Lambda Functions with Amazon DevOps Guru for Serverless. * 👯 IoT TwinMaker is now generally available, and while your host doesn’t understand, luckily Ryan is on hand to talk about its uses. * 🔊 AWS Amplify Studio is also now generally available. Justin’s keen to play with it, but Ryan’s convinced it’s compensating for the shortcomings of a managed platform. You decide! * 🌌 Aaaand finally, Amazon Aurora Serverless v2 is now generally available. Nothing says success like a sequel interface.
GCP: Start Your Engines * 🤕 Fixing problems it caused in the first place, here’s version selection for Terraform solutions. * 🏁 Google revs its engine with seven reasons why its WMware beats the competition.
Azure: Push the Button * 🔴 Microsoft and Red Button team up for attack simulation testing. Now you can run that DDOS attack you always dreamed of without the risk of the FBI knocking on your door. * 🚫 Controls to block domain fronting behavior on customer resources are now generally available. Our question: How is this an opt-in choice? Just… turn it on, Azure.
Oracle: A Busy Week * 🏗️ Gartner hits bullseye, asserting that Oracle users fail to get that moving apps to cloud means business transformation. * ♻️ Oracle goes green with accelerated sustainability commitments in the form of environmentally conscious data center provider partnerships. * 🐇 The Oracle Cloud VMware Solution spring release is here, and Oracle is going hard on comparisons with AWS.
TCP Lightning Round ⚡ Justin firmly leads the way with the scores at Justin (5), Ryan (1), Jonathan (2), Peter (1). Other Headlines Mentioned: * AWS Announces General Availability of openCypher support for Amazon Neptune * EC2 Auto Scaling now lets you set a default instance warm-up time for all instance scaling and replacement actions * Amazon Kendra releases Box Connector to enable search on documents in Box Enterprise repository * Amazon Macie adds support for discovering more types of sensitive data * Amazon SES V2 now supports email size of up to 40MB for inbound and outbound emails by default * New AWS Wavelength Zone in Toronto – The First in Canada
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
May 17th - Google Security Summit
June 9th - Applied ML Summit * AWS Summits
May 11-12th - Berlin
May 18th - Tel Aviv
May 23-25th - Washington DC * Microsoft Security Summit - May 12th * IBM Think - May 9th-13th * DevOps Enterprise Summit Virtual - Europe - May 10th-12th | Registration Open | CFP Open * Kubecon EU - May 16th-20th * Google Next - June 6th-8th * RSA Conference - June 6-9th * Amazon Re:Mars - June 21st - 24th * AWS Reinforce - June 28th-29th → Now Moved to Boston * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * Microsoft events - TBD Check for status
On The Cloud Pod this week, the team rediscovers who Ryan is after an eternity (a secret agent). Plus AWS Fargate now delivers faster scaling of applications; new features for Oracle Support Rewards; and Google Cloud Optimization AI: Cloud Fleet Routing API from GCP.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Witness the magic of AWS Fargate scaling of applications — harder, faster, better, stronger. * 🚨 Ooooh! Unveiling brand new shiny features for Oracle Support Rewards. * 🚨 Better planning with more routes: GCP unleashes Optimization AI, API for Cloud Fleet Routing (CFR).
Top Quotes * 💡 “Because of that Fargate-specific limitation, [with] the first three services you're concurrently updating, you'll actually get a much faster rate through ECS test launches, but that fourth service will be slower. At that point, if the math works out where you're better off hosting it on EC2 … it's a lot more complex. I've worked with a lot of teams on trying to get ECS services to scale faster, and usually I look at them a little skeptically — do you really need this fast?” * 💡 “In terms of looking at lists of interview questions from Google algorithm questions and the traveling salesman problem and optimizing journeys through multiple locations, multiple cities, everything else, it's a really hard problem. It only gets exponentially more difficult. And then the more efficient you are with that, the more it costs the environment, the more it costs in time or it costs money. So yeah, it's actually a worthy problem to solve.”
General News: Microsoft Feels the Heat * 🤝 We’re feeling the pain of Microsoft’s licensing, as its tactics to win the cloud battle lead to new antitrust scrutiny.
AWS: A Very Fargate Indeed * 🍺 NetApp’s ONTAP, so line up your glasses for a very fine update indeed. Check out the podcast where we interviewed their very own Anthony Lye. #ShamelessPodcastSalesmanship * 🌉 AWS Fargate now delivers faster scaling of applications, and you can see it in action with ECS. Understand token buckets and how AWS uses them, and if you need a hero, Vlad Ioenscu is here. * ✅ Microsoft Active Directory geeks rejoice: a favored topic of the masses with configurable synchronization launched via Single Sign-On. * ♨️ The Log4j saga simply won’t die: Apache hotpatch issues get a report here.
GCP: Taxi, Please * 💭 Combining data and cross cloud analytics: BigQuery Omni is here, and customers are going to be very happy. * 🚖 API for cloud fleet routing appears in the form of Optimization AI — your route’s going to be a lot easier now.
Azure: The Beauty of Grafana * 🎨 Extend that Azure SQL Migration for Azure Data Studio and make those dreams come true. * 🖼️ Visual Studio Code extension for Azure Container Apps is now in preview, so get a good look while you can. * 📊 You’re stylistically spoiled with Azure Managed Grafana’s data visualizations, now in preview.
Oracle: Second Prize... * 🏅 Oracle Support Rewards has some shiny new features.
TCP Lightning Round ⚡ There’s not much of a move this week, with the scores standing at Justin (4), Ryan (1), Jonathan (2), Peter (1) Other Headlines Mentioned: * General availability: Azure Archive Storage now available in Switzerland North * Azure Purview is now Microsoft Purview * Introducing DevSecOps Solutions from AWS DevOps Competency Partners * Crate.io extends database service offering to Google Cloud * General availability: Azure Cosmos DB autoscale RU/s entry point is 4x lower * Amazon Kendra releases Quip Connector to enable document search in Quip repository
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
May 4th - Google Workspace Summit * AWS Summits
May 4-5th - Madrid
May 11-12th - Berlin
May 18th - Tel Aviv
May 23-25th - Washington DC * IBM Think - May 9th-13th * DevOps Enterprise Summit Virtual - Europe - May 10th-12th | Registration Open | CFP Open * Microsoft Security Summit - May 12th * Kubecon EU - May 16th-20th * Google Next - June 6th-8th * RSA Conference - June 6-9th * Amazon Re:Mars - June 21st - 24th * AWS Reinforce - June 28th-29th → Now Moved to Boston * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC
Microsoft events - TBD Check for status
On The Cloud Pod this week, the team rediscovers who Ryan is after an eternity (a secret agent). Plus AWS Fargate now delivers faster scaling of applications; new features for Oracle Support Rewards; and Google Cloud Optimization AI: Cloud Fleet Routing API from GCP.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights *
In this TCP Talks episode, Justin Brodley and Jonathan Baker talk with Anthony Lye, Executive Vice President and General Manager of NetApp’s Public Cloud Services Business Unit. An industry veteran for over 25 years, Anthony has been at the forefront of cloud innovation for over half this time.
Anthony shares his insight on the importance of embracing disruption in the tech industry. He discusses how NetApp seized the right opportunities, got lucky, and came to dominate the Cloud space — even while younger app developers may have no idea what it was.
"They don't comprehend — nor should they — the complexities of infrastructure,” Anthony explains. “And I really love the fact that we've been able to democratize ONTAP, because it's cool, but you’ve got to be really smart to get the best out of it. And so we just decided we would be the smart ones.”
What’s really behind innovation in tech? “The context is where you are. And people like to think that the world operates through evolution. And sometimes it's revolution –- sometimes, you have to do something radically different.”
Anthony also discusses cloud computing trends, the importance of customer focus, what NetApp does differently, and the multi-cloud. Featured Guest 👉 Name: Anthony Lye
👉 What he does: Anthony is Executive Vice President and General Manager of the Public Cloud Services business for NetApp
👉 Key quote: “You’ve got to put the customer in the middle of your business. And you’ve got to go where they want you to go. If you don't, your hold may last a while, but it won't last. And I still can't believe that what we did we got away with, and we've gotten so much time to build so aggressively. It's great.”
👉 Where to find him: LinkedIn Key Takeaways * 🚨 There are two halves of the cloud space: the IT half and the app half. IT people see huge opportunities in extending data centers. App people want to and can build and run their own stacks, and Anthony took advantage of this. “They don't have to wait for the IT people,” Anthony says. “And I wanted to build something for them — I didn't want to just hang out on the IT side. I went and asked a whole bunch of application people: what do you need?” * 🚨 NetApp spies huge business growth potential on the horizon with recurring revenues. “Recurring revenues are the best kinds of revenues you can get,” Anthony clarifies. But people don’t always consider this. “Because they're different, they sort of ignore them — they don't like them. And before they know it, they're years behind and caught. And passed as if they're standing still.” * 🚨 The customer is and always should be focused on as front and center of any business. For NetApp, the software and implementation are the same, but the unique integrations are what makes the service stand out. With SaaS, it’s now the second “S” — the service — that matters most. “The rule of SaaS is the other Henry Ford thing: you can have it in any color you want, as long as it's black,” Anthony says. “We're going to run it for you as a service, and you're going to love it”, NetApp tells customers, increasing developer productivity and providing a much higher release cadence.
Resources Here's what was mentioned in the episode 👉 * ✔️ ARM: the most widely used family of instruction set architectures with over 200 billion ARM chips produced. * ✔️ CloudCheckr: an end-to-end cloud management platform with cost, security, resource and service functionality. * ✔️ CI/CD (continuous integration/continuous delivery): software development approaches often used in tandem for rapid code delivery and deployment. * ✔️ Databricks: a data warehouse and machine learning company. * ✔️ Elastic Block Service (EBS): an AWS scalable block service. * ✔️ EMC: Dell’s hybrid cloud solution. * ✔️ Filament: a cloud-native platform for data analysis. * ✔️ Grafana: a fully managed service for scalable, managed backend for metrics, logs, and traces. * ✔️ HP Cloud: Hewlett-Packard (HP)’s doomed set of cloud services. * ✔️ ITIL: a library that defines the organizational structure and skill requirements of an IT organization for SOPs and management. * ✔️ Magic Quadrant: a Gartner research methodology. * ✔️ Marketing Research Management (MRM): software for marketers to manage their assets, with planning, budget, production, and program and campaign execution capabilities. * ✔️ "Managed Service Providers (MSP)": cloud management service. * ✔️ ONTAP: NetApp’s data management software. * ✔️ Platform-as-a-Service (PaaS): a model for running applications across all enterprise sizes. * ✔️ Request for Proposal (RFP): an open-source software that uses APIs or a dashboard to control pools of compute, storage, and networking resources. * ✔️ Amazon S3: an AWS cloud object service. * ✔️ SAP: a PaaS cloud service for custom web app development and deployment. * ✔️ Apache Spark: a cloud workload deployment engine. * ✔️ Spot: NetApp’s cloud automation and cost optimization software. * ✔️ VMWare Cloud (VMC): a joint-engineered cloud service between AWS and VMWare.
Top quotes in this episode [8:43] “People talk about us now as a cloud native storage product. They don't ever think now that it's something we lifted and shifted, because we didn't. We really reimagined and engineered it to be unlike any other cloud service.”
[12:02] “You've got to disrupt yourself, I think you've got to come at it from a very different perspective, it's hard. Most people don't really like change — they'd like to know that tomorrow will be like yesterday. And what makes this industry so good is how often it's disrupted. The frequency of disruption in tech is just amazing … there's been so much innovation … now every company is a software company — everybody. It's been really, really fun.”
[31:45] “In the cloud, you have to show how good you are before you get to really take on some of these mega relationships that we had. And we had to show Amazon that we were good enough to be in the cloud — that we were fast enough. And we could prove to Amazon that we could release at cloud speed and operate and run a cloud business. And honestly, you kind of have to beat them a few times. And we did that. And we did something with Microsoft no one's ever done. We did something with Google no one's ever done. And now we've done something with Amazon that no one's ever done. So we've got these three industry firsts. And it was probably more about just us proving ourselves time and time again, and pestering them time and time again, and proving to them time and time again, that we were a credible partner for a very core and fundamental service.”
On The Cloud Pod this week and with half the team gone fishin’, Justin and Peter hash it out short and sweet. Plus Google Cloud SQL Insights, Atlassian suffers an outage, and AWS finally offers accessible Lambda Function URLs.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Atlassian suffers an outage, sparking fears of data loss. * 🚨 AWS offers some very welcome accessibility for Lambda Functions. * 🚨 Google announces Cloud SQL Insights for MySQL.
Top Quotes * 💡 “When Lambda first came out, before I even used it, this is how I thought it would work … then it didn't. So it's cool that it's now available. I'm surprised it wasn't the default — the starting point — before getting more complex, like API gateways.” * 💡 “It's almost required: These tools are so important when it's a managed service and you can't get under the covers yourself. So it's cool, for sure. Especially when you get into how these things work with your cloud and how they interact with each other, it becomes even more important.”
General News: Atlassian Made a DevOops * 🔌 While only 0.25% of their customer base was affected, Atlassian’s outage is not a good look. The company continues to be haunted by it, with data loss fears. * 🌇 Sungard is doomed. A Chapter 11 bankruptcy filing confines them to history’s unmarked grave of discarded cloud victims.
AWS: Lambda Finally Does What It Was Always Meant To * ⛺ Accessible Lambda Function URLs are now yours — something that would’ve been nice when it first came out. * 👮 Security Hub launches five controls and one new integration partner, in a move that seems to open the door to start using it for all sorts of non-security checks. * ⛩️ Amazon ECS now allows you to run commands in a Windows container running on AWS Fargate. Peter doesn’t want to do this at all, but maybe someone does. * 👯 Something you always thought would have been there but didn’t know actually existed: Amazon RDS for SQL Server now supports SQL Server Agent job replication. * ✂️ Ooooooh: PrivateLink, Transit Gateway and Client VPN services all get a data transfer price reduction — a good first step! * ⚙️ In case you’re looking (Peter’s not), there are two new Amazon EC2 bare metal instances. * 🔓 Whoooo this one’s bad: An RDS vulnerability leads to internal service credentials. While it was definitely risky, it’s no longer exploitable. Another fine example of happiness when you’re doing security in layers.
GCP: Great Powers of Observation Unlocked * 🔮 The all-important Cloud SQL Insights for MySQL is now in preview. * 💎 An epically long subsea cable project called Topaz connects Canada and Asia. * ☁️ Breaking out the big bucks: Google Cloud and SADA launch an expanded partnership with a goal of $2.5 billion in cloud sales. * 🔫 MongoDB announces a pay-as-you-go offering on Google Cloud Console — you go, Mongo!
TCP Lightning Round ⚡ With Ryan and Jonathan out of action this week, Peter feels bad about the prospect of giving Justin a point, with the scores staying at Justin (4), Ryan (1), Jonathan (2), Peter (1). Other Headlines Mentioned: * Azure Data Explorer supports Azure private endpoints * Public preview: Azure Backup supports metrics and metric alerts for Azure Blobs * AWS Shield Advanced now supports Application Load Balancer for automatic application layer DDoS mitigation * Generally available: Service tags support for user-defined routing
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
May 4th - Google Workspace Summit * SQL Server & Azure SQL Conference - April 5-7th * AWS Summits
May 4-5th - Madrid
May 11-12th - Berlin
May 18th - Tel Aviv
May 23-25th - Washington DC * IBM Think - May 9th-13th * DevOps Enterprise Summit Virtual - Europe - May 10th-12th | Registration Open | CFP Open * Kubecon EU - May 16th-20th * Google Next - June 6th-8th * RSA Conference - June 6-9th * Amazon Re:Mars - June 21st - 24th * AWS Reinforce - June 28th-29th → Now Moved to Boston * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Google Cloud Next - October 11th - 13th * Oracle Cloud World - October 16-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * Microsoft events - TBD Check for status
Google Biglake takes the feature of the week with the ability to federate data from multiple data lakes. On The Cloud Pod this week, the team discusses the most expensive way to run a VM (Oracle wins). Plus some exciting developments, an AWS OpenSearch 1.2 update with several new features, and Azure’s having a party, so bring your own IP addresses (BYOIP).
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 The Cloud Pod goes fishing on Google BigLake with a new tackle box and a whole lot of data. * 🚨 AWS opens up the market with its OpenSearch 1.2 update boasting several new features and which could attract more customers. * 🚨 Azure implements a fancy new bring your own IP addresses (BYOIP) policy.
Top Quotes * 💡 “Are they saving BigOcean for the next layer of unification above when we need to aggregate multiple BigLakes?” * 💡 “It is good to be able to do it, and I still pity the poor companies who need to migrate IP addresses and anchor their IPs to a provider in order to get their DVR functionality. So this now makes that possible, however bad a pattern that is in the cloud.”
General News: Decisions, Decisions * 🗺️ VentureBeat discusses how to choose the right AWS region for your business, but they seem to be missing a few considerations (sovereignty, anyone?). Also, picking a region isn’t a great idea for a business (like an e-commerce site) that needs to be multiregional to survive if things go sideways.
AWS: Opening up the Search Nice and Wide * 🤝 Amazon EKS now supports Kubernetes 1.22 — maybe AWS bribed the Kubernetes governance board because they were tired of trying to keep up with Kubernetes’ quarterly patch releases. * 🧑🚀 Good news for console users who no longer have to click through five separate pages of configurations, with the new and improved Amazon EC2 console launch experience. * 🔒 Cue applause track: AWS Organizations now provides central AWS account closure. We’ve been waiting for this for years. * 🙋 Amazon EC2 now performs automatic recovery of instances by default — a no-brainer, really. * 💾 Killing the need for all those expensive backup software solutions, AWS Backup now allows you to restore virtual disks from protected copies of your VMware virtual machines. You can use it for decades. * 💰 Could there be a more expensive way to run a VM than VMware Cloud on AWS Outposts? Yes, as it happens: Oracle. But this is a not-so-distant second place. * 📠 Not ideal, but there should be a workaround, as Amazon EC2 now reduces the visibility of public Amazon Machine Images (AMIs) older than two years. * 🔎 Amazon OpenSearch Service releases OpenSearch version 1.2, with new features which could appeal to more customers.
GCP: It’s Fishing Season, so Let’s Get on the BigLake * 🤑 Cloud Spanner gets some juicy cost reductions for scaling costs (up to 50%!) and a whopping double the provisioned storage. * 🎣 If you’re excited about all things big data (we know we are), Google has announced new capabilities with Google BigLake and Spanner Change Streams.
Azure: Azure’s Partying, so Bring Your Own IP Addresses * 🔌 Increased remote storage performance with Azure Ebsv5 VMs is now generally available, offering some serious IOPS. * 💪 It’s about time: Azure previews its VMs with Ampere Altra Arm-based processors — Ultra Disk Storage isn’t available yet, but it is coming soon. * 🍺 Bring your own… IP addresses? Azure’s new BYOIP policy offers a Custom IP Prefix. Fancy! * 📈 How do you build a spot market? Witness the preview of AKS capacity reservation support. * 🤵 There’s now dedicated host support in AKS, too. Is the Azure team listening to the Cloud Pod and copying our great ideas?
Oracle: It’s Baseball Season * ⚾ To support strategic objectives, the San Francisco Giants proudly choose the ‘best’ cloud provider as their sponsor — no prizes for guessing who they went with.
TCP Lightning Round ⚡ With Ryan AWOL, Jonathan gets a leg up this week, making the scores Justin (4), Ryan (1), Jonathan (2), Peter (1). Other Headlines Mentioned: * Public preview: Azure Bastion support for Kerberos authentication * Amazon FSx for NetApp ONTAP now enables you to change the throughput capacity of your file systems * The AWS Lambda console now supports bulk update of layers * Sustainability Pillar is now available in AWS Well-Architected Tool * Amazon ECS announces increased service quota for container instances per cluster * Amazon SageMaker Data Wrangler now supports Databricks as a data source * Announcing general availability of Amazon Athena ACID transactions, powered by Apache Iceberg
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
May 4th - Google Workspace Summit * AWS Summits
April 20th-21st - San Francisco
May 4-5th - Madrid
May 11-12th - Berlin
May 18th - Tel Aviv
May 23-25th - Washington DC * IBM Think - May 9th-13th * DevOps Enterprise Summit Virtual - Europe - May 10th-12th | Registration Open | CFP Open * Kubecon EU - May 16th-20th
On The Cloud Pod this week, Ryan is in the doghouse and he’s been suspended (with full pay). Plus, we’re comfortably numb with AWS Cloud NGFW, GCP suspends hosts for big savings, and Azure is once again shutting the Front Door on us.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 AWS Cloud NGFW cost calculations leaves us comfortably numb. * 🚨 GCP boasts big savings by temporarily suspending unneeded hosts. * 🚨 Azure is once again shutting the Front Door with a new, modern cloud service.
Top Quotes * 💡 “I'm ready to make my [AWS] re:Invent next year's first prediction, which will be an AmazonBasics version of that for 1/10th of the cost.” * 💡 “I’m very curious to actually see the comparison … in cost because, assuming performance is relatively similar, cost is what this always comes down to.”
AWS: Pay Less, More Often! * 💸 Helping you bleed cash by the hour instead of writing one big annual check, AWS presents the new Cloud NGFW. Ouch. * 👣 Knock yourself out with up to 10 GB ephemeral storage supported with AWS Lambda. It’s cheap (at $0.0000000309 for every GB-second), but they’re not giving it to you — they’re selling it to you. * 🔴 We’re slightly concerned about the general availability of AWS Proton support for Terraform Open Source and its effects on potential future innovation. * 🕹️ Amazon hops on Google’s gamification bandwagon with Amazon GameSparks now in preview.
GCP: GCP Equalizes With a Quiet Week * 🚟 Nice job, Google: a feature with an edge over other cloud providers that offers big savings by temporarily suspending unneeded Compute Engine VMs. Awesome!
Azure: It All Comes Down to Costs * 🚪 Azure shutting the front door on us once again with the now generally available modern cloud CDN service, Azure Front Door. This probably gives them a competitive advantage over AWS for at least a week or two. * 🇮🇳 In a surprising turn of events, Microsoft announces its intent to establish an India datacenter region in Hyderabad. As that’s where most of their employees are, how was there not one there already? * ⚖️ It’s like UPnP for cloud, so do not use lightly: Azure Load Balancer now allows you to manage port forwarding for a backend pool. We seriously recommend discussing this with your security team in advance.
TCP Lightning Round ⚡ Peter finally levels up, making the scores: Justin (4), Ryan (1), Jonathan (1), Peter (1). Other Headlines Mentioned: * Generally available: On-demand capacity reservation with Azure Site Recovery safeguards VMs failover * General availability: Azure Bastion native client support * Managed entitlements in AWS License Manager now supports license usage for AWS Marketplace licenses * Amazon RDS Free Tier now includes db.t3.micro, AWS Graviton2-based db.t4g.micro instances in all commercial regions * Amazon RDS now supports Internet Protocol Version 6 (IPv6) on RDS Service APIs * Amazon EC2 Auto Scaling instance lifecycle states are now available via the Instance Metadata Service * Amazon Kendra releases Slack Connector to enable Slack messaging search
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
April 6th - Data Cloud Summit
May 4th - Google Workspace Summit * SQL Server & Azure SQL Conference - April 5-7th * Azure Modernize and Migrate with Hybrid cloud flexibility digital event - April 13th 9:00 AM-11:00 AM Pacific (5 reasons to attend) * AWS Summits
April 12th - Paris
April 20th-21st - San Francisco
May 4-5th - Madrid
May 11-12th - Berlin
May 18th - Tel Aviv
May 23-25th - Washington DC * IBM Think - May 9th-13th
On The Cloud Pod this week, it’s a brave new world for Ryan, who learns all kinds of things. Plus the Okta breach leads to customer outrage over not telling them for months, AWS announces its new Billing Conductor, and Google expands Contact Center AI for a reimagined customer experience.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Okta is in big trouble with furious customers after it fails to disclose a security breach… for months. * 🚨 AWS announces the brand new and very welcome AWS Billing Conductor to much fanfare and great rejoicing. * 🚨 Google expands end-to-end with Contact Center AI for a touted “reimagining” of the customer experience.
Top Quotes
General News: Okta Breach Shenanigans * 🤬 Change your credentials immediately. Customers are raging at Okta, which manages 100 million logins but failed to disclose a security breach for months. Just who is running things over there?
AWS: Money Money Money * ⛳ Donald Trump’s golf courses are going to be very unhappy to learn that AWS is investing $2.3 billion in UK data centers over the next two years, taking advantage of the Moray West Wind Farm off the coast of Scotland — creating 1000 jobs and injecting £500,000 into the Scottish economy. * 👊 Billing and accounting departments across the land rejoice as AWS announces its very welcome and much improved AWS Billing Conductor. * 🤝 Sharing is caring: AWS Lambda console now supports the option to share test events between developers.
GCP: ReAImagining Customer Experiences * 🤖 “Agent, please.” Let’s hope Google’s Contact Center AI expansion won’t leave customers as frustrated as they usually are and that this is a step in the right direction for support. * 🏎️ Go go go! Announcing Go 1.18, now generally available with Google Cloud. But will Rust eat Go’s launch? * 🤞 Google is leading the way to our zero-trust future with its new CA Service.
Azure: Got Your PhD in Acronyms Yet? * 🏔️ Epic new instances as HBv3 VMs for HPC are now generally available with AMD EPYC CPUs with AMD 3D V-Cache. Quite a mouthful. * 🔐 Private Link support for Azure API Management now allows you to secure your APIs. Maybe no one wants to standardize APIs, but can we at least standardize instance names across clouds so we know what we’re talking about? * 📈 We’re surprised new graphics card-based instances are being deployed, but here we are with NVads A10 v5. COVID-related supply chain issues, maybe? * ✨ Azure has added new features to Azure Virtual WAN, including two new partners — Fortinet and Versa — to expand SD-WAN capabilities, branch connectivity, custom traffic selectors, and more.
Oracle: After Weeks of Silence, a Story Emerges * 🤝 The OCI VP says the need to take advantage of microservices in order to use the cloud is a myth. Not quite: It’s just if you don't take advantage of micro services, you're paying through the nose for cloud services.
TCP Lightning Round ⚡ Justin rockets ahead while Peter’s absence leaves him continuously flagging, with the scores standing at: Justin (4), Ryan (1), Jonathan (1), Peter (0).
Other Headlines Mentioned: * AWS Backup Audit Manager adds new controls to help prove compliance of maintaining immutable backups across AWS Regions and accounts * Amazon RDS for PostgreSQL now supports tds_fdw extension for SQL Server Databases * Amazon RDS supports itemized billing for RDS Storage, IOPS and backup features * Amazon Chime SDK now supports sessions with up to 10,000 live participants * Zscaler, Okta, CrowdStrike seek to combat zero trust ‘confusion’
Things Coming Up: * Google Cloud Summit Series (Updated Regularly)
April 6th - Data Cloud Summit
May 4th - Google Workspace Summit
April 12th - Paris
April 20th-21st - San Francisco
May 4-5th - Madrid
May 11-12th - Berlin
May 18th - Tel Aviv
May 23-25th - Washington DC
On The Cloud Pod this week, the team discusses Peter’s concept of fun. Plus digital adventures with AWS Cloud Quest game, much-wanted Google price increases, and a labyrinthine run-through of the details of Azure Health Data Services.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 AWS gamifies cloud training with the release of Cloud Quest, along with two new initiatives in a bid to build foundational cloud skills for younger people. * 🚨 Google announces price changes while framing it as “choice”: Some services will decrease in price while others will increase. * 🚨 Microsoft launches Azure Health Data Services, the details of which turn out to be super fun trying to get your head around.
Top Quotes * 💡 “If you've ever wanted the job of living in a 3D world where a construction worker runs up to you and tells you that the server running in this weather app is failing and helping them figure this out, this game is for you. And you can earn gems and build and it feels very much like Roblox…. I give it an A for effort and an F for execution.” * 💡 “One of the arguments that people have made against the cloud forever is that once you're locked in, they're gonna jack the rates up, and then you're screwed because you're stuck there. It's that exact thing. This is now giving credence to those naysayers who traditionally will say that's not really true. … Now we have an exact use-case: Google did it. So what’s to stop Azure and AWS from doing it?”
AWS: Slay the Dragon and Rescue the Cloud * 💪 New bigger and badder EC2 X2idn and X2iedn Instances for you to throw your money away on are now here — supporting memory-intensive workloads with higher network bandwidth. * 🥧 If you’re excited about Pi Day, Jeff Barr helps celebrate with a bragging blog post on the number of objects Amazon S3 now boasts (with some fun galaxial anecdotes to boot). * ⬆️ A feature we can finally appreciate: Amazon ECS Update Service API now supports updating Elastic Load Balancers, Service Registries, Tag Propagation, and ECS Managed Tags. * 🪟 And moving onto an AWS feature we don't care about, Amazon ECS now supports on-premises workload orchestration on Windows OS. * 🛑 More Windows support arrives, this time for containerd runtime on EKS starting with Kubernetes 1.21. We don’t know about you, but we’re starting to get releases mixed up here. * 🏁 Don't get fooled by the marketing folks: There’s still work for the dev team to do with the general availability of AWS AppConfig Feature Flags. * 🗃️ We’re not sure who wants to use this, but Amazon RDS for PostgreSQL now supports mysql_fdw extension for Amazon Aurora, MySQL and MariaDB Databases. Wait… wasn’t that just patched in Log4j? * 🗡️ Get your role-playing gear on, as AWS Cloud Quest has been announced. There are two new initiatives from AWS to help build foundational cloud skills. Use them as a reward or a punishment for your children — you decide!
GCP: Announcement of the Week * ✂️ You may see a price cut… or a price increase (uh-oh) with updates to GCP’s infrastructure capabilities. Of course, it’s framed as giving you more “choice”. * 🧾 Techcrunch breaks it down with a nice summary. In short: If you don't touch it very often, your pricing probably went down. * 💻 Hacker News has some interesting commentary worth thinking about when choosing your cloud provider. * 🐮 Maximizing savings on Cloud Spanner just got easier with new committed use discounts (yep, CUDs). Imagine a whole bunch of Google salespeople wearing a chewing cow t-shirt with the tagline just chew our CUD! * 🏅 With an eye on the bottom line and a march toward reducing, customer support offerings are changing. Say goodbye to existing Silver, Gold and Role-based support services, which are ending May 31. * ✊ Layoffs, breakdown of trust and tensions build with Google’s leadership under fire from employees. * 📄 If there must be firings, let it be from marketing, because the Chronicle team is publishing on Medium about security operations instead of the official Google blogs.
Azure: Health and Data and Services, Oh My! * 🤝 Azure partners is everyone’s favorite topic, and Microsoft doesn’t disappoint. An Azure Ponzi scheme allows resellers to generate margin by cutting their own deals with the ISPs on the marketplace. * 🎖️ Justin is in line for a medal for making it all the way through the details of the Azure Health Data Services launch. * 🏥 From Text Analytics, de-identification and event notification through to Synapse Analytics and FHIR capabilities as well as Microsoft Power BI, there’s a wealth of information for you to pore over at your leisure. * 🏷️ There’s even a pricing model based on consumption and only paying for what you use. Have fun!
TCP Lightning Round ⚡ Justin jumps ahead again and Peter just can’t catch a break. The scores: Justin (4), Ryan (1), Jonathan (1), Peter (0). Other Headlines Mentioned: * Amazon MSK Connect now supports external secrets and configuration with config providers * Amazon Comprehend launches entity-based sentiment analysis * AWS Systems Manager Change Manager now supports taking actions on multiple change requests together * Public preview: Azure Purview workflows * Public preview: Azure Backup support for trusted launch Azure Virtual Machines * Amazon Route 53 Resolver DNS Firewall significantly reduces service cost * AWS Cost Anomaly Detection supports integration with AWS Chatbot * Zscaler, Okta, CrowdStrike seek to combat zero trust ‘confusion’
Things Coming Up: * AWS Summits - US - April-October, APAC - May, EMEA - April-June * SQL Server & Azure SQL Conference - April 5-7th * Google Cloud Summit Series (Updated Regularly) - Data Cloud Summit - April 6th * IBM Think - May 9th-13th * DevOps Enterprise Summit Virtual - Europe - May 10th-12th | Registration Open | CFP Open * Kubecon EU - May 16th-20th * Google Next - June 6th-8th * RSA Conference - June 6-9th * AWS Reinforce - June 28th-29th * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * MS Build - TBC
On The Cloud Pod this week, the team reminisces about dealing with awful database technologies, which Ryan luckily managed to avoid. Plus all things cybersecurity as Linux gets hit with a huge security emergency, Google acquires Mandiant for $5.4 billion, and Orca Security catches a major Azure cross-tenant vulnerability.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Linux is on the backfoot as it’s hit by the most severe vulnerability in years. * 🚨 Google has acquired the cybersecurity giant Mandiant for a cool $5.4 billion. * 🚨 Orca Security catches a huge Azure cross-tenant vulnerability.
Top Quotes * 💡 ”But is Mandiant now going to be suddenly finding the vulnerabilities and publishing the vulnerabilities that they're finding in Azure and AWS, and happen to maybe not mention the ones externally that are happening in GCP? They're no longer an independent third party.” * 💡 “Even with these things happening, you're still safer running in the cloud. Even though there are outages, you're still more highly available in the cloud. I hate to see these things in the news.”
General News: Linux Is Feeling the Pain * 🆗 Knative is now officially a CNCF incubating project — any competitors in the market? * 😦 As Linux is bitten by its most high-severity vulnerability in years, we take back everything we said about Windows vs Linux security.
AWS: Solving Very Cloudy Problems * 🗄️ Faster failover is the name of the game with AWS this week: its RDS for MySQL & PostgreSQL Multi-AZ deployment option comes with improved write performance. Jonathan is also very, very excited about their JDBC driver for MySQL. * 👀 AWS customers can now request their CyberGRX report for due diligence on third-party suppliers. But who watches the watchmen? * ⏱️ Ryan’s always suffered from slow performance, but now he can now get specific about how his bad code is affecting it, thanks to Amazon DevOps Guru’s extended support for Lambda with CodeGuru Profiler integration.
GCP: Getting Out the Wallet * 🤫 Google pays $5.4 billion in hush money to Mandiant in a move that’s sure to massively boost their credibility in the cybersecurity arms race. Mandiant’s biggest customer? GCP itself. * 🔧 You can now leverage OpenTelemetry to democratize Cloud Spanner observability — which of course they want everyone using.
Azure: Take Shelter From the Storm * ⛈️ Microsoft’s new security chief says it’s time to take shelter in the cloud. Between this and Mandiant, is Amazon missing out here? * 🐋 Orca Security is back on the hunt as it catches a catches a massive Azure cross-tenant vulnerability. * 📈 Azure introduces dynamic lineage extraction from Azure SQL Databases in Purview, whatever this means. Luckily, Jonathan is here to decipher it for us (and if the Microsoft PR department is listening, he’s ready to accept consulting requests).
Oracle: Oracle Customers Seeking Improved Performance With... Oracle? * 🤝 Oracle provides its top reasons why a multicloud improves performance, but they’re short on the data to back up this claim — it’s also not clear which customers they asked. Was it, by any chance, Oracle’s own customers?
TCP Lightning Round ⚡ Justin charges ahead once again and Peter’s (sadly) still lagging, making the scores Justin (3), Ryan (1), Jonathan (1), Peter (0). Other Headlines Mentioned: * SOC reports now available in Spanish * Generally available: Azure Chaos Studio Key Vault and Classic Cloud Services faults * Public preview: Schedule automated emails of your saved cost views * Amazon Genomics CLI adds the Snakemake workflow management system * Amazon Kendra adds spell checker for queries * You can now choose from two different compression options on Amazon FSx for OpenZFS * Zscaler, Okta, CrowdStrike seek to combat zero trust ‘confusion’
Things Coming Up: * AWS Summits - US - April-October, APAC - May, EMEA - April-June * SQL Server & Azure SQL Conference - April 5-7th * Google Cloud Summit Series (Updated Regularly) - Data Cloud Summit - April 6th * IBM Think - May 9th-13th * DevOps Enterprise Summit Virtual - Europe - May 10th-12th | Registration Open | CFP Open * Kubecon EU - May 16th-20th * Google Next - June 6th-8th * RSA Conference - June 6-9th * AWS Reinforce - June 28th-29th * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * MS Build - TBC
On The Cloud Pod this week, the team heads down a Cisco business model rabbithole. Plus cloud status pages struggle with reality, AWS is tracking carbon footprints, and Microsoft sees serious security business growth with Defender.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 Cloud status pages aren’t reflecting reported issues, in what appears to be a cover-up by error-shy cloud providers. * 🚨 AWS introduces a new carbon footprint dashboard to help customers track their sustainability for cleaner, greener living. * 🚨 Following on the heels of AWS and Azure, Microsoft Defender now provides security on Google Cloud, and is also available for Azure Cosmos DB.
Top Quotes
💡 “Understanding the thresholds would be nice, but it's difficult, because if you have an instance up and running just fine, but you can't launch a new instance, is EC2 down? Is the control plane being down the same as the service itself being down? The ability to launch a new instance would be fairly instrumental to using the service. There're lots of very fine distinctions made between whether something's working or not. I think a little more transparency is needed. But I don't think they're trying to mislead anybody.”
💡 “They're so strong in other areas, I think it's a mistake to try to compete everywhere with the two other companies that are roughly [their] size. Do the thing you're really good at and just keep doing it better.” General News: Move Along, Everything’s Fine Here * 😕 It seems like cloud providers are on a customer gaslighting mission, with cloud status pages not reflecting reported issues.
AWS: Continuing Its Tradition of Silly Names * 🥗 In a badly timed announcement, AWS shows off its new unified Health Dashboard. It does make sense to keep it in one place, though. * 🧮 Amazon S3 showcases important, super valuable new additional checksum algorithms. If it’s computationally expensive, push it back onto the client. * 🏊 Amazon EC2 Auto Scaling Warm Pools has two new hibernation and scale-in features — a great solution for penny-pinchers who invested in Windows. * 👮 The new AWS CloudSaga tool allows for security event simulation and testing. A great first step in what should prove to be cheaper than bringing in a whole team to do it. * 🌐 How many IPv6 workloads are you running? Now you can connect them to IPv4 Services. * 🦶 Six months too late for Jonathan, AWS’ new Customer Carbon Footprint Tool allows customers to track sustainability, helping to reach those clean and green goals. * GCP: Slow News Week * 🏪 It’s incredible how difficult it can be to find something in the marketplace when you know exactly what you're looking for. Luckily, here are four ways Google Cloud Marketplace simplifies buying cloud software.
Azure: Ring, Ring * ☎️ If you’re a telco operator looking to sell cloud services, you’re in luck. The new Azure for Operators solutions and services are paving the way for the future of telecoms. * 🛡️ In a nice strategic play, Microsoft joins AWS and Azure as it expands Defender security to Google Cloud. * 📓 Logz.io now integrates seamlessly with Microsoft Azure. Why didn’t Microsoft just buy it? Simple: so that Elasticsearch remains somebody else's problem. * 🌌 More moves from Microsoft Defender, now available for Azure Cosmos DB. We just wish it had come a year ago.
Oracle: Finally Fixed its RSS Feed * 🎚️ Oracle announces its new on-demand capacity feature, which probably should’ve already been available. * 🔬 Skipping out on AI and ML and going the data science route, Cloud Guard Threat Detector is now available in Oracle Cloud Infrastructure. Does this mean Oracle can be sued if things go wrong?
TCP Lightning Round ⚡ With Ryan absent this week, Justin jumps ahead, but Peter’s still flagging behind, rendering the scores Justin (3), Ryan (1), Jonathan (1), Peter (0). Other Headlines Mentioned: * AWS QnABot adds support for Genesys Cloud contact center, client filters and sensitive information log redaction * AWS App Runner adds a Java platform * AWS Firewall Manager now supports AWS Network Firewall Centralized Deployment Model * Students, start your engines! AWS DeepRacer Student Virtual League is now underway * AWS Trusted Advisor introduces Priority for AWS Enterprise Support customers (Preview) * Amazon Fault Injection Simulator now supports Task-Level Faults for Amazon Elastic Container Service * Amazon CloudWatch Container Insights adds support for Helm chart using AWS Distro for OpenTelemetry
Things Coming Up: * AWS Summits - US - April-October, APAC - May, EMEA - April-June * SQL Server & Azure SQL Conference - April 5-7th * Google Cloud Summit Series (Updated Regularly) - Data Cloud Summit - April 6th * IBM Think - May 9th-13th * DevOps Enterprise Summit Virtual - Europe - May 10th-12th | Registration Open | CFP Open * Kubecon EU - May 16th-20th * Google Next - June 6th-8th * RSA Conference - June 6-9th * AWS Reinforce - June 28th-29th * DevOps Enterprise Summit Virtual - US - August 2nd-4th * Blackhat USA - August 6th-11th * VMWorld - US - August 29th-September 1st * DevOps Enterprise Summit US Flagship Event 🎉 The Cosmopolitan of Las Vegas - October 18th-20th * Kubecon US - October 24-28th * MS Ignite - November 2nd-4th * AWS Reinvent - November 28th-Dec 2nd (assumed) * Oracle OpenWorld - TBC * MS Build - TBC
On The Cloud Pod this week, order in the court! Plus tackling those notorious latency issues with AWS Local Zones, things get quick and rusty with AWS s2n-quic, and GCP flexes with Dataplex data mesh.
A big thanks to this week’s sponsor, Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. This week’s highlights * 🚨 AWS takes on network latency issues — its customers’ #1 complaint — with AWS Local Zones. * 🚨 AWS is getting quick and rusty this week with s2n-quic, its new open-source protocol for Rust implementation. * 🚨 GCP announces Dataplex in Google Cloud is now generally available, enabling the creation of the data mesh view.
Top Quotes * 💡 “We must be hitting some huge brick walls in web performance that are really hurting certain application workloads that require low latency, because if you look at both these announcements back-to-back, they're really trying to improve performance.” * 💡 “This is definitely a hard problem for companies to solve. Data is not going to be uniform, and you're going to have many different sources of it, and you want it to all play nice together so it's usable across a larger view than it used to be. I like these types of solutions, where they're applying governance and a way of doing things that's not just everyone reinventing these wheels — which is what we've been doing up until now.”
General News: Order in the Court! Judge Ryan Presides * ⚖️ Best Buy selects AWS as its strategic cloud provider, but Peter and Ryan argue that it may not be all that exclusive. * ☁️ VentureBeat reveals that Optimizely is partnering with Google Cloud. Justin thinks the reason the company chose GCP over AWS comes down to wanting to feel special.
AWS: Goodbye Network Latency? * 🌐 With AWS’ announcement of the global expansion of AWS Local Zones, will its customers’ number one complaint (network latency) be finally addressed? No doubt a good move forward. * 💨 AWS is also getting quick and rusty this week with the introduction of s2n-quic, the new open-source QUIC protocol for Rust implementation. For encryption nerds, this is it. * 👯 The general availability of AWS Backup for Amazon S3 is sure to be a great enablement — not to mention a massive cost saving for those using the age-old solution of full data replication between buckets. * 🧾 Amazon comes to the rescue with auto-adjusting budgets — something to add to budgets, not a tool to replace them. Super valuable nonetheless!
GCP: The Great Dataplex Data Mesh Flex * 🪢 You can now build a data mesh on Google Cloud with Dataplex — very fancy and very helpful. * 🐶 If you’ve got security concerns (who doesn’t?), the new FIDO security key support answe
On The Cloud Pod this week, Jonathan’s got his detective hat on. Plus Akamai steps up to CloudFare with Linode acquisition, AWS’ CloudFormation Hooks lift us up, and EPYC instances are now available.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Akamai notes CloudFare’s aggressive pivot to edge computing and acquires AWS competitor Linode for $900m. * 🚨 AWS announces the general availability of AWS CloudFormation Hooks, which should prove very useful. * 🚨 Amazon provides EPYC-powered instances, with up to 15% improvement in price-performance.
Top Quotes * 💡 “When AWS announces general availability of an instance, I have never been unable to launch that instance to test it. … I can't say the same thing for workloads on GCP.” * 💡 “If you ever take a laptop that has no security patches on it and you put it on a network … it'll be hacked within minutes. It's crazy how bad it is, actually. This is what we always talk about: it’s when you get hacked, not if you get hacked. Because if you have vulnerabilities, there's always a chance. It's just a matter of time before someone figures it out.”
General News: Akamai Steps Up Its Game * 🛡️ Capitalizing on existing relationships, F5 unveils its new cloud platform with a huge advantage in security — but it might be a tough sell. * 🉐 Akamai acquires AWS competitor Linode for $900m. Clearly Akamai saw what CloudFare was doing and thought I gotta get me some of that.
AWS: Getting Its CloudFormation Hooks In * 🪝 AWS announces the general availability of its CloudFormation Hooks. Very nice. * 🪵We wish we’d had Amazon CodeGuru Reviewer’s new security features back in December — now it’s February and no one cares about Log4j anymore. * 🪢 A nice freebie comes in the form of improved performance for Amazon Elastic File System (EFS). * ⛰️ Epic new EC2 c6a instances are powered by EPYC processors, providing up to 15% price performance improvements next to c5a instances. And there was much rejoicing. * 🛑 Protect your login page against credential stuffing attacks with AWS WAF Fraud Control. * 🏠 We don’t completely hate the new Billing console home page experience. Actually, it’s pretty good. * 🤔 Ryan thinks AWS’ Migration Hub Refactor Spaces (now generally available) sounds cool, but he’s suspicious as to how effective it will actually be.
GCP: Also Wants To Be Epic * 👷 Vertex AI has nifty
On The Cloud Pod this week, Ryan grapples with life in the confusion matrix. Plus money money money with Q4 2021 earnings announcements, shiny new digital badges from AWS, and Google Serverless Spark lights the way on data processing and data science jobs.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Q4 2021 earnings: Amazon and Microsoft are killing it with impressive cloud revenues (the only part we care about), and Google is losing money but its cloud is still growing. * 🚨 Nothing much from AWS (again) as performance reviews continue over there; but there are some new digital badges to show off your AWS cloud storage knowledge. * 🚨 Serverless Spark is now available on Google Cloud to simplify data processing and data science jobs, allowing more focus on code and logic, and less on managing clusters and infrastructure.
Top Quotes * 💡 “There's the rub: it's in the details as usual. You do need to operate as a business and achieve that transformation together. No matter what, any kind of migration is going to have an impact on product delivery and feature roadmap, which will have an impact on the ability to sell. So it really does take everyone marching to the same tune in order to get that done, or it just causes infighting.” * 💡 “The safest move is always to take a small [proof of concept], push that, and do your cloud landing zone with that… But then you're left — at a certain point — with the thing that makes you the most amount of money [not fitting] your plans… It's a huge risk: a lot of businesses get stuck trying to modernize. How do you justify the interruption to the revenue streams and the lack of feature delivery while you're doing that transformation to the thing that pays all the bills?”
General News: Q4 2021 Earnings Are In and It’s Looking Good * 📈 Some serious cloud revenue growth reports from AWS, Microsoft, and Alphabet with growth at 40% or higher, despite Amazon losses. And if you ever want to own Google stock, now’s your chance. * ⏩ Meanwhile, VentureBeat reports on best practice for strategically maximizing the ROI of cloud migrations, although one or two of those metrics are questionable.
AWS: Performance Reviews Keep Things Quiet * 📛 Now you can demonstrate your cloud storage knowledge and skills with brand new shiny digital badges! Very pretty — and good to stick on the resumé. * ⚖️ 52 AWS cloud services declare adherence to the CISPE Data Protection Code of Conduct in compliance with the GDPR. Tricky but important. * 🏃 We’re very glad to see that VPC Support for App Runner is finally here. It took a while! * 👯 You can
On The Cloud Pod this week, we’re back to a full house (at least for one episode.) Plus, introducing AWS open-source Cloud Map, GCP announces new Bigtable autoscale feature, and Oracle gives us a retro tour of a data center.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 In a move that shows it supports open source when convenient, AWS introduces new Cloud Map capabilities, and U-turns on proposed charges after 30 days. The new console still sucks, by the way. * 🚨 GCP introduces the very welcome Bigtable autoscaling feature, with new optimizing and manageability features and improvements. * 🚨 Oracle comes bearing over a hundred gifts from its blog, and gives us a look inside a data center.
Top Quotes * 💡 “I'm starting to wonder what's going on over at AWS. We’ve talked about the Orca issues, the security rollout … And now we have this: We're turning on things in your account that are going to cost you money. I saw the earnings… they look pretty good, so I'm not entirely sure why they're turning on features that cost money — with no notice — and putting the onus on me to turn this stuff off.” * 💡 “So isn't that really just a rehashing of the same problem that most IT professionals have been doing for the last 20 years? On the other hand, I don't want to manage my own legacy Oracle footprint, so the fact that they're going to take that, move it to the cloud, and then run it for me — I'm all for that.”
General News: Zero Trust ‘Hijacked’ by Network Security Firms * 0️⃣ Zscaler CEO Jay Chaudhry gets us wise to network security firm marketing tactics, highlighting that practicing zero trust and investing in network security are incompatible with each other.
AWS: Not Amazon’s Best Month… * 💳 In a ridiculous move that completely violates the trust of its customers, AWS attempts to charge after a 30-day trial when no one is paying attention — but everyone noticed. First Orca, now this. * 😭 Watch out you don’t make your CFO cry with the launch of the very nice but very expensive new Amazon X2iezn instances. * 🎮 AWS shows its open-source credentials — but only because it’s convenient — with the rollout of the new AWS Cloud Map MCS Controller for K8s.
GCP: Coming for Crypto * 🤑 Cloud Bigtable’s new autoscaling feature promises cost optimization and improved manageability. Two times the data for the same price and it autoscales? We’re sold. * ⛏️ GCP launches a new dedicated Dig
On The Cloud Pod this week, Jonathan is still AWOL. Also Amazon is on GuardDuty with credential exfiltration, Google Cloud Deploy is generally available, and Azure is suffering from more serious DDoS attacks.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon’s been on GuardDuty with enhanced detection of EC2 instance credential exfiltration. * 🚨 Google Cloud Deploy (GCD) is now generally available, making continuous delivery on Google Kubernetes Engine (GKE) easier. * 🚨 Azure reports that it spent the last half of 2021 dealing with distributed denial-of-service (DDoS) attacks that are increasing in both severity and frequency.
Top Quotes * 💡 “The biggest risk to cloud infrastructure is that you’re one secret access key away from a big booboo.” * 💡 “Last November, [Azure] had just mitigated a pretty large attack — at the time the largest in history, at least from ones that have been reported to the world. … Things have gotten worse in Q3 and Q4 — not only the levels [of attacks], but the complexity has gotten worse.”
AWS: Beefing Up GuardDuty * 🛡️ The threat detection service Amazon GuardDuty — which monitors your accounts for malicious activity and unauthorized behavior — is pretty great already. In the aftermath of the Superglue issue, however, AWS is ramping things up with enhanced detection of EC2 instance credential exfiltration. * ⚕️ AWS Security Hub has been integrating with AWS Health and with AWS Trusted Advisor (TA). Does this mean everything annoying gets reflagged? Thanks, TA! * 🏢 In a move that makes a lot of sense, Amazon Elastic Container Service (ECS) now supports ECS Exec and Amazon Linux 2 for workloads running on-premises with Amazon ECS Anywhere. No more yum and Red Hat-based Fedora deployment sounds great, although it would be nice to have a few more implementation details ahead of rolling it out. * 🪢 Replication is now possible for Amazon Elastic File System (EFS), but watch out for those pesky inter-region transfer fees — which do rack up — before enabling this.
GCP: Google Cloud Deploy Makes Your Life Easier * 🧮 Google Cloud Deploy (GCD) is now generally available, making it easier to do continuous delivery to GKE. We’ve also done the math on this and it seems to be cheaper than Ryan: GCD customers get their first active delivery pipeline per account free, and pay a $15/month management fee for each additional pipeline. Whereas Ryan is, frankly, expensive.
Azure: Azure Under Attack and It’s Getting Worse * 🔈 In an announcement that isn’t really an announcement, you can now leverage elastic integrations for your observability of Spring Boot apps on Azure. * 💸 Azu
On The Cloud Pod this week, the team decides 2022 is already a long, cursed year — bring on 2023. Plus nuggets of wisdom from Gartner, Orca discovers breaksformation and Glue vulnerabilities, and 10 questions to help boards (and others) maximize cloud opportunities.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Gartner reveals six cloud trends for 2022: Take what you need for your organization and throw away the rest. * 🚨 Orca Security discovers vulnerabilities in AWS’ CloudFormation, and — more seriously — Glue. * 🚨 GCP releases 10 questions to help boards safely maximize cloud opportunities — which can also give you the opportunity to bag that promotion.
Top Quotes * 💡 “Look at the rate of growth of cloud over the past few years. The rate of training new people could not possibly keep up. … [Organizations] want to hire someone who's got 20 years’ experience in something that's only been around for five years. I can see it being a real problem in terms of quality of output.” * 💡 “Because Orca published a blog post, we know about this — would AWS have disclosed it to us? If there are other people out there doing research against AWS and they're not publishing these things, there could be other things that we don't know about, that are not being addressed. Transparency is important.”
General News: Get Out the Crystal Balls * 🔮 SiliconANGLE published a guest blog from Gartner’s Paul Delory on his six predictions for what is coming to the cloud in 2022. * ⏩ VentureBeat has five considerations for saving more and wasting less on cloud services. We didn’t learn much, but everyone’s mileage varies.
AWS: CloudFormation’s Breaking Apart and the Glue Doesn’t Stick * 🐋 Orca Security Research Team’s been hunting in AWS waters, and found a vulnerability in CloudFormation. AWS responded that on further inspection, there was no threat to customers or resources. * ⚠️ There’s something more troublesome afoot, though: The Orca team also discovered a vulnerability with Glue. AWS Principal Engineer Anthony Virtuoso thanked Orca for its findings: but a coordinated effort between AWS and Orca might have avoided all of this. * 🎛️ AWS releases its new console which, overall, looks a lot like the old one with new lipstick — it still doesn’t appear to deliver.
GCP: 10 Questions and Some Fire in the Works * ❓ GCP helpfully published a list of 10 questions to help boards understand how to use the cloud in business. It sounds terrible, but actually proves
On The Cloud Pod this week, Peter finally gets to share his top announcements of 2021. Plus, Google increases security with Siemplify, Azure updates Defender, and AWS comes into the new year with a lot of changes.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning, and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud, and Azure.
This week’s highlights * 🚨 AWS confirms that applications can now be deployed on Amazon EKS using the IPv6 address space. * 🚨 Google looks to boost its security operations by acquiring SOAR provider Siemplify. * 🚨 Azure spent December updating Defender: was it worth it?
Top Quotes
💡 “All the cloud providers are embracing containerization and the technologies that allow containerized workloads to work well on their platform. But the side effect is that they also run equally well on everybody else's platform.”
💡 “[As Vice President of Google Cloud Phil Venables wrote in a blog post,] ‘The race by deep-pocketed cloud providers to create and implement leading secure technologies is the tip of the spear of innovation.’ Which is interesting, because I think this is an area where Google's really crushed it, and I think Amazon has failed. Not failed, but not invested as much as they should have.” General News: Google Acquires Siemplify * 💰 Google acquired Siemplify, a security orchestration, automation and response (SOAR) provider. The hope appears to be that it will help security teams using GCP better manage their threat responses.
AWS: Plenty of Non-Outage News * 🤨 IPv6 applications are now deployable through Amazon’s Elastic Kubernetes Service (EKS). This prevents IP exhaustion, minimizes latency, and simplifies routing configurations. On the downside, IPv6 can’t be added retroactively, and this EKS add-on only supports Linux — a dealbreaker for the team. * 👩💻 The AWS compute optimizer has been enhanced to allow users to specify both x86 and ARM as their preferred architecture for their EC2 instance type recommendations. This is a big blow to other tools that perform the same operations. * 🎵 AWS announced the general availability of the EC2 Hpc6a Instance. It’s built for HPC workloads to leverage AMD EPYC 3rd-generation processors. This release expands AWS’ portfolio of HPC compute options. Plus, according to Justin, the instance name reminds him of the song “abcdefu” by GAYLE. * 💡 According to a recent job posting, AWS plans to completely re-imagine how its network is managed. It allegedly has two secret projects that could mitigate the risk of cloud outages — like the one that impacted the company in December of 2021.
GCP: Phil Venables on the Keyboard * ✍️ Phil Venables, the venerable Google VP and Chief Information Security Officer, wrote a blog post about megatrends he’s identified in the cloud security world. It’s worth a re
EDITORIAL NOTE: Your Cloud Pod hosts are on vacation until early January!! Enjoy our 2021 wrapup and look ahead to 2022 and we'll be back in your Podcast feed mid January!
Justin, Jonathan, and Ryan are minus Peter in this episode as they review the year in cloud computing.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning, and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud, and Azure.
This week’s highlights * 🚨 It’s the last podcast of 2021. The next one premieres in the third week of January. * 🚨 Log4j came back with a vengeance during the holiday season. * 🚨 The team looks back at its 2021 predictions and forecast for 2022.
Log4jackass * 📅 Using AWS security services to protect against, detect, and respond to the log4j vulnerability is still an issue. Suggestions to upgrade to version 2.16 for Apache log4j security issue for EKS, ECS, and Fargate customers wasn’t enough. Customers are asked to upgrade to 2.17. By the end of 2021, it will probably be 2.22 just to get into the spirit.
Did The Team’s 2021 Predictions Come True? 👔 The hosts reviewed their 2021 predictions to see if they came true. * Johnathan’s prediction about bracket computing and other quantum technology didn’t come true to break TLS. It’s still a long way off but there are now more classes in quantum programming to prepare for the cutover. Jonathan takes half a point on his merit. * Peter believed The biggest blocker to cloud adoption would be costs, with individuals spending too much on poor cloud migrations. Justin believes he’s way off on this prediction. Though cost is a big consideration it’s definitely not the blocker. However, Jonathan believes more controls are needed to prevent overspending. * Justin’s prediction on the verticalization of the cloud in fintech, health, retail, etc. came true. Ryan says it makes a lot of sense for industries to go this route instead of building everything out. * Ryan said work from home (WFH) would be a permanent trend, further breaking traditional security. Justin agreed on the first part but not the second on security issues. Though plenty of workers still log in through their companies’ VPNs, there is a big move to implement zero-trust security.
Favorite Announcements Of 2021 📢 The hosts reviewed their favorite announcements of 2021. * Justin is happy that Amazon released its Redshift Serverless program to compete with Snowflake * Jonathan’s most favorite announcement was the introduction of OpenSearch. Especially how it went from notification to general release in a short period. Justin is impressed at the community working to improve OpenSearch. He hears more about this product now than elasticsearch. * Ryan puts AWS announcing the cloud con
On The Cloud Pod this week, Oracle finally has some news to share. Plus Log4j is ruining everyone’s lives, AWS suffers a massive outage post re:Invent, and Google CAT releases its first threat report.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 A critical vulnerability in Apache Log4j wrought havoc over the weekend. Cloud platforms and developers alike are racing to fix the bug, which gives hackers an opportunity to take control of systems remotely. * 🚨 On the heels of re:Invent, AWS suffered a major outage last Tuesday in its US-EAST-1 region, which had staggering repercussions across the cloud. * 🚨 Google Cybersecurity Action Team (CAT) releases its first Threat Horizons report, revealing its top three concerns threatening cloud users today.
Top Quotes * 💡 “It’s amazing how much of our infrastructure and applications live on these open source contributions of one or two people, and how critical they are to the entire ecosystem. And when they break or they're vulnerable, it becomes a huge issue for us very quickly.” * 💡 “Think about what Microsoft did: They started signing device drivers and signing applications that run in Windows, and everyone thought Oh, they’re just exerting control, what a terrible idea. They're just trying to corner the market. And now, of course, 15 years later, binding authorization is probably the most critical next step in securing the cloud.”
General News: The Log4j Vulnerability is COVID for Tech * 🔥 In light of the critical Apache Log4j 2.0 vulnerability that gives attackers the ability to to execute arbitrary code on other systems, AWS has released a hotpatch for the logging platform. The aim is to help developers mitigate risk as they work to update their systems to 2.15 or newer. * ⏩ VentureBeat reminds us that while the Log4j debacle is bad, at least organizations now have tools and processes in place to respond quickly to zero-day bugs. * ✅ GCP has released a set of recommendations for those who are investigating and responding to the Log4j 2.0 vulnerability. * 🔎 To help customers detect whether their systems have been compromised by the Log4j bug, Google has updated its IDS signature to automatically scan for any Log4j exploit attempts. * 🛡️ Google creates a new Web Application Firewall (WAF) rule to detect and block Log4j exploit attempts by attackers.
AWS: What Better Way to Follow Up re:Invent Than With a Giant Outage? * 💀 On the Tuesday after re:Invent, AWS experienced a major outage that left many of its users
On The Cloud Pod this week, the team finds out whose re:Invent 2021 crystal ball was most accurate. Also Graviton3 is announced, and Adam Selipsky gives his first re:Invent keynote.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon’s re:Invent 2021 featured a ton of new updates, including AWS CloudWatch Evidently, AWS Private 5G, and a new AWS Sustainability Pillar. * 🚨 Justin’s prediction pick — Graviton 3 — was announced on Day Two of re:Invent, along with serverless options for data analytics, and a free machine learning (ML) database for existing AWS customers. * 🚨 Amazon CEO Adam Selipsky missed the mark at his re:Invent debut, announcing fewer new releases than expected to a low-energy crowd.
Top Quotes
💡 “This is Adam’s [Selipsky] first keynote as CEO of AWS… I do feel it was a missed opportunity. Number one, he didn't drive out a ton of announcements, which everyone expected. There was a miss across the entire audience — people were expecting something they didn't get. And then number two, OK, maybe you're not the best public speaker: maybe you should go with a different model.”
💡 “In the keynote, the message was really clear: They're trying to democratize access to machine learning, they're trying to give this access to more than just the elite data scientists and programmers. And that made me think that if you expand that out to no-code in general, that’s a really powerful thing” AWS: re:Invent 2021 feat. a Mechanical Cat * Amazon highlights its top announcements of AWS re:Invent 2021 and gives details of new releases and updates across the platform.
Pre:Invent: Because Every Good re:Invent needs a Warmup * 👩🏫 In support of its mission to educate 29 million people by 2025, AWS expands access to its free cloud skills training to empower learners to pursue careers in technology. * ⚠️ AWS Elastic Disaster Recovery is now generally available to provide fast, reliable recovery of on-premises and cloud-based applications for its enterprise customers. This scalable solution enables customers to use AWS as an elastic recovery site rather than relying on an on-premise disaster recovery infrastructure. * 🐦 AWS Control Tower users can now created nested organizational units within the platform. Huzzah! * 📊 AWS Audit Manager users can now simplify their audit preparations with the new dashboard feature that enables them to instantly track the progress of audit assessments relative to common control domains. * ⛔
The Cloud Pod: Oh the Places You’ll Go at re:Invent 2021 — Episode 144
On The Cloud Pod this week, as a birthday present to Ryan, the team didn't discuss his advanced age, and focused instead on their AWS re:Invent predictions. Also, the Google Cybersecurity Action Team launches a product, and Microsoft announces a new VM series in Azure.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS releases new G5 instances, which feature up to eight NVIDIA A10G Tensor Core GPUs. That’s super, super fast. * 🚨 Google’s Cybersecurity Action Team adds Risk and Compliance as Code (rCaC) Solution. * 🚨 Microsoft announces the NDm A100 v4 Series, and claims another spot on the TOP500 supercomputers list.
Top Quotes * 💡 “[AWS Resilience Hub] is already building on top of the FIS, which is interesting, but at some level I just want you to execute Lambda functions that validate things for me, and then tell me that I'm resilient because I validated it with Lambda.” * 💡 “Anything that empowers more dynamic and interactive web development I'm all for.”
Amazon Web Services: Give Us Your Car * 🚘 AWS is releasing new G5 instances, which feature up to eight NVIDIA A10G Tensor Core GPUs. For the cost of a small car every month, you too can get up to 40% better value on inferencing and graphics-intensive operations. * 💪 AWS is releasing the Resilience Hub, a service designed to help you define, track and manage the resilience of your applications. * 🐧 Unified Search in the AWS Management Console now sources results from blogs, knowledge articles, events and tutorials. Buyer beware with this one: It will pull outdated information that is still available on AWS, and you could end up with a giant albatross that costs you a fortune. * 🐌 Amazon ECS is improving ECS Capacity Providers to deliver faster cluster auto scaling. When you're using a capacity provider, it's painfully slow to get the underlying hosting infrastructure to scale fast enough, so we’re presuming AWS has addressed this in the back end. * 😁 Manage access centrally for JumpCloud users with AWS Single Sign-On. We’re super happy to see this: Take notes, Azure AD. * 👏 Amazon ECS adds container instance health information. This is nice to see and will help improve your application resiliency.
AWS re:Invent 2021 Predictions * Prediction rule: If it’s already been officially announced by Amazon, then it doesn’t count. It needs to be in the rumor mill and somewhat specific. * Each contestant will also pred
On The Cloud Pod this week, the pod squad is down to the OG three while Ryan is away. Also AWS announces serverless pipelines, GCP releases Spot Pods, and Azure introduces Chaos Studio.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS releases Serverless Application Model (SAM) pipelines to save development teams time. These pipelines streamline CI/CD configurations for AWS applications. * 🚨 In the spirit of savings, new GCP Spot Pods help GKE Autopilot users run fault-tolerant workloads while spending less money. Hooray! * 🚨 Azure Chaos Studio helps development teams wreak controlled havoc with a managed experimentation service, allowing them to safely build, break and optimize their apps with reckless abandon.
Top Quotes * 💡 “I think for some people when they're looking at, OK, we're gonna make this commitment to a different architecture, at that point in time, they've looked at serverless versus containerized apps, and most companies went the containerized apps route, but that might change in the next wave.” * 💡 “Python 3.10 looks really interesting. It's got a bunch of new features … around data handling specifically, which is really what people have been using Python for for years: bioinformatics and data science. But it has really neat features around matching different schemas of data and things like that.”
AWS: Finally, a Pipeline We Can Get Behind * ⏲️ AWS releases Serverless Application Model (SAM) pipelines, a new feature of the AWS SAM CLI, to help users simplify CI/CD configurations for AWS serverless applications. The new feature will help development teams minimize the amount of time spent creating pipelines, while also ensuring safe deployments. * 🍗 With AWS Fault Injection Simulator, users can now create and run FIS experiments that check the state of Amazon CloudWatch alarms and run SSM automations. We hope the only fault injections you have are in your EC2 instances, not in your Thanksgiving turkey. * 🪄 AWS customers running Windows containers rejoice: New Amazon ECS Exec allows you to execute commands or get information directly from your Windows container shell. Magic! * 🇨🇦 Amazon is doubling down on Canada. AWS announced plans to open a second Canadian region, in Calgary, bringing the company’s total region count to nine. The Calgary region is set to open in late 2023 or early 2024, and AWS has committed to using renewable energy to help build it out.
GCP: Hitting the Spot with New GKE Autopilot Spot Pods * 🖼️ Google is making it easier to improve application scale-up times with its “revolutionary” (read: evolutionary
On The Cloud Pod this week, the team wishes for time-traveling data. Also, GCP announces Data Lakehouse, Azure hosts Ignite 2021, and Microsoft is out for the metaverse.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 GCP releases its data lakehouse, a new architecture that offers low-cost storage in an open format. The real question is, can we book it on Airbnb? * 🚨 Microsoft kicks off Azure Ignite 2021, announcing new capabilities for its hybrid, multicloud and edge computing platforms. * 🚨 Microsoft also unveils plans for its own metaverse, including upgrades to Teams, Dynamic 365 Connected Spaces and more.
Top Quotes * 💡 “I'm a big fan of IDE for coding and that integrated environment to reduce context shifting, but when you're talking about access to data, Jupyter is something that's hosted, that you can protect and grant access to, versus an IDE like RStudio. It becomes a much trickier scenario to maintain any kind of data sovereignty, or protect that in any way, just because, by its true nature, you have to open it up.” * 💡 “Between the Facebook Metaverse and Microsoft, who's going to win the race? Everyone wants to build “Ready Player One.” And Facebook owns Oculus and they have all my data, then they can get my brain as well: They can just monetize the crap out of my profile. And then Microsoft has their augmented reality things… . But I think the power of the Azure cloud actually gives them the advantage versus Facebook, in my opinion. “
General News: ‘Tis Earnings Season * 📈 Microsoft was the first to announce its quarterly revenue, boasting a $45 billion increase. This jump of 22% beats Wall Street expectations, and includes Microsoft Azure, LinkedIn commercial revenue, Office 365, and Xbox. * 💰 Google also posted impressive results, rounding out the quarter at $18.9 billion, up a whopping 68% from one year ago. Much of this success came from Google Ads and GCP, where revenue was up 45% or about $5 billion. * 📉 Due to ongoing supply chain issues and labor shortages, Amazon missed the mark on its earnings forecast, posting a profit of $3.2 billion, a 49% decrease from last year. AWS, however, outperformed (as usual), with a 39% rise in revenue to $16.1 billion.
AWS: The Official Cloud Storage Provider of MI6 * 🐟 Now generally available, AWS Babelfish allows users to migrate from expensive, proprietary MSSQL to the Amazon Aurora compatible edition. With Babel
On The Cloud Pod this week, half the team misses Rob and Ben. Also, AWS Gaudi Accelerators speed up deep learning, GCP announces that its Tau VMs are an independently verified delight, and Azure gets the chance to be Number One for once (with industrial IoT platforms.)
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS is using Gaudi Accelerators to speed up deep learning models — for nearly $10,000 a month. * 🚨 Google announces that Tau T2D VMs are now available in preview, and takes the opportunity to report that Phoronix has identified these Tau instances as the best price-performing ones yet. * 🚨 Azure bags the Number One spot in the Gartner Magic Quadrant category of Industrial IoT Platforms. We’re wondering how much schmoozing Microsoft had to do to pull this off.
Top Quotes
💡 “I guess [AWS Gaudi Accelerators] solve the problem of lack of availability of NVIDIA CPUs. It's almost impossible to buy a decent graphics card, and I'm sure the cloud providers are suffering horrendously with not being able to scale their machine-learning instances the way they wanted to, because of the chip shortage.”
💡 “We've said it for a long time now that with Google coming to the market when they did, it was very easy to take all the major gripes of AWS and Azure and improve on them. And they banged it out of the park. So kudos to them, because it is a much better user experience than [what you get with] the other two cloud providers.” General News: HashiCorp Increases Access to its Service Mesh 🚦 HashiCorp introduces its new Consul API Gateway to help route traffic to applications running on the Hashicorp Consul Service Mesh. This seems like an early release, given its fairly basic capabilities. AWS: Rolling Out Gaudi Accelerators — Not Architecture * 📹 AWS announces AWS Panorama, which is an appliance and SDK that allows users to process video data at the edge of their locations. AWS Panorama was first introduced at the last re:Invent, and is now generally available. * 🏇 Amazon joins Microsoft, Google, IBM, Honeywell and more in the race to build a quantum computer, partnering with Caltech to open a new center in Pasadena. * 4️⃣ To save Peter some time in the lightning round, we combined four Amazon DocumentDB updates into one announcement: Users can now enjoy additional support for access control; support for $literal, $map and $$ROOT; capabilities for storying, querying, and indexing Geospatial data; and a
In this TCP Talks episode, Justin Brodley and Jonathan Baker talk with Jonathan Heiliger, co-founder and partner at Vertex Ventures: an early-stage venture capital firm backing innovative technology entrepreneurs.
Earlier in his career, at just 19, Jonathan co-founded web hosting provider GlobalCenter and served as CTO. He went on to hold engineering roles at Walmart and Danger, Inc., the latter of which was acquired by Microsoft. He was also Vice President of Infrastructure and Operations at Facebook (now Meta), and a general partner at North Bridge Ventures. The latter firm’s portfolio included Quora, Periscope, and Lytro (which has been acquired by Google.)
At Vertex Ventures, Jonathan has helped cutting-edge companies like LaunchDarkly and OpsLevel revolutionize the tech space with continuous delivery and IT service management solutions. Jonathan shares his insights into the shifting market of IT services and explains why decentralizing infrastructure management can help digitally native companies operate at a faster pace.
According to Jonathan, the question of IT service infrastructure isn’t being adequately addressed. Without properly defining service ownership, businesses looking to scale run the risk of siloing critical knowledge, and losing track of services networks.
Jonathan also discusses his own experiences running infrastructure at Facebook (oops, Meta), the merits of both centralized and decentralized IT services management, and how he and his partners at Vertex Ventures approach new investments. Featured Guest 👉 Name: Jonathan Heiliger
👉 What he does: Jonathan is a co-founder and partner at Vertex Ventures, an early stage venture capital firm that backs B2B software entrepreneurs. He held his first CTO role at 19, and has previously worked for Walmart; Danger, Inc.; Facebook (soon to be known as Meta); and North Bridge Ventures.
👉 Key quote: “We need systems to help us build bridges from the world of paper-based and in-memory to scaling to tens and then hundreds of microservices. It’s that pain point of tracking all the info about apps and their services, dependencies, ownership and versions that I think is this big problem lurking below the surface.”
👉 Where to find him: LinkedIn | Twitter Key Takeaways 🚨 As companies rely on an increasing number of IT services, Jonathan says that it’s imperative that technology leaders establish ownership of IT service management, and meticulously track their software and vendor partners.
According to Jonathan, this kind of IT management is still done in a fairly rudimentary way, even for larger companies. “Every engineering team — even the most well run engineering orgs — the majority of them use Excel spreadsheets to track who owns what service, and even what services may talk to one another,” he says. He sees this as a big problem that’s going to catch up with companies one day.
🚨 When considering whether a centralized or decentralized IT management service infrastructure is best for you, Jonathan suggests doing a deep dive on your business objectives.
For example, digitally native businesses, which rely on a vast network of microservices, might work better with a decentralized infrastructure. Non-digitally native brands, on the other hand, might benefit from a centralized system to ensure continuity in the technology.
🚨 Avoiding vendor lock-in — i.e. becoming too dependent on a single service provider — is critical in keeping your business flexible and agile, but it can be tricky. Jonathan describes a situation at Facebook where vendor lock-in became a problem. The solution the company settled on involved bringing data center creation and management in-house.
He argues, “the biggest w
On The Cloud Pod this week, the team’s collective brain power got a boost from guest hosts Rob Martin of the FinOps Foundation and Ben Garrison of JumpCloud. Also, AWS releases Data Exchange, Google automates Cloud DLP, and Azure Synapse Analytics is available for pre-purchase.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS announces Data Exchange for Amazon Redshift, which will allow users access to and management of third-party data. Watch out, Snowflake. * 🚨 Google is making its Cloud Data Loss Protection (DLP) automatic so users no longer have to worry about manually monitoring their data. * 🚨 Azure has made Azure Synapse Analytics available for pre-purchase for customers looking to manage their analytics workloads.
Top Quotes
💡 “There's always that line: If you build a module that is very effective for users across the board, regardless of what they're doing, at some point it just becomes a resource. It’s pretty tough to build complex modules that everybody's going to use as-is, and not want to end up making their own.”
💡 “I do not envy security people in this current climate. The proliferation of cloud computing, edge computing, has really had to get a lot of creative minds working together to try and secure data outside your four walls of sanctity. … And so it's good to see big companies starting to chime in and address that, because I think it's just going to continue to keep growing.” General News: Hashicorp + AWS = A Match Made in Heaven * 💰 At .conf21, Splunk announces a new workload-based pricing model for its smaller customers that will help drive retention. Clearly Splunk has been listening to TCP complaining about its insanely expensive model. * 🧳 HashiCorp releases the public beta of HCP Packer, which allows teams to track and automate build updates across their packer and terraform workflows. * 🤝 AWS and HashiCorp are partnering to make developers’ lives easier with new terraform modules for AWS, as well as an API path that will enable users to quickly deploy AWS resources while keeping modules lightweight and composable. Justin is stoked for this!
AWS: AWS Data Exchange is Coming for Snowflake * 📝 AWS releases its Security at the Edge: Core Principles whitepaper to help business and technology leaders ensure their cloud network security extends to workloads running on the edge. The paper points out three strategic areas to address: AWS Services at the edge location, AWS security best practices, and additional edge services. * 🪲 AWS Glue Crawlers now support Amazon S3 event notifications, making discovering data sets simpler and reducing the cost and time a crawler needs to update frequently changing tables. * 🌐
In this TCP Talks episode, Justin Brodley and Jonathan Baker talk with Josh Stella, co-founder and CEO of Fugue, a cloud security company that helps businesses run faster on the cloud without breaking any rules.
Josh shares insights from Fugue’s State of Cloud Security 2021 Report, and highlights key themes, including preventative security measures, automation, and engineering-first compliance.
According to the report, within the next two years, all but 1% of security breaches will be caused by misconfiguration of cloud resources. Josh and his team at Fugue aim to minimize these mistakes by simplifying cloud security through a systems-based approach.
One way to streamline security, Josh notes, is to take advantage of automation. With cloud environments becoming increasingly complex, relying on pure knowledge will soon be untenable. Josh urges business leaders to embrace automation to reduce the risk of human error in their security systems.
Josh also discusses how businesses can declutter security tech stacks, the “land grab” happening in the cloud, and trends he predicts will shape the future of cloud compliance. Featured Guest 👉 Name: Josh Stella
👉 What he does: Josh is the co-founder and CEO at Fugue, a cloud security company on a mission to help businesses move faster by ensuring safe cloud environments. He has over a decade of experience in the cloud security space, including positions at Amazon Web Services and in national security.
👉 Key quote: “If Fugue as a software vendor and as domain experts in cloud security can't make your job a lot easier through tooling, then we're not doing our job.”
👉 Where to find him: LinkedIn | Twitter | YouTube Key Takeaways 🚨 While compiling the State of Cloud Security 2021 Report, Josh and his team at Fugue interviewed over 300 organizations. They found that as cloud environments have grown and become more complex, organizations are seeing more instances of misconfigurations.
According to the report, 49% of respondents experienced over 50 misconfigurations per day. Another interesting detail: For the first time since Fugue started compiling its annual report, Identity and Access Management (IAM) was the number one concern regarding misconfigurations.
🚨 Josh argues that automation is the next step in making cloud environments more secure. Fugue aims to make security automation easy by providing pre-built rules and templates to automatically check code and monitor deployments.
Looking forward, Josh is optimistic that automation will become a key piece in enterprise cloud security. “The thing I would like to see a change in is the attitude that security problems are because people are screwing up … [I would like to see people] thinking about how to actually solve these problems, which is through computer science and automation,” he says.
🚨 One way to enable automation is to put engineering departments in charge of compliance, as opposed to traditional security teams. According to the State of Cloud Security 2021 Report, more than 66% of businesses are delegating security policy to engineering teams — a trend Josh hopes to see continue.
He says that today, engineering and DevOps teams work so fast security teams struggle to keep pace. Businesses that haven’t moved responsibility for security over to these teams are more likely to experience those potentially dangerous misconfigurations. Resources Here's what was mentioned in the episode 👉 ✔️ Fugue: cloud security company aimed at helping businesses run faster and safer.
✔️ Fugue Regula: an open-source tool that evaluates infrastructure-as-code templat
On The Cloud Pod this week, Jonathan reveals his love for “Twilight.” Plus GCP kicks off Google Cloud Next and announces Google Distributed Cloud, and Azure admits to a major DDoS attack.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 After a few awkward keynotes, Google Cloud Next kicks off days one and two, highlighting new features and announcing Google’s $10 billion investment in cybersecurity advancements. * 🚨 At Google Cloud Next, GCP announced the Google Distributed Cloud: A network of hardware and software to help organizations improve cloud strategies. * 🚨 After tooting its horn for reduced DDoS attacks in 2021, Azure reveals details about the largest DDoS attack in its history. This 2.4 terabits/second attack was launched in late August against an Azure customer in Europe.
Top Quotes * 💡 “It is kind of crazy, because [Google Distributed Cloud] is an open source project that's basically how to run Google Cloud in your own data center. It's probably a smart risk, because I do believe workloads will just eventually end up on Google Cloud.” * 💡 “The tools have the functionality built in, but unless you're offering that as a service to your end users … and thinking about the holistic management of the settings, the deployment and the full lifecycle of those things, it's the difference between enabling your business to be secure and just shooting it in the foot.”
AWS: Keeping Quiet This Week for Google Cloud Next * 🕵️♀️ Amazon Fraud Detector can now store event datasets and use this historical data to boost performance for ML models — all at a 56% reduction in price. * 📱 AWS Console Mobile Application has (finally) added ECS, which will allow users to view and manage a select set of resources to support incident responses from their devices. Clearly someone at AWS listens to TCP and has heard Justin’s many complaints about this. * 🚦 CDK8s (say that five times fast) is now generally available and supports the Go programming language. Using CDK8s, you can define your K8 applications and apply K8 YAML to any cluster. * 🪱 Tired of accidentally deleting your backup with your cloud formation stack? The newly released AWS Backup Vault Lock solves this problem by using safeguards to ensure users store their backups using a Write-Once-Read-Many (WORM) model.
GCP: Thank U Google Cloud Next * 📦 Ahead of Google Cloud Next, GCP makes Artifact Registry generally available for Java, Node.js, and Python packages. Users can host their internal codes as packages to their centralized private repositor
On The Cloud Pod this week, the team is running at half-duplex without Peter and Ryan. Plus Cloudflare R2 is here, Facebook died for a day, and AWS releases Cloud Control Plane.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Cloudflare’s new R2 service is making waves in the cloud object storage space, offering incentives like no egress fees and lower rates than its competitors. * 🚨 Influencers, boomers and bored teenagers collectively screamed on October 4th as Facebook and its associated apps experienced an unprecedented six-hour outage. * 🚨 AWS Cloud Control Plane offers developers an easier way to manage their third-party and AWS services with a new set of common APIs.
Top Quotes * 💡 “The bigger impact is actually WhatsApp, because for a large portion of the world, Whatsapp is the primary method of communication. If you go … to different countries overseas … everyone's on WhatsApp. Everybody. So to not have that communication is a huge loss. And you have to wonder, does Facebook need to think about diversifying their backend in some way? Should all of their DNS be inside Facebook?” * 💡 “[AWS Cloud Control API] is probably going to be a requirement for any new services that launch in AWS … which means that we will no longer be waiting weeks or months for new services to be available in CloudFormation.”
General News: The day that Facebook died (for six hours) * ☁️ Cloudflare is getting into the cloud object storage market with its new, competitively-priced R2 Service. Unlike other storage services, Cloudflare is nixing the dreaded egress cost, and will charge 10% less than AWS, its largest competitor. * 💀 Facebook is having a rough week. On October 4th — the day before a former employee testified to Congress about the social media giant’s negative impacts — Facebook accidentally unpublished itself and its affiliated apps for around six hours. A seemingly routine update caused issues with its BGP routes: Read the company’s account of events here.
AWS: On a mission to control the cloud * 📊 In a rush to release before the next AWS summit, Amazon Managed Service for Prometheus is now generally available. With Prometheus, users can easily monitor their containerized apps at scale, and new features like alert manager and ruler let users integrate SNS with various destinations. * 🎛️ AWS releases Cloud Control API, a new set of common APIs designed to help developers manage their AWS and third-party services. According to AWS, three groups will benefit the most f
On The Cloud Pod this week, Justin may be out but the cloud stops for no one. Also, AWS announces a New Zealand region, GCP releases GKE Backup, and Azure Functions 4.0 is now in public preview.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Grab your togs and sunnies! AWS is opening a New Zealand region to serve Asia Pacific. The move is expected to create more than 1,000 jobs in the next 15 years. * 🚨 GCP users can now protect their GKE workloads with GKE Backup, which helps automate recovery tasks and shows reporting for compliance and audit purposes. * 🚨 Azure Functions 4.0 has arrived — in public preview, that is. It’s expected to be generally available by November 2021, just in time for the .NET 6.0 release.
Top Quotes * 💡 “Microsoft Excel is still the most powerful tool for making business decisions. And [Amazon QuickSight] is the same thing: It's a way to visualize the raw data you have. Being able to ask a service a question in normal words is gonna be super powerful.” * 💡 “It’s funny because for at least the last 18 months, this has been my daily life: Thinking hard about how software makes it from environment to environment and into production. And no matter where you're hosting this workload — what cloud provider, what technology — there are trials and tribulations and hurdles that have to be overcome … So I’d like to see more of these bespoke deployment technologies that are really focused on doing one thing really well, rather than doing all things.”
AWS: AWS says ‘Kia Ora’ to its Newest Region: New Zealand * 👓 With the newly available Amazon QuickSight, business users can use natural language (read: normal words) to quickly create interactive BI dashboards and receive accurate insights and data visualizations. * 🇳🇿 Look out, Kiwis and hobbits: Amazon is set to open new data centers in New Zealand by 2024, adding the AWS Asia Pacific (Auckland) Region to its 81 existing availability zones. It’s estimated that the new region will create 1,000 jobs in the next 15 years, but we believe it will have an even bigger impact. * 🕵️♂️ Tracing support is now generally available in AWS Distro for OpenTelemetry. Users can now send telemetry data to various AWS applications as well as partner destinations. Telemetry, dear Watson. * 🪄 AWS releases AQ UA (Advanced Query Accelerator) for Amazon Redshift RA3.xlplus nodes. This new distributed and hardware-accelerated cache enables Redshift to run up to 10X faster than AWS competitors by boosting certain query types. Magic! * 🤬 AWS users can now easily select, detect and manage sensitive data with Amazon Macie. Using machine learning and pattern matching, users can
On The Cloud Pod this week, the whole team definitely isn’t completely exhausted. Meanwhile, Amazon releases MSK Connect, Google offers the Google Cloud Digital Leader certification, and DORA's 2021 State of DevOps report has arrived.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Users of AWS’s fully managed Apache Kafka service can now use MSK Connect to easily set up and deploy Kafka Connect clusters. * 🚨 GCP releases the new Google Cloud Digital Leader training and certificate program, which trains users on all things Google in just four classes. * 🚨 Google Cloud’s DevOps Research and Assessment (DORA) team publishes the 2021 State of DevOps, identifying key trends.
Top Quotes * 💡 “From a least-privileged perspective, it'd be better to have a purpose-built tool that does one thing really well — what you need it to do — versus building out this huge AWS CLI you have to install on every server and expose attack vectors if it has the wrong permissions.” * 💡 “Digital transformation is such a broad thing for so many industries … and giving them this cloud knowledge helps them drive outcomes from a technical perspective, and map the business need to the technical need … It's helpful for [business users] to get a little bit of language, but also for the technical person to actually learn how to translate technical ideas into business ideas that have value.”
General News: F5 Absorbs Threat Stack * 💰 F5 sets its sights on Threat Stack, paying $68 million to add this Boston-based cloud monitoring company to its growing list of cloud and security software acquisitions. This recent buy brings F5’s investment in cloud monitoring capabilities to over $2 billion.
AWS: MSK Connect – the New Easy Button for Managed Kafka Service users * 🏋️ AWS is eliminating undifferentiated heavy lifting for users of its fully managed Apache Kafka service, by introducing MSK Connect, which allows users to configure and deploy a connector using Kafka Connect with a few clicks. * ⌨️ Amazon Redshift users can now use RSQL, a fully-featured command-line client, to interact with their clusters and databases. Working as a complement to the PostgreSQL psql command line tool, RSQL is available for Linux, Windows, and macOS X.
GCP: Anointing Future Digital Leaders * 🪣 Google introduces the new Cloud Storage trigger in Eventarc, which eliminates the need for audit logs and supports bucket filtering. Now you can do what you’ve always done in Eventarc, only better. * 🙏 Google has answered its customers’ prayers with its new Cloud Digital Le
On The Cloud Pod this week, AWS releases OpenSearch and EKS Anywhere, Google Cloud is now available in the Toronto region, and Microsoft deals with two critical security issues.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS releases OpenSearch (previously Elasticsearch) and makes EKS Anywhere generally available — to those who run VMware. * 🚨 Google Cloud opens a Toronto region, expanding its core Google portfolio into three new zones. How aboot that? * 🚨 Security issues continue to plague Microsoft, with critical vulnerabilities exposed in both its ACI and OMI features. Hopefully new hire, Charlie Bell, can help them out.
Top Quotes
💡 “I hope that the reason [AWS is] integrating with VMware only is because they're deeply integrating with that platform and they can spin up new VMs, deploy new infrastructure, and provide the scaling you need to make EKS Anywhere work the way it works in the cloud.”
💡 “Everything now is driven by the cloud in a big way, where you pay by the drip. So now I need to make the drip as efficient as possible. And if I can give you dedicated silicon to do that, that's the best thing for me. And so it's quite interesting.” General News: Jump On It * 🚀 The Cloud Pod sponsor, JumpCloud, raises $159 million in its Series F round, bringing its total funding to $350 million. Remote working has catalyzed growth for this cloud directory service, now valued at $2.56 billion. Take that, AD.
Amazon Web Services: New Features, Who Dis? * 🔎 Amazon Elasticsearch is now OpenSearch. In addition to the new name, AWS has also added a host of new features like advanced security, SQL query syntax, updated reporting capabilities, and more. Overall, we are super happy with this first release! * ✨ Amazon EKS Anywhere is now generally available… as long as you use it on top of VMware. EKS (almost) Anywhere helps users manage any Kubernetes cluster, and offers automation tooling for cluster lifecycle support. This comes two weeks late for Justin, who included it in his predictions draft. Bummer. * 📹 Livestreamers rejoice! AWS is launching EC2 T1 instances for live multi-stream video transcoding, which will provide resolution up to 4K Ultra HD. Using GPUs for graphics processing — what an idea!
Google Cloud Platform: Google Welcomes Toronto to the Family * 🕹️ In addition to giving users dedicated CPUs, GCP is now offering CPU allocation controls which will allow users to do background processing for their asynchronous tasks in Cloud Run container instances. * 🇨🇦 Break out the maple syrup because
On The Cloud Pod this week, the team wishes there was something else on tap, not just NetApp. Also, AWS Storage Day has come and gone again, and Azure is springing into the enterprise cloud.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 The third annual AWS Storage Day brought a few presents, including new features for files and transfers. * 🚨 One announcement was the general availability of Amazon FSx for NetApp ONTAP. Hell has frozen over, and you can now get Netapp Filers on top of AWS. * 🚨 Azure announces the launch of Spring Cloud Enterprise, a managed service for Spring optimized for enterprise developers.
Top Quotes * 💡 “I assume this is all built natively on top of AWS, and they are managing the service for you on EC2. If that's the case, I believe this is the first of this type that AWS has offered. We've talked about Google partnering with people to operate appliances on your own VPCs, same as Azure. So this is probably the first of many partner integrations.” * 💡 “I don't know if it's [Amazon S3 Multi-Region Access Points] they wanted, but I think at these prices, they definitely didn't want it. If the price was more attractive or if it was simpler to process and calculate — more predictable — I think people would potentially be excited about this.”
General News: Whisk It * 🥚 DigitalOcean acquired three-year-old startup Nimbella, which develops multi-cloud serverless software. It’s an interesting alternative to, say, building its own serverless stack with OpenWhisk.
Amazon Web Services: Hell Has Frozen Over * ⛄ Here’s what happened at AWS Storage Day 2021. We recommend you check out the recordings, because it actually wasn’t a snooze fest. * 🍺 AWS announces general availability of Amazon FSx for NetApp ONTAP. If you want to import data into a data lake, this would be one way to do it. * 🤸 AWS announces Amazon EFS Intelligent-Tiering to optimize costs for workloads with changing access patterns.This gives you some flexibility that you didn't have before — but it’s still expensive. * 🤑 AWS lays out how to accelerate performance and availability of multi-region applications with Amazon S3 Multi-Region Access Points. Be
On The Cloud Pod this week, AWS releases new features including Managed Grafana, GCP Serverless solves the cold start problem, and Wiz hacks into CosmosDB.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS shows no sign of slowing down after the Summit, making Managed Grafana generally available and releasing new features for VPC, CloudFormation, and CloudWatch. * 🚨 Google introduces new capabilities to minimize cold starts, giving serverless customers the option of using — gasp! — servers. * 🚨 Wiz finds a critical security flaw in CosmosDB which allowed it to hack into thousands of Azure customers’ databases. Looks like Microsoft needs to make some calls.
Top Quotes * 💡 “I just think about all the companies who were … trying to build their own ML models for document recognition and how far they are versus how far Amazon and Google are and Azure. … this is the reason why using your cloud vendor might be the better choice. Because they're not even getting this kind of scale and or price reduction for anything they're doing on top of ML.” * 💡 “I think the main benefit for this change is going to be shared tenancy systems because, with virtualization, everytime there’s a context switch between different tenants on the CPU, you have to throw away that entire cache. The smaller that cache is, the faster that's going to be, and the better overall performance you'll get from the system.” * 💡”There's servers behind everything. So nothing’s serverless just how exposed are you to it? And to me, I think that level of exposure where it's no longer serverless is if I have to patch it.”
General News: Docker goes “Full Oracle” * 💩 Docker announces it will begin charging enterprise customers to use it’s desktop app. Enterprise companies with over $10 million in revenue or greater than 250 employees have until January 31st, 2022 to buy the subscription. In Justin’s words, “that’s just dirty.”
Amazon Web Services: Can’t Stop Won’t Stop * 🧭 To enable East-West traffic, Amazon has removed some VPC routing restrictions, allowing users to inspect, analyze or filter all traffic flowing between two subnets. * 🚫AWS CloudFormation users are sharing a collective sigh of relief as they can now disable the automatic rollback when a cloud formation fails and retry stack operations from the point of failure. Peter is jumping for joy. * 💨AWS announces a 32% price reduction for Amazon Textract users in 8 regions as well as a 50% reduction in processing times for asynchronous jobs. Fast or cheap? We choose both. * 🔘Cloudwatch dashboards now support custom wi
On The Cloud Pod this week, the results of the AWS Summit prediction draft are in. It was probably worth getting up early for — especially if you’re Jonathan.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 At the Summit, AWS announces AWS Backup Audit Manager, sealing the prediction draft winner: Congratulations, Jonathan. * 🚨 Outside the Summit, AWS announces MemoryDB for Redis, new split charge rules, and cybersecurity updates. * 🚨 Former AWS leader Charlie Bell is joining Microsoft. What his role will be is unclear, but we speculate that he’ll play some part in improving Azure availability.
Top Quotes * 💡 “I suspect that certificate-based access to the console is going to be more prevalent. I don't know of this in Microsoft Azure or Amazon, but I also know that this is one of the things popping up in custom security audits or in documentation that I've started to see more and more, which is, how do you control access to this publicly available API?” * 💡 “This could be an additional $5 billion boost in revenue for Microsoft Office 365, which is important to us because Microsoft 365 is included in the Azure number and reported as one line item. So a $5 billion increase could be a pretty big increase in revenue and growth that Azure could then tout and say, We are finally the biggest, fastest-growing cloud.”
General News: Later Days * 👋 GitHub is saying goodbye to password authorization, but you can still create a personal access token to log in.
Amazon Web Services: We’ve Reached the Summit * 📣 Redis users in select regions can now use Amazon MemoryDB to boost their application performance with data durability, microsecond read, and single-digit millisecond writes. Unlike ElastiCache, MemoryDB does not require adding a cache from your database to achieve low latency. * 🎂 Amazon EC2 turns 15 this year. Launched with a single instance in 2006, there are now over 400 variations of instances. Happy birthday, EC2 — next year we’ll buy you a car. * 💰 Good news for finance pros: AWS Cost Categories will now allow you to create split charge rules to allocate shared costs to different categories. Time to bust out the corporate card. * ☁️ IAM Access Analyzer users can (finally) get rid of localized cloud trails and consolidate them into a single account. This makes us super happy, except for Justin, who lost a point in the prediction draft because AWS did not announce this at the summit. * 💾 AWS has released its
On The Cloud Pod this week, everyone’s favorite guessing game is back, with the team making their predictions for AWS Summit and re:Inforce — which were not canceled, as they led us to believe last week.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS CTO talks about continuous configuration (CC) at Amazon in his latest blog post. CC has made it possible for the company to keep services running while it also adapts and reacts in real-time. * 🚨 Google launches monitoring and troubleshooting for virtual machines (VMs). Developers will be able to access visual guides talking them through various scenarios. * 🚨 Microsoft launches a lawsuit in response to AWS winning a $10 billion NSA contract, the content of which is reportedly related to the organization’s attempts to modernize the way it stores classified data.
Top Quotes * 💡 “When it comes to streaming VR, you can be very smart about what you send to a consumer and what you don't. I mean, there's still enough compute power locally that it has a good idea of what most of the scenes can look like. So potentially, local computers do the background or the bits that are complex, and you just stream the complexity with the bits that do need to be latency sensitive.” * 💡 “I feel like all the monitoring tools out there have been missing this [monitoring and troubleshooting for VMs] for a long time, in that they seem to have all the features you need, but then getting the things you want is so difficult.”
General News: Here We Go Again * 🙄 Amazon has won a secret $10 billion cloud computing contract from the NSA. This is JEDI all over again: Microsoft is not happy and has already launched a lawsuit. * 👏 AWS CTO Dr. Werner Vogels talks about continuous configuration at Amazon. There are a lot of helpful tips in this article, particularly if you’re in Dev, DevOps or Ops.
Amazon Web Services: A Good Brew * 👍 AWS Codebuild allows project owners to make build logs and artifacts publicly accessible to anyone outside of AWS Console. This is a great way to build trust in your product: thumbs up from us. * 🍺 AWS continues to muddy the waters of Glue DataBrew with announcements about logical conditions, numerical format transformations,
On The Cloud Pod this week, it’s been an interesting few days in the cloud, so the team members have made themselves comfortable with plenty of adult beverages to keep them going. Also, Elastic has forked everyone with its latest Elasticsearch move.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Elastic has modified the Elasticsearch Python client so it won’t work with forked versions, including the relatively recently released OpenSearch 1.0. * 🚨 AWS CloudWatch Synthetics now supports visual monitoring. Customers with web apps can see defects that can’t be scripted but would be visible to end users. * 🚨 Google introduces the Unattended Project Recommender. It uses machine learning to identify projects that have likely been abandoned and forgotten about, so you can cull them from the cloud.
Top Quotes * 💡 “People were originally attracted to Elasticsearch because it was an open source project. So this [amending the Elasticsearch Python client] is taking away one of the main reasons they were able to acquire the users they did. I don't get the strategy, unless they're pulling a ripcord right now, because they're bleeding.” * 💡 “I know a lot of companies are moving their services into the cloud, and a lot of security engineers are restricting outbound access, or tightly controlling egress. These things [Google’s Private Service Connect] have to happen — these things are absolutely needed — to keep them secure, and allow those companies to sell their services. Good catch-up feature.”
General News: We’re Not Angry Just Disappointed * 🐍 Elastic amends Elasticsearch Python client so it won't work with forked versions — and proves it knows how unpopular this is by blocking GitHub comments. This is forcing people to choose sides, and is a really disappointing move. * 😐 AWS details its commitment to keeping OpenSearch and Elasticsearch compatible with open source. Elastic has managed the impossible: it’s made AWS look like the good guys.
Amazon Web Services: Unbreaking The Rules * 🧑 Amazon’s senior cloud leader Charlie Bell is leaving the company after more than 23 years. Knowing how fast AWS moves, we feel tired just thinking about working there that long. * 👍 Amazon EC2 Auto Scaling enhances Instance Refresh with new features. Clearly the company is listening to its customers (in this respect, at least.) * 😎 AWS WAF
On The Cloud Pod this week, the team is back in full force and some are sporting fresh tan lines. Also, it’s earnings season, so get ready for some big numbers — as well as some losses.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS is finally killing off EC2-Classic. EC2 was launched in 2006, with one instance type (m1.small), security groups, and the US-EAST-1 Region. * 🚨 The 2021 Gartner Magic Quadrant for Cloud Infrastructure and Platform Services is out, and AWS, Google, Microsoft and Oracle have all made it. Although some scraped in by the skin of their teeth. * 🚨 Get consistent Kubernetes definitions with the new Anthos Config Management feature. The Kubernetes Resource Model (KRM) helps users define and update resources with minimal effort on their part.
Top Quotes * 💡 “I would say Google's getting market share because they are able to leapfrog everyone else on Kubernetes, big data, and machine learning.” * 💡 “Considering all the different vendors that are involved in a hospital, just being able to have a standard data format with FHIR is huge. And they also now power that with the cloud. There are lots of really interesting use cases that get unlocked with this [Azure Healthcare APIs] solution.”
General News: Earn Baby Earn * 💲 Google’s parent company, Alphabet, crushed earnings expectations. It still lost a lot, though. Increasing the price of YouTube TV could have limited the damage. * 🤪 Microsoft's revenue is up 21% overall. Azure’s revenue doubled, which is nuts. * 😨 Amazon’s revenue is up 27% overall — but that’s down from the 41% year-on-year increase the company saw in Q2 of 2020. It’s starting to see post-COVID-19 corrections.
Amazon Web Services: Not Fit for Consumption * 😡 AWS named as a Leader for the 11th consecutive year in the 2021 Gartner Magic Quadrant for Cloud Infrastructure & Platform Services. It’s interesting to see the 20% renewal push included, which is clearly a sore point for AWS customers. * 🛰️ AWS support for
On The Cloud Pod this week, it’s a merry-go-round of vacations, with Jonathan returning and Ryan escaping while Peter tunes in from Hawaii. Also, there is some big news in an otherwise quiet week.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS announces that Virtual Private Cloud (VPC) users can now assign IPv4 and IPv6 prefixes to EC2 instances. It should help simplify the process of using container and networking applications that require multiple IP addresses. * 🚨 AWS releases a new feature for SAM CLI, SAM Pipelines. It provides quick and easy access to the benefits of CI/CD, making it easier to get out new products faster and check for errors. * 🚨 Microsoft has acquired security platform CloudKnox, which was designed to work across multi-cloud and hybrid cloud environments.
Top Quotes * 💡 “I hope to see more of these [SAM Pipelines-style features]. It’s been one of my mental blocks. I've been using serverless ever since Lambda was announced, but building into a pipeline is such a chore. And Jenkins is such a chore in itself. So if you have a canned way to deploy a pipeline, it's great.” * 💡 “I think it [CloudKnox] had a potential to be really interesting and really valuable. But Azure was actually building a lot of these capabilities into their cloud natively, including least privilege access. And Google's building that kind of stuff too. So I don't know if there's a long runway left for them to get a lot of adoption and a lot of new customers, or if they’re going to be replaced by the cloud providers over time, and ultimately not be needed.”
General News: Don’t Off Slack * 💀 Salesforce has completed its acquisition of Slack for $27.7 billion. Hopefully they don’t kill slack because we do not want to use Teams.
Amazon Web Services: Winning * 👍 Amazon Virtual Private Cloud customers can now assign IP prefixes to their EC2 instances. Being able to assign multiple IPs is super helpful, so there are some great use cases for this. * 📦 AWS Serverless Application Model (SAM) Pipelines is a new feature of the AWS SAM CLI. We hope to see more of these types of announcements, this out-of-the-box function is so good. * 🐃 AWS is releasing the Amazon Route 53 Application Recovery Controller. We’re hoping the high price tag is just to slow the stampede of people who w
On The Cloud Pod this week, if you were impressed by Matthew Kohn’s ability to wing it last time, then you’re in luck because he’s back. Also, the team hopes AWS is listening to the show and reading these notes, so it can get on with creating its own unified agent for CloudWatch.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS has launches HIPAA eligible Amazon HealthLake. The service enables information exchange across healthcare systems, pharmaceutical companies, clinical researchers, health insurers, patients, and others parties. * 🚨 Google previews new Cloud IDS for network security. The system makes it easier to manage threat detection from the cloud. * 🚨 Microsoft announces the evolution of the Azure Migration Program (AMP). The new Azure Migration and Modernization Program (AMMP) will help enterprises improve their apps while moving them to Azure.
Top Quotes * 💡 “I have a couple of customers that I sent this [HealthLake] press release over to, and they're very excited. They have no idea how they want to use it yet, but they're very excited to figure out how to do something interesting with it. So I'm really curious to see how people actually start to play with this, and figure out how to use it to be beneficial for their companies.” * 💡 “I was surprised that they limited the open-source UDP proxy to just gaming. I get that there's some undifferentiated heavy lifting that is provided with session management security. But a UDP proxy that scales is something valuable to most companies that are using some legacy protocols. I wouldn't be surprised to see this expand a little bit to enable some other UDP use cases in the future.”
Amazon Web Services: Swimming Upstream * 🏊 AWS has launched a HIPAA eligible service for customers in healthcare and life sciences, called Amazon HealthLake. We recommend checking out the pricing before getting excited, as it seems expensive to us. * 🧊 AWS EBS io2 Block Express volumes are now generally available. Make sure you’re caffeinated when you dive in: it’s a complex space. * 👍 Amazon EKS now supports Kubernetes 1.21. Nice to see Amazon delivering on its promise of faster re
On The Cloud Pod this week, with a couple of no-shows, Justin and Ryan’s Happy Hour includes returning guests Matthew Kohn and Sara Tumberella. Also, the team is curious to see what’s going to change at AWS with its new CEO.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon has finally launched OpenSearch 1.0. They’re hoping to make the transition to as simple as possible for open-source Elasticsearch users. * 🚨 AWS customers can now pre-pay for their usage. This will allow customers to pay future invoices automatically. * 🚨 Google announced the general availability of its new Google Cloud Certificate Authority Service (CAS). It hopes the service will help address the increased need for digital certificates.
Top Quotes * 💡 “I'm curious to see if you can do things like optimization, where you can reference a security group rule many times across multiple security groups. [You could] simplify a lot of your ecosystem by having maybe a catalog of rules that you apply selectively.” * 💡 “I still haven't seen much talk about what they're doing with Beats, and if they're going to fork Beats as well. Initially, they weren’t going to, but then it sounded like Elasticsearch basically pulled the rug out from under them on that too. I wouldn't be surprised to see that also get forked at some point in the future as well.”
General News: Red Tape
Security: Ryan’s Going to Space * 👮 Research suggests security tools are fighting for attention, and there’s a rise in false-positive alerts. When companies want the latest and greatest security applications, they often end up competing with each other, and it makes troubleshooting difficult.
Amazon Web Services: Setting Fire to Dumpsters * 🚓 AWS announces new VPC security group rule IDs. We’re curious to dig into the details: for example, will it allow users to reference one security group rule across multiple security groups? * 👏 AWS launches OpenSearch 1.0. We get the impression AWS is handling this project differently, by really investing in the community. * 😐 AWS now allows customers to pay for their usage in advance. We think they should offer a big discount as an incentive. * 👍 AWS lowers data processing charges for
On The Cloud Pod this week, Ryan was busy buying stuff on Amazon Prime Day and didn’t want to talk about JEDI, so he arrived late to the recording. Also, long-time sponsor of The Cloud Pod, Foghorn Consulting, has been acquired by Evoque, so the team grilled Peter for the juicy details.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 The $10 billion JEDI cloud contract has been canceled by the Pentagon. In its place, the DOD announced a new multi-vendor contract known as the “Joint Warfighter Cloud Capability.” * 🚨 Evoque Data Center Solutions has acquired cloud engineering experts Foghorn Consulting. This is a key part of the company’s Multi-Generational Infrastructure (MGI) strategy, which it announced the same day as the acquisition. * 🚨 AWS released some incredible numbers from Amazon Prime Day. Jeff Barr gives his annual take on how AWS performed and the record-setting event.
Top Quotes * 💡 “The Pentagon has called off the $10 billion cloud contract [JEDI]. It was being dragged through the courts by Amazon and Microsoft, and this is sort of an admission that the Pentagon didn't want Donald Trump to get subpoenaed and testify on what his involvement was in the whole contract.” * 💡 “This is a big problem that almost every business has: how do you stop a deployment, especially a large deployment? Typically, we throw people at it, and we have them watch millions of dashboards, and hopefully, they catch it. But usually, it's a problem somewhere that's exposed to the customer that triggers that. So if we can have more tools like Gandalf that detect problems earlier, it’s great.”
General News: Some People Can’t Take a Joke * 🥳 Evoque Data Center Solutions acquires Foghorn Consulting. Congratulations to Peter on this exciting news! * 😠 The AWS Infinidash story has taken on a life of its own. What started as a joke has led to backlash from the community complaining about it being a form of technology gatekeeping.
JEDI: We’re Not Talking About This Anymore * 💀 The Pentagon has canceled the $10 billion JEDI cloud contract. It’s not really dead, they've just turned it into a joint multi-cloud offering, which is what we said they should do six months ago.
Amazon Web Services: A Little Gooey * 🚀 Andy Jassy thanks AWS employees as he takes over as Amazon CEO. We wonder if Bezos is bored yet. Between the Blue Origin launch and The Washington Post, he’s probably not. * 🕵️♂️ Jeff Barr is back with his annual take on
On The Cloud Pod this week, with the first half of the year full of less-than-ideal events, the team is looking forward to another next six months of less-than-ideal events. Also, everyone is excited to see how they can manipulate the AWS BugBust Challenge for a free ticket to re:Invent.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS launches the BugBust Challenge in the hopes of finding and fixing 1 million bugs. The challenge aims to help developers improve code quality, eliminate bugs and boost application performance while saving millions of dollars in application resource costs. * 🚨 Google has announced new features for Cloud Monitoring Grafana plugins. The new features include popular dashboard samples, more effective troubleshooting with deep links, better visualizations through precalculated metrics and more powerful analysis capabilities. * 🚨 Azure VM Image Builder service is now generally available. Image Builder will make it easier to build custom Linux or Windows virtual machine images.
Amazon Web Services: Does Not Have Bugs * 🐜 AWS announces the world’s first global competition to find and fix 1 million software bugs. We don’t think they’re referring to Amazon bugs, just software bugs in general. * 🤷 AWS launches customized images for Amazon EMR on Amazon Elastic Kubernetes Service. If you’re looking to reduce the time it takes to build images, that’s a good thing: otherwise it’s a fully managed service, so we’re not sure that users will care. * 🦸♀️ Amazon announces new Java Detectors and CI/CD Integration with GitHub Actions for CodeGuru Reviewer. We’re amazed by how quickly GitHub Actions is being adopted. * ❓ AWS acquires communication technology company Wickr. We want to know why Amazon is buying this: maybe they’re trying to enhance their enterprise and public sector application suites. * 🤓 AWS now supports container images to simplify continuous integration tasks. Continuing to build the ecosystem around serverless applications is a smart move by AWS.
Google Cloud Platform: Smart Player * 👍 Google announces that a new public dataset for Google Trends
On The Cloud Pod this week, Jonathan pulls a classic move from 2020 and doesn’t realize he’s on mute. Also, the team completely destroys an article about the cloud being too expensive for what you get.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 VC firm a16z calls the cloud a “trillion-dollar paradox” in a blog post, noting the pressure cloud computing puts on margins can start to outweigh the benefits. We think there are quite a few holes in their analysis and the Dropbox example doesn’t work. * 🚨 AWS releases Step Functions Workflow Studio. Developers new to Step Functions will enjoy being able to build workflows faster. * 🚨 Google announces that Quantum computers from IonQ are now on its marketplace. Developers, researchers and enterprises alike can now access IonQ’s high-fidelity, 11-qubit system via Google Cloud.
General News: A Trillion-Dollar Paradox * 😠 Venture capital firm Andreessen Horowitz, known as "a16z," thinks the cost of cloud computing outweighs its benefits. Dropbox is a terrible example to use in this case. * 👀 Splunk launches Splunk Security Cloud and announces a billion-dollar investment by a private equity firm. We think it’s having some integration problems in the background — it’s something to keep an eye on.
Amazon Web Services: Jonathan, You’re On Mute * 👍 AWS launches Step Functions Workflow Studio. This is great for developers new to Step Functions as it reduces the time it takes to build their first workflow. * 🚗 AWS invites individual developers and small teams to take the Graviton Challenge. They’re obviously trying to drive adoption. * 🥳 AWS Key Management Service is introducing multi-region keys. A nuisance that has plagued Justin for years has finally been solved. * 😺 AWS announces a public registry for CloudFormation, providing a searchable collection of textensions. People have been asking for this for a long time so it’s nice to see.
Google Cloud Platform: Tell Us How To Use It * 🤷 Google announces Quantum computers from IonQ are now available in
On The Cloud Pod this week, Matthew Kohn joins the team as a substitute for Jonathan and Peter, who have gone AWOL. Also, Google demonstrates again why its network is superior to the other cloud providers.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS now allows crash-consistent AMIs without requiring a reboot. No more manual processes needed. * 🚨 Google is building a subsea cable named Firmina. The cable, to be comprised of 12 fiber pairs, will carry traffic quickly and securely between North and South America. * 🚨 Oracle announces improvements to its block volumes. Its Ultra-High-Performance (UHP) block volume comes with up to 300,000 IOPS and 2,680 MB/s throughput per volume and is generally available across all OCI commercial regions and on all interfaces.
General News: Not Dead Yet * 💀 Hashicorp Vagrant 3.0 will maintain its Ruby-based features while being ported to Go. We thought this was on a path to death but apparently not.
Amazon Web Services: Proceed With Caution * 👏 AWS announces a new region in Tel Aviv, Israel. AWS clearly realized it was behind the other cloud providers on building new regions. * 😎 Amazon launches AWS Proton in general availability. There are some super cool improvements that have been done to this. * ✔️ Amazon EC2 now allows you to create crash-consistent Amazon Machine Images (AMIs). This is one of our EC2 wish list items — it’s great to tick it off the list. * 🤗 AWS announces per second billing for EC2 Windows Server and SQL Server Instances. It’s nice to only be billed for what you actually use. * 🎉 AWS removes NAT Gateway’s dependence on Internet Gateway for private communications. This has been a big annoyance for a while so nice to see it sorted!
Google Cloud Platform: Just Figure It Out * 🤷♀️ Google is announcing the general availability of Ubuntu Pro images on Google Cloud. Doesn’t make a lot of sense to embrace open source by purchasing an enterprise product. * 👍 PLAID guest posts
Is sending the former CEO of one of the biggest technology companies in the world to space a good idea? On The Cloud Pod this week, the team discusses the potential economic catastrophe that could follow if Jeff Bezos becomes space junk.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Jumpcloud, which provides cloud directory services, enables remote access, eases onboarding and offboarding of users and enables zero trust access models.
This week’s highlights * 🚨 Amazon is sending the old junk it found in the attic into space. * 🚨 Google is now fully qualified to direct traffic. * 🚨 Azure turned its out-of-office message on and hoped no one would notice.
General News: Frenemies * ⛄ Snowflake had its annual user conference and announced some new tools and features. Pretty good! * 👾 Jeff Bezos is joining the first human flight to space with his company Blue Origin. This is super risky, even if he’s no longer CEO. * 👍 Fastly blames global internet outage on a software bug. This is the right way to address outages — nice one, Fastly!
Amazon Web Services: Watch This Space * 😐 Amazon announces auditing feature for FSx for Windows File Server. This needs an acronym. * 👀 AWS has added a third availability zone to the China (Beijing) region operated by Sinnet. Nice to see. * 🧠 AWS Sagemaker Data Wrangler now supports Snowflake as a data source. Smart move.
Google Cloud Platform: Sneaky Sales Tactics * 🤷 Google announces the release of container-native Cloud DNS for Kubernetes. Powerful building block or Achilles heel? * 🤔 Google announces new capabilities for Cloud Asset Inventory. Makes so much sense to come from the provider because they know what you have. * 🤭 Google releases new Microsoft and Windows demos on Google Cloud Demo center. This is absolutely not a sales tool... * 😺 Introducing Google Cloud Service, Kf for Cloud Foundry, on Kubernetes. Another good p
This week on The Cloud Pod, apparently there was a machine learning conference because there is A LOT of machine learning news. For the listeners (and hosts of The Cloud Pod) who don’t understand machine learning, buckle up because this will be a long episode for you.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning, and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon is acting like it’s helping but really it’s lying with numbers. * 🚨 Google is pretending the 1991 Ford Fiesta it’s selling is a 2021 Mustang. * 🚨 Azure got a little overexcited with the use of its naming bot.
General News: Fake It Until You Make It * 😐 Amazon data shows more diversity among senior leaders after the definition of “executive” loosened. Well, that’s one way to do it. * 🎉 Amazon’s Andy Jassy is warming up for the CEO role. We hope competitors don’t expect him to tread softly when he starts. * 😲 Pluralsight will acquire A Cloud Guru to address growing cloud skills gap. This is earth-shattering.
Amazon Web Services: Busy As Usual * 🤗 Amazon Redshift Machine Learning is now generally available. There’s a helpful table to explain the different machine learning products. * 😞 Amazon ECS Anywhere is now generally available. A bit disappointed that they haven’t addressed the networking issue more. * 🎥 Introducing Amazon Kinesis Data Analytics Studio for analyzing streaming data. They’re really into studios at the moment. * 👍 Amazon SQS now supports a high throughput mode for FIFO Queues. This is nice. * 🚚 Amazon Location Service is now generally available with new routing and satellite imagery capabilities. Just so you don’t run your truck under a bridge that’s too low.
Google Cloud Platform: Not A Robot In Disguise * 🥱 New Cloud TPU VMs make training machine learning models on TPUs easier. We told you this wou
This week on The Cloud Pod, Ryan is stuck somewhere in a tent under a broken-down motorcycle but is apparently still having fun.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon went back to school to become a detective. * 🚨 Google was voted prom queen at the virtual homecoming. * 🚨 Oracle shocks everyone with its new look.
General News: Great Partners * 👏 Hashicorp has partnered with AWS to launch support for predictive scaling policy in the Terraform AWS provider. This will be hugely popular for people new to the cloud.
Amazon Web Services: Dropping Stories For No Reason * 🐜 AWS Lambda Extensions are now generally available with new performance improvements. This has pretty limited regional availability, though. * 👍 Amazon releases the AWS Shield threat landscape 2020 year in review. One of our favourite blogs. * 😊 AWS EKS Add-Ons now supports CoreDNS and kube-proxy. This is neat! * 🐦 Introducing the AWS Application Cost Profiler — there have been a few complaints about this on Twitter. * 😺 AWS Compute Optimizer launches updates to its EC2 instance type recommendations. This is awesome. * 🌎 AWS Outposts launches support for EC2 Capacity Reservations. Being able to use the same tool regardless of where you are is a good thing! * 😃 An AWS Region in the United Arab Emirates (UAE) is in the works. Great!
Google Cloud Platform: Prom Queen 2021 * 😐 Google VM Manager with OS configuration management is now in Preview. This is basically patch and agent management. * 🥳 Forrester names Google Cloud a leader in Unstructured Data Security Platforms. Good job, Google! * 😭 Google has released a better way to manage firewall rules with Firewall Insights. We just want a firewall manager that does everything for us. <!--
-->
This week on The Cloud Pod, the team discusses the fine art of writing the podcast show notes so there are bullet points for when Peter shows up without doing the homework.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon is catering to the unimaginative with its version of a vanilla milkshake. * 🚨 Google now performs commitment ceremonies but they come at a cost. * 🚨 Azure did an online pastry course and can now make croissants.
General News: La France Est Méconnaître Amazon (France Is Ignoring Amazon) * 😴 VMware picks longtime executive Raghuram as its new CEO. So many people were overlooked for this position. * 🍟 France says Google and Microsoft Cloud Services are OK for storing sensitive data. Bit of a snub for Amazon.
Amazon Web Services: Busy Little Bees * 🚀 AWS SaaS Boost released as open source. Sounds more like a product than it actually is. * 🦆 AWS announces general availability of AWS Application Migration Service. If play is to lift and shift, with no thought of transformation at all, this is for you. * 🛡️ AWS CloudFormation Guard 2.0 is now generally available. It’s great that this supports more than just cloud transformation. * 🦹♂️ AWS Premium Support launches Support Automation Workflows (SAW). This will make the exchange of data so much easier. * 🗳️ Amazon Elasticsearch Service announces a new lower-cost storage tier. This is great news for everybody. * 😐 Amazon announces the release of EKS 1.20 — the raddest release ever. * 🏃 AWS launches another way to run containers with App Runner. Just in case you don’t want to use one of the other billion container services.
Google Cloud Platform: Here To Confuse You * ⭐ Google will bring Starlink satellite connectivity to enterprises in late 2021. Cool! * ☁️ Google is offering new committed use
This week on The Cloud Pod, Justin is away so the rest of the team has taken the opportunity to throw him under the bus.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 The Pentagon has had enough of the kids fighting so no one gets the toy. * 🚨 Amazon has given developers the happy ending they’ve always wanted. * 🚨 Google is playing with fire and hopes no one gets burnt.
JEDI: Play Nice * 🚸 Pentagon officials are considering pulling the plug on the star-crossed JEDI cloud-computing project. Reminds us of when we were kids and our parents took toys away when we couldn’t play nice together.
Amazon Web Services: We’ve Made All the Money * 💯 AWS announces a price reduction for Amazon Managed Service for Prometheus. That’s an awful lot of samples. * 🙏 Amazon Virtual Private Cloud (VPC) announces pricing change for VPC Peering. Just get rid of the ridiculous data transfer fees! * 🤩 AWS Organizations launches a new console experience. We’re excited to try this out! * 👍 AWS announces IAM Access Control for Apache Kafka on Amazon MSK. This is great. * 😐 AWS Systems Manager now includes Incident Manager to resolve IT incidents faster. This might initially fall short of some of the other offerings on the market. * 😆 AWS Local Zones are now open in Boston, Miami and Houston. They’re continuing on the Oracle model of racks in random garages. * 🎈 Amazon now lets you create Microsoft SQL Server Instances of Amazon RDS on AWS Outposts. A big hooray for people using Outposts.
Google Cloud Platform: Smells A Bit * 😬 Google announces Agent Assist for Chat is now in Preview. Hopefully this is better than predictive text, which is often highly inappropriate. * 👃 Google releases a handy new Google Cloud, AWS and Azure product map. This press release has an Oracle smell about it. * 👏 Browse and query Google Cloud Spanner da
This week on The Cloud Pod, Yahoo is back and cheaper than ever. Just kidding, it’s Ryan who is back and the team is curious as to how he managed to extricate himself out from under that kitten.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon has been doing yoga and the results are paying off. * 🚨 Google bought a hard hat and is getting into the construction business. * 🚨 If you need to get your kid to sleep, let them read this from Azure.
General News: Yahoo’s Renaissance * 💀 Verizon dumps Yahoo-AOL for rock-bottom price. But they’re not dead yet! * 👍 Amazon posts record profits as AWS hits $54B annual run rate. That’s pretty good! * 🚙 Microsoft beats Q3 revenue expectations, spurred by strong cloud sales. Get on the bandwagon, Azure. * 💰 Alphabet announces first quarter results for 2021. It does include GCP and G-Suite revenue. * 🤯 Cloud infrastructure spending grew 35% to $41.8B in Q1 2021. These numbers boggle our minds.
JEDI: Just Keeps Getting Better * 🤣 Court snubs Microsoft and the U.S. government’s request to throw out Amazon's complaint against JEDI cloud contract decision. We can’t wait to hear what Trump says under oath.
Amazon Web Services: Bring Your Own Talent * 🚀 AWS is launching Amazon FinSpace, a data management and analytics solution. Step one, invent the universe. * 🤷 AWS Proton introduces customer-managed environments. We had to look up what Proton actually is. * 🤩 AWS Proton allows adding and removing instances from an existing service. We’re looking forward to some re:Invent sessions on this. * 💳 Amazon launches CloudFront Functions for the lowest possible latency. A great solution that can reduce your costs quite a bit. * 👎 Happy 10th birthday to AWS Identity and Access Management. Ten years on and still a pain in the ass. * 🏭 Introducing Amazon Nimble, a new service that creative studios can use to
Justin and Jonathan kick off this week’s episode of The Cloud Pod by themselves, Peter joins the party late because he’s been fighting dinosaurs and Ryan is unable to attend as he can’t move from under the weight of the kitten on his lap.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon will find any excuse to use GIFs just like the rest of us. * 🚨 Google has given Cardi B a headstart on a theme song for its new product. * 🚨 Azure sent the wedding invites out late but still expects you to show up.
Amazon Web Services: Cheaper Than Healthcare * 👩⚕️ Amazon RDS on VMWare no longer requires the use of a VPN tunnel back to AWS. Still cheaper than paying for healthcare. * 🤗 Amazon Elasticsearch Service announces support for Asynchronous Search. This is really cool! * 👍 Amazon EC2 now allows you to replace the root volume for a running instance. There are some great use cases for this. * 🎅 Red Hat Enterprise Linux with High Availability is now available on Amazon EC2. Good to see IBM isn’t throwing up barriers. * 🌉 AWS is releasing the new Amazon FSx File Gateway. Hopefully this is easy to implement. * ⌚ AWS announces moving graphs for CloudWatch Dashboards. Also known as GIFs for CloudWatch.
Google Cloud Platform: Closet Fans of Cardi B * 🖥️ Google announces PHP, a general purpose programming language, is now on Cloud Functions. Visit thecloudpod.net to see a live example of PHP, also known as the Wordpress platform we built our website on. * 😉 GCP is launching Web App and API Protection (WAAP), which provides comprehensive threat protection for web apps and APIs. Do not confuse this with the Cardi B song. * 💰 Google has made the Doc AI solutions generally available. If you’ve sent a fax lately, you know how expensive it is. * 😟 Google announces new multi-instance NVIDIA GPU on the
On The Cloud Pod this week, the team admits to using the podcast as a way to figure out what day it is. Justin also relents and includes Azure news because he couldn’t handle any more Oracle mobile apps announcements.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Social media influencers can breathe a sigh of relief. * 🚨 Amazon is dangling a carrot in front of one of its partners. * 🚨 Azure is throwing a spanner in the works.
General News: Not Cool News * 💣 The FBI arrests a man for his plan to kill “70% of the internet” in an AWS bomb attack. 70% is quite a stretch but we’re sure it would have caused a crappy day for a lot of people. * 🥳 Hashicorp has released its Boundary 0.2 release with several new features. We’re really excited about this. * 😐 Announcing HashiCorp Terraform 0.15 General Availability. If you believe it, this is really great news.
Amazon Web Services: Good At Compromising * 💯 AWS announces AQUA is now generally available. Justin should have gotten a prediction point for this one. * 🤗 Amazon Managed Service for Grafana now offers more support. We’ll see if Grafana can actually make money out of its partnership with Amazon. * 👏 Amazon RDS for PostgreSQL now integrates with AWS Lambda. This is really cool! * 🤑 Decrease machine learning costs with instance price reductions and savings plans for Amazon SageMaker. Some pretty significant savings here.
Google Cloud Platform: Colossal * 🏊♀️ Google takes a deep dive into its scalable storage solution, Colossus. Nothing new here. * 🔧 Google announces tracking index backfill operation progress in Cloud Spanner. This is super important. * 🗺️ The new Google Cloud region in Warsaw is open. Nice to see Eastern Eu
On The Cloud Pod this week, Ryan has given all his money to the Amazon press team to write really confusing headlines just to annoy Peter. Also, Jonathan is missing presumed cranky buns.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 IBM is spinning off its infrastructure services business — the new public company will be called “Kyndryl.” * 🚨 Teresa Carlson has left the AWS building. The AWS VP is headed to big-data analytics company Splunk Inc. as its new chief growth officer. * 🚨 Google’s like the cool kids who know how to party.
General News: Eventual Degradation of Profits * 🤣 IBM to name its infrastructure services business “Kyndryl”. We hope they didn’t spend a lot of money coming up with that name. * 🤷 Top AWS executive Teresa Carlson joins Splunk as President and Chief Growth Officer. We thought she might have been a candidate to succeed Andy Jassy.
Amazon Web Services: 5G Not Included * 👂 AWS formally launches the OpenSearch project. Seems like it’s listened to the open source feedback. * 🚽 Amazon EC2 Auto Scaling introduces Warm Pools to accelerate scale-out while saving money. Please don’t let Andy name anything. * 🧑🤝🧑 AWS and Verizon team up to provide 5G-powered edge computing infrastructure. Justin got his COVID-19 vaccination and was disappointed it didn’t come with 5G. * 🎅 Amazon Redshift now supports data sharing when producer clusters are paused. We wonder what underlying tech made this possible?
Google Cloud Platform: Excel at No Code * 🍃 Leaf Space enables next-gen satellites on Google Cloud. This fills a very obvious gap in the market and is pretty cool. * 🤓 Google introduces a new blog series: Cloud CISO perspectives. Hopefully some cool stuff will be announced. * 💻 Google announces its business process automation app AppSheet is now generally available. We feel bad for the poor sap that has to maintain this on the bac
On The Cloud Pod this week, the team discusses the future of the podcast and how they’ll know they’ve made it when listeners use Twitter to bombard Ryan with hatred when he’s wrong.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon gives Justin a long overdue birthday present. * 🚨 Google wants to educate the people. * 🚨 Azure has a new best friend but could they be a wolf in sheep's clothing?
General News: Goodbye, Friend * 😢 The Apache foundation has decided to send Mesos to the attic. This makes us sad because we loved the concept.
Amazon Web Services: Happy Birthday, Justin * 👍 New AWS WAF Bot Control to reduce unwanted website traffic. This is great! * 🏷️ AWS is releasing the Amazon Route 53 Resolver DNS firewall to defend against DNS-level threats. Pricing is interesting on this one. * 🙏🏻 AWS launches CloudWatch Metric Streams. After years of complaints, they’re finally fixing this issue. * 💰 AWS Lambda@Edge changes duration billing granularity from 50ms down to 1ms. Nice price cut! * 😊 AWS Direct Connect announces MACsec encryption for dedicated 10Gbps and 100Gbps connections at select locations. AWS has fulfilled their promise to Justin — three years later. * 🐍 Amazon announces new predictable pricing model up to 90% lower and Python Support moves to GA for CodeGuru Reviewer. If this goes down next week, blame Ryan.
Google Cloud Platform: So Pretty * 👸 Google is releasing an open-source set of JSON dashboards. This is super important. * 🏫 Google announces free AI and machine learning training for fraud detection, chatbots and more. We recommend you check these out. * 🦆 Google Clouds Database Migration Service is now generally available. Everything is so beautiful on paper. * 🔧 Google introduces request
In this episode of TCP Talks, Justin Brodley and Jonathan Baker talk with Miles Ward, the founder of the Google Cloud’s Solutions Architecture practice. Currently, Miles leads the cloud strategy and solutions capabilities as the Chief Technology Officer for consulting and IT services company SADA.
Startups have helped increase the popularity of open source products among enterprise businesses. Changing systems can be a struggle for larger, more traditional companies. But legacy businesses also want to accomplish more in a shorter amount of time, which requires shedding clunky, legacy systems.
“Those building blocks make it so that companies operate at a certain rate of change. And I know zero companies asking me to slow down their rate of change,” he notes.
The evolution of product compatibility is also discussed. Product sellers need to help customers understand how much of their system fits and how much doesn’t fit in one solution compared to another, Miles says. Customers need to have a clear understanding of what’s involved and how much work it’s going to be.
In addition, Miles shares his thoughts on the role of the CTO as well as the benefits of rebranding a product everybody hates. Featured Guest 👉 Name: Miles Ward
👉 What he does: As CTO of SADA, Miles leads the cloud strategy and solutions capabilities. His remit includes delivering next-generation solutions to challenges in big data and analytics, application migration, infrastructure automation, and cost optimization; and engaging with customers on their most complex and ambitious plans around Google Cloud.
👉 Key quote: “There used to be big crunchy legacy impediments to adoption... But it's 2021 — live in the future, that shit works. Now it's more about making it easy enough and predictable enough to consume that folks can unlock the business justification.”
👉 Where to find him: LinkedIn | Twitter Key Takeaways * 🚨 Gone are the days when products from different technology providers, like Oracle or SAP, couldn’t work together to solve a customer problem. These days, companies need to make products easy and predictable enough so customers can unlock the business justification straight away. * 🚨 For Google Cloud, the next phase of growth will require investment in higher-level relationships with customers. Miles references his experience with current Google Cloud CEO Thomas Kurian (TK). * “TK is super focused about spending the majority of his time face to face with customers,” he says. “He's not doing it to be a glad-hand, he's deal making and proposal pushing and thinking through the machinery of how to build higher level relationships.” * 🚨 There’s a huge opportunity to help the “the real world divisions inside of real world businesses” — not just serve the IT department. * Miles says, “I think there's a bunch of cloud providers that are working really hard now to facilitate the plumbing and governance and oversight and security controls and operational management of what is — not a hybrid between their data center, and a cloud — a hybrid between their SaaS fleet and the couple of things they still need to run on their own.” * 🚨 Worried about leveraging a Google solution and then having them pull the plug on it? Miles doesn’t think you should be too concerned about deprecation. * “I think they have heard this feedback really loud and clear,” he says. “There's a whole bunch of people that have made it really obvious that if you're going to provide these kinds of tools to outside team members, you're going to have to figure out how to maintain them long term. I think the clearest and easiest path for that is to have the majority of products be buil
On The Cloud Pod this week, the team is feeling nostalgic and a little nerdy, as you can see from the show title — a throwback to Serial Console and its ability to add a ton of characters when you didn’t want it to.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud, and Azure.
This week’s highlights * 🚨 Amazon should be singing a different tune. * 🚨 Google has astonished us all by actually sharing something interesting. * 🚨 Azure is the strict school principal that just canceled lunch.
General News: Justin Said It First * 🥇 VentureBeat predicts industry clouds could be the next big thing. Justin will take the royalties check anytime, VentureBeat.
Amazon Web Services: Please Don’t Keep It To Yourself * 🤷 Red Hat OpenShift Service on AWS is now generally available. Surprising because we don’t remember it going into beta. * 🔭 AWS Distro for OpenTelemetry adds StatsD and Java support. We’re glad to see the continued investment in OpenTelemetry. * 🤯 AWS DevOps Monitoring Dashboard solution is now generally available. The solutions library is a Rube Goldberg machine. * 👍 Amazon Lookout for Metrics is now generally available — perfect for Ryan, who has no machine learning experience. * 🎵 Amazon Elasticsearch Service announces a new Auto-Tune feature for improved performance and application availability. We wish Amazon would open source this. * 👼 AWS SSO credential profile support is now available in the AWS Toolkit for VS Code. Thank you, Jesus. * 🍎 Amazon is developing a chip to power the hardware switches that shuttle data around networks. Apparently Google and Apple are also doing this. * 🦇 Troubleshoot boot and networking issues with new EC2 Serial Console. Must be useful for someone, maybe the people using enclaves?
Google Cloud Platform: Blame Active Directory * 😊 Google wants customers to rethink their cloud migration strategy. Actually quite an interesting blog post — no, this is not sarcasm!
Disappointed not to see Amazon take the opportunity to increase its executive diversity with its new CEO.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 If Amazon was the royal family, this would be like Harry becoming King. * 🚨 Google found slugs in its lettuce and is not happy about it. * 🚨 Azure wants to shut The Cloud Pod up for good this time.
General News: Nothing Spicy * ☁️ Sysdig is releasing unified cloud and container security with the launch of Unified Threat detection across AWS cloud and containers. Interesting that it uses Cloud Custodian.
Amazon Web Services: No Longer Hiring * 🤯 Tableau CEO Adam Selipsky will return to Amazon Web Services as CEO. We did not see this coming. * 👂 Introducing Amazon S3 Object Lambda. They listened to us!
Google Cloud Platform: Slurm It Up * 👎 Google Cloud caps sales commissions as losses mount. This will remove the motivation to go after smaller deals. * 😊 Google announces a new method of obtaining Compute Engine instances for batch processing. We thought it was attacking our workloads but it actually wasn’t — our bad. * 🥔 Google is announcing the preview of its Network Connectivity Center. No potatoes, thankfully. * 🐌 Announcing the newest set of features for Slurm running on Google Cloud. Worst name ever. * 🦹♀️ Google announces A2 VMs are now generally available with the largest GPU cloud instances with NVIDIA A100 GPUs. Is this the computer version of scalping tickets? * 🤷 Google announces high-bandwidth network configurations for General Purpose N2 and Compute Optimized C2 Compute Engine VM families. We’d love to know what the technology is behind this.
Azure: Not Happy With The Cloud Pod * 🌎 Azure announces plans to expand the Azure Availability Zones to more regions. We’ll take credit for this one.
TCP Lightning Round ⚡ After a large amount of debate about who should win, Jonathan takes this week’s point, leaving scores at Justin (3), Ryan (3), Jonathan (5). Other headlines mentioned:
On The Cloud Pod this week, the team debate the merits of daylight savings and how they could use it to break things in a spectacular fashion.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon is injecting the fun back into the party. * 🚨 Google is going mission-critical, spare a thought for its employees. * 🚨 Azure has released a new storage defender to reduce the threat of storage exploitation.
General News: Back From The Dead * 👑 Docker CEO talks about their progress, product-led strategy, and coders as “kingmakers.” We’re not sure how solid that funding is but we’ll see how it goes when the renewals come around.
Amazon Web Services: So Many Faults * 💉 Amazon is launching the AWS Fault Injection Simulator (FIS) for controlled fault experiments on AWS workloads. We can’t wait for FIS to go wrong and start injecting faults where they don’t belong. * 💵 Amazon announces price reduction for S3 Glacier. We can hear the cash registers ringing in the background. * 🧔 Amazon is celebrating 15 years of Amazon S3 with “Pi Week” livestream events. It’s not a sentient being! * 🤗 Amazon gives customers an easy way to execute commands in a container running on ECS ec2 based instances or Fargate with ECS Exec. A little clunky to set up but it’s amazing! * 😂 Amazon announces end of life date for ECS-optimized Amazon Linux AMI. We’re predicting Amazon announces an extension announcement in January 2023! * 👍 Amazon is launching a new set of Graviton2 based instances for memory-intensive workloads. This sounds really good. * 🤑 Amazon is adding policy validation to IAM Access Analyzer. Can’t argue with the price, it’s been so helpful.
Google Cloud Platform: Yell At Us * 😡 Google is releasing a new service called Mission Critical Services (MCS). Meaning you get to yell at Google if it goes wrong.
Azure: Epic * 😺 Azure and AMD announce a landmark partnership in confidential computing evolution. Cool!
On The Cloud Pod this week, Jonathan’s brain is a little scrambled and he can’t remember when he last went out for dinner even though it was with Justin on Tuesday.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 The honey pot might be about to dry up for Microsoft's lawyers. * 🚨 If you need a headache to get out of dinner with the in-laws, read this. * 🚨 Google has finally started listening to the sage advice from The Cloud Pod.
General News: Burn, Baby, Burn * 🥺 Okta says it’s buying security rival Auth0 for $6.5 billion, sending its stock plunging. The company’s not telling us its plan so don’t panic just yet. * 🔥 OVH data center burns down knocking major sites offline. Brutal.
JEDI: Things Are Not Going Well * 🤣 With a $10 billion cloud-computing deal snarled in court, the Pentagon may move forward without it. We can’t wait to see what this has cost taxpayers.
Amazon Web Services: Bottom Of The Barrel * 👍 AWS Lambda has received four new trusted advisor checks. This is a real advantage! * 🤯 AWS Secrets manager now lets you replicate secrets across multiple AWS regions. This makes our brains hurt.
Google Cloud Platform: Just Listen To The Cloud Pod * 🔨 Introducing Apache Spark Structured Streaming connector for Pub/Sub Lite. Easy tools to make life easier! * 🎠 Google’s Cloud Healthcare Consent Management API is now generally available. Could be a Trojan horse. * 🙏🏻 Save the date for Google Cloud Next ‘21: October 12–14, 2021. Thank you, Jesus, it’s not nine weeks long! * 😐 Managing cloud firewalls at scale with new Hierarchical Firewall Policies. This is a terrible name.
Azure: Hot Potato * 💖 Scale your critical applications cost-effectively with Azure Disk Storage. Always love a good disk storage story. * 🤷♀️ Architect and optimize your internet traffic with
On The Cloud Pod this week, Peter is spending the next 12 hours in a rejuvenation chamber like a regular villain straight out of a James Bond film.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon is on a mission to replace humans so we can go on holiday permanently. * 🚨 Google is a bit early with the April Fools’ joke. * 🚨 Azure is, much to our surprise, ahead of everyone else for once.
Amazon Web Services: Battle Bots * 😞 Amazon announces Alexa Conversations is now generally available for voice app development. We’re still a bit disappointed in her voice — it would be nice to hear something a bit more natural. * 🍬 Amazon launches computer vision service to detect defects in manufactured products. Soon we’ll just be sitting around eating bon bons — we can’t wait! * 🎎 AWS Asia Pacific (Osaka) region now open to all, with three availability zones and more services. We think this is a reaction to the huge cloud growth in Japan. * 🏅 AWS DeepRacer League’s 2021 season launches with new Open and Pro divisions. Apparently it's gone virtual and is being dominated by experts.
Google Cloud Platform: A Bit Jealous * 👩✈️ Google introduces GKE Autopilot, a revolutionary mode of operations for managed Kubernetes. Autopilot makes it sound like an Oracle product. * 🤣 Google announces the Risk Protection Program to enhance trust in cloud ecosystems. Google wants you to pay insurance in case its cloud goes down… * 👍 Google extends BigQuery BI engine for faster insights across popular BI tools. Pretty cool! * 👏 New enhancements for Google Cloud Marketplace Private Catalog including Terraform support. This is pretty good for internal teams managing private catalogs.
Azure: Killing It * 🐑 Microsoft has announced a trio of new industry clouds. We think other providers will follow very soon. * 😬 Microsoft to establish the first datacenter region in Indonesia as part of
On The Cloud Pod this week, Jonathan has returned and is sitting in his garage letting it get darker and darker before he turns a light on. Gartner says low-code is growing!! NOOOOOO!
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS is teaming up with TV to make hockey more exciting. * 🚨 Google is no longer stuck in the 90s. * 🚨 Oracle thinks it’s ruggedly handsome — it is not.
Follow Up: Somebody’s In Trouble * 🌞 SolarWinds hackers downloaded some Microsoft source code for Azure, Exchange and Intune. Intune is probably the most damaging — this is not good news for Microsoft.
General News: The Glowing Puck * 💲 Gartner is reporting that Low-Code development tool growth has grown 23% this year. Gartner, pay to play. * 🏒 AWS provides the National Hockey League with cloud, AI and machine learning services. It’s great to see computer tech adding to viewer engagement. * 👍 Hashicorp announces the general availability of the Terraform Cloud Operator for Kubernetes. It’s an interesting solution to a very hard problem.
Amazon Web Services: Everyone’s On Vacation * 😯 Amazon EC2 Mac Instances now support macOS Big Sur. Completely stunned by this, aren’t you. * 🎉 Amazon EC2 Auto Scaling now shows scaling history for deleted groups. This actually solves a small but annoying problem for Justin.
Google Cloud Platform: Jumping Back To 1994 * 👏 Google introduces schedule-based autoscaling for Compute Engine. Finally catching up to Azure and AWS, both of which have had this for a few years now. * 🔨 Google adds several new features to Google Cloud VMware Engines to support workloads moving from the cloud. We just want the VMware tools. * 🦖 Google launches Cloud Domains to make it easy to register and use custom domains within its platform. Should have had this a long, long, long time ago.
Azure: Copying Things That Are Good Ideas * 🤷 Introducing private Azure marketplace for simplified app governance and deployment. Apparently this is a t
On The Cloud Pod this week, Jonathan is getting his beauty sleep so you’ll have to make do with the comic stylings of Justin, Peter and Ryan.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Like The Very Hungry Caterpillar, Amazon is turning into a beautiful butterfly. * 🚨 Google is helping to monetize Jonathan's beauty sleep. * 🚨 It’s the end of the world, we can Azure you.
Amazon Web Services: The Weird Kid in Class * 🦋 AWS announces Amplify Flutter is now generally available. Get your flutter on in the cloud. * 👽 Amazon EKS now supports Kubernetes version 1.19. Weird use case, but OK. * 👏 AWS Direct Connect announces native 100 Gbps dedicated connections at select locations. No discount for more data — well done, Amazon.
Google Cloud Platform: Jonathan’s Money Maker * 🍰 Easily build Kubernetes applications that span multiple clusters with Google’s new multi-cluster services (MCS). Now you can have your cake and eat it, too! * 😴 Google announces general availability of Service Directory. Now Jonathan makes money while he sleeps. * 😐 Google announces 9TB SSDs to bring ultimate IOPS per dollar to Compute Engine VMs. Still not that exciting.
Azure: Lost in Space * 🔥 Azure announces Firewall Premium is now in preview. No more excuses for sticking with standard firewall protection. * 🤣 Microsoft will establish its next U.S. datacenter region in Georgia’s Fulton and Douglas Counties. Not only did Georgia go blue, they went Azure blue. * 👩🚀 Azure announces partnership with HPE and the upcoming launch of the Spaceborne Computer-2 (SBC-2). Also known as SkyNet. * 🧠 Azure has added the ability to backup Linux systems with Azure Backup. This is such a no-brainer; all cloud providers should have this.
TCP Lightning Round ⚡ Justin will have nightmares about supporting more than
On The Cloud Pod this week, The Team are on the brink and three more months of the pandemic will likely push the podcast over the edge into an abyss of garble that no one can understand.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon has a gender reveal party and introduces its latest bundle of joy. * 🚨 Google is eating croissants for breakfast. * 🚨 Azure is dangling a pair of juicy fruits in front of us.
Follow Up: The Mad Men Are Back * 🤔 Amazon announces its “Other” business segment, which consists mostly of its advertising business, has surpassed its “subscription services” segment. There’s speculation that Andy Jassy might split Amazon's advertising business out once he becomes CEO.
General News: Rolls Right Off The Tongue * 😒 Vantage, an AWS Console alternative, has acquired ec2instances.info. They better not mess it up!
Amazon Web Services: Undoing Your Hard Work * 👾 New Amazon Elastic Block Store Local Snapshots on AWS Outposts makes it easier to meet data residency and local backup requirements. It’s like playing a video game and building up your weapons, only to start from scratch when you move regions. * 👶 Amazon introduces CloudFront Security Savings Bundle. We appreciate the savings, but not sure about the bundle.
Google Cloud Platform: Our Buzzword Bingo Is On Point * 🙈 Google launches improved troubleshooting with Cloud Spanner introspection capabilities. We love these types of tools, except if they’re on SQL Server. * 🤷 Google launches Apigee X to help enterprises manage their digital transformation assets. What is it with X? What happened to 8 and 9? * 🤳 Google introduces real-time data integration for BigQuery with Cloud Data Fusion. For people who don’t want to read, they just want to see pretty pictures. * 🦘 Google introduces Assured Workloads Support. The Aussies will always be the best. * 🥐 The Dunant subsea cable, connecting the US an
It’s Peter’s washing night so please enjoy the soothing sounds of the odd spin cycle as we dive into the huge news coming out of Amazon on The Cloud Pod this week.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 America’s version of Queen Elizabeth has stepped down. * 🚨 Google is a bit late to the party but brings the ice so we forgive its team. * 🚨 Azure is trying to claim it came first but the chicken says otherwise.
Follow Up: A Bit Slack * 👉 Slack explains how the January 4th outage occurred. It was all Amazon’s fault. * 🥳 FogOps for Linux is now available via the AWS Marketplace. Congratulations on getting FogOps on the marketplace, Peter! * General News: It’s Earnings Season! * 🥜 Microsoft releases its earnings. This is nuts. * 😶 Alphabet also released its earnings. We hope all the money it’s investing in infrastructure and data centers pays off in the long run, because that’s a big loss. * 🤪 Amazon announces financial results and CEO transition. That’s some crazy profit. * 🙋♀️ Outgoing Amazon CEO Jeff Bezos addresses employees. But who will head AWS now?
Amazon Web Services: Bon Voyage, Bezos * 🤨 AWS launches multiple private marketplace catalogs for AWS organizations. Not a problem any of us have so not wowed by this. * 👎 AWS PrivateLink for Amazon S3 is now generally available. We like it but don’t like the pricing. * 👍 Amazon Macie announces a slew of new capabilities. Check out our sponsor OpenRaven, which is much better at solving the same issue and is much cheaper.
Google Cloud Platform: Stop Blaming Our Database * 😕 Google announces a CentOS 7-based Virtual Machine image to achieve optimal Central Processing Unit and network performance on Google Cloud. We had to look a few of these terms up. * 👏 Google introduces Cloud SQL Insight
It’s a Wednesday so things could be better, but spare a thought for the team as they battle Mother Nature on The Cloud Pod this week.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon is forking people off big time. * 🚨 Google wants to help you lose those pandemic lockdown pounds. * 🚨 Azure didn’t overwhelm anyone with its “problem.”
General News: The Elastic Kerfuffle * 🤣 Elastic blames Amazon for forcing it to change its licensing. One of the most ridiculous blog posts ever. * 🍽️ Logz.io looks to launch a true open-source distribution for Elasticsearch and Kibana. Everybody’s forking now. * 💀 AWS has also announced that it will also fork its project for a truly open source Elasticsearch. The beginning of the end for Elasticsearch. * 👏 Logz.io followed up its previous announcement by announcing it’s combining its efforts with Amazon. This is great news for the open-source community.
Amazon Web Services: Let’s Talk * 👍 AWS Lex has released a new console experience and new V2 APIs to make it easier to build, deploy and manage conversational experiences. We’ve played with it and it’s very nice. * 🤫 Amazon CloudWatch Agent now supports OpenTelemetry APIs and Software Development Kits. Could be a sign it’s about to make a lot of investments in OpenTelemetry and is moving away from CloudWatch. * 🚓 Amazon GuardDuty enhances security incident investigation workflows through new integration with Amazon Detective. Integrated security — we like it! * 😒 Amazon Chime SDKs for iOS and Android now support screen share. It’s great it has functionality that other apps have had from the start. * 🤩 Amazon ECS Agent v1.50.0 allows customers to execute interactive commands inside containers. This makes Justin’s life complete.
Google Cloud Platform: Making Peter’s Dreams Come True * 🤗 Google announces the general availability of its comprehensive
On The Cloud Pod this week, news has been a bit slow coming out of the Cloud Providers; the team suspects they might be curled up on the floor in fetal position after the events of last year.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon has gone to the gym over the holidays and is now kicking butt. * 🚨 Helping teach us the ways of the cloud, Google is. * 🚨 There’s nothing remotely funny about Azure this week.
General News: Ryan Doesn’t Want to Wear Pants * 🙄 Amazon has kicked controversial social media platform Parler off AWS. The multi-cloud people are going to be unbearable now. * 💌 Amazon defends its decision to suspend in response to Parler’s lawsuit. Most people don’t know Amazon sent Parler notices for months — it’s not like they weren’t warned. * 👎 F5 Networks to acquire edge-as-a-service startup Volterra for $500M. There’s so much buzzword lingo in this announcement, we suspect this service will lack substance. * 👒 Red Hat buys Kubernetes security startup StackRox. We’re surprised Google didn’t buy it. * 🔨 Pat Gelsinger is stepping down as VMWare CEO to replace Bob Swan at Intel. We think he has a very long road ahead to get Intel back on track.
Amazon Web Services: Family Time * 🤞 AWS announces Transfer Family now provides support for EFS file systems as well as S3. Would be nice if this would tie into Incognito or Simple Directory Service. * 😐 Amazon EMR now supports Apache Ranger for fine-grained data access control. Neat. * 🤷 Achieve faster database failover with Amazon Web Services MySQL JDBC Driver now in preview. Why not just re-resolve the DNS?
Google Cloud Platform: Ruby Red * 👌 Google Cloud Function is bringing support for Ruby, a popular, general-purpose programming language
On The Cloud Pod this week, it appears 2020 is not done with us yet and Ryan receives a mystery emergency alert to kick the show off.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
Open Raven, the cloud native data protection platform that automates policy monitoring and enforcement. Auto-discover, classify, monitor and protect your sensitive data.
Due to the pandemic and the cancellation of just about every in-person event, Justin has hundreds of stickers at his house that (his wife says) need to go. Head to The Cloud Pod store and use codes 100EPISODE or 2020SUCKS for 75% off.
This week’s highlights * 🚨 Amazon won’t be taking a holiday to China anytime soon. * 🚨 Google is tapping Linux users for new ideas. * 🚨 Azure is being annoyingly helpful to the healthcare industry.
Amazon Web Services: Ready For Battle * 🤷 AWS Certificate Manager is now compliant with FedRAMP, the Federal Risk and Authorization Management Program. What exactly makes up the compliance requirement? We’re not sure. * 🐼 Amazon Web Services launches appeal after losing $12-million AWS trademark war in China to local biz Actionsoft. You know who should be suing everyone? The American Welding Society, which has been around since the 1800s. * 😮 Amazon SQS announces tiered pricing for monthly API requests. Discounts are good but we’re surprised they’re using tiered pricing. * 😩 Amazon Elastic Container Service launches new management console. We want to like this but it sort of just aggravates us.
Google Cloud Platform: Bowing to Demands * 👏🏽 Google announces a new tool to mimic the behavior of tail -f which displays the contents of a log file to the console in real time. Thank you Linux users for demanding this!
Azure: Opt-in * 📎 Introducing the Azure Health Bot, an evolution of Microsoft Healthcare Bot with new functionality. On the one hand, this is super helpful. On the other, it’s Clippy (the annoying paper clip assistant) and dear God, go away! * 🕵🏽♂️ Microsoft promises 99.99% uptime for Azure Active Directory from April 1. Reading between the lines, could there be a replacement for Active Directory coming for the cloud? * 👍 Azure Application Change An
Note: This interview is part of a paid sponsorship between Open Raven and The Cloud Pod.
In this TCP Talks episode, Justin Brodley and Jonathan Baker talk with Mark Curphey, Chief Product Office and Co-Founder of Open Raven, a fully integrated platform for security and privacy workflows. Featured Guest
Name: Mark Curphey
What he does: Mark is Chief Product Officer and Co-Founder of Open Raven.
Where to find him: LinkedIn | Twitter
Listen to Mark discuss the Open Raven strategy for protecting your data, the use of serverless workflows to scale to enormous workloads. Protecting your data and ensuring compliance using the Open Policy Agent – and more. Key Points Discover – Classify – Monitor – Protect “The cloud has moved in incredibly fast; security has been moved off to the side and as a result companies don’t know where their data is, breaches are happening constantly, and these are the big things that get companies in the press.” Macie “Every single customer that we spoke to in the early stages said, a) It doesn't work b) It's ridiculously expensive, and c) It's only on s3 buckets. Well, whilst The Register is always reporting breaches of S3 buckets, my customer data is in RDS! That's a real piece of the problem for me; sure, it's popular, but I shouldn't just be thinking about trying to protect myself from getting on The Register.”
Part of the challenge is that data is not one thing... I may have a name, I may have an address, I may have a card number. There are all sorts of different parameters, and the data could be stored in multiple ways. So you have the concept of like data adjacency; If I have a CCV number, and expiry date and name associated to it that might be something which is real.
With Macie, even if you just use the straight matching techniques, you don't have control over the adjacency thing, so that's why a lot of the basic trivial cases get completely missed. Security at the edge? "If you are protecting data in the cloud, you have to wire the tools into the cloud to understand which IAM has access, which routes, which security groups can give you access? That’s the only way to understand the context to protect it. You can't do it in some sort of edge device." Getting started with Open Raven Visit openraven.com to get a 15 day trial. Spin up a SaaS instance and go play.
“We already think we're a better choice than Macie, but don't think that's the end goal. Come partner with us, work with us on the end goal, because those are things that we love; solving massive, complex, and interesting problems.”
https://www.openraven.com/thecloudpod
On The Cloud Pod this week, the team looks back on the incredibly weird year that was 2020 and how all we want is to give each other a hug (but we don’t because social distancing is important).
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Open Raven, the cloud-native data protection platform that automates policy monitoring and enforcement. Auto-discover, classify, monitor and protect your sensitive data.
This week’s highlights * 🚨 Amazon hurts Google’s feelings with its harshly worded message. * 🚨 Google is tapping into its inner dictator by vying for world domination. * 🚨 Azure wants you to know it made something cheaper.
Recapping the Shit Year That Was 2020 The Predictions That Were Made for 2020 * Justin: Amazon and Microsoft will work hard to compete with GKE. * Peter: Kubernetes workloads will double in the next year. * Jonathan: Amazon will open data centers across growing African economies, RISC-V based RISC instances will release (and Slack will be acquired this year for sure). * No One: A global pandemic and Ryan would join the podcast (coincidence?).
Favorite Announcements of 2020 Ryan: * AWS Serverless host and run applications, bringing it closer to what developers need. Tooling, savings plan * Covid-19 response, from each vendor, from public data lakes, responding to capacity needs, database of research and overall support of WFH * A big shift for Container Ecosystems, Split from enterprise/developer, Docker.com on downward trend, download limits
Peter: * Google’s creation of the Open Usage Commons for trademarks * Amazon Braket * WFH trend — which may be permanent
Jonathan: * Solarwinds Hack, and the risk of a supply chain hack occurs * Confidential Computing and the enclave needs.
In its final week, re:Invent continues to deliver a slew of announcements, which are captured on The Cloud Pod this week. It came and went quickly for the team unlike Google Cloud Next, which seemed to go on forever.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Open Raven, the cloud native data protection platform that automates policy monitoring and enforcement. Auto discover, classify, monitor and protect your sensitive data.
This week’s highlights * 🚨 Amazon and Microsoft are acting like children that need to be separated. * 🚨 Infrastructure nerds are rejoicing at re:Invent. * 🚨 You can spend while you sleep with Google.
General News: Everyone's Favorite Topic * 🍑 A heavily redacted version of AWS's latest protest against Microsoft and the JEDI contract has been unsealed. Trump made them do it. * 🤗 U.S. Treasury and Commerce Department communications were reportedly compromised by a supply chain attack on security vendor SolarWinds. Go hug a security team this week.
Amazon Web Services: The Presents Keep On Coming re:Invent Continued * 🏆 AWS launches the VPC Reachability Analyzer to measure reachability between two endpoints without sending any packets. Anything that makes life easier is a win. * 🤓 The re:Invent infrastructure keynote lacked announcements but gives insight into how AWS thinks about data centers. Old school infrastructure nerds, take note of this one. * 🤩 AWS announces the general availability of Amazon EMR on Elastic Kubernetes Service. EMR fans will be super happy about this. * 😲 AWS has released an Infrastructure Code Template generator to make it easy to start using Spot Instances. You can go straight to production now, no testing! Just kidding… Please test. * 👍 Amazon EBS reduces the minimum volume size of Throughput Optimized HDD and Cold HDD Volumes by 75%. This is kind of nice! * 👻 Amazon EC2 announces new network performance metrics for EC2 instances. Troubleshooting these is a nightmare, so this will be great. * 👼 AWS has expanded the capability of the AWS transit Gateway for SD wan with the new AWS Transit Gateway Connect. Thank you, Jesus!! * 😃 Amazon EMR Studio makes it e
This week on The Cloud Pod, the team admits defeat and acknowledges they are not experts in machine learning. Joining them in that club is the rest of us.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Open Raven, the cloud native data protection platform that automates policy monitoring and enforcement. Auto discover, classify, monitor and protect your sensitive data.
This week’s highlights * 🚨 Amazon is helpfully pointing out all your mistakes. * 🚨 Google knows you have deep pockets and wants a piece. * 🚨 Microsoft is really bad at keeping secrets.
General News: Jonathan Called It * 💀 Salesforce has acquired Slack for $27.7 billion. We’re hoping Chatter will die a horrible death now.
Amazon Web Services: Error 404 😔 Amazon explains the Thanksgiving Kinesis outage that occurred in North East Virginia. We feel bad for the Ops team that had to support this. re:Invent Continued * 💪 Amazon adds stronger Read-After-Write consistency to S3. A really fantastic technical feat. * 👍 Amazon announces S3 Replication support for multiple destination buckets. Nice and simple! * 🤩 Amazon S3 Replication now has the ability to replicate data from one source bucket to multiple destination buckets. Super excited about this! * 😲 Integrate Amazon Honeycode with popular SaaS applications, AWS services and more. It’s finally usable now. * 🌳 Amazon announces new AWS Region is in the works for Melbourne, Australia. It will also use 100% renewable energy, which is cool. * 🤪 Fully serverless batch computing with AWS Batch Support for AWS Fargate. Batch is a weird service to begin with. * 😕 Amazon debuts Trainium, a custom chip for machine learning training in the cloud. We’re confused by this one. * 🏥 Amazon HealthLake stores, transforms and analyzes Health Data in the Cloud. Machine learning, while confusing, is great for the healthcare industry. * 🥶 Amazon launches Lookout for Metrics, an anomaly detection service for
Santa arrived early and he brought all the goods with him to The Cloud Pod this week. The team dives into all the big announcements from AWS re:invent 2020.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon flips the bird at Microsoft with its Babelfish announcement. * 🚨 AWS is angling for a free Jeep Wrangler with its new service. * 🚨 AWS is helping customers get out of the sticky situation they’re in and don’t know it.
Amazon Web Services: Thankfully They Didn’t Ruin Our Predictions * 🌊 Amazon launches managed workflows for Apache Airflow to simplify data processing pipelines. Interesting to see it giving some alternative options. * 🦃 AWS Lambda now has Code Signing, a trust and integrity control to confirm code is unaltered and from a trusted publisher. Not a nice way to start Thanksgiving if you are Palo Alto. * 🆗 Amazon announces centralized account access management of AWS Single Sign-On and Attribute-based access control. Has a few rough edges. * 🤗 Multi-Region Replication is now enabled for AWS Managed Microsoft Active Directory. We’re so glad this is finally here. * ♻️ Amazon announces reusable building blocks called modules to define infrastructure and applications in AWS CloudFormation. Amazon is jumping on the reusable elements bandwagon with this one. * 👮 AWS Security Hub integrates with AWS Organizations for simplified security posture management. Basically a centralized security hub.
AWS Elasticsearch Announcements: * Amazon Elasticsearch Service announces support for Elasticsearch version 7.9 * Amazon Elasticsearch Service now supports anomaly detection for high cardinality datasets * Amazon Elasticsearch Service introduces Piped Processing Language (PPL) * Amazon Elasticsearch Service announces support for Remote Reindex
This week on The Cloud Pod, the team used their slightly cloudy crystal balls to share their predictions for Re:Invent 2020. They hope Amazon doesn’t ruin them before the event.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon spoils the prediction party by revealing a new product just before Re:Invent. * 🚨 Google is making sandcastles by itself in the sandbox. * 🚨 Azure is smart enough not to announce anything exciting right before Amazon’s big day.
Amazon Web Services: Crushing Hopes and Dreams * 💡 Amazon Lightsail lets developers easily deploy containers in the cloud. This is like the cloud version of candy-flavored tobacco — somebody out there will be excited. * 📸 Amazon announces visual data preparation tool AWS Glue DataBrew. Really cool — we wish they’d created this sooner! * 👏 AWS Key Management Service now supports three new hybrid post-quantum key exchange algorithms. We’re just happy that the defense is ahead of the offense this time. * 😡 Amazon launches AWS Network Firewall, a highly available, managed network firewall service for VPC. Peter is angry that Amazon killed one of his Re:Invent predictions. * 👓 Introducing Amazon S3 Storage Lens for organization-wide visibility into object storage. We think the dashboard is built on years of customer complaints, not experience.
Re:Invent Predictions Prediction rule: If it’s already been officially announced by Amazon, then it doesn’t count. It needs to be in the rumor mill and somewhat specific. * Peter + Integration between Sumerian and Chime/Slack (messaging service) for virtual in-person meetings + Major upgrade to CloudWatch/Logs/GuardDuty/CloudWatch Events (SIEM) but an actual SIEM product. Will have its own name or does something to GuardDuty + Robot SDK for tight integrations into AWS Cloud * Jonathan + Serverless graph database + Live migration for some instance types between EC2 hosts so maintenance events don’t cause the same level of damage + Detailed discussion of their use of IOT and AWS services for COVID
This week on The Cloud Pod, the team is getting ready to share their predictions for re:Invent, and that may or may not involve greasing the palms of some Amazon employees.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon is becoming a connoisseur of international cuisine with its new region. * 🚨 Google is borderline nefarious in the scientific community. * 🚨 Azure adds a long overdue feature.
Amazon Web Services: Spicing Things Up * 🍛 AWS announces the new Hyderabad region in India will open in mid-2022. We’re surprised at how long this took to happen. * 🕒 AWS launches managed messaging service Amazon MQ for Rabbit MQ. Only took three years of Justin whinging. * 🤷 Amazon now allows customers to proactively manage the EC2 Spot instance lifecycle using the new capacity rebalancing feature. Not sure this needed a whole blog about it. * 👌 AWS announces AWS Gateway Load Balancing for easy deployment, scalability and high availability for Partner Appliances in the cloud. Thanks for helping us out, Amazon! * 🖌️ AWS makes it easier to export DynamoDB table data to S3 with no code writing required. At lots less Lamda spackle, we like it. * 🛁 AWS announces a full set of features across the storage family as part of AWS Storage Day 2020. Buckets, buckets and more buckets.
Google Cloud Platform: Doing What It Does Best * 🤡 Google Cloud SQL now supports Postgres 13. Next up, Google announces deprecation of Postgres 13… Just kidding. * 💖 GCP launches a unified console for document processing with Document AI platform. For anyone who hates data entry, you’ll love this! * 😲 Google is launching a public preview of a suite of fully managed AI tools designed to solve medical challenges. Google has been accused of us
While waiting on tenterhooks to find out who will win the U.S. presidential race, the team welcomed guest Jacques Chester to The Cloud Pod this week.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
Cloud Academy, which provides an intuitive and scalable training platform to meet teams wherever they are along the cloud maturity curve. Use the code THECLOUDPOD for 50% off its training platform.
Manning Press is offering a 40% discount on any Manning Publication, and we highly recommend Knative in Action by guest Jacques Chester. Use the code PODCLOUD20 to receive 40% off; additionally, the first five people who retweet this episode from the official @thecloudpod1 twitter account will get a free copy.
This week’s highlights * 🚨 AWS will be enjoying fondue in Switzerland. * 🚨 Google is clearing out the old junk in the attic. * 🚨 Dr. Microsoft is now taking appointments.
General News: Money, Money, Money * 🙄 Microsoft has reported its earnings for the first fiscal quarter of 2021. Microsoft is over 2020 already. * ☠️ Google’s parent company Alphabet crushed expectations for both earnings and revenue in its third-quarter earnings results. This could be a good sign it’s not planning on killing Google Cloud just yet. * 💪 Amazon reports $96.1 billion in Q3 2020 revenue. Overall a pretty strong quarter!
Amazon Web Services: Spend Or Save? * 🔐 Amazon launches AWS Nitro Enclaves to carve out isolated environments on any EC2 instance that is powered by the Nitro System. A great increase in security for no additional cost. * 🎉 Customers can now use Jira Service Desk to track operational items related to AWS resources. This is great for the start-ups and smaller organizations that are using Jira! * 🤗 Amazon announces new Application Load Balancer Support to make it easier to use gRPC with your applications. Another great feature! * 🤤 New AWS Europe region will allow customers to run their applications and serve end-users from data centers located in Switzerland. Happy for Europe but can we get more in the U.S.? * 🤢 AWS delivers up to 2.5x the deep learning performance with new GPU-Equippe
On The Cloud Pod this week, the team discusses the conspiracy theory surrounding media coverage of daylight savings and continues counting down to re:Invent.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon sells a whole bunch of stuff on its website. * 🚨 Google is nosy and wants people to know what files you’ve been looking at. * 🚨 Azure wants people to think more with its new knowledge center.
Amazon Web Services: Getting Excited for re:Invent * ⛰️ Jeff Barr shares how AWS helped to make Prime Day a reality for its customers. Congratulations to the Amazon Ops and Dev teams for this amazing feat. * 🎀 AWS Global Accelerator announces the ability to override destination ports used to route traffic to an application endpoint. Pretty neat! * 🏗️ AWS is launching AWS Distro for Open Telemetry in preview. We’re excited to see what this builds out to become. * 🤪 AWS launches fully managed publishing/subscribing messaging service enabling message delivery to a large number of subscribers. This is great and we already have use cases for this. * 🏆 Amazon introduces the AWS Load Balancer Controller to simplify operations and save costs — a huge win for anyone using EKS today. * 🤷 AWS CloudFormation now supports increased limits on five service quotas. Sounds good unless you’re trying to make smaller CloudFormation templates.
Google Cloud Platform: A Bit Confused * 🥔 GCP is introducing new Scale-in controls for Compute Engine, to prevent the autoscaler from reducing a managed instance group size too far. We’re a bit confused by the term “Scale-in.” * 🔍 GCP improves security and governance in PostgreSQL with Cloud SQL. Great for companies that are highly audited. * 😺 Google updates Firebase with new emulator and data analysis tools. Really great stuff!
Azure: Busy Building Services It Promised For JEDI * 🥳 Microsoft announces multiple
In this TCP Talks episode, Justin Brodley and Jonathan Baker talk with Forrest Brazeal, a Senior Manager at A Cloud Guru, a cloud education platform that has attracted more than two million students. A Cloud Guru offers full certification training and technical deep dives for Amazon Web Services, Microsoft Azure, Google Cloud Platform, and more.
Forrest talks about why companies need to invest in training to reap the benefits of “cloud fluency,” and how A Cloud Guru is contributing to cloud adoption success at Fortune 500 companies.
While discussing knowledge gaps, Forrest highlights how important it is to clearly identify which cloud services and knowledge areas you’re going to become certified in to avoid missing important high level areas.
“Going through the certification training and prep really helps you to avoid those blind spots that will keep you from speaking effectively to the other teams that you work with,” says Forrest. Featured Guest * 👉 Name: Forrest Brazeal * 👉 What he does: Forrest is a Senior Manager at cloud learning platform A Cloud Guru. * 👉 Key quote: “When I look at people who are going from the data center to the cloud today, they are thinking about the cloud as something that's going to take undifferentiated heavy lifting away from them.” * 👉 Where to find him: LinkedIn l Twitter | Personal Website
Key Takeaways * 🚨 Be strategic with your cloud certifications. If you’re trying to reach a certain number of certifications, make sure you have a plan or you might end up with gaps in your knowledge. “It’s so easy to do, right?” Forrest says, “as I'm sitting on one team, and I'm touching one technology all the time, I could go two, three, four years and never know anything about networking because all I'm doing is databases, right? Or never know anything about compute, because all I'm doing is storage. Going through the certification training prep really helps you to avoid those blind spots that will keep you from speaking effectively to the other teams that you work with.” * 🚨 College grads beware: Just because you have a Computer Science degree doesn't mean you'll just be writing algorithms all day. If you’re looking at a career in programming, the day to day job includes negotiating with people and figuring out what requirements of the business are - not just writing algorithms. Forrest says “it's figuring out requirements, and it's writing the same line of code and then deleting it because it turns out the business requirement changed.” * 🚨 Scaling to zero, where a function can be reduced down to zero replicas when idle and brought back to the required amount of replicas when needed, is one example of how the underlying principles adopted by the serverless community that might have been considered “radical” five or six years ago is now seen as welcome wisdom in the broader cloud community. The term, “serverless,” might be retired eventually, but the fundamental principles will remain and evolve into “cloud native.”
Here's what was mentioned in the episode 👉 * ✔️ Microsoft Azure: Cloud Computing Services * ✔️ AWS: Amazon Web Services * ✔️ Google Cloud Platform: Cloud Computing Services * ✔️ AWS Serverless Hero: Forrest is an AWS Serverless Hero * ✔️ AWS Certified DevOps Engineer - Prof
On The Cloud Pod this week, the team acknowledges the very real issue of canine confusion as a result of everyone wearing face masks.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon is in the Halloween spirit with its tricky new feature. * 🚨 Google is solving a potentially nonexistent problem for retailers. * 🚨 Microsoft is sending Azure into spaaaaaaaaaaace to power satellite projects.
General News: All About Hash(iconf) * 🤔 HashiCorp Consul is now available in public beta while Vault is available in private beta. We’re hesitant to trust anything from HashiCorp. * 💔 Terraform 0.14 is now available in beta and includes feature improvements in security, visibility and stability. Justin looks forward to the upgrade that breaks everything later this year. * ❄️ HashiCorp Consul 1.9 introduces new service mesh visualization tools. Pretty minor but cool! * 😄 HashiCorp launches Boundary for simple and secure remote access based on trusted identity. We see huge potential in this. * 🗡️ HashiCorp launches Waypoint, a new open source project that provides developers a consistent workflow. These types of announcements are a dagger through Ryan’s heart. * 📦 HashiCorp introduces Consul Terraform Sync, a new tool for automating network infrastructure. Really powerful but really packed in a way we don’t understand.
Amazon Web Services: Handy * 👍 Amazon launches Cloudwatch Synthetics Recorder, a Chrome browser extension, to help monitor endpoints and APIs. We hope this does better than others we’ve tried in the past. * 🗿 Amazon announces better cost-performance for Amazon Relational Database Service databases. Has some rough edges but once you overcome them, this is rock solid. * 🤗 Amazon Aurora now enables dynamic resizing for database storage space. Nice that you’ll now only pay for the storage you actually use! * 🙏 Amazon announces AWS Budgets Actions to reduc
On The Cloud Pod this week, Peter turns into an old man in his yard, yelling at cloud providers.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 The big cloud providers must not tell lies about their cloud customers. * 🚨 Google keeps us guessing if features will survive after the Preview. * 🚨 Microsoft launches the world’s smallest Machine Learning degree.
General News: An Expensive Gimmick * 🤡 Microsoft, AWS and others boast of exclusive cloud customers that aren’t actually exclusive to them. At the end of the day, being “all in” is a gimmick. * 💰 Palo Alto Networks, Inc. announced it’s adding four new cloud security modules to Prisma Cloud. All for the low, low price of a lot of money. * ❓ Red Hat, Inc. ties Ansible automation to Kubernetes cluster management to improve automation in cloud-native infrastructure. The only thing that’s going to make Kubernetes easier to manage is a whole bunch of Ansible catalogues and code that you don’t understand. * 😡 Spinnaker-as-a-service startup Armory raises $40M in new funding. This makes us all cranky — these giant one-stop solutions are not the answer.
Amazon Web Services: Strangely Quiet * 💚 Amazon EventBridge now supports Dead Letter Queues, making event-driven applications more resilient. We love this! * 🏇 Amazon EKS now officially supports Kubernetes version 1.18. We’re taking bets on when version 1.19 comes out.
Google Cloud Platform: Apply Sunscreen * 🧯 Google announces that all new GCP products will launch in Preview or General Availability. Tread carefully here — we’ve been burned by previews before where features don’t make it into General Availability. * 😕 Google launches support across Google Cloud for buildpacks to easily create container images. Don’t be fooled: Problems you had with Docker files
On The Cloud Pod this week, Ryan is shocked the rest of the team managed so well without him while he was on vacation.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Progress is tapping its inner Freddy Kruger after acquiring Chef. * 🚨 AWS is soothing the burns of many with its Compute Optimizer. * 🚨 Google is behind the eight ball with the launch of its healthcare API.
General News: On The Chopping Block * 💔 IBM is splitting itself into two public companies to focus on high-margin cloud computing. We’re not sure about this strategy so we’ll keep an eye on this one. * 😃 Google will give up direct control of the Knative cloud open-source project. We’re glad to see this is getting closer to a resolution. * 👩🍳 Business application platform Progress is making job cuts at recently acquired enterprise automation technology company Chef. The cuts included part of the Chef engineering team — when you’re buying a product company, that doesn’t seem like a good play.
Amazon Web Services: In Happier News * 👍 Amazon S3 on Outposts expands object storage to on-premises environments. If only this had existed a year ago! * 🥳 AWS Systems Manager now enables developers to view, author and publish Automation runbooks directly from Visual Studio Code. We like this! * 🥂 Amazon launches several new features with Redis 6 compatibility to Amazon ElastiCache for Redis. These enhancements are making it well on its way to being useful on a big project. * 💲 Amazon SageMaker leads the way in machine learning and announces up to 18% lower prices on GPU instances. That’s a huge price cut that we think is great! * 🚔 Three new security and access control features are now available in the Amazon S3 update. This is a big improvement for customer experience. * 🤓 AWS launches a new Identity and Access Management (IAM)
Your hosts have an action-packed episode in store for you on The Cloud Pod this week, and Ryan is back after surviving the wild Oregon forest.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon is helping you figure out where your money is going. * 🚨 Google isn’t wowing anyone with its AI Platform Prediction improved reliability. * 🚨 Azure has some underwhelming improvements you should read about.
General News: This Is What Happens When You Go On Vacation * 🛍️ VMware, Inc. is acquiring SaltStack, Inc. to enhance its vRealize cloud management software suite. It’s interesting that this comes only a few weeks after Chef was acquired.
Amazon Web Services: Always Comes Through For Us * 😲 AWS launches Glue Studio, which provides a simple visual interface to compose jobs that move and transform data and run them on AWS Glue. Surprised it wasn’t just an integration with Visual Studio Code. * 🤗 AWS Backup now supports application-consistent backups of Microsoft workloads. This is not the cloud way to do it. * 🔐 AWS Security Hub has released 14 new automated security controls for the AWS Foundational Security Best Practices standard. Typical Amazon — gives you a control that costs you more money. * ⚠️ Preview the Anomaly Detection and alerting now available in AWS Cost Management. It’s great to have these features for those weird quirky things that can happen when you’re spending money. * 😺 Usability improvements for AWS Management Console are now available. Some of us are super grumpy with this and others super happy, so up to you to decide! * 🙊 AWS backtracks on plans to block old-style S3 paths. You now have some unknown time period plus a year to sort this out. You’re welcome?
Google Cloud Platform: The Detectives On The Case * 🎈 Cloud Run for Anthos now includes an events feature allowing customers to easily build event-driven systems o
On The Cloud Pod this week, your hosts eagerly await next week's Google product announcements so they can update their old phones.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * When the girls get coding!. Join us on your screens, Oct 13, for the live@Manning “Women in Tech” conference to celebrate the rising movement of women in technology. http://mng.bz/MolW
This week’s highlights * 🚨 Amazon is helping stop the insanity with patching. * 🚨 Google is tired after its event but has still managed to give us new tools. * 🚨 Microsoft’s new data center is an igloo in the desert.
Amazon Web Services: Do the Work For Us * 🦝 Amazon API Gateway enhances the security of APIs to protect data from client spoofing and man-in-the-middle attacks with mutual TLS support. Twice as nice and great for the financial industry! * 🕵️♀️ Amazon Detective now analyzes IAM role sessions to assist security analysts in diagnosing issues and understanding their root cause. The Detective is on the case! * 🦥 Amazon CloudWatch Agent is now Open Source and included with Amazon Linux 2. Not really a fan of doing a multi-billion dollar company’s job... * 🧩 AWS Security Hub now supports viewing patch compliance findings across AWS accounts. Now the question is, do people shadow patch so no one knows they’re out of date? * 🏛️ AWS Perspective is a new AWS Solutions Implementation that helps customers build detailed architecture diagrams of workloads. Be wary of how much this will cost to run. * 🌊 Three new AWS Wavelength Zones on Verizon’s 5G Ultra Wideband network are now available in Atlanta, New York City and Washington, D.C. With COVID shutting everything down and more things going online, this tech could be amazing.
Google Cloud Platform: Blue Screen Of Death * ⚰️ Google Cloud makes it easier to manage Windows Server VMs. Nice — it’s a tool that gives you a p
On The Cloud Pod this week, your hosts just want to be wowed and Ryan is off motorcycling somewhere in the desert.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * When the girls get coding!. Join us on your screens, Oct 13, for the live@Manning “Women in Tech” conference to celebrate the rising movement of women in technology. http://mng.bz/MolW
This week’s highlights * 🚨 Fighting words from Amazon over JEDI loss. * 🚨 Microsoft has gone to crazy town with their AWS connector pricing. * 🚨 Oracle taps their inner millennial to win the Tik Tok U.S bid.
General: A Bit Picky * 💰 Business App Platform Progress will acquire automation technology company Chef for $220 million. That’s a bargain price when you look at their recurring revenue. * 🥇 Pentagon reaffirms Microsoft as winner of $10B JEDI cloud contract. Nobody says the government is the most efficient at doing anything so picking the second best cloud vendor is unsurprising. * ⚔️ AWS has responded to the Pentagon reaffirmation of Azure with a harshly worded blog post. Well, life’s just not fair. * 🥳 Foghorn Consulting (sponsor alert!) are teaming up with Hashicorp and sponsoring a virtual Q&A with Kelsey Hightower on September 24. Head to The Cloud Pod Slack page after to discuss!
Amazon Web Services: You’ll Need Some Pain Relief * ☁️ AWS named Cloud Leader in Gartner’s Infrastructure & Platform Services Magic Quadrant. Gartner, are you listening to The Cloud Pod? * 👍 Amazon CloudFront now supports Transport Layer Security v1.3 for improved performance and security. Good move for privacy, but will cause a lot of pain. * 👓 Amazon CloudWatch now monitors Prometheus metrics to reduce monitoring tools needed for application performance degradation and failures. Might be worth the money — we’ll see. * 🛒 Bezos’s likely Amazon successor is an executive made in Bezos’s image. Considering the source, are they floating this idea to see how people react? * 🚀 AWS turns its
On The Cloud Pod this week, your hosts introduce the idea of plaques to commemorate a feature suggestion becoming a product.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * When the girls get coding!. Join us on your screens, Oct 13, for the live@Manning “Women in Tech” conference to celebrate the rising movement of women in technology. http://mng.bz/MolW
This week’s highlights * 🚨 Active Directory just will not die. * 🚨 Someone is excited about Google’s Data Fusion pipelines. We just don’t know them. * 🚨 Azure gets features that AWS and Google already have.
General: Did You Do Your Homework? * 💀 Former Google engineer Steve Yegge resurrects his blog to explain why Google’s deprecation policy is killing user adoption. We’re still bitter about Google Reader. * 🎈 The Cloud Pod is sponsoring the Rust Conference and Women in Tech conference. We’re super excited about both of these conferences and supporting more women in the technical world.
Amazon Web Services: So confused * 🎮 AWS launches second Local Zone in Los Angeles for customers requiring very low latency. This caused massive confusion when they launched the first one as they already had a localized region concept they forgot about. * ⚰️ Connect to AWS Directory Service for Microsoft Active Directory seamlessly with new AWS Linux feature. No one has jumped on board with killing Active Directory yet. Someday we’ll get there. * 😕 AWS now lets you log all Domain Name System queries to understand how your applications are operating. We don’t really know why you would want this (except maybe Jonathan). * 🤗 AWS launches Bottlerocket to improve security and operations of containerized infrastructure. Really a joy to set up and makes you feel really secure, without needing a therapist. * 🏆 AWS Site-to-Site now supports Internet Key Exchange that allows customers to connect to other cloud providers. Like Superman in disguise, there’s more to this under the surface. * 👍🏽 Publish and deliver messages with
Note: This interview is part of a paid sponsorship between Protera and The Cloud Pod.
In this TCP Talks episode, Justin Brodley and Jonathan Baker talk with Patrick Osterhaus, CTO and Founder of Protera Technologies, a preeminent provider for SAP and cloud managed services.
Patrick discusses how the cloud, COVID-19, and work-from-home are influencing SAP and legacy enterprise software packages today, and Protera’s goal to provide the very best SAP services available on the cloud.
Covering issues around migration to SAP, Patrick takes the opportunity to reflect on Protera’s history, while also addressing corporate IT integration. “We call this the transformation journey-site assessment, specific to each client’s needs, looking beyond SAP to the SAP systems, we use a tool we call [Protera] FlexBridgeSM,” notes Patrick.
Featured Guest Name: Patrick Osterhaus
What he does: Patrick is CTO and Founder of Protera Technologies.
Key quote: “The complexity of moving to public cloud is getting those non-cloud native applications into the cloud, and then looking at the transformation of those applications once they're in the cloud.”
Where to find him: LinkedIn | Twitter Key Takeaways The best way to prepare for cloud migration is what Patrick calls “the journey,” which involves a site assessment of the customer environment and understanding how everything on-premise, or in a hybrid environment, is working together.
COVID-19 has accelerated migration to the cloud and has forced companies to plan their disaster recovery systems. Patrick says businesses aren’t just thinking about their earpiece systems — the thinking extends to ancillary systems like CRMs and web access systems — “all these systems to be connected and have it fully available in the cloud as a backup.” He adds, “We've seen a natural interest in what is good practice,” which is to have a protection plan for critical SAP applications.
Working with many compliance-heavy industries, such as financial or military and defense clients, Protera stresses has learned the importance of not only application security, but also the physical security necessary around data centers. He says the discussing the real-world protection of data centers — “who owns the data, how it’s governed, how it’s protected” — is important to raise with the client. Resources Here's what was mentioned in the episode ✔️ SAP: Systems in Application Products and Data Processing
✔️ "What is DevOps?": An AWS blog post explaining the DevOps model
✔️ Microsoft Azure: Cloud Computing Services
✔️ Amazon Redshift: Cloud Computing Services
✔️ Google Cloud Platform: Cloud Computing Services
✔️ DR system: Multi-cloud disaster recovery system
✔️
Your hosts kick off this week’s episode of The Cloud Pod by discussing the elephant in the room… the great Google outage.
A big thanks to this week’s sponsors: * Commvault is data-management done differently. It allows you to translate your virtual workloads to a cloud provider automatically, greatly simplifying the move to the cloud or your disaster recovery solution to the cloud. * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon gives customers the opportunity to spend lots of money with them. * 🚨 Your hosts sit on the fence discussing Google’s new platform. * 🚨 Azure gets features everybody else already has.
General: The Great Google Outage * 🤷 Google explained how and why big chunks of its cloud crashed last week — turns out it broke itself. Google didn’t tell us who broke it because developers shouldn’t be publicly shamed... although they did break Google. That’s pretty bad.
Amazon Web Services: Dollar Bills * 👍 Amazon introduced the newest AWS Heroes who go above and beyond to share AWS knowledge and teach others. It’s great to see friend of the show, Ian McKay, recognized for his awesomeness. * 👮 AWS Firewall Manager now supports security groups on Application Load Balancers and Classic Load Balancers. Slowly but surely, it’s becoming the tool we’ve always wanted. * 🖇️ Amazon launches new API Gateway to manage business rules around how data is created, stored and changed in AWS services. We think this is a complete rewrite due to the fact they’re having to reimplement integrations. * 🏗️ AWS Controllers for Kubernetes is a new tool that makes it simple to build scalable and highly-available Kubernetes applications. We’re pretty impressed by the controller which centralizes your deployment. * 🕺 AWS releases the latest update to Provisioned Input/output Operations Per Second (IOPS) allowing users to dial in the level of performance that they need. Amazon now gives you the opportunity to give them more money. How nice!
Google Cloud Platform: To Be or Not To Be * 🔨 Google announces a number of improvements to log storage and management for Cloud Logging. We feel mixed emotions regarding these improvements. * 🚀 Google launches new Dataflow Flex template capable of publishing unlimited high-volume JSON messages to a Google Cloud Pub/Sub topic
Your hosts set right what once went wrong in this week’s quantum episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Commvault is data-management done differently. It allows you to translate your virtual workloads to a cloud provider automatically, greatly simplifying the move to the cloud or your disaster recovery solution to the cloud. * live@Manning: Sign up for RustConf and Manning's Women in Tech conferences here.
This week’s highlights * 🚨 Amazon and Rackspace may be growing closer soon. * 🚨 Your hosts may or may not know how quantum computing works. * 🚨 Google is now available for 35 more minutes out of the month.
General: High Stakes * 💰 Reuters reported that Amazon is looking to acquire a stake in cloud infrastructure and services company Rackspace Technology. It is unclear exactly how much of the company Amazon may buy.
AWS: A Discrete Quantity of Computers * ⚛️ You can now run Amazon Braket on real or simulated quantum chips. We’ll try to explain quantum computing to you if we ever understand it ourselves. * 🧏 AWS Step Functions has been updated to Amazon State Language. Alright, let’s learn this thing the hard way! * 🔒 AWS Security Hub Automated Response & Remediation is now generally available. It’s an old architecture, but cool to see formalized. * 🥉 The new Distributor capability of AWS Systems Manager installs and manages third party agents, and that’s pretty cool. * 🔘 AWS Fargate for Elastic Kubernetes Service and Elastic Container Service now supports Elastic File System. It’s the interface that really makes it work. * 🖥️ Amazon Elastic Container Service now supports EC2 Inf1 instances. * ✍️ Serverless icon Ben Ellerby wrote an article about SLS-Dev-Tools for Serverless on the AWS Open Source Blog. If you’re doing a lot of serverless work, we recommend giving this one a read. * 🆓 Application and Classic Load Balancers now support
It’s a new week, and that means you can be sure that Google Next is still going on… and of course, we’ve got a new episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Commvault is data-management done differently. It allows you to translate your virtual workloads to a cloud provider automatically, greatly simplifying the move to the cloud or your disaster recovery solution to the cloud. * live@Manning: Sign up for RustConf and Manning's Women in Tech conferences here.
This week’s highlights * 🚨 Foghorn has two new solutions we’d love for them to advertise with us. * 🚨 Azure advances the open-source front. * 🚨 Oracle wins the 4th place medal in the VMware race. What would a 4th place medal be — aluminum?!
JEDI: Wait and See * ⏱️ The Department of Defense has been granted an additional month to issue its remand decision. Neither Amazon nor Microsoft have objected to the delay.
COVID-19 * 💉 AWS is supplying Moderna with the computing as they work on their COVID-19 vaccine. Our deepest gratitude to the 30,000 human subjects in the phase 3 trials.
AWS: Brought to You by Foghorn * 📶 The AWS Wavelength 5G partnership is now available in Boston and San Francisco. Inevitably though cloud platforms, like the iphone, will need to break free from their provider-locks. * 📯 TCP sponsor Foghorn has developed VPC-In-A-Box℠ for Amazon VPC creation and management, and the Fog360 Security security analysis and visualization service. Send all your questions our way! * 🕸️ The new AWS App Mesh is a service mesh that features a new default mesh configuration. It’s an interesting concept for sure but it might not be for the best. * 💰 AWS Glue 2.0, now generally available, starts jobs ten times faster and has one tenth the minimum billing time. Apparently this is enough to make people like Glue!
Google: YouTube Tutorials * 📋 An International Data Group study<!--
-->
It’s an unexpectedly short and sweet conference week on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Commvault is data-management done differently. It allows you to translate your virtual workloads to a cloud provider automatically, greatly simplifying the move to the cloud or your disaster recovery solution to the cloud.
This week’s highlights * 🚨 Alphabet and AWS release their first all-pandemic quarterlies. * 🚨 Google leverages their machine learning horsepower. * 🚨 You can get your kicks on our Route 53 console rant after the lightning round.
General: Growth Mindsets * 🔻 For the first time in its 16 years as a public company, Alphabet’s quarterly sales have dropped. This is of course due to pandemic-related macroeconomic effects. It will be interesting to see if the ad revenue business model is changed long-term. * 🔺 Despite being less than anytime in the last two years, Amazon reported AWS revenue up 29%. The retail end of Amazon is faring even better, with sales up 43% in North America.
COVID-19 * 🤝 Google Cloud AI and Harvard Global Health Institute have partnered to create the COVID-19 Public Forecasts model. You can query the forecasts for free in BigQuery or download as CSV.
AWS: Accepting Applications * 💲 Anomaly and threat detection for Amazon Simple Storage Service is coming to Amazon GuardDuty at an 80% discount. You can get a 30 day free trial of the improved and affordable service even on accounts already enabling GuardDuty. * 📥 The new AWS Community Builders Program is now open for anyone (to apply to). If you’re as interested as we are, be sure to sign up before September 15. * 💾 Amazon Simple Storage Service resources can be found in AWS Toolkits for Visual Studio Code using AWS explorer view. Tools like this that make things easier on developers are a good investment for AWS. * 📋 AWS CodeBuild now supports Test Reporting for code coverage. This will go a long way to help CodeBuild catch up to some of the more mature options on the market. * 🔒 AWS Security Hub has released
In this TCP Talks episode, Justin Brodley and Jonathan Baker talk with Bart Castle, an AWS and cloud computing trainer and media personality. Bart works with IT training company CBT Nuggets and also does cloud-migration consulting projects.
Bart shares the patterns he seems based on training demand and also advises how to decide which certification to go for next. He discusses the importance of solving business problems that will help achieve the business’ goals while retooling and transforming systems.
"At this point in my career, every technical conversation that I have is always paired up with a business value conversation," he notes.
But how should a data team shift focus to better solve business problems? He suggests looking for patterns. Uncovering patterns can help determine actionable steps to maximize efficiency and enable new business opportunities.
Bart also discusses cloud computing trends, CloudFormation stacking, hybrid deployments, and containers. Featured Guest * 👉 Name: Bart Castle * 👉 What he does: Bart is a cloud computing and AWS expert and technical trainer, as well as a consultant. * 👉 Key quote: “In the end, we're still looking for those tools that will bridge gaps. This is why, for me, being an integrations professional and getting what integration means is skill number one across all different arenas. Everywhere you look, it's an integration problem.” * 👉 Where to find him: LinkedIn | Twitter | YouTube
Key Takeaways * 🚨 When thinking about all the different training options, Bart suggests pursuing the certification that would help you land a specific job or role. If you're not sure what your next job might be, look at SysOps administration first since it is closest to traditional network help desk operations support roles. * 🚨 Based on his training background, Bart sees a rising interest in network automation. Many teams are working with various vendors to address networking and connectivity and to make the transition from command line administration to Python automation.
“A lot of what I'm seeing here is the switch from real deep specialty to real broad generalization, and that can be an overwhelming bite to take when you look at how much information there is to consume,” says Bart. * 🚨 Learning how the tools work is the easy part, but you have to dig deeper to make it work for your specific business use case. Bart recommends looking for white papers, as well as case studies and blog posts. Communities (like TCP!) can also point you in the right direction.
Bart says, “Once you get those examples of how a piece of input data with the right transformation with this pairing of reporting can solve this problem — now, you're putting tools in your belt that are going beyond just using the tools, and how to actually solve business problems with them.” Here's what was mentioned in the episode 👉 ✔️ CBT Nuggets: provides in-demand training, primarily in IT, project management, and office productivity topics.
✔️ Amazon Simple Storage Service (S3): a cloud object storage service.
✔️ "What is DevOps?": an AWS blog explaining the DevOps model.
✔️ "Infrastructure as Code" (IaC): a Microsoft blog describing the IaC managing model.
✔️ Amazon Redshift: a data warehouse that can query data into an AWS S3 data lake.
✔️
Ian Mckay fills in for Jonathan on this week’s double-stuffed episode of The Cloud Pod.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Commvault is data-management done differently. It allows you to translate your virtual workloads to a cloud provider automatically, greatly simplifying the move to the cloud or your disaster recovery solution to the cloud.
This week’s highlights * 🚨 A string of attacks deletes, but does not leak, unsecured databases. * 🚨 Cloudfare’s Matthew Prince plans to be the next top dog of data. * 🚨 Following the eight weeks of Next’ 20 we’ll get three weeks of Re:Invent.
General: Cat Got Your Data? * 💹 It’s earnings season and revenues are up for Azure, but for whatever reason Azure isn’t happy with it. * 🌊 Aqua Security announced Aqua Wave and Aqua Enterprise. Check out our interview with Liz Rice for more. * 😼 The rash of automated “Meow” attacks has deleted at least 3,800 databases. The deleted text is replaced with random text and the word “Meow”, hence the name. And deleting unsecured databases does keep it from being leaked... * 🥇 Matthew Prince of Cloudflare believes their new Workers Unbound platform will beat the big three providers on performance and price. Good luck making money on those margins.
AWS: Remote Viewing * 📅 It’s official: Re:Invent will be all digital this year. Not only that, but it will run for three weeks starting November 30. * 🗺️ AWS’s 77th availability zone will also be their fourth in the Seoul Region. * 📹 The new Amazon Interactive Video Service allows you to integrate live video to your apps and websites. Doesn’t seem like there’s much difference from MediaLive. * 🆕 The Cloud Development Kit (CDK) for Terraform and the CDK Pipelines construct library for AWS CDK are now in preview. * ☎️ The new Contact Lens AI features will help optimize contact centers using Amazon Connect. Connect is really taking the contact center world by storm with its ease of adoption. * 💾 Amazon now offers “d” variants to all three
The Cloud Pod Confidential — Episode 79
Your hosts kick off the nine weeks of Google Next on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsor:
This week’s highlights * 🚨 We kicked off this year’s Google Next by crowning our draft picks winner! * 🚨 Friend of the show Ian Mckay wrote a tool to automate your auto-remediation. * 🚨 Azure is here too. (We just wanted them to feel included this week.)
Google: What’s Next? * 🥇 The Google Cloud Next keynote address was this week, and Jonathan has taken the win for our draft picks by predicting new collaborations and productivity tools in Google Meet. Congratulations, Jonathan! * 😠 Google launched the Open Usage Commons framework to support Open Source development. Google has donated the ISTIO trademark to the Commons, upsetting IBM. * 🦾 AutoML Tables has received several user-friendliness features, including explanations for online predictions. (Not that any of us use AutoML.) * 🕸️ Google is releasing Network Endpoint Groups, which is a collection of network endpoints to use as backends for some load balancers. This is what you need to have if your hybrid cloud isn’t going to be just a transition. * 🔮 The new Active Assist portfolio of tools promises to help you reduce the complexity of your cloud operations. Moving around the complexity, how very… Oracle of you. * 🗳️ Assured Workloads for Government, now in private beta, promises to help government customers, suppliers and contractors meet the security and compliance standards of federal agencies. The compliant-but-not-isolated model can be expected to bleed out into non-governmental workloads. * 🤔 BigQuery Omni will allow you to access and analyze data across your multi-cloud environment. It’s a solution to the data gravity problem, but keep in mind it’s still an onramp to GCP. * 🤐 The Confidential Virtual Machines product, now in beta, is the first tool in the Confidential Computing portfolio. Apparently this is revolutionary, but we’re only sold on “neat.” * 📧 The new Customer to Community (C2C) platform is an exclusive community for cloud professionals among Google Cloud customers.
In this TCP Talks episode, Justin Brodley and Jonathan Baker chat with Liz Rice, VP of open source engineering for Aqua Security, which provides tools to secure cloud-native deployments.
Liz describes Aqua's evolution over the years: From a provider of container security to its acquisition of CloudSploit and its development of open-source security solutions. Most customers are using cloud native software, and Aqua wants to secure those workloads and engage that community.
"As a business, we have to be where the discussions are. Having open-source tools that are genuinely useful gives us a good way to participate in that community," Liz explains.
In addition to her role at Aqua Security, she is the chair on the CloudNative Computing Foundation's (CNCF) Technical Oversight Committee. During the conversation, Liz gives an overview of how they handle projects. Key Takeaways
Resources Here's what was mentioned in the episode 👉
Architect Matt Kohn fills in for Peter on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Ian McKay has cool tools for the new Honeycode service. * 🚨 Amazon shoots for the stars with their new Aerospace and Satellite Solutions business unit. * 🚨 A new family of Virtual Machines boast powerful performance benchmarks.
AWS: Business! In! Space! * 🍯 Amazon’s No-Code solution has finally shipped in the form of Amazon Honeycode, fully managed and now in beta. Friend of the show Ian McKay has created Honeycode export and appflow integration projects which add a lot of usability to the service. * 🧘 After a six-month beta period, Amazon CodeGuru is now generally available featuring CodeGuru Reviewer and CodeGuru Profiler. CodeGuru is still sticking to Java support, so if you’re working in another language, you won’t find much here. * 🧡 AWS CodeCommit now supports a limited set of Emoji Reactions to comment on pull requests and commits. The set includes 👍, 👎, 😊, 🧡 and “ship-it”, though we’d have rather used 💩, 🙄, 😕, 🤬 and 🤡. * 🚀 AWS announced a foray into the space sector with the launch of the Aerospace and Satellite Solutions business unit. AWS appointed former director of Space Force Planning Clint Crosier to lead the unit. * 📦 On the last day of June, AWS launched AWS App2Container to help containerize currently running applications without the need for code changes. Once this applies to applications other than .NET 3.5+ and Java, we expect this to be adopted like hotcakes. * 🧹 On the first of July, AWS announced the Porting Assistant for .NET, a tool to port .NET Framework applications to .NET Core running on Linux. This should clean up the last of the .NET apps in the next, say, 25 years. * 💳 Amazon Relational Database Service instances are now available on AWS Outposts with mySQL and PostgreSQL support. The management fee can be a bit pricey, but compared to what you’d already be paying for Outpost, you probably won’t even notice.
Azure: I Studied the Blade * 🆕 The first release of Docker Desktop’s integration with Microsoft Azure
Google Cloud Next Predictions Your show hosts come to you with their cloudy crystal balls to give us Google Cloud Next Prediction show for Thomas Kurian's keynote.
Justin 1. CloudSQL/Firebase/BigQuery via Anthos 2. More Granularity in Stackdriver reports/analytics around status reports (Thanks /u/casper_man) 3. Cloud endpoint Security Protection (Antivirus, Endpoint DLP, HIDS)
Jonathan 1. New Collaborations & Productivity tools Google Meet, New or Improved 2. Price reduction (token for Anthos (Small cut pacify the haters) 3. Thomas Kurian will speak about community governance
(Peter) Matt 1. GCP will launch a new region somewhere in the midwest 2. Partnership with a pro-sports league. 3. Will announce their commitment to cloud infrastructure beyond 2023
Ryan 1. Tout their amazing bigquery & ML stuff to help with Covid research 2. A significant price reduction for Anthos drop it by more than 40% or removing 12 month commitment 3. Layer 7 network inspection and egress filtering
Honorable Mentions * Endpoint Security will run in the hypervisor (Agentless) - Jonathan * Tool Similar to Sagemaker * Threat Hunting Tools * ML/AI chops to Cloud Monitoring * Configuration Management Endpoints * Major Updates to Docs, Sheets, Slides, * Quantum Computers
Tie Breaker: Number of Virtual Attendees on the Register? * Ryan - 45,000 * Matt - 60,000 * Jonathan- 85,000 * Justin - 100,000
Your hosts see a new cloud on the horizon and anticipate a flood on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 HashiCorp enters the ring with HashiCorp Cloud Platform. * 🚨 Microsoft offers free AI classes. * 🚨 Bayer Crop Sciences pushes cluster size to new heights.
General News: A Challenger Approaches * ☁️ HashiCorp has launched the HashiCorp Cloud Platform featuring managed Consul as the single initial service. HashiCorp is currently soliciting feedback on the alpha version of HashiCorp Cloud Platform and is planning on releasing Vault next.
AWS: Let it Snow * 🍧 The AWS Snow family of devices is now joined by AWS Snowcone, a four-and-a-half pound eight terabyte data storage and transfer device, both the most storage and least weight yet. Don’t lose it though — this little guy runs around $2,000. * 🦥 Aurora Global database now supports write request forwarding for low latency global data reads. This is fantastic news for lazy devs like us. * 😃 Amazon EC2 Auto Scaling Groups now support the Instance Refresh feature, eliminating the need for custom scripts and systems. This is a long-anticipated feature for TCP. We can’t believe it’s taken until 2020! * 📚 The new Lambda Powertools library within the Serverless Lens for the Well Architected Framework features Tracer, Logger and Metrics as its three core utilities. Using these tools to get yourself set up will save you a lot of strife down the line.
Azure: An ‘Udacious’ Plan * 🤝 Azure and Udacity are partnering to launch a scholarship program and the free Azure Machine Learning course to address the growing demand for AI specialists. We’ve had good experiences with Udacity so this offering appeals directly to us. * 🦾 Azure is catering to users new to ARM templates with new features including a template Quickstart gallery and Azure Resource Manager Tools in Visual Studio Code. How did we ever get by without this?
Google: Seeds and Nodes * 🔐 Google rolled out Transport Layer Security 1.3 featuring updated ciphers and low handshake latency as the new default for Cloud CDN and Global Load Balancing customers. Of course, you’
Your hosts (minus Jonathan) talk outages and instances on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Mark Russinovich (twitter: @markrussinovich) published a guide on scaling-up during the pandemic. * 🚨 Sagemaker Ground Truth lets robots see in 3D. * 🚨 Check out our interview with Spot CEO Amiram Schachar.
General News: Not Our Fault * 🤐 IBM assigned the cause of a several-hour global outage on June 10 to an unnamed third party. We can expect a full formal report from IBM soon. * 💰 Data warehouse specialist company Snowflake is rumored to be filing for initial public offering at $20 billion, 1,333% of its valuation just two and a half years ago. It’s just a matter of time until Amazon Redshift makes a move to break into Snowflake’s space.
COVID-19 * 📓 Chief Technical Officer at Azure Mark Russinovich detailed how Azure scales Microsoft Teams during the pandemic in what appears to be a face-saving measure after Azure’s recent capacity issues. It’s a weighty article — we recommend checking this one out for yourself if you’re encountering any scaling issues of your own.
AWS: The Third Dimension is Data * 🏺 AWS CodeArtifact, a managed artifact repository service, is now generally available. Everyone has to store their Build Artifacts somewhere, so this is an exciting tool, especially at this price point. * 🏷️ Amazon Sagemaker Ground Truth can now label 3D point clouds using a new editor and assistive labeling features. We don’t know how this one works but expect widespread adoption in advanced machine learning. * 💵 New EC2 instances with Graviton2 processors are now generally available. Whether you choose C6 or R6, expect some hefty price-performance improvements. * 📁 AWS Lambda functions can now connect to Amazon Elastic File Systems. Sure, some people may make the point that this runs counter to the purpose of Lambda, but just think of the use cases! * 🛡️ The AWS CloudFormation Guard open-source command-line interface is now available in preview. An ounce of prevention is worth a pound of remediation, and it’s good to see that made easy.
Azure: An Instance of Poor Optics * 📹 The live video analytics platform Azure Media Services is now in preview. Enjoy your automated live video feed analytical capabilities, Department of Defense! Pinky swear you’ll be responsible with it? * 💾 Azure released
Your co-hosts announce parity with the leading cloud-computing podcast hosts on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Amazon is suing their former vice president of marketing. * 🚨 AWS introduces new instances. * 🚨 Google pulls the perfect hat-trick and celebrates parity with AWS three times.
General News: What? Amazon is Litigious? No... * 👨⚖️ Amazon is suing their former vice president of marketing Brian Hall over the breach of his non-compete agreement after taking a position with Google Cloud. We will see whether Amazon’s inconsistent enforcement of their non-compete agreements will give Hall a win in court. * 🤝 Slack is partnering with AWS, integrating Slack Calls with Amazon Chime. For an interview with Chime GM Sid Rao, check out friend of the show Corey Quinn’s podcast Screaming in the Cloud. * 🆕 Rackspace rebranded this week to “Rackspace Technology.” This shift mirrors their move from selling equipment to selling services.
AWS: Instant Hits * 💸 AWS launched new EC2 instances, this time bumping up to second generation AMD EPYC processors. Well, it’s cheaper than the Intel counterpart. * 🤖 EC2 G4dn bare metal instances are now available with up to eight NVIDIA T4 GPUs. You’ve got to be working on some seriously cool machine learning projects to need something this expensive. * 🔍 You can now find the machine-learning powered anomaly detection feature and interactive SQL tools in Amazon Elasticsearch Service. Chamberlain and Boyce (inventors of SQL) should be proud — it’s everywhere these days. * ❓ You can now write the results of an Amazon Redshift query
The Cloud Pod Gets Their Groove Back — Episode 74
Your co-hosts have cooked up a good one on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Your co-hosts cover DockerCon 2020. * 🚨 Chef announced several new features at ChefConf 2020. * 🚨 Google Cloud Platform (GCP) teaches you how to take an online certification exam.
General News: Prince Ali * 💸 Mirantis has released the first major update to Docker Enterprise since it acquired the platform in November — a loss for the startup community. * 🎙️ Over 60,000 people registered for the online DockerCon, the first DockerCon after the loss of Enterprise. During the keynote, Docker CEO Scott Johnston announced a strategic partnership with Microsoft. * 📈 Chinese cloud titan Alibaba’s revenue grew 62% in the first quarter of 2020, though it remains behind AWS, Microsoft and Google for now. With the regional advantage, it seems all Alibaba needs to do is maintain parity with AWS features to stay on top.
Chef Conference: Too Many Cooks * 👩🍳 Predominant Configuration Management software platform and TCP punching-bag Chef held their virtual ChefConf where they debuted several new capabilities. + Chef Compliance now features Chef Compliance Audit and Chef Compliance Remediation. + Chef Desktop helps IT managers centrally deploy, manage and secure an organization’s laptops, desktops and workstations. + Chef Infra and Chef Automate now integrate with ServiceNow Configuration Management Database.
AWS: No Back-SaaS * ✍️ Upgrading contracts for SaaS and usage-based products on the AWS Marketplace is now easier. Look to this for grabbing those high-volume discounts when scaling up. * 🔑 AWS Single Sign-On now integrates with Okta Universal Directory. This one’s a sure-fire hit. * 📱 AWS Amplify iOS and Amplify Android libraries and tools are now available. We...are not a group of iOS experts here at TCP. Let us know what you think of these! * 📋 Elastic Load Balancing now
In this episode of TCP-Talks we chat with Amiram Shachar, founder and CEO of Spot, which aims to help its customers reduce complexity and compute costs by up to 90% in the AWS, GCP and Azure clouds.
We talk about the impact on the spot pricing market, and the differences between the AWS, GCP and Azure approach to spot pricing and delivery, and whether customers are asking for multi cloud solutions.
Amiram discusses the problems Spot solves, why they chose to partner with NetApp and reveal the mystery of the rebrand from Spotinst, then takes us on a deeper dive into Spot's Ocean, a Serverless Infrastructure Engine for Containers,.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 An unusually short AWS segment this week featured new Backup customizations. * 🚨 Azure is bringing their HoloLens2 to a new set of countries. * 🚨 We celebrate BigQuery’s 10th birthday and the accompanying BigSale.
AWS: Only Three Stories Somehow * 🐈 Jonah Jones of the AWS Open Source Blog published an article on how to use the PromCat (Prometheus Catalog) to monitor AWS services used by Kubernetes. It’s great to see Prometheus and Kubernetes continue to take over the world. * 💾 You can now opt-in or opt-out of AWS Backup services at the account level. Opt-in is nice and all, but opt-out provides peace of mind to the largest user base. * 🗺️ Information on AWS regions and servers is now available programmatically in the AWS Systems Manager Parameter Store. It’ll be nice when we see other tools pulling this data.
Azure: Mixed With What? * 👓 HoloLens 2, the latest in Azure’s “mixed reality” glasses technology, is now available in 10 countries and will be coming to more soon. Once the technology becomes as functional as it is in the advertisements, we’re going to be thrilled to play with it. There’s a lot of potential here for industrial applications that are already being explored. * 🌈 The Azure Arc preview now supports Kubernetes which was hotly requested in customer feedback. Expect to see some very interesting use cases from Azure Arc in the next 12 months.
Google: Happy Birthday! * 🎖️ After dropping out early in the JEDI contract competition citing conflicts with its AI principals, Google has signed a seven-figure contract with the Department of Defense’s Defense Innovation Unit. Google anticipates that this may lead to future business deals with branches of the DoD. * 😊 Serverless VPC Access now features ingress settings. It’s really nice to see a tightening down of function access on VPCs and vice versa. This should make a lot of people happy. * 🔒 Google’s new open-source tool IAP Desktop allows users to access and manage Windows VMs conveniently and securely. Glad to see Google supporting the zero-trust remote admin access story. * 🎂 Data warehous
This week Chris Riley DevOps Advocate for Splunk and Podcast Host of Developers Eating the World joins us. We ask the tough questions, like what is Observability exactly? We touch on the risk of robots taking my job, with AI-Ops, and if it is marketing buzzwords or a product. Plus the mad rush to SRE all the NOCs, because GOOGLE DOES IT and more on TCP-Talks.
Twitter: https://twitter.com/hoardinginfo Developers Eating the World Podcast
Your co-hosts cover conferences past and yet to come on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsor:
This week’s highlights * 🚨 We take a good, hard look at the ways Google Cloud has AWS beat. * 🚨 Microsoft Build 2020 featured the fifth most powerful computer in the world. * 🚨 Google Cloud Next is here to stay for a long, long time.
General News: Let Me Count the Ways * 🔢 Peter Wayner of InfoWorld wrote an article listing the 13 ways Google Cloud beats AWS. Well…he didn’t say they were all good reasons.
AWS: That’s a MTHFL * 🔨 AWS announced the Cloud Development Kit for Kubernetes called cdk8s is now in alpha. Rolls right off the tongue, doesn’t it? * 🔒 You can now use Attribute-based access control with EC2 Instance Connect to define Secure Shell access permissions based on attributes. It’s good to move away from passing around all those extra keys. * 👨🏽💼 State Manager features for Systems Manager now integrate with AWS CloudFormation. Assuming we’re parsing the naming conventions correctly in these press releases, that’s good news! * 🧘 Amazon CodeGuru Profiler added -javaagent switch, and CodeGuru Reviewer now supports Atlassian Bitbucket Cloud. Obviously, profiling and reviewing are totally different services — how could anyone get those mixed up? * ❓ The AWS CloudTrail console has been redesigned. It’s just the S3 user interface again, so it’s not a very intuitive interface. * 📁 Amazon Elastic Container Service now supports environment files to store environment variables for containers using the EC2 Launch type. * 📖 The new Amazon Elastic Kubernetes Service Best Practices Guide
We crown the winner of the AWS Summit Draft Picks on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsor:
This week’s highlights * 🚨 We crown the winner of this year’s AWS Summit Draft Picks! * 🚨 Amazon and Microsoft keep slinging blog posts over JEDI. * 🚨 We’re all just trying to stay sane, honestly.
AWS Summit: Draft Picks * 🏈 While it wasn’t a particularly accurate set of predictions this year (with no honorable mentions scoring and even the tiebreaker non-functional), Justin managed to squeak out a win by correctly predicting a price cut in EC2, S3, or Networking and the Covid Crazy Growth Numbers. Jonathan scored the only other point with his prediction of improved DLP Tools for S3. * 💰 Amazon Macie simplified its pricing plan and dramatically reduced costs. Is the 80% price cut the new way of announcing a product is generally available? * 💵 Amazon Elastic Compute Cloud cut prices across all regions for Standard Reserved Instances and EC2 Instance Saving Plans. * 💸 Inter-Region Data Transfer prices have been reduced for data coming out of São Paulo, Bahrain, Cape Town and Sydney.
General News * 👩⚖️ Amazon filed a second, concurrent bid protest to the Department of Defense. Microsoft and Amazon continue to snip at each other in public blog posts.
COVID-19 * 🏘️ Amazon will allow non-warehouse employees to work from home for at least five months. Microsoft updated their WFH policy, and will give employees the option to work remotely through October.
AWS * 🧘 Amazon CodeGuru Reviewer has seen pricing changes. Now CodeGuru’s terrible payment model is much less terrible. * 🆕 Amazon Elastic Kubernetes Service now supports Kubernetes version 1.16. It’s good to see they’re putting out these updates progressively faster. * 🧙♂️ A new wizard will allow for simplified creation and management of Elastic Kubernetes Service clusters. This should clean up some of the EKS console nicely. * 🔏 AWS Identity and Access Management introduced basic password strength requirements. Thank goodness. * 📠 AWS Internet of Things Device Management service’s Device Jobs feature now costs
Josh Stella (twitter: @joshstella) joins us to talk about the state of cloud security. We discuss Fugue's new report, the complexity and challenges of IAM, and the most common cloud misconfiguration aren't always the ones you would expect.
Fugue ensures cloud infrastructure stays in continuous compliance with enterprise security policies. Our solution identifies cloud infrastructure security risks and compliance violations and ensures that they are never repeated. Fugue provides baseline drift detection and automated remediation to eliminate data breaches, and powerful visualization and reporting tools to easily demonstrate compliance.
The Three Musketeers have gained their D’Artagnan and take on the world (metaphorically and from home) on this week's episode of The Cloud Pod.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Take a break with us and enjoy a music video. * 🚨 Oracle managed a whole two headlines this week! * 🚨 Jonathan called it: AWS opens the Africa (Cape Town) Region.
General News: Chime After Chime * + 🎵 Tim Leehane and Spencer Johnson released a working-from-home anthem titled Chime After Chime we just had to share with you.
COVID-19 * 🔮 Zoom picked the dark horse of cloud platforms Oracle for their next upscaling deal. Zoom is moving around 93 years of video through Oracle servers every day. * ❓ AMD revealed an anonymous customer (probably Oracle or Microsoft) deployed 10,000 new Epyc servers in just 10 days.
AWS: Summit Predictions * Jonathan 1. Improved DLP Tools for S3 2. AI Powered submarine to explore the depths of the ocean 3. ES service will pivot to Open Distro for ElasticSearch * Ryan 1. Docker Exec based Debugging tools/capability 2. Remote Debug capabilities for Lambda Functions 3. Security Code Scanning service (similar to code guru). (static and dynamic code analysis) * Peter 1. Direct Competitor to Anthos 2. DLP for VPC, always wanted a layer 7 like proxy. Filtering/Domain Whitelisting 3. A caricature of larry ellison will appear on the screen in the slides * Justin 1. Price Cut in EC2, S3 or Networking 2. Covid Crazy Growth Numbers (service dig on Azure) 3. A Diplo T-shirt will be worn by Werner Vogel
Honorable Mentions: * Amazon Crucible their first person shooter game, online multiplayer game * Dr. Matt Wood will make a passionate attempt for people to love sagemaker * 6 foot distancing robots * Keyspaces will be on the HIPAA BAA list
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 AWS Summit Online is on May 13. * 🚨 Drama brews in the developing JEDI contract story. * 🚨 Please welcome Ryan Lucas as our new full-fledged non-guest host!
General News: This Isn’t the Evidence You’re Looking For * 📛 AWS Summit Online is free to attend on May 13. Expect to hear our predictions soon! * 🎖️ Following a partial review, the Department of Defense’s inspector general’s office announced they have found no evidence of the DoD awarding the JEDI contract unfairly. Meanwhile, Jon Palmer, Deputy General Counsel for Microsoft argued that allowing AWS a second bid would give Amazon an unfair advantage. But who inspects the inspector?
COVID-19 * 👖 Verizon is breaking out the big bucks to purchase video conference company BlueJeans for $400 million. It’s interesting to see BlueJeans back in the spotlight. * 💵 The Information reports that AWS has been comparatively inflexible on cloud bill payments compared to Azure and Google Cloud Platform. At the same time, AWS has maintained the messaging that it is “here to help” during this “unprecedented time.”
AWS: A Snowball’s Chance at the JEDI Contract * ❄️ The Snowball family of devices received a ton of updates. All that work on military applications and no JEDI contract to apply it to. * 🔺 Federated querying is now generally available on Amazon Redshift. It’s clear that Amazon is investing heavily in Redshift. * 🔎 AWS Security Hub launched the BatchUpdateFindings API and the Workflow Status field. Good to see some of these issues worked out. * 🤐 This one goes out to all the auditors: AWS Secrets Manager now integrates with AWS Config. And when the auditor’s happy, everyone’s happy. * 📇 AWS IAM will allow you to identify who performed actions when viewing AWS Cloudtrail logs. Now you don’t have to keep track of hundreds of federated accounts manually! * 📦 Amazon Route 53 Doma
Ryan Lucas and Ian Mckay fill in for Jonathan on this week’s free-tier episode of The Cloud Pod.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 GitHub announced a new business model. * 🚨 Amazon announced a giant pile of Beanstalk updates. * 🚨 Google published a free book on secure and reliable systems.
General News: [Upgrade to Premium for Full Segment Title] * 💸 GitHub has switched to a freemium business model — core features will be free to all users, and premium features like Security Assertion Markup Language will require a paid plan. This is a great new direction, though they may lose a few paid customers tempted to downgrade to the new free tier.
AWS: Amazon Golden Goose * 🧙 The new AWS Launch Wizard for Solutions and Pricing (SAP) service will orchestrate resource provisioning to help customers deploy or migrate SAP workloads. If you’re paying the premium for a big fancy SAP instance, you’re going to want to be invested in how your infrastructure is set up. * 🌱 Amazon unveiled a giant pile of Beanstalk updates this week. The AWS Elastic Beanstalk console is now generally available, and upcoming features can be followed the roadmap on GitHub. New generations of Docker, Corretto and Python platforms built on Amazon Linux 2 will all run applications on Elastic Beanstalk. Elastic Beanstalk has added API support for listing platform branches. Beanstalk is looking to be a very popular option for smaller developers, and is getting more impressive with every update. * 👛 You can now preview Amazon RDS Proxy with PostgreSQL compatibility, which resolves connection pool issues. This is going to be a super helpful service and at about three cents per hour to run a proxy, it’s also extremely cost effective. * 🆕 AWS Fargate updated to version 1.4.0, with new features including EFS Endpoint Support, consolidated 20gb ephemeral storage and new options for metrics and statistics. You have a month to test before this becomes the default version.
Google:
Jacques Chester author of Knative In Action and Principal engineer at Pivotal joins us to educate us on Knative. Knative is an open-source tool to run functions as a service on top of Kubernetes and is gaining popularity in Kubernetes deployments. Learn all about Knative, Kubernetes maturity, Googles involvement in Knative, and more.
If you are are interested in checking out Knative in Action, I have a coupon code for you to save today on any Manning press publication including Knative in Action!
https://www.manning.com/books/knative-in-action?query=Knative%20in%20Action
Code: podcloud20
Your hosts meet online to work on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Profits of The Cloud Pod’s sticker sales will be donated to charity. * 🚨 DeepComposer is now generally available. * 🚨 You can play around with March Madness simulations in BigQuery.
General News: The Cloud Pod Tackles COVID-19 🏷️ We’re donating profits of our sticker sales to the John Hopkins University COVID-19 Research Response Program through July 1, 2020. AWS: Staying Productive 🤔 The Amazon CloudWatch Contributor Insights feature, which gives users an overview of their operational problems, is now generally available. CloudWatch Contributor Insights is also generally available for DynamoDB, though it is 50 percent more expensive per million log events than Insights not for DynamoDB. You can build some neat automation around this.
☁️ Back in Episode 51, we covered the new instances with ra3.16xlarge nodes, and now Amazon is adding instances with ra3.4xlarge nodes, which lack the excess power of ra3.16xlarge. At a quarter of the price of the larger larges, that’s some considerable savings.
📏 Amazon Redshift now features elastic resize, allowing users to change node types within minutes. This will be helpful if you want to make the move to those cheaper instances.
🎹 If you’re looking for something fun while sheltering in place, you may be pleased to hear that AWS DeepComposer is now generally available (and with new features!) You can buy an Amazon keyboard for $99 or a generic for $50.
💰 Amazon RDS for SQL Server now supports In-Region Read Replicas on SQL Server Enterprise Edition in the Multi-AZ config with Always On Availability. Careful though, you can really rack up a bill this way if you’re careless.
⏩ Amazon announced that Amazon Elastic File System has quintupled its speed for General Purpose mode file systems to 35,000 read operations per second. That leads into our next headline: Amazon Elastic Container Service now supports Amazon Elastic File System, replacing the interesting hacks previously required to allow containers on different hosts to access the same data set. Maybe we’ll rebuild our TCP website?
📦 AWS
Jonathan is out with a back injury, so it’s just Justin and Peter on this week’s intranational episode of The Cloud Pod.
A big thanks to this week’s sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
This week’s highlights * 🚨 Teleconferencing services continue to boom. * 🚨 Amazon opens up a new avenue of attack on Microsoft’s JEDI contract. * 🚨 Azure UK declares it will triage who gets service if need be.
General News: Cloud Provider Moves to Internet for Business 💰 Business for web conferencing applications has boomed this month. Microsoft Teams gained 12 million users in a week and Slack’s paid version gained over 7,000 customers since the start of February. Hopefully people continue to use these tools to stay more connected even after we’ve gotten through this pandemic.
✍️ With AWS testing centers closed, AWS Certification is now offering all exams online with online proctoring. Considerations are being made for those who need to reschedule. AWS: Chipping Away at JEDI 🏷️ The price of Amazon GuardDuty use over 10,000 gigabytes (GB) was reduced from 25 cents to 15 cents per GB.
⏱️ The normally quiet CloudFront announced they have cut propagation times down to five. Propagation times used to average between 17 and 35 minutes. CloudFront has always been cost-effective, but now it’s as efficient as it needs to be.
👁️ Amazon QuickSight launched image support on dashboards through the insight editor. Neat, but indicative of a slow news week.
🔏 AWS Site-to-Site VPN now enables you to use digital certificates for all site-to-site connections. This is great for mobile devices or other cases without static IP addresses.
👩⚖️ In our developing coverage of the JEDI contract, AWS has now charged that the DoD is unfairly granting Microsoft a “do-over” on flawed portions of its bid.
🧮 The UpdateShardCount API for Amazon Kinesis Data Streams upgraded from a 500 shard capacity to a 10,000 shard capacity. If you want to work with social media, this may be a tool for you.
☎️ Amazon Connect now features voicemail, which not only works as a traditional voicemail but also includes transcriptions. It’s all very serverless in its methodology. Google: A Strong Third Place 🧪 Forrester Research named G
Your hosts join the rest of the world in phoning one in on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure
This week’s highlights * 🚨 More conference cancellations roll in due to the ongoing global pandemic. * 🚨 Amazon Redshift made several improvements this week. * 🚨 We take a look at a bug-hunt by a Site Reliability Engineer at Google.
General News: Working From Home 📴 As the pandemic response ramps up across the world, teleconferencing services like Slack and Zoom have struggled to meet demand. Microsoft Teams users in Europe reported difficulty logging into the service. If you’re looking for an open-source web conferencing application, AWS recommends you use Jitsi. If you’re a startup with more AWS credits to spend than money, we recommend you check it out.
🚫 In the continued wave of canceled conferences, Microsoft moved the May 19-21 Build developer conference to a virtual-only format. Even virtual conferences aren’t entirely safe bets, as Google has postponed Google Cloud Next 2020: Digital Connect. Perhaps they will try to wait until they can safely host a physical conference again, but who knows when that will be? AWS: Redshifting Into Gear 🟥 Amazon Redshift now allows users to pause and remove clusters so they are not billed for their use while unneeded. In other Amazon Redshift news, the cloud data warehouse now supports materialized views functionality. We suspect that Redshift will be going serverless before long.
🚪 As a part of its release, API Gateway will offer private integrations with AWS Elastic Load Balancers and AWS CloudMap. There’s a lot there, but we wish it had a Lambda endpoint.
🌎 Amazon ElastiCache for Redis announced Global Datastore, a fully managed service for secure cross-region replication. It’s great that they’re doing what they can to make this easy, but you should be aware of the limits of a service like this.
📦 AWS AppConfig now
Ryan Lucas (@ryron01) fills in for Peter again as we practice social distancing on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights * 🚨 Details emerged from the ongoing legal battle surrounding the JEDI contract. * 🚨 Amazon shows off its new operating system. * 🚨 Powershell 7.0 brings long-awaited features to Windows.
General News ❌ Due to the ongoing global pandemic, AWS Summits have been (responsibly) cancelled in Sydney, Singapore, Mumbai, Paris, San Francisco and Brussels. Hopefully we’ll see these events move online.
👩⚖️ Court documents from Amazon’s injunction have been unsealed. The documents reveal that Microsoft’s bid included “non-compliant storage” which was not counted against them. The Department of Defense responded that Amazon’s bid did not include technically compliant storage either.
📰 Our very own Justin Brodley made the news! His comments are included in an article covering a cloud alternatives panel discussion at Altitude 2020.
🗂️ VMware Inc. overhauled its portfolio of products to focus on Kubernetes support. Expect to see the whole host of products available by May 2020. AWS: ⏰ The new CloudWatch composite alarms will allow you to combine alarms and get a clearer picture of what is happening when something goes wrong.
🔊 You can now host your applications with the AWS Amplify Console via S3 and CloudFront. If you checked out Amplify last year, it’s changed a lot since then so it might be worth another look.
🗃️ AWS Serverless Application Repository now allows you to share applications with Organizations. Anything you can manage at an organizational level is
Ryan Lucas (@ryron01) fills in for Peter as we cover all the news you can use on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights * 🚨 AWS restructures its sales force. * 🚨 Google Cloud Next ’20: Digital Connect is canceled. * 🚨 Who’s else is excited to re-network their printers!?
General News 🎙️ We’re proud of the Bonus Episodes we’ve produced lately. Check out our interviews with Rob Martin and Ben Kehoe!
✈️ Check out Aviatrix’s panel on Multi-Cloud architecture and networking — featuring our very own Justin Brodley. And if you’re here because you saw Justin’s panel, welcome to TCP!
🆚 Global research firm Gartner has named AWS the top leader in Cloud AI developer services. Gartner categorizes industry leaders as having a complete vision and the ability to execute on it. Microsoft and Google were close behind, though unlike Microsoft, Google spread the news. AWS: Human Salesforce, AI Oversight 🤭 Amazon Transcribe can now automatically redact personally identifiable information. You can rest assured when a robot collects your personal information for data analysis, it will use discretion in what it shares with humans.
🏷️ AWS Global Accelerator users may now use their own IP addresses and tag resources. We already had AnyCast, but the tagging is nice.
💲 Faced with tougher competition, AWS plans to double the size of its sales team. This will be the first major sales restructuring for AWS in several years.
👣 AWS Config’s advanced query feature now supports configuration aggregators. This feature will save you a ton of sweat managing a large AWS footprint.
🏗️ If you’re going to
One of the most exciting cloud computing technologies of the last few years is Serverless computing, whether it be via AWS Lambda, Azure Functions, GCP functions or technologies like K-Native. This week Jonathan and Justin talk to Ben Kehoe Chief Roboticist at iRobot and AWS Serverless hero. We ask Ben the burning questions about Serverless Computing, robotics, AWS and more! Listen today.
Your hosts talk about AWS Lambda, Azure’s Cybersecurity of Things and Google’s loquacious AI on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights * 🚨 AWS Lambda sees savings and supports Dart. * 🚨 Your kitchen appliances are safer with developments in the Internet of Things. * 🚨 It’s the last week of our trial of the new Lightning Round format. Comedy’s hard.
TCP News ☁️ ICYMI, check out our second episode of TCP Talks: Finops in the cloud with Rob Martin. We learned some things about financial operations, and we’re sure you will too. AWS Lambda Updates 🐑 AWS Compute Savings Plans now apply to your AWS Lambda workloads. That’s nice, but even a decent percentage of such a cheap service probably won’t impact your expenses all that much. In addition, those Lambda workloads now support Dart, an open-source programming language made by Google. If you’re making mobile apps, you’ll be happy to use this. If you’re not making mobile apps, you probably didn’t need to read this paragraph.
🔒 AWS Identity and Access Management now allows you to control access for requests made on your behalf by AWS services. It’s a great security feature. We’re looking forward to AWS taking this a step further at this year’s re:Inforce conference.
🔑 Amazon Elastic Container Service now supports previous Secrets Manager versions and can read keys directly from JSON objects. It’s going to be much more convenient now that you can use one key instead of, say, 10.
🌿 AWS Chief Evangelist Jeff Barr outlined a laundry list of updates to Amazon FSx for Lustre in this blog post. All these changes add up to SageMaker integration, to make SageMaker more attractive to customers. Spherical Things 📠 At this year’s RSA cybersecurity conference, Azure announced several improvements to Azure Security Center for Internet of Things (IoT). It’s good to see the time and energy being put into IoT security. Your personal computer may be secure, sure, but wha
We follow continuing stories with the JEDI contract, GigaOM and our new Lightning Round format on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights * 🚨 Amazon makes progress contesting the JEDI contract. * 🚨 AWS and Azure introduce shared cloud block storage. * 🚨 Google shows signs of shifting priorities.
Arrested Development 👩⚖️United States judge Patricia Campbell-Smith has granted Amazon’s request to temporarily halt work on the JEDI contract by Microsoft. She also ordered Amazon to post $42 million in the event the injunction was issued wrongfully. AWS Not First to Share Blocks 🥞CloudFormation StackSets users can now manage multiple AWS accounts. We recommend you get your organizational units structured properly now so you’re ready for when that must-have feature for your organization is added.
💽AWS customers running Linux on Ec2 can now attach provisioned IOPS (io1) EBS volumes to Multiple Ec2 instances. Be careful though: wielding fine control over your data means taking responsibility for your data losses, as well. This news comes a day after Azure announced their own Azure Shared Disks, which was, for those sweet brief hours before AWS’s announcement, the industry’s only shared cloud block storage. What’s in the Box? 🧪Azure released a new GigaOM study which backs up the findings from the GigaOM study we covered on episode 58. How incredible — Azure, which paid for the scientific (and unverifiable) study, was found to be the best at everything once again!
📦The Azure Backup service now offers a preview of the Azure Data Box. You can kick-start your large-scale backups by loading up to 80 terabytes of data into the Data Box and sending it to Azure, where it will be integrated into a standard cloud backup. Google Shifts Focus 📐Google has introduced
The most terrifying part of moving to the cloud isn't security, migration techniques or learning new infrastructure as code tools, it is managing that pesky cloud bill. To some CFO's it might even be downright terrifying. Join Jonathan and Justin as they talk about all things FinOps with Rob Martin from Apptio (formerly Cloudability) where they discuss cost management techniques, getting help via the Finops Foundation and more.
A big thanks to TCP-Talks Sponsor: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning, and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
Peter’s returned from his trip to Asia and the band’s back together on this episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights * 🚨 Registration for Amazon Re:Mars 2020 is now open! Academics can use code ACAD20REMARS for a discount. * 🚨 Google releases several new tools for building and managing data pipelines. * 🚨 We tried out a new format for our lightning round!
Amazon Web Services: To Infinity and Beyond 🔭 Registration is open for the Amazon Re:Mars 2020 robotics and technology conference running June 16-19 in Las Vegas. Tickets cost $1,999, but astronauts get in free! Academics and students registering with a .edu email address can use the discount code ACAD20REMARS if a couple grand is too pricey.
🗺️ AWS Sync Routes is available on the AWS Open Source blog to allow you to synchronize routes across tables. If you’ve got only a few VPCs, you might have the right use case for this.
🐦 AWS CodeDeploy’s blue/green deployments for Amazon ECS now include “linear and canary deployments.” Hidden in that announcement is the implication that they seem to have invented linear deployments.
👁️ You can now use a full-screen narrative editor with a preview mode thanks to enhancements to Amazon QuickSight. You can also add static and dynamic URLs within those narratives.
📐 If you’re a Well-Architected Framework practitioner, the new Serverless Lens for AWS Well-Architected Tool may improve your architecture assessments.
🌎 If you (somehow) have a workload that can tolerate lost events, the Multi-Region Asynchronous Object Replication Solution may be for you. We’ll hope for a global bucket option to replace this down the line with something more elegant. Azure’s Safety and Retiring 🦺 Mark Russinovich, Chief Technology Officer of Azure, published Advancing safe deployment practices detailing Azure’s best practices for their deployments. If you use Azure, we absolutely recommend giving it a read.
👴🏽 Azu
Your hosts are joined again by Ryan Lucas (@ryron01) who is filling in for Peter as we recap the week in cloud.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights * 🚨 It’s earnings season as the top dogs show their growth. * 🚨 Azure gets back in the headlines with a bold but contested study. * 🚨 Google fulfills an old TCP prediction with reports of a unified service.
Certificates of Doom Update 📅 Amazon has given customers an extension until March 5, 2020 to rotate their SSL/TLS certificates. Previously, rebooting or manually changing a relational database service (RDS) instance would automatically switch to the new certificate authority, even if the customer didn’t have their application ready to do so. IBM Changes Leadership 👔 Speaking of new authorities, major changes are coming to IBM. Arvind Krishna will replace current CEO Ginni Rometty on April 6 and current Red Hat CEO Jim Whitehurst will become president. Hopefully the changes in leadership and the acquisition of Red Hat will be what IBM needs to turn around what’s been a rough decade for the tech giant. Earnings Season 📈 It’s that time of the year where financial analysts are breaking out the line graphs to show investors just how much their holdings are growing. Let’s see what the quarterly reports had to say this time around: * Microsoft saw a rebound from slowing cloud growth last quarter with Azure up 62 percent, Surface up 6 percent, and LinkedIn up 24 percent. * Google Cloud growth was strong enough for the company to brag, but still lags behind AWS, Azure and even Google’s own YouTube. * Amazon joins the Trillion Dollar Club alongside Apple, Alphabet and Microsoft after a strong holiday season. Amazon also released their tax details to push back against accusations that it does not pay its taxes. Amazon paid ab
Your hosts are back at it — well some of them are. Ian Mckay (@iann0036) fills in for Peter this week as we cover all of the triumphs and troubles in cloud.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights * 🚨 Ian Mckay gives an Aussie perspective on the AWS outage in Sydney. * 🚨 Amazon streamlines permissions with the IAM policy simulator. * 🚨 Google competes with AWS with competitively priced services.
Amazon Pressures Pentagon, Suffers in Sydney ⚖️ On January 22, Amazon filed a motion to halt work on the JEDI contract between Microsoft and the Department of Defense until a court rules on the protest filed by Amazon last year. Expect more news here as the story develops through February.
🕕 That same day, Amazon Web Services (AWS) suffered a six hour outage across multiple services in the Sydney region “including EC2, elastic load balancing (ELB), relational database service (RDS), AppStream 2.0, ElastiCache, WorkSpaces and Lambda.” After the issue was resolved, Amazon assured customers it will use this experience to learn and improve future operational performance. AWS Adds, Updates and Improves 💾 AWS DataSync has received an update: You can now use DataSync to quickly transfer large amounts of data to and from Amazon FSx for Windows File Server. Previously, DataSync was not fully compatible with Windows applications and environments.
🖥️ All seven sizes of the T3 instances are now available on single-tenant hardware. It might help you meet your compliance goals by physically isolating your machine from other AWS accounts, but the unlimited bursting capability makes us wonder what use cases Amazon has in mind for these.
🛡️ Amazon GuardDuty has globally released a threat detection enhancement which should allow customers with common architectures to see fewer false alarms, and ultimately 50 percent fewer alerts overall.
📷 You can now export Amazon Relational Database Service or Amazon Aurora snapshots to Amazon Simple Storage Service as Apache Parquet. Compared to uncompressed text, Parquet is twice as fast to export and takes up
Your hosts are back at it — well some of them are. Ian Mckay (@iann0036) fills in for Peter this week as we cover all of the triumphs and troubles in cloud. A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights *
Justin Brodley and Jonathan Baker kick off our new TCP Talks bonus episodes with a chat with Mike Kelly, CTO at Blue Medora. Monitoring can be hard on-premises or in the cloud. As a result, it can be downright scary with multi-cloud strategies, hybrid cloud, and legacy tools. Bring order chaos, by centralizing the management of metrics and logs. From solving out of disk space alerts to building observability techniques, Stackdriver and Bindplane can help. Adopting these practices and principals will help your Observability and SRE teams in the cloud.
Your co-hosts move from the atmosphere to DigitalOcean as they recap the week in Cloud on this episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights 🚨 Microsoft releases an ambitious plan to erase its carbon footprint.
🚨 Amazon slashed prices for two services.
🚨 Google Cloud fights for market share as connections change with Epic and Sabre.
Justin’s Adventures in Oracle Cloud Revisited 🔎 On Episode 54 we featured an investigative segment where Justin sought answers as to whether non-boot volume cross-region backups were available yet. And while that sleuthing was still an informative experience, Max Verun, a Product Manager at Oracle, has reached out to let us know that those answers were also in paragraph two of the very article we linked to.
Thanks, Max. We’d love to have you on the show sometime. Microsoft and DigitalOcean Make Major Reductions (But Not the Same Kind) 📣 Microsoft has declared an ambitious plan to remove all of the carbon it has ever emitted from the atmosphere, a goal that far outstrips that of other tech giants. Currently carbon neutral, Microsoft plans to use a combination of forestation, reforestation and other carbon sequestration technologies to go carbon negative and completely remove its legacy carbon footprint.
📉 DigitalOcean, on the other hand, is reducing its workforce by about 10 percent with a round of layoffs. Co-founder Moisey Uretsky assured the public that the move is a strategic one, and not indicative of any sort of poor financial health. Amazon Web Services (AWS) — New Features and Price Reductions AWS announced four new features this week, starting with: 1. AWS Health organizational view, which can now aggregate health events across all accounts in your organization. 2. Perhaps as a step towards Fargate support for EFS, Amazon ECS now supports EFS filesystems in ECS task definition.
Your co-hosts discuss the National Security Agency, the Department of Defense, the UK Home Office and more on this week’s episode of The Cloud Pod.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights 1. Amazon seeks a restraining order in a move to contest the JEDI contract. 2. Our first 2020 prediction comes true in a Microsoft/IBM team-up. 3. Jonathan takes a 200 percent lead in the Lightning Round with Amazon Cognito.
Matters of National Security Amazon Web Services (AWS) is going to court over allegations that the $10 billion JEDI contract was awarded to Microsoft due to improper pressure from the president as part of his personal issues with Amazon CEO Jeffrey Bezos. Expect the temporary restraining order to be granted or denied on February 11. Amazon may try to drag out proceedings until after the election — and a more favorable administration.
For those of you running Windows 10 or Windows Server 2016, be sure to grab the new patch advised by Microsoft and the National Security Agency. The patch solves a vulnerability that was found in a decades-old component called CryptoAPI, and would allow an attacker to copy the digital signature of legitimate software. Amazon Web Services — Seven Short Sweet Stories Though AWS may be hoping to stall the JEDI contract, business as usual shows no sign of slowing. Here are the seven AWS stories we talked about this week: * You can now go to Github for the public roadmap of AWS Elastic Beanstalk and voice any of your input. * UK Home Office (think Department of Homeland Security) has announced they’ll renew their public cloud services deal with AWS for another £100 million over four more years. To put that in context, it’s 0.13 percent the size of JEDI. * Former Vice President of Worldwide Marketing Ariel Kelman has left to join Oracle, and in his absence, AWS is taking the opportunity to reorganize its executive ranks. * Amazon EFS introduces two new features: EFS access p
Your co-hosts kick off their first regular news episode of the year with Consumer Electronics Show 2020, Google Cloud Next 2020 and Justin’s Oracle adventure.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights 1. Amazon flexes its tech at the Consumer Electronics Show with an automotive exhibit. 2. Use coupon code GRPABLOG2020 for $500 off your ticket to Google Cloud Next 2020. 3. Justin does a bit of investigative journalism to understand Oracle’s new boot volume backup announcement.
Amazon Web Services (AWS) at the Consumer Electronics Show 2020 — Cars and CAs Those attending the Consumer Electronics Show in Las Vegas last week saw Amazon show off the practical uses of AWS technology and machine learning at their automotive exhibit. The exhibit includes an array of demonstrations from an in-vehicle digital assistant to car-to-home integrations to a fleet of autonomous cars in China. We’d like to see this sort of in-vehicle technology have constant cloud connectivity, where software updates can continue to be pushed out.
And speaking of updates, you may have already seen a notification or email for AWS’s upcoming 2019 certificate authority. From the article:
“If you are using Amazon Aurora, Amazon Relational Database Service (RDS), or Amazon DocumentDB (with MongoDB compatibility) and are taking advantage of SSL/TLS certificate validation when you connect to your database instances, you need to download & install a fresh certificate, rotate the certificate authority (CA) for the instances, and then reboot the instances.” -Jeff Barr Yeah, it’s a chore and it sucks to do, but if you use it and you don’t update your CA, you’ll have an outage. Is doing this once every five years really so bad? Lastly, in all AWS regions except China, you can now use Private DNS names to access your AWS PrivateLink based services. We’re happy to see it. Azure Recaps Cost Management for 2019 While Azure’s been quiet since Christmas, their cost management program manager published an article this week recapping the tools they’ve released over the last year to help you monitor and optimize the costs of your cloud operations. Not only can you now use Azure Cost Management to analyze your Azure and AWS spends, but GCP support is on the horizon too. Google: Access, Freeze, Next The new
Your co-hosts recap 2019 and make predictions for the year ahead on the first episode of 2020. We’re skipping the Lightning Round this week to focus on a collaborative Q&A segment pulled from our Slack channel.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights 1. Our top 3 favorite headlines of the year. 2. Google released a white paper to help you comply with the California Consumer Privacy Act (CCPA.) 3. We read your questions from our TCP Slack channel for our first Q&A!
2019 Cloud Computing Predictions and Headlines Recap Last year (episode 4), we shared our predictions for what might happen in 2019.
Peter took the lead, predicting container-based models would continue to see more adoption over serverless. Justin — who predicted mergers in cloud providers would create a new top contender, and Jonathan, who predicted an acquisition of Slack — haven’t been vindicated. (Yet!)
Our 3 favorite headlines of the year.
Justin: * Google Anthos is probably the best thought-out strategy for being multi-cloud with Kubernetes (if currently pricey.) * Azure Tardigrade uses machine learning to address hardware failures before they impact uptime. * Cloudwatch Container Insights shows off the power of Cloudwatch.
Peter: * Transit Gateway became a viable method of creating a global network. * DocumentDB (with MongoDB Compatibility) sets the direction for new business models for SaaS companies. * EKS SLA reaches a 3 nines standard of reliability.
Jonathan: * Google’s Explainable AI provides a way we can understand and begin to implement machine learning in important areas like healthcare. * Wavelength<
Your co-hosts settle into the winter holidays by unwinding from Re:Invent and recording the last episode of The Cloud Pod of 2019.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data — no matter its source — with the world’s leading monitoring and analytics platforms.
This week’s highlights 1. Amazon picks fights with Microsoft, the New York Times and the President. 2. Oracle’s finances reflect the trouble we predicted they’d be in when Amazon pulled out. 3. Google sets its sights on dramatically increasing its market share by 2023.
Return of the JEDI It’s official: the Joint Enterprise Defense Infrastructure (JEDI) contract has been awarded to Microsoft to modernize the Department of Defense’s IT systems to the tune of $10 billion. Amazon, which anticipated that it would be awarded the JEDI contract, believes the decision was politically motivated, and that Microsoft is under-equipped to deliver on their promises, highlighting the dangers of a vulnerability in such a sensitive system.
In case you missed it, Sundar Pichai will be taking over as the new CEO of Google. Since he was already the CEO of Google’s parent company Alphabet, don’t expect any drastic changes.
And speaking of CEOs, Safra Catz is now officially the sole CEO of Oracle following the death of her co-CEO Mark Hurd. After Amazon’s migration, she’ll have to deal with the company’s revenue challenges and falling stock prices. It’s not a great time for Oracle as the company continues to lose face with CIOs after years of licensing audits and exorbitant penalties. Football in the Amazon Amazon may have lost the contract with the DoD, but it can proudly claim to be the cloud computation provider for the Seattle Seahawks. Not only that, but Amazon will be partnering with the entire NFL for a new safety initiative analyzing impact data with a “digital athlete.
AWS CEO Andy Jassy gave an
Your co-hosts celebrate the one-year anniversary of the podcast by returning to the place where it all started - AWS Re:Invent. Joining us once again is Ryan Lucas (@ryron01) as we recap the largest week in Cloud.
A big thanks to this week’s sponsors: * Foghorn Consulting, which provides full stack cloud solutions with a focus on strategy, planning, and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure. * Blue Medora, which offers pioneering IT monitoring integration as a service to address today’s IT challenges by easily connecting system health and performance data–no matter its source–with the world’s leading monitoring and analytics platforms.
This week’s highlights * Machine Learning took center stage as the engine behind many of the new machines introduced over the week, and we expect to see it implemented more and more.
AWS Draft — and the Winner is… On episode 49, we drafted each of our top three picks for what we thought would be announced at Re:Invent. It’s a three-way tie for first! Each one of us correctly guessed one of our three picks, and nobody guessed that Anderson .Paak would make a musical appearance, leaving the tie unbroken. (Peter predicted that Formula 1 racing would be included, but it was a runner-up choice and goes uncounted.)
Moving on to Re:Invent, we cover the announcements day-by-day:
Sunday Toys and Security AWS launched DeepComposer, the world’s first machine learning enabled keyboard. The 32-key, 2-octave keyboard is designed to help developers to get hands-on with AI. You can train the program to generate compositions based on musical genres, but don’t expect any compelling vocals from it yet, though. Check out the announcement for sample selections. For only $99 you will be able to buy a MIDI keyboard (worth about $50) with the AWS logo on
DeepRacer, a machine-learning based toy from yesteryear has received its own upgrades (a stereo camera and LIDAR sensor) which allow the cars to be trained to race each other physically in addition to virtually.
Identity and Access Management (IAM) Access Analyzer launches for free as a way to get an overview on your access control policies — it mathematically analyzes access control policies attached to resources and determines which resources can be accessed publicly or from other accounts.
A preview version of EC2 Image Builder has also launched to help you maintain secure OS images for Windows Server and Amazon Linux 2. This is especially good for anyone just starting their cloud journey. We’re glad to see this available now, but where was it four or five years ago when it should
Sponsors: * Foghorn Consulting * Blue Medora
Your co-hosts are back from Thanksgiving and Re:Invent, and we’re running through all of it for you. In this episode, we cover the lead-up to opening day. Next week, we’ll release an episode fully devoted to Re:Invent coverage. This week’s highlights
CloudWatch has been growing quietly into a much more robust tool with 11 updates since the last episode.
Attribute-based access control comes to AWS. This should allow a finer control over your security privileges.
CloudTrail Insights launches with machine learning to help you separate the signal from the noise in your user activity and API usage.
Amazon EC2 introduces new API We’re one step closer to actually paying for what we use with the announcement that EC2 T2 instances will support Unlimited Mode at the account level. If your workload is spread out among multiple accounts, this will be something you should look at. But if you’re looking for load balancer updates, there’s a new batch of those for you too. We especially like the Weighted Target Groups, which have been needed for blue/green deployments for a while now. Restores and Replicas Migrating to the cloud has gotten a bit easier with differential and log restores on RDS for SQL servers. Like a lot of the recent announcements, simplicity was highlighted in the announcement of increased availability of DynamoDB tables using global table replicas.
“It’ll only take a few clicks” makes it sound like Amazon thinks clicking things must be very taxing on us. Secrets and Cents CloudTrail Insights will alert you to unusual activity at a cost of 35 cents per 100,000 write management events analyzed. It’s hard to know yet whether how expensive that will end up being, but it sounds cheap. AWS Single Sign-On will connect to Azure AD, making it easier to migrate to Amazon, and AWS Secrets Manager will make it easier to rotate your secrets by handling it at the API level.
AWS is moving from role-based to attribute-based access control and will be implementing Tag Policies to allow you to control the standardization of your tags. Implementing these should serve to become better organized with less pain. WAF has grown up, having gained a number of improvements. With a threat research team maintaining the rules, you’ll have protection even before you customize your rules. Devops and Devtools
AWS is getting ready for the biggest event of the year, Re:Invent 2019 in Las Vegas. Your Co-Hosts do their best to guess what AWS may announce, we cover some preannouncement news, and more!
NOTE: This episode was recorded on November 20th, to let the co-hosts enjoy Thanksgiving! This episode is AWS specific, as well as our first show after the Re:Invent conference. If you want to stay up to date on Azure or GCP in the interim, follow our Twitter @thecloudpod1 or join our Slack Channel.
Sign up for our Newsletter!! Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Topics AWS * CloudFormation Update – CLI + Third-Party Resource Support + Registry * Announcing Firelens – A New Way to Manage Container Logs * In The Works – New AMD-Powered, Compute-Optimized EC2 Instances (C5a/C5ad) * Amazon EKS adds support for provisioning and managing Kubernetes worker nodes * AWS Systems Manager Explorer – A Multi-Account, Multi-Region Operations Dashboard * Application Load Balancer Simplifies Deployment with Weighted Target Groups * Add defense in depth against open firewalls, reverse proxies, and SSRF vulnerabilities with enhancements to the EC2 Instance Metadata Service * Welcome to AWS Storage Day * Continuously monitor unused IAM roles with AWS Config
Reinvent Draft Jonathan 1. Zero/Low code application platform 2. Anthos like hybrid/multi-cloud platform/option 3. Transit Gateway cross-regional and/or Security group support
Peter 1. Layer 7 Egress Filtering Gateway 2. Cloudwatch Dependency Mapping (mute alerts if downstream from another alert) 3. Outposts GA and/or Shipping
Justin 1. Cost Reduction for the Network Tier 2. A device with a camera, like a drone, thing, etc that will replace the deepracer 3. Visual Threat Detection modeling for their security tools
Artist Pick * Jonathan: Calvin Harris * Peter: Marshmello - The Licks * Justin: David Guetta
Runner Ups
Docker sells off its enterprise business to Mirantis. Amazon gets upset with the pentagon and launches a data exchange. Azure wins a lucrative contract and GitHub actions. Google buys cloudsimple complicating things for the VMWare on Azure offerings.
Sign up for our new Newsletter! Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up Jonathan - Follows up on Redshift Topics General News/Topics * Container shakeup: Docker sells enterprise business to Mirantis, appoints new CEO * Amazon protests Pentagon’s cloud contract award, citing ‘unmistakable bias’
AWS * Import Existing Resources into a CloudFormation Stack * AWS Data Exchange – Find, Subscribe To, and Use Data Products * Continuous delivery of container applications to AWS Fargate with GitHub Actions
Reinvent Tips & Suggestions * Attending Sessions * Reinvent Parties * Replay
Google * Google launches new service for monitoring multicloud networks * Google makes biggest gains in ThousandEyes’ report on public cloud network performance * Google acquires CloudSimple to bring more VMware workloads into its cloud * Multi-tenancy support in Identity Platform, now generally available
Azure * In a win for Microsoft, Salesforce will migrate its Marketing Cloud to Azure * GitHub Actions for Azure is now generally available * Save more on Azure usage—Announcing reservations for six more services
Lightning Round (Jonathan 13, Justin 18, and Guest 5): * Amazon CloudSearch provides option to mandate HTTPS & minimum TLS version * <
AWS releases new RI option called the savings plan, IBM builds a financial services cloud, and @jeffbarr celebrates 15 years of blogging for AWS! Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up * Halloween Downtime RCA - Google
Topics General News/Topics * Capital One replaces security chief after data breach * Amazon doubles down on Boston as a robotics hub with new $40M facility * IBM: Bank of America Know-How Will Differentiate Financial Services Cloud
AWS * 15 Years of AWS Blogging! * New – Savings Plans for AWS Compute Services * Cross-Account Cross-Region Dashboards with Amazon CloudWatch * An outsider’s inside view on open source at AWS * AWS supports Automated Draining for Spot Instance Nodes on Kubernetes * Amazon QuickSight goes Mobile, launches Cross Source Join and More * PostgreSQL 12.0 Now Available in Amazon RDS Database Preview Environment
Reinvent Tips & Suggestions Google * Google releases its Skaffold tool for automating Kubernetes into general availability * Opening the door to more dev tools for Cloud Spanner
Azure * 10 user experience updates to the Azure portal * What’s new with Azure Monitor
Lightning Round (Jonathan 12, Justin 17, and Guest 5): * Updating Google App Engine with more new runtimes: Nodejs 12, Go 1.13, PHP 7.3 and Python 3.8 * Amazon EC2 now supports Microsoft SQL Server 2019
This week we discuss the Microsoft Ignite conference, announcements and new features and how we did on the Azure Draft. AWS announces a new Spain region and GCP had a lengthy halloween incident. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up * Amazon fails to stop ex-sales staffer winging it to Google Cloud * Accused Capital One hacker had as much as 30 terabytes of stolen data, feds say * Senators Wyden and Warren sic trade lapdog on AWS over Capital One hack culpability
Topics AWS * Amazon Web Services to expand into Spain with new cloud region * Post-quantum TLS now supported in AWS KMS
Google * GCP Halloween Outage - 10/31 6:30 PM Pacfic - 10/2 - 10:51 AM * Celebrity Recognition now available to approved media & entertainment customers * Cloud storage data protection that fits your business * Introducing TensorFlow Enterprise: Supported, scalable, and seamless TensorFlow in the cloud * Exploring container security: Use your own keys to protect your data on GKE
MS Ignite Draft Jonathan 1. Digital Assistant to compete with Alexa or Google Home. 2. 3 more Azure Regions in US 3. More or Improved tooling for Devops Community
Peter 1. Istio for AKS 2. 1 more region in Canada 3. Visual Studio Online
Justin 1. Azure Portal Redesign 2. Sagemaker/Databricks like Competitor. 3. Oracle on Stage
Azure * Microsoft Azure customers reporting hitting virtual machine limits in U.S. East regions * Companies of all sizes tackle real business problems with Azure AI * Simply unmatched, truly limitless: Announcing Azure Synapse Analytics
The DOD awards the coveted Jedi contract, the MS ignite Draft, Earnings season and more this week on The Cloud Pod. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up Topics * Pentagon awards controversial $10 billion cloud computing deal to Microsoft, spurning Amazon * Even after Microsoft wins, JEDI saga could drag on
General News/Topics Earnings Season * Microsoft’s cloud shines again as it easily tops earnings targets, but Azure slows * Despite AWS cloud growth, Amazon shares sag on lower forecast * Google Cloud fails to lift Alphabet enough to please investors
AWS * 200 Amazon CloudFront Points of Presence + Price Reduction * Native Container Image Scanning in Amazon ECR * AWS Global Accelerator Now Supports EC2 Instance Endpoints
Google * Updates make Cloud AI platform faster and more flexible * Advancing Customer Control in the Cloud * Swipe right for a new guide to PCI on GKE * Bring Your Own IP addresses: the secret to Bitly’s shortened cloud migration * What’s happening in BigQuery: New features bring flexibility and scale to your data warehouse
Azure * Preview: Server-side encryption with customer-managed keys for Azure Managed Disks * New in Stream Analytics: Machine Learning, online scaling, custom code, and more
MS Ignite Draft
Jonathan 1. Digital Assistant to compete with Alexa or Google Home. 2. 3 more Azure Regions in US 3. More or Improved tooling for Devops Community
Peter 1. Istio for AKS 2. 1 more region in Canada 3. Visual Studio Online
Justin 1. Azure Portal Redesign
Peter goes Absent With Out Leave - AWOL. Redhat can't save IBM's earnings, AWS starts detecting anomalies, Google adds 100-Gbps direct connect links to their data centers, and Azure gets FHIR-Y. We also take a few somber minutes to talk about the passing of Mark Hurd, Oracle's former Co-CEO. Plus the world famous lightning round.
Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up Topics General News/Topics * Oracle’s Mark Hurd, who was on medical leave, has died at 62 * Despite Red Hat boost, IBM misses revenue targets ? * Defense Secretary Mark Esper pulls out of JEDI cloud computing contract review
AWS * Amazon CloudWatch Anomaly Detection * Now Available – Amazon Relational Database Service (RDS) on VMware * Containers and infrastructure as code, like peanut butter and jelly * Amazon joins the Java Community Process (JCP)
Google * Improve your connectivity to Google Cloud with enhanced hybrid connectivity options * Leave no database behind with Cloud SQL for SQL Server
Azure * Microsoft unveils two open-source projects for building cloud and edge applications * Announcing the general availability of larger, more powerful standard file shares for Azure Files * Azure API for FHIR® moves to general availability
Lightning Round (Jonathan 11, Justin 16, and Guest 4): * AWS IoT Things Graph now provides workflow monitoring with AWS CloudWatch * Amazon CloudWatch now sends alarm state change events to Amazon EventBridge
Sponsors: Foghorn Consulting - fogops.io/thecloudpod * Ryan Lucas (@ryron01) fills in for Peter as we review the latest batch of cloud news. AWS re:Invent 2019 is just a month away and there’s no shortage of announcements this week either.
This week’s highlights * AWS re:Invent 2019 session catalog is live. If you haven’t gotten into the panels you want, you'll have to get on a waitlist. We’re also considering a podcast meetup! Please let us know if you’d be up for that. Reach out on Twitter or through the contact form. * Look at migrating from Oracle. It may take some time and effort to accomplish, but the savings Amazon’s had are results that bear an attempt at repeating. * You might be in luck if you have an open-source project. AWS is offering promotional credits to promote certain open-source work. Amazon completes massive migrations from Oracle After moving 75 petabytes of data involving 100+ teams, Amazon has finished migrating the last database of their first-party programs from Oracle to AWS services. The slashes in operational costs and latency may have the Amazon teams happy, but Oracle will definitely be watching to see if their other customers will be tempted to follow suit. A 90 percent reduction in cost would be an enticing prospect to switch providers of any service, and half the latency is nothing to sneeze at either.
Amazon looks to be taking some of those savings and turning them right back around into more projects. Of note, they will be offering promotional credits to those working on open-source projects, especially if you are working in Rust. If you manage to get a whole year of funding through Amazon that will mean more time working on what you really care about and less trying to keep the grants coming in every quarter or, worse, every month.
Rounding out AWS news, we discussed four other stories: 1. VPC security groups come to Firewall Manager. Finally. You’d think this would be included day one, but at least it’s here now. Maybe soon it’ll be updated to include federated access? 2. New M5n/R5n EC2 instances will offer up to 100 Gbps networking speeds. If you need to move around larger sets for machine learning, for instance, the price is reasonable. 3. EC2 instances will also be available in Arm-based bare metal form. The bare metal probably won’t grant much of an efficiency edge anymore, but hey, maybe it will help meet especially strict compliances. 4. AWS announced that another 18services have been FedRAMP authorized. If you’re working in the federal government, you now have a total of 48 AWS services available to you. The announcement comes off the back of Oracle gaining FedRAMP authorization for a handful of services. Way to laugh in Oracle’s face, AWS! Google offers new cloud architecture trainings
In an effort to
Justin is back from vacation and gets the podcast back on track. Justin, Peter and Jonathan talk about their guest spot on roaring elephants and Justin's AWS lambda fireside chat video. Elasticsearch sues AWS over trademark infringement, AWS gets its IQ raised, Oracle gets fedramp certified cloud regions and Google enhances their github app for cloud build. Plus the world famous lightning round. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up Topics Roaring Elephant https://roaringelephant.org/2019/10/08/episode-161-the-cloudpod-weather-report-part-1/
AWS
https://www.youtube.com/watch?v=8Aq2DIMRIIg&t=1s General News/Topics * Oracle Launches FedRAMP-Authorized Government Cloud Regions * Oracle will add 2,000 jobs and 20 data centers in cloud infrastructure push * AWS faces Elasticsearch lawsuit for trademark infringement * Ansible holds the pole position for automation, but is it too good and too small?
AWS * Now use AWS Systems Manager to execute complex Ansible playbooks * AWS DataSync News – S3 Storage Class Support and Much More * AWS IQ – Get Help from AWS Certified Third Party Experts on Demand * EC2 High Memory Update – New 18 TB and 24 TB Instances LR? * Amazon EKS Windows Container Support now Generally Available
Google * Cloud Build brings advanced CI/CD capabilities to GitHub * Optimize your Google Cloud environment with new AI-based recommenders * Announcing updates to AutoML Vision Edge, AutoML Video, and Video Intelligence API * Extending Stackdriver Logging across clouds and providers with new BindPlane integration
Azure
Chef finds a bad recipe for success, AWS rolls out Step Functions, Google launches its native load balancer for Kubernetes and Microsoft confuses us further with premium tier storage offerings. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Topics General News/Topics * A CIO’s guide to cloud success: decouple to shift your business into high gear * What’s Going on with GKE and Anthos? * Chef Saga + DevOps biz Chef roasted for tech contract with family-separating US immigration, forks up attempt to quash protest - 9/19 + Chef’s Position on Customer Engagement in the Public and Private Sectors 9/19 + An Update to the Chef Community Regarding Current Events 9/20 + A Personal Message From the CTO 9/20 + An Important Update from Chef 9/23 * A ‘Grass Roots’ Campaign to Take Down Amazon Is Funded by Amazon’s Biggest Rivals
AWS * Now Available – EC2 Instances (G4) with NVIDIA T4 Tensor Core GPUs * New – Step Functions Support for Dynamic Parallelism * Amazon S3 introduces same region replication * vCPU-based On-Demand Instance Limits are Now Available in Amazon EC2
Google * Virtual display devices for Compute Engine now GA * Container-native load balancing on GKE now generally available
Azure * Azure Files premium tier gets zone redundant storage * Introducing cost-effective increment snapshots of Azure managed disks in preview
Lightning Round (Jonathan 10, Justin 15, and Guest 4): * Introducing new Amazon EC2 Windows Server AMIs for DISA STIG compliance
Justin goes to Oracle World and comes back with a new understanding of OCI customers. VPC Flow logs get new metadata and we get an update on AWS outposts, but no date or pricing yet. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up * Investors send Cloudflare’s shares soaring 20% after IPO hauls in $525M
Topics AWS * Learn From Your VPC Flow Logs With Additional Meta-Data * Running AWS Infrastructure On Premises with AWS Outposts * What is an AWS Outpost? * AWS Service Catalog Announces Budget Visibility * Firelens now in Preview * Introducing NoSQL Workbench for Amazon DynamoDB — Now in Preview
Google * Google teams up with Mayo Clinic on AI-powered medical research * Anthos simplifies application modernization with managed service mesh and serverless for your hybrid cloud
Azure * Microsoft and Disney aim to speed up movie and TV production with new ‘scene-to-screen’ cloud deal * Announcing user delegation SAS tokens preview for Azure Storage Blobs * Announcing Azure Private Link
Oracle * Oracle co-CEO Mark Hurd takes leave of absence for unspecified health reasons * Introducing Simple, Unified Billing for Partner Solutions on Oracle Cloud Marketplace * Oracle Cloud Infrastructure Brings More Innovations to Customers * In an Industry First, Oracle Brings Autonomous Operation to Linux
Episode 39: Recorded on September 10th, 2019. Show Title: The Cloud Pod goes Quantum
This week AWS releases the Quantum Ledger Database, Google gets shielded GKE nodes and Microsoft gets a new shiny datacenter in Germany Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up * Slack stock plunges on bigger-than-expected loss forecast
Topics AWS * Introducing Fine-Grained IAM Roles for Service Accounts * Optimize Storage Cost with Reduced Pricing for Amazon EFS Infrequent Access * Building Spinnaker Features for Amazon ECS * Amazon EKS now supports K8 1.14 * Use AWS Config Rules to Automatically Remediate Non-compliant Resources * Now Available - Amazon Quantum Ledger Database (QLDB)
Google * Announcing the general availability of 6 and 12 TB VMs for SAP HANA instances on Google Cloud Platform * Exploring container security: Bringing Shielded VMs to GKE with Shielded GKE Nodes
Azure * Microsoft acquires infrastructure visibility provider Movere * Azure HPC Cache: Reducing latency between Azure and on-premises storage * Microsoft Azure available from new cloud regions in Germany * Satellite connectivity expands reach of Azure ExpressRoute across the globe * Building cloud-native applications with Azure and HashiCorp
Lightning Round (Jonathan 8, Justin 15, and Guest 4): * Introducing Analyzing Text with Amazon Elasticsearch Service and Amazon Comprehend
US-East-1 has a hiccup in a single AZ, Lambda fixes cold start launches inside a VPC, Google gets an AD service and Microsoft goes cloud neutral in Switzerland. Plus special guest @ryron01 Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up * In updated IPO filing, Cloudflare seeks up to $483M at $3.5B valuation
Topics AWS * US-Tire-Fire-1 had an outage * Operational Insights for Containers and Containerized Applications * Port Forwarding Using AWS System Manager Session Manager * Now use Session Manager to interactively run individual commands on instances * Client IP Address Preservation for AWS Global Accelerator * 64 AWS services achieve HITRUST certification * Take the AWS certified cloud practitioner exam in your home or office 24/7 * AWS Chatbot Now Supports Notifications from AWS Systems Manager * Amazon ECS now exposes runtime ContainerIds to APIs and ECS Console * Announcing improved VPC networking for AWS Lambda functions
Google * Managed Service for Microsoft Active Directory (AD) * Using Google Cloud Speech-to-Text to transcribe your Twilio calls in real-time * August on GCP
Azure * How Microsoft and Oracle became cloud buddies, and what’s next for their improbable partnership * Microsoft Azure's cloud regions in Switzerland are now open for business
VMWare acquires Pivotal and Carbon black, plus VMworld debrief. Google kills more products and AWS reduces the cost of SageMaker training. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Topics General News * Oracle files new appeal over Pentagon’s $10B JEDI cloud contract RFP process
VMWorld * VMware pays billions to acquire Pivotal Software and Carbon Black * VMWorld US 2019 Monday Recap * VMWorld US 2019 Tuesday Recap * VMware CEO Pat Gelsinger weighs in on acquisitions, blockchain, security and more * VMware Delivers a Hybrid Cloud Platform Powering Next-Generation Hybrid IT * VMware Announces VMware Tanzu Portfolio to Transform the Way Enterprises Build, Run and Manage Software on Kubernetes
AWS * Amazon Forecast is now GA * Introducing AI powered health data masking * Managed Spot Training: Save Up to 90% On Your Amazon SageMaker Training Jobs * AWS Systems Manager Parameter Store announces intelligent-tiering to enable automatic parameter tier selection
Google * Introducing Cloud Run Button: Click-to-deploy your git repos to Google Cloud * Cloud Text-to-Speech expands its number of voices by nearly 70%, now covering 33 languages and variants * Google will shut down Google Hire in 2020
Azure * Preview of custom content in Azure Policy guest configuration
AWS introduces new kernel panic API trigger, Azure storage gets complicated, and Google's big query gets a terraform module. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up * Cloudflare files for IPO, revealing revenue of $129M in first half of 2019
Topics General News * Alibaba blows past earnings estimates cloud business hits 4.5b run rate * Digital Ocean launches new managed MySQL and Redis Database Services
AWS * New – Trigger a Kernel Panic to Diagnose Unresponsive EC2 Instances * Amazon Prime Day 2019 – Powered by AWS * AWS App Mesh now supports routing based on HTTP headers and specifying route priorities * Easily enable AWS Systems Manager capabilities with Quick Setup * Amazon ECS Now Supports Per-Container Swap Space Parameters * 081319 Amazon Letter to Sen Wyden RE Consumer Data.pdf * Original letter: https://www.wyden.senate.gov/imo/media/doc/080519%20Letter%20to%20Amazon%20re%20Capital%20One%20Hack.pdf * Amazon Redshift now recommends distribution keys for improved query performance
Google * Skip the heavy lifting: Moving Redshift to BigQuery easily * Shining a light on your costs: New billing features from Google Cloud * Introducing the BigQuery Terraform Module
Azure * Improving Azure Virtual Machines resiliency with Project Tardigrade * Geo Zone Redundant Storage in Azure now in pr
Github.com gets a CI/CD Service, Lakes are forming with lake formation and Google and Azure get EPYC this week on the show. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up * Amazon and Capital One face legal backlash after massive hack affects 106M customers * Intersect.AWS music festival has released ticket and lineup information
Topics General News * GitHub gets a CI/CD service * Announcing the preview of Github Actions for Azure * Pentagon pushes back JEDI winner decision by weeks amid fresh review * Pentagon Makes case for Return of the Jedi: There's only one cloud biz that can do the job and its starts with an A (or rhymes with loft) + https://media.defense.gov/2019/Aug/08/2002168542/-1/-1/1/UNDERSTANDING-THE-WARFIGHTING-REQUIREMENTS-FOR-DOD-ENTERPRISE-CLOUD-FINAL-08AUG2019.PDF * Apple is a filthy AWS, Azure, Google Reseller, grip punters: iPhone giant accused of hiding iCloud's real backend
AWS * Local Mocking and Testing support with Amplify CLI * AWS Lake Formation - Now GA * Amazon Aurora Multi-Master is Now GA + https://aws.amazon.com/blogs/database/building-highly-available-mysql-applications-using-amazon-aurora-mmsr/ * Preview Release of the new AWS tools for Powershell * AWS step functions adds support for nested workflows * New AWS Training Courses teach APN partners to better help their customers * Amazon Rekognition now detects violence, weapons and self-injury in images and videos; improves accuracy for nudity detection
Special guest Josh Stella joins us to talk about the Capital One breach. AWS releases PartiQL, one query language to rule them all, Microsoft licensing changes and more. Plus we talk more about Josh's company @Fuguehq in Cool Tools. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up Capital One * A Technical Analysis of the capital one cloud misconfiguration breach
Topics General News * Cloudflare reportedly files to go public in September
AWS * Amazon acquires enterprise flash storage startup E8 Storage * Amazon sues former AWS exec for joining rival Google division as cloud wars escalate * AWS CloudFormation Update – Public Coverage Roadmap & CDK Goodies * Introducing the preparing for the california consumer privacy act whitepaper * Announcing PartiQL: One query language for all your data
Google * Google debuts migration tool for its Anthos hybrid cloud platform * New protections for users, data, and apps in the cloud
Azure * Introducing Azure Dedicated Host * Cisco and Microsoft integrate their Kubernetes container platforms * Azure Archive Storage is better with new lower pricing * Microsoft has updated licensing rights for dedicated cloud hosts + https://twitter.com/Werner/status/1158458860790779905 + https://twitter.com/RobertEnslin/status/1159225726949720064?s=20 * Microsoft launches new Azure Security Lab, offering up to $300k to anyone who can hack its public cloud
Lightning Round (Jonathan 8, Justin 11, and Guest 3):
Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Follow Up AWS Reinvent Music Festival - https://intersect.aws/ Topics General News * Earnings + Amazon shares dip missing profit expectations tech giant posts 63.4billion in Q2 revenue + Microsoft trumpets record year with $126b in Annual Revenue up 14% as quarterly profits beat estimates + Google Cloud's run rate is now over $8B + Alphabet announces second quarter 2019 results
AWS * eksctl – the EKS CLI * AWS Released resource optimization recommendations * Stackery lets AWS lambda developers debug their serverless programs locally on a laptop * AWS Launches a chatbot for chatops * AWS client VPN now adds support for split tunneling * AWS Secrets Manager now supports VPC endpoint policies * Announcing the new AWS Middle East Bahrain Region
Google * Google partners with VMWare to bring virtualized workloads to GCP * Brick by Brick: Learn GCP by setting up a kid-controllable Minecraft server
Azure
Gartner releases the new magic quadrant for IaaC and PaaS Cloud providers and Amazon continues to dominate. AT&T gets busy with the cloud, Google introduces spinnaker and Microsoft invests 1B in OpenAI this week on The Cloud Pod. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Topics * Introducing the Amazon Corretto Crypto Provider for improved Crypto Performance * Advancing Microsoft Azure reliability * Introducing proximity placement groups * IBM inks multi-billion dollar cloud computing deal with AT&T * Microsoft & AT&T sign $2B+ cloud infrastructure and services deal * The case against Amazon: Why the tech giant is facing antitrust scrutiny on two continents * Arrested Development: Cops Dump Amazon's facial-recognition API after struggling to make the thing work properly * AWS named as leader in Gartner's Infrastructure as a Service (IaaS) Magic Quadrant for 9th consecutive year * Introducing Spinnaker for Google Cloud Platform - CD made easy * Azure is making it easier to bring your linux based web apps to Azure App Service * Microsoft will invest $1B for OpenAI aimed at improving Azure cloud platform
Lightning Round (Jonathan 8, Justin 9, Peter 1 and Guest 3): * Azure is Silo Busting with new Multi-Protocol access for the Azure Data Lake * Azure Monitor for containers with Prometheus now in preview * Amazon ECR now supports increased repository and image limits * AWS Cost Explorer
The team is back after some well deserved time off, with a busy two weeks they try to cover everything. AWS NYC event, Azure Migration Program, EC2 Instance connect and AWS budget reports. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Topics * Announcing the General Availability of Azure Premium Files * AWS OpsCenter - A new feature for streamlining IT Operations * Amazon Aurora PostgreSQL Serverless - Now GA * Amazon EventBridge - Event Driven AWS Integration for your SaaS applications * AWS Cloud Development Kit (CDK) for typescript and python are now GA * NYC Summit draws Protests * Google Acquires Storage Startup Elastifile for reportedly 200m * Production debugging comes to Google Cloud Source Repositories * Google has introduced a new Jenkins GKE plugin to deploy software to K8 * Google Announces new Cloud Region and Google Data Center in Nevada * Introducing Equiano, a subsea cable from Portugal to South Africa * Introducing the Azure Migration Program * Announcing preview of Azure Data Share * Session Manager launches tunneling support for SSH and SCP * Introducing Amazon EC2 Instance Connect * Introducing AWS budgets reports * Amazon Cloudwatch Anomaly Detection - Now in Preview
We talk about AWS EKS 1.13 release, Slack IPO, GCP Workload identity and more this week on the cloud pod. Note: This episode was recorded after reinforce recap show due to vacation schedule of the hosts. We will cover the first few weeks of July for all cloud providers in Episode 31 and then back to normal schedule. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod
Topics * App Engine second generation runtimes now get double memory, plus go 1.12 support and PHP 7.3 * Virtual machine scale set insights from Azure Monitor * Amazon EKS now supports K8 1.13, ECR Private Link and Kubernetes Pod Security Policies * The cloud goes 'cloudless' * AWS @ OSCON 2019 * Slack stock soars 50% in direct NYSE listing, Now valued at $20 billion + dolalrs * Amazon RDS now supports Storage Autoscaling * GCP Workload Identity: Better Authentication for your GKE Apps
Lightning Round (Jonathan 7, Justin 9, Peter 1 and Guest 3): * Microsoft Positioned as a Leader in the Forester WaveTM: Database as a Service * Amazon Quicksight now supports fine-grained access control over Amazon S3 and Athena * Amazon API Gateway Adds Configurable Transport Layer security version for Custom Domains * AWS Glue now provides workflows to orchestrate ETL workloads * Amazon Aurora with PostgreSQL compatability supports data import from Amazon S3 * AWS Lambda Console shows recent invocations using cloudwatch insights * AWS has announced
We recap the AWS Reinforce conference from Boston Massachusetts. Draft results, overall impressions of the conference and we break down each announcement.
Sponsors: * Foghorn Consulting - fogops.io/thecloudpod * Turbonomic - turbonomic.com/cloudpod
Reinforce Results Justin 1. DLP Cloud solution on AWS 2. SIEM for AWS 3. Endpoint Security Tools
Jonathan 1. Redlock or Trusted Advisor for security 2. VPC Security Group Improvements 1. Lists of Source IP’s 2. IP/Name matching/Tag sources for Security Groups 3. Machine Learning around Flowlogs and Payload data
Peter - Wins! 1. L7 Egress Firewall/proxy 2. Flowlogs with Payload data/Packet Capture - VPC Traffic Flow Mirroring 3. Security Scanning of Container for ECR
Honorable Mention * Justin + WAF Enhancement + Client VPN based Dynamic Access/Security Groups + Tagging Namespace fix * Jonathan + Organizations enhancements to make security easier across a set of accounts * Peter + Lunch will be free
Reinforce Announcements * AWS Certificate Manager Private CA now supports Root CA hierarchy * You can now use IAM access Advisor with AWS Organizations to set permission guardrails confidently * Network Load Balancer Now Supports UDP Protocol * Amazon FSx for Windows File Server Now Enables you to use your File Systems Directly with Your organizations self-managed active directory * Amazon FSX for WIndows File Server now enables you to use a single AWS Managed AD with file systems across VPC's and Accounts * File Gateway Adds options to enforce encryption and signing for SMB shares * New Service Quotas: View and manage your quotas for AWS services from one central location * Amazon DynamoDB now supports up to 25 unique items and 4 MB of data per transactional request<
It is the week before AWS Re:Inforce and that means it is time for the draft! Cloud Endure migrate is now free of charge, Azure has a shared image gallery and Mongo comes to Google Cloud this week on the podcast. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod * Turbonomic - turbonomic.com/cloudpod
Topics: * Cloud Endure Migration is now available at no charge * Azure Shared Image Gallery now GA * Microsoft FHIR server for Azure extends to SQL * 15 Highlights from the 2019 AWS Public Sector Summit Keynote * Amazon S3 Update - SigV2 Deprecation Period Extended & Modified * Github acquires Pull Panda to power up Collaboration for software teams * 2 new AWS C5 instance types and 1 new C5 metal server * Announcing the preview of Microsoft Azure Bastion * Mongo DB Atlas comes to Google Cloud * Azure launches first middle east regions
Reinforce Predictions * Justin + DLP Cloud solution on AWS + SIEM for AWS + Endpoint Security Tools
Honorable Mentions * Justin + WAF Enhancement + Client VPN based Dynamic Access/Security Groups + Tagging Namespace fix * Jonathan + Organizations enhancements to make security easier across a set of accounts * Peter + Lunch will be free
Lightning Round (Jonathan 6, Justin 9, Peter 1 and Guest 3): * Amazon Aurora with Post
Google Publishes RCA on their outage, Microsoft and Oracle enter into a cloud alliance and AWS improves incident resolution with Systems Manager Opscenter. Sponsors: * Foghorn Consulting - fogops.io/thecloudpod * Turbonomic - turbonomic.com/cloudpod
Follow Up: * Google Cloud networking incident 19009 Final RCA
Topics: * Google releases new Translate API Capabilities to help localization experts and global enterprises * Google now allows you to save money by stopping and starting compute engine instances on a schedule * Google has created more choice, less complexity in their latest Google Compute Engine Pricing updates * Azure forecasting has added several new features * Microsoft Azure and Oracle Partner Up * Microsoft and Oracle to interconnect Microsoft Azure and Oracle Cloud * Overview of the Interconnect between Oracle and Microsoft * AWS is introducing AWS Systems Manager Opscenter to enable faster issue resolution * Google continues to preach multi-cloud with the acquistion of Looker * Amazon Personalize is now GA * Lightning Round (Jonathan 6, Justin 9, Peter 1 and Guest 3): * Amazon API Gateway now supports VPC Endpoint Policies * AWS Glue now provides VPC interface endpoint * Amazon Inspector adds CIS Benchmark support for Amazon Linux 2 * Google has announced integrated partnership for Snowflake on Google Cloud Marketplace * Azure has released new Mobility SDKs for Azure Maps * AWS organizations now support tagging and untagging of AWS Accounts * Amazon ECS now supports increased ENI limits for tasks i
Peter is back after a few weeks away from the show. Azure launches new Event Grid features, Palo Alto Networks picks up Twistlock and Puresec and Google has a really bad day. Plus the amazing lightning round with Peter.
Sponsors:
Foghorn Consulting - https://fogops.io/thecloudpod Topics: * 25th Episode Blog Post * Azure has simplified event-driven architectures with new updates to Event Grid * Palo Alto Networks enters into definitive agreement to purchase Twistlock and Puresec * Oracle Lays off hundreds from its Seattle office as its cloud strategy remains grounded * Azure Adaptive network hardening in Azure Security Center is now GA * Amazon EBS adds ability to take point-in-time, crash-consistent snapshots across multiple EBS volumes * Announcing Tag-Based Access Control for AWS Cloudformation * New Data API for Amazon Aurora Serverless * Amazon Managed Streaming for Apache Kafka (MSK) - Now Generally Available * Google Cloud has Major Outage on 6/2 + Google Cloud Outage resolved, but it reveals holes in cloud computing atmosphere + An update on Sunday's service disruption
Lightning Round (Jonathan 6, Justin 9, Peter 1 and Guest 3): * AWS is Announcing Windows Server version 1903 AMI's for Amazon EC2 * Amazon Chime now supports United States Toll-Free Numbers * AWS Storage Gateway Service adds capability to move Virtual Tapes from S3 Glacier to Glacier Deep Archive * AWS has introduced Fraud Detection capabilities using Machine Learning
This week we talk about Cloud Center of Excellence, New Encryption options, open source update on Firecracker and more. Elise Carmichael (twitter: @uncfleece) from @tricentis joins us to talk about some of their tools. Sponsors: Foghorn Consulting - https://fogops.io/thecloudpod Topics: * New - Updated Pay-Per-Use Pricing Model for AWS Config Rules * Google Says some G-Suite Passwords were stored in Plaintext since 2005 * Google Cloud - Optimize your organizations cloud journey with a Cloud Center of Excellence * Amazon RDS for SQL Server increases database limit per database instance up to 100 * AWS Opt-In to Default Encryption for New EBS Volumes * AWS Ground Station - Ready to ingest & process Satellite Data * Firecracker Open Source Update May 2019 * Application Management made easier with Kubernetes Operators on GCP Marketplace * Amazon RDS for SQL Server now supports Always On Availability Groups for SQL Server 2017 * Github launches Sponsors, lets you pay your favorite open source contributors * Manage your cross cloud spend using Azure Cost management
Lightning Round (Jonathan 5, Justin 9, Peter 1 and Guest 3): * AWS now allows you to enable Hibernations on EC2 instances at the same time as you launch the AMI * Amazon Document DB (with MongoDB Compatibility) is now SOC 1, 2, 3 Compliant * AWS Marketplace enables long term contracts for AMI products * AWS Budgets now Supports Variable Budget Targets for Cost and Usage Budgets * Amazon RDS Recommendations Provide Best Practice Guidance for Amazon Aurora * All US Azure regions now approved for FedRAMP High impact level
Kubecon is happening in Barcelona, Spain, VMWare purchases bitnami, Apptio buys Cloudability and a ton of Kubernetes announcements out of KubeCon this week on The Cloud Pod. Sponsors: Foghorn Consulting - https://fogops.io/thecloudpod Topics: * A Cosmonaut's guide to the latest Azure Cosmos DB Announcements * VMWare snaps up Bitnami to broaden its multi-cloud strategy * Apptio buys Cloudability as cloud cost management market heats up * Introducing Terraform Cloud Remote State Management * Cloudwatch container insights for EKS and Kubernetes Preview * Digital Ocean K8 service is now Generally Available * Google Announces new enhancements to ease adoption of GKE + In celebration of K8 5th birthday GCP is giving away a free month of learning at Coursera with the Architecting with GKE course. (valid until September 30th)
Lightning Round (Jonathan 5, Justin 8, Peter 1 and Guest 3): * EKS has simplifed K8 cluster authentication with new CLI Sub command for generating the authentication token for connecting * You can now use custom chat bots with Amazon Chime * Performance insights now supports Amazon Aurora Global Database * AWS Migration hub now provides right-sized Amazon EC2 instance recommendations * Amazon Sagemaker Ground Truth now supports Automated Email Notifications for Manual Data Labeling * AWS APAC Mumbai region adds third availability zone * AWS APAC Seoul Regions adds third availability zone
This week on The Cloud Pod, Amazon S3 deprecates path style routing, then changes their mind. Azure reliability suffers in the first part of the year, and Google summarizes their IO cloud announcements. Sponsors: Foghorn Consulting - https://fogops.io/thecloudpod Topics * Amazon S3 will no longer support path-style API requests starting September 30th, 2020 + https://github.com/SummitRoute/aws_breaking_changes + https://aws.amazon.com/blogs/aws/amazon-s3-path-deprecation-plan-the-rest-of-the-story/ * Azure App Service update: Free Linux Tier, Python and Java support, and more * New – The Next Generation (I3en) of I/O-Optimized EC2 Instances * Azure SQL Data Warehouse releases new capabilities for performance and security * Google Cloud at I/O: The news you need to know * Steve Singh stepping down as Docker CEO * AWS Secrets Manager supports more client-side caching libraries to improve secrets availability and reduce cost * Microsoft may be all-in on cloud computing, but Azure Reliability is lagging the competition + https://searchcloudcomputing.techtarget.com/news/252463190/Microsoft-to-reduce-Azure-outages-with-Project-Tardigrade
Lightning Round (Jonathan 5, Justin 7, Peter 1 and Guest 3) * Azure has improved their portal with improvements to search, change tracking, faster and more intuitive resource browsing * Azure Integration Services has simplified adoption of serverless with Azure Functions including new SAP connectors, Logic Apps and API Management * Azure now introduces health to azure deployment manager to detect problems with your deployment and automate rollback processes * Amazon and its Partners can now resell VMWare on AWS
Azure suffers an outage, AWS Snowballs drive block storage at the edge, S3 Batch Operations and Fully Managed Blockchain all this week on the cloud pod! Plus Lightning Round and Cool Tools with Jonathan. Sponsors: Foghorn Consulting - https://fogops.io/thecloudpod Follow Up * VMWare CEO implies Amazon Partnership is more important than Azure
Topics * Use AWS Transit Gateway & Direct Connect to Centralize and Streamline Your Network Connectivity * AWS Snowball Edge adds block storage for edge computing workloads * New — Analyze and debug distributed applications interactively using AWS X-Ray Analytics * Migrate your aws site-to-site VPN connection from Virtual Private Gateway to an AWS Transit Gateway * Amazon S3 introduces S3 Batch operations for Object Management * 5/2 Azure Outage & RCA * Azure Fully Managed Blockchain Service * Azure Intelligent Edge Innovation across data, IOT and Mixed Reality * Azure Making AI real for every developer and every organization * AWS Amplify launches an online community for fullstack serverless app developers + https://amplify.aws/community * A deep dive into what's new with Azure Cognitive Services * Partnering with the community to make Kubernetes easier * Accelerating DevOps with GitHub and Azure * Google Cloud and Service Now announce strategic partnership to enable intelligent digital workflows
Lightning Round (Jonathan 4, Justin 7, Peter 1 and Guest 3)
A New Cost Management blog, APAC gets a new AWS region and Docker Hub gets hacked. Plus Alphabet, Microsoft, and Amazon all release earnings and we break out the highs and lows. With special guest, Ian Mckay @iann0036 talks about his new AWS tool www.former2.com Sponsors: Foghorn Consulting - https://fogops.io/thecloudpod Follow Up * Apple actually reducing dependence on Amazon Cloud services
Topics * Ford Partners with Amazon to build cloud service connected cars * New AWS cost management blog launches * New Query for AWS Regions, Endpoints, and More using AWS Systems Manager Parameter Store * Earnings Season + Microsoft beats Wall street expectations, posting $30.6B in revenue, powered by cloud division + AWS revenue approaches $8 Billion in Q1, up 41% compared to last year + Despite Cloud growth, slowing revenue at Alphabet sends investors fleeing * AMD EPYC-Powered Amazon EC2 T3a instances * Now Open - AWS Asia Pacific (Hong Kong) Region * Slack renegotiated its deal with AWS in 2018, will spend 212 million more through 2023 * 190,000 user accounts exposed in hack of Docker Hub Database * Microsoft container registry unaffected by recent docker hub data exposure * VMWare brings its virtualization software to Microsoft Azure * AWS Deep Racer League Virtual Circuit is now Open
Lightning Round * AWS Single Sign-On now offers certificate customization to support your corporate policies
Google Kubernetes Engine Advanced, Jedi Contract Finalists, Cloud Migrations services and Apple’s 30 million a month spend on AWS this week on The Cloud Pod, plus the lightning round. Sponsors: Foghorn Consulting - https://fogop.io/thecloudpod Topics: * Improve Enterprise IT Procurement with Private Catalog, now in Beta * Introducing GKE Advanced - Enhanced reliability, simplicity and scale for enterprise + https://medium.com/@tinder.engineering/tinders-move-to-kubernetes-cda2a6372f44 * Amazon Cloudfront is now available in mainland China * Move your data from AWS S3 to Azure Storage using AzCopy * Announcing Azure to AWS Migration support in AWS Server Migration Service * Rewrite HTTP headers with Azure Application Gateway * Much to Oracles' chagrin, Pentagon names Microsoft and Amazon as $10B JEDI contract finalists * Announcing Azure Government Secret Private preview and Expansion of DOD IL5 * AWS Organizations now available in the AWS Govcloud regions for Central Governance and Management of AWS accounts * Google Hires 27-year SAP veteran Robert Enslin to boost cloud sales and support * Cloudbees buys Electric Cloud to strengthen Devops Platform * Microsoft Open sources data accelerator an easy to configure pipeline for streaming at scale * Apple spends more than 30m a month on AWS * AWS Cloudformation coverage updates for EC2, ECS and ELB
Lightning Round * Announcing the new AWS ce
We are back to our normal show after our GCP Next recap. This week the new AWS APAC region, Azure premium tiers and the AWS open letter on climate change. Plus the lightning round and cool tools. Sponsors * Foghorn Consulting: fogops.io/thecloudpod
Topics * Alerts in Azure are now all the more consistent * Self-Service exchange and refund for Azure Reservations * Unlock Dedicated resources and enterprise features with Service Bus Premium * Extending Azure Security Capabilities * AWS Boosts presence in Asia with new Indonesia cloud region * Spinnaker continuous delivery platform now with support for Azure * Azure Front Door service is now GA * Amplify Framework simplifies configuring Oauth 2.0 flows, hosted UI and AR/VR scenes for Mobile and Web * Introducing the App Service Migration Assistant for ASP.NET applications * Azure security center exposes crypto miner campaign * Gizmodo reports that Amazon is Aggressively pursuing big oil as its clean energy initiative stalls * 6562 Amazon employees have signed letter * AWS simplifies replatforming of MS SQL databases from Windows to Linux * New Release for Open Distro for ES 0.8.0
Lightning Round (Jonathan 4, Justin 4, Peter 1 and Guest 3) * AWS Cloudwatch launches search expressions * AWS Cloud 9 announces support for ubuntu development environments * Announcing the Azure Functions Premium plan for enterprise serverless workloads * Windows Server 2019 support now available for Windows Containers on Azure App Service
Google Next has wrapped up in San Francisco and we break down the announcements, talk about Google's enterprise play, and more. Special guest Ryan Lucas @ryron01 #googlenext19 #thecloudpod #gcp Sponsors Foghorn Consulting: fogops.io/thecloudpod Audible: audibletrial.com/thecloudpod
Topics Google Next Draft Results General Thoughts/Impressions Pre-Next Announcements * Introducing Compute and Memory Optimized VMs * Announcing the Cloud Healthcare API (Beta) * Google Cloud Memorystore Now with Redis 4.0 and Manual Failover API's
Next Announcements * Google Anthos * Cloud Run * Fully Managed Open Source Partnerships * Enterprise Databases Managed For you Enhancements and New Engines * Big Query Business Intelligence Engine * Google Voice for G Suite * New Storage Features * Google Cloud is the best place to run your microsoft windows apps * Introduce Cloud Code IDE integrations * New GCP Regions in Seoul and Salt Lake City * Choose your own environment with Apigee hybrid API management * Introducing Traffic Directory and other network enhancements * Increasing Trust - Visibility, Control and Automation
Episode 17 Azure announces new data and discovery classification features, AWS APN changes go into effect, and Chef goes 100% Open Source. Jonathan, Justin and Peter draft their Google Next 2019 predictions and more on the cloud pod. #thecloudpod Sponsors * Foghorn Consulting: fogops.io/thecloudpod * Audible: audibletrial.com/thecloudpod
Follow Up * KubeCTL - Cuttle or Control or C-T-L * Mitigating Risk in the hardware Supply Chain
Topics * Now Go Build #2 * Channel 9 releases information on Global Azure Bootcamp * Azure has announced preview of Data Discovery and Classification for Azure SQL Data Warehouse * Azure Search has new storage optimized service tiers in preview * AWS 2019 APN Changes in Effect * Amazon DynamoDB drops the price of global tables by eliminating associated charges for DynamoDB Streams * Scale Storage out with new Elastifile Cloud File Service for GCP * Chef goes 100% Open Source
Google Next Prediction Draft * Jonathan Picks
New languages for functions
Justin Picks
Major spanner enhancement
Google Siem Product
Peter Picks
Major announce around GKE in particular monitoring integration
Hybrid Service mesh. ISTIO like for hybrid cloud
Honorable Mention -
Lightning Round * AWS Firewall Manager now supports AWS Shield Advanced * Amazon Comprehend now supports AWS KMS encryption * Amazon Aurora with Postgresql now supports logical replication
AWS Summit Season 2019 is officially underway. Justin, Peter and special guest Chris Short @chrisshort. Plus the famous lightning round. Sponsors Foghorn Consulting: fogops.io/thecloudpod
Audible: audibletrial.com/thecloudpod Topics AWS Multi-Account Support for Direct Connect Gateway Introducing AWS Deep Learning Containers AMD Processors now available on AWS Ec2 Instances AWS S3 Glacier Deep Archive GA AWS App Mesh now Generally Available Concurency Scaling for Amazon Redshift New ALB Request routing for HTTP customer headers AWS Transfer for SFTP now supports VPC's and Private Link AWS Toolkit for IntelliJ GA and Visual Studio Code now in Preview Amazon EKS opens public preview for Windows Container Support ECS now supports local testing AWS Fargate and ECS now support external deployment control Episode #2 of Now Go Build New IAM permissions to enable accounts for new regions Google Releases new SRE tools and Training Azure has released new capabilities for Hybrid Cloud Service Control Policies in Organizations enable fine-grained permissions Lightning Round
Google finds a use for unused Kubernetes capacity by calculating PI, The Hyperscalers double down on gaming platforms and Azure beats Amazon to DOD certification! Plus the lightning round and cool tools with Jonathan. Sponsors * Foghorn Consulting: fogops.io/thecloudpod * Audible: audibletrial.com/thecloudpod
Follow Up Open Distro for ES * Free Software is the only Winner Elastic NV vs AWS - Adam Jacobs * Cloud Open Source Powder Keg
Topics AWS Re:inforce 2019 Registration now open Azure Simplifies environment setup with new blueprints for ISO27001 environments Workload Importance for Azure SQL Data Warehouse in Preview
Gaming Developers Conference
Microsoft Game Stack allows you to Achieve More Google Cloud makes Game Development More Open and Flexible AWS announced 190 new features for Lumberyard 1.18 Amazong Gamelift Realtime Servers in Preview Google Cloud has reached a new record computing 31.4 trillion digital of PI on Pi Day The Google Cloud Next 19 Session guide is Now available GCP Turning Data into NCAA March Madness Insights Cloudflare raises Fresh 150 million round delaying IPO AWS Joins the GraphQL Foundation Azure Government is First Cloud to Achieve DOD impact level 5 Provisional Authorization & GA of DOD regions Azure Data Studio - Open Source Gui for Postgres Lightning Round AWS Private Link now supports access over VPC Peering Amazon FSX for Lustre now supports access from amazon Linux Amazon RDS for Oracle now supports in region read replicas with Active Data Gu
This week Matt Adorjan (@mda590) joins us to talk about AWS's open distro for ElasticSearch, Breaking up big tech, and F5 acquiring Nginx. Plus the lightning round and Cool Tools with Jonathan. Thanks to our sponsors! Foghorn Consulting: fogops.io/thecloudpod Audible: audibletrial.com/thecloudpod Show Topics How does your cloud storage grow? With a scalable plan and a price drop Azure Premium Blob storage now in public preview Simply Enterprise Threat Detection and Protection with Google Cloud Security Services Elizabeth Warren bold plan to break up big tech Azure Devops Server 2019 now available AWS Announces Open Distro for Elastic Search Adrian Cockcroft publishes blog on keeping open source open Elastic.Co Response to open distros open source F5 Acquires NGINX Lightning Round AWS Performance Insights is now GA for SQL Server
https://aws.amazon.com/about-aws/whats-new/2019/03/performance-insights-is-generally-available-for-sql-server/
AWS SSM on-Premise now handles large hybrid environments (Previously less than 1000 instances)
https://aws.amazon.com/about-aws/whats-new/2019/03/AWS_Systems_Manager_on-premises_instance_management_for_large_hybrid_environments/
AWS Coretto 11 is now available as a release candidate
https://aws.amazon.com/about-aws/whats-new/2019/03/amazon-corretto-11-is-now-available-as-a-release-candidate/
AWS Step functions adds tag based permissions
https://aws.amazon.com/about-aws/whats-new/2019/03/aws-step-functions-adds-tag-based-permissions/
New AWS Direct Connect Console
https://aws.amazon.com/about-aws/whats-new/2019/03/announcing-the-new-aws-direct-connect-console/
Starbucks launches its latest drink the cloud macchiato
https://www.cnbc.com/2019/03/04/starbucks-launches-its-latest-drink-the-cloud-macchiato.html
AWS Code Commit now supports VPC Endpoints
https://aws.amazon.com/ab
Lyft goes all in on AWS and commits big money to AWS in their IPO. Several new solutions for security from the cloud vendors at RSA this week, and Jeff Barr stops by Reddit to tell us all about cloud formation! Plus the lighting round and cool tools with Jonathan. Sponsors: Foghorn Consulting: fogops.io/thecloudpod Audible: audibletrial.com/thecloudpod Show Topics: Lyft goes all in on AWS Google Releases csp config management for k8 GCP introduces new KMS client libraries Instantly restore your machines with Azure Backup SuperMicro hardware weakness lets researches backdoor into an ibm cloud server RightScale state of the cloud reports indicates Azure gaining on AWS * https://twitter.com/QuinnyPig/status/1100893328348831745
Maria DB ceo accuses hyperscalers of strip mining open source Azure announces preview of sentinel security Azure GA of Lab Services Jeff Barr stops by Reddit to drop a quick cloudformation update * Original Thread
Azure Security Center new Capabilities Azure announces new firewall capabilities Lightning Round: Amazon Worklink now works with Android Phones -
https://aws.amazon.com/about-aws/whats-new/2019/02/amazon-worklink-now-works-with-android-phones/
Aurora Serverless now publishes logs to cloudwatch - https://aws.amazon.com/about-aws/whats-new/2019/02/amazon-aurora-serverless-publishes-logs-to-amazon-cloudwatch/
Amazon Document DB now supports aggregations in arrays and indexing - https://aws.amazon.com/about-aws/whats-new/2019/02/Amazon-DocumentDB-new-features-for-aggregations-arrays-and-indexing/
AWS SSM now supports document sharing across accounts -
Episode 12 This week we talk about Athena Workgroups, Spotinst AWS partnership, Spatial Anchors in Azure and Microsoft and Google handle several employee issues. Sponsors: Foghorn Consulting: fogops.io/thecloudpod Audible: audibletrial.com/thecloudpod Show Topics Athena now supports Workgroups to segment/isolated data Azure has GA’s several new features to create more reliable event driven applications in Azure Spotinst Announces partnership with AWS Google Rethinks Federated Identity with Continuous Access evaluation protocol Next 19 Qwiklabs Challenge Azure Announces Spatial anchors for collaboration and mixed reality apps Microsoft Workers protest army contract Microsoft CEO Satya Nadella says company will not walk away from contract Google ends forced Arbitration for Employees - Lightning Round EFS now supports tag on create - https://aws.amazon.com/about-aws/whats-new/2019/02/amazon-efs-now-supports-tag-on-create/
AWS Code commit now supports programmatic creations of commits - https://aws.amazon.com/about-aws/whats-new/2019/02/aws-codecommit-supports-programmatic-creation-of-commits-contain/
Performance Insights now supports counter metrics for RDS Postgres, RDS Mysql and Aurora Mysql - https://aws.amazon.com/about-aws/whats-new/2019/02/Performance-Insights-Counter-Metrics-MS-PG-AMS/
Amazon Ec2 Fleets now let you increase target capacity limits - https://aws.amazon.com/about-aws/whats-new/2019/02/amazon-EC2-fleet-now-lets-you-increase-the-fleets-target-capacity-limits/
Amazon Data Lifecycle Manager adds support for shorter backup intervals - https://aws.amazon.com/about-aws/whats-new/2019/02/amazon-data-lifecycle-manager-adds-support-for-shorter-backup-intervals/
Azure Monitor aiops now supports alerts with dynamic thresholds- https://azure.microsoft.com/en-us/blog/announcing-azure-monitor-aiops-alerts-with-dynamic-thresholds/
Mysql and Maria RDS instances now support T3 and r5 instances
Episode 11
This week we have special guest Corey Quinn (twitter: @quinnypig). We talk about Googles Culture, Managed Database Services, Amazon HQ2. Plus the world famous lightning round and Jonathan's cool tools. Sponsors: Foghorn Consulting: fogops.io/thecloudpod Audible: audibletrial.com/thecloudpod Follow Up Azure security center helps protect you from RunC vulnerability - https://azure.microsoft.com/en-us/blog/how-azure-security-center-helps-you-protect-your-environment-from-new-vulnerabilities/
Ballmer’s Clippers select AWS in the first round for their public cloud partner * https://www.geekwire.com/2019/steve-ballmers-los-angeles-clippers-sign-cloud-deal-microsoft-rival-amazon-web-services/
News Google Cloud Security talks at RSA - https://cloud.google.com/blog/products/identity-security/announcing-google-cloud-security-talks-during-rsa-conference-2019
Liz Fong-Jones posts about her decision to leave Google and the toxic culture - https://medium.com/s/story/google-workers-lost-a-leader-but-the-fight-will-continue-c487aa5fd2ba
Digital Ocean launches Managed Database Service - https://siliconangle.com/2019/02/14/expanding-cloud-platform-digitalocean-launches-managed-database-service/ https://blog.digitalocean.com/announcing-managed-databases-for-postgresql/
Amazon introduces Lower cost storage class for EFS - https://aws.amazon.com/about-aws/whats-new/2019/02/amazon-efs-introduces-lower-cost-storage-class/
Amazon drops plans for New York (Queens) HQ2 - https://techcrunch.com/2019/02/14/amazon-drops-plans-for-new-york-hq2/
Azure releases Monitoring at Scale Features with Multi-resource metric alerts - https://azure.microsoft.com/en-us/blog/monitor-at-scale-in-azure-monitor-with-multi-resource-metric-alerts/
IBM CEO says they will be #1 in cloud chapter 2 - https://www.forbes.com/sites/siliconangle/2019/02/14/analysis-ibm-ceo-declares-chapter-2-of-cloud-and-ai-at-ibm-think-2019/#7968ea5c648f https://www.businessinsider.com/ibm-ceo-ginni-rometty-hybrid-computing-2019-1
AWS Announces five new amazon ec2 bare metal instances -
https://aws.amazon.com/about-aws/whats-new/2019/02/introducing-five-new-amazon-ec2-bare-metal-instances/
Amazon Updates Professional level certificates - https://aws.amazon.com/about-aws/whats-new/2019/02/updated-profes
Episode 10 Peter returns from his vacation, Major Docker security vulnerability, Azure gets FHIR and the Warriors choose a public cloud partner. Plus the lightning round! Sponsors Foghorn Consulting: fogops.io/thecloudpod Audible: audibletrial.com/thecloudpod Topics CVE-2019-5736 Docker RunC vulnerability - * Vulnerability - https://seclists.org/oss-sec/2019/q1/119 * AWS - https://aws.amazon.com/security/security-bulletins/AWS-2019-002/ * Google - https://cloud.google.com/kubernetes-engine/docs/security-bulletins * Azure - https://github.com/Azure/AKS/releases/tag/2019-02-12
Azure Account Failover now in Public preview - https://azure.microsoft.com/en-us/blog/account-failover-now-in-public-preview-for-azure-storage/
Google Cloud now provides bigquery sandbox without credit card - https://cloud.google.com/blog/products/data-analytics/query-without-a-credit-card-introducing-bigquery-sandbox
Azure API for FHIR - https://azure.microsoft.com/en-us/blog/lighting-up-healthcare-data-with-fhir-announcing-the-azure-api-for-fhir/
MSFT Healthcare Bot brings Conversational AI to healthcare - https://azure.microsoft.com/en-us/blog/microsoft-healthcare-bot-brings-conversational-ai-to-healthcare/
Azure announcing updates and GA for 3 Azure Data Services - https://azure.microsoft.com/en-us/blog/individually-great-collectively-unmatched-announcing-updates-to-3-great-azure-data-services/
Golden State Warriors Chase Center names Google Cloud as their public cloud provider- http://www.sportspromedia.com/news/golden-state-warriors-chase-center-google-cloud
Build Containers faster with Cloud build with Kaniko - https://cloud.google.com/blog/products/application-development/build-containers-faster-with-cloud-build-with-kaniko
Jib 1.0 released by Google Compute to simplify Java Docker Containers - https://cloud.google.com/blog/products/application-development/jib-1-0-0-is-ga-building-java-docker-images-has-never-been-easier
Amazon acquires Eeero - https://www.imore.com/amazon-buying-popular-mesh-wi-fi-company-eero https://www.theverge.com/2019/2/12/18221441/amazon-buying-eero-disappointing Lightning Round Google Announces support for 6 new cryptocurrencies in bigquery public datasets - https://cl
Episode 9 Its earnings season and we take a look at both AWS and Googles earnings, plus recap the Azure earnings from last week. We also talk about AWS Corretto GA, Microsoft DNS outage causes data loss?, Mongo DB SSPL licensing and more. Special Guest Ryan Lucas Sponsors Foghorn Consulting: fogops.io/thecloudpod Audible: audibletrial.com/thecloudpod Topics Earnings * AWS Earnings - https://www.cnbc.com/2019/01/31/aws-earnings-q4-2018.html * Alphabet (Google) Earnings - https://siliconangle.com/2019/02/04/alphabet-beats-earnings-forecast-costs-weigh-shares/
Google Cloud Firestore Nosql Database hits GA - https://techcrunch.com/2019/01/31/googles-cloud-firestore-nosql-database-hits-general-availability/
DNS Outage results in azure database outage - https://nakedsecurity.sophos.com/2019/02/01/dns-outage-turns-tables-on-azure-database-users/
MS Launches AMD powered Azure Instances - https://siliconangle.com/2019/02/01/microsoft-launches-amd-powered-azure-instances-analytics-databases/
Oracle AMD instances Outperform AWS - https://blogs.oracle.com/cloud-infrastructure/oracle-amd-instances-outperform-and-outprice-comparable-aws-instances
Amazon Corretto 8 is now GA - https://aws.amazon.com/blogs/opensource/amazon-corretto-8-generally-available/
Oracle CISO: Are Audits and Certifications enough? - https://blogs.oracle.com/cloud-infrastructure/security-in-the-cloud:-are-audits-and-certifications-really-enough
MongoDB SSPL Licenses rejected by RHEL - https://www.zdnet.com/article/mongodb-open-source-server-side-public-license-rejected/
Slack IPO - https://siliconangle.com/2019/02/04/months-rumors-team-chat-leader-slack-files-ipo/ Lightning Round Amazon RDS for Oracle now supports t3 instances - https://aws.amazon.com/about-aws/whats-new/2019/01/amazon-rds-for-oracle-now-supports-t3-instance-types/
Azure announces GA for Query store for sql data warehouse - https://azure.microsoft.com/en-us/blog/announcing-the-general-availability-of-query-store-for-azure-sql-data-warehouse/
Google Cloud now supports websockets for app engine flexible environment - https://cloud.google.com/blog/products/application-development/introducing-websockets-support-for-app-engine-flexible-environment
Azure now tells you when your hardware is degraded with scheduled events -
Episode 8 - Now With Insane Magic This week we talk about TLS support for NLB, AWS Worklink, Kubernetes Metering and retailers pushing back on AWS. Plus the lightning round and cool tools with Jonathan. #thecloudpod Thanks to our Sponsors: Foghorn Consulting: fogops.io/thecloudpod Audible: audibletrial.com/thecloudpod News Microsoft Earnings - http://fortune.com/2019/01/30/microsoft-stock-down-slowdown-azure-cloud/
Idera acquires Travis CI - https://techcrunch.com/2019/01/23/idera-acquires-travis-ci/
Google Gives Wikipedia Millions - https://www.wired.com/story/google-wikipedia-machine-learning-glow-languages/
NLB now supports TLS Termination - https://aws.amazon.com/blogs/aws/new-tls-termination-for-network-load-balancers
Microsoft Acquires Citus Data - https://blogs.microsoft.com/blog/2019/01/24/microsoft-acquires-citus-data-re-affirming-its-commitment-to-open-source-and-accelerating-azure-postgresql-performance-and-scale/
AWS Worklink secures on premise website and apps - https://aws.amazon.com/blogs/aws/amazon-worklink-secure-one-click-mobile-access-to-internal-websites-and-applications/
GKE Usage Metering
https://cloud.google.com/blog/products/containers-kubernetes/gke-usage-metering-whose-line-item-is-it-anyway
Albertsons picks Azure to run cloud workloads due to Amazon being a competitor - https://www.fool.com/investing/2019/01/28/amazon-fear-is-driving-retailers-to-microsofts-clo.aspx Lightning Round Python Shell for AWS Glue - https://aws.amazon.com/about-aws/whats-new/2019/01/introducing-python-shell-jobs-in-aws-glue/
AWS Elasticsearch Service now supports maximum cluster size of 200 nodes - https://aws.amazon.com/about-aws/whats-new/2019/01/amazon-elasticsearch-service-doubles-maximum-cluster-capacity-with-200-node-cluster-support/
AWS SSM now supports management of in guest and instance level configuration - https://aws.amazon.com/about-aws/whats-new/2019/01/aws-systems-manager-state-manager-now-supports-management-of-in-guest-and-instance-level-configuration/
AWS Public Datasets now available from UK meteorological office, queensland government, university of Penn, buildzero and others - https://aws.amazon.com/about-aws/whats-new/2019/01/aws-public-datasets-now-available/
Amazon ECS and ECR now support AWS Private Link - https://aws.amazon.com
Episode 7 - The Cloud Pod now 99.9% available Jonathan, Justin, and Peter talk about the latest news in AWS, Google and Azure. This week we talk about the AWS Backup Services, Oracle Cloud launching in Toronto and AWS Re:Mars. Plus the lightning round and Jonathan's cool tools.
Sponsors
Foghorn Consulting: fogops.io/thecloudpod Last Week in AWS: lastweekinaws.com Audible: audibletrial.com/thecloudpod News * Nvidia Tesla T4 GPU's now available in beta - https://cloud.google.com/blog/products/ai-machine-learning/nvidia-tesla-t4-gpus-now-available-in-beta * AWS Announces AWS Backup and support for multiple services - https://aws.amazon.com/blogs/aws/aws-backup-automate-and-centrally-manage-your-backups/ + https://aws.amazon.com/about-aws/whats-new/2019/01/aws-storage-gateway-integrates-with-aws-backup-to-protect-volume/ + https://aws.amazon.com/about-aws/whats-new/2019/01/aws-backup-integrates-with-amazon-DynamoDB-for-centralized-and-automated-backup-management/ + https://aws.amazon.com/about-aws/whats-new/2019/01/introducing-amazon-elastic-file-system-integration-with-aws-backup/ + https://aws.amazon.com/about-aws/whats-new/2019/01/amazon-ebs-integrates-with-aws-backup-to-protect-your-volumes/ * Oracle Cloud launches in Toronto region and plans Mumbai region - https://blogs.oracle.com/cloud-infrastructure/oracle-cloud-infrastructure-launches-toronto-region + https://inc42.com/buzz/oracle-plans-data-centre-in-india-to-challenge-aws-google-cloud/ * Oracle says open source vendors locking down licensing proves they were never really open - https://www.theregister.co.uk/2019/01/17/oracle_exec_opensource_vendors_locking_down_licenses_proves_they_were_never_really_open/ * AWS Announces RE:Mars event June 5/6th - https://www.geekwire.com/2019/amazon-launches-remars-event-focusing-ai-second-stage-invite-mars/ * AWS Trusted Advisor announces 9 new best practices - https://aws.amazon.com/about-aws/whats-new/2019/01/aws-trusted-advisor-expands-functionality/
Lightning Round * AWS GA Party + Kinesis Data Streams + https://aws.amazon.com/about-aws/whats-new/2019/01/amazon-kinesis-data-streams-announces-99-9-service-level-agreement/ + Kinesis Data Firehose
Episode 6 - The Cloud Pod Now Supports Resource Tagging Jonathan, Justin, Peter talk about the latest news in AWS, Google and Azure. This week we talk about the TSO Logic Acquisition, Document DB, TriggerMesh Lambda, Azure win of the DOD contract, plus much more including the lightning round and cool tools by Jonathan. Sponsors Foghorn Consulting: fogops.io/thecloudpod Last Week in AWS: lastweekinaws.com Audible: audibletrial.com/thecloudpod Show Topics Ring Privacy Story - https://bgr.com/2019/01/10/ring-camera-customer-feeds-accessed-creepy-privacy-violation Amazon Acquires TSO Logic - https://www.geekwire.com/2019/amazon-web-services-acquires-tso-logic-vancouver-startup-working-cloud-spending-analysis/ Azure Wins 1.76b DOD Contract - https://siliconangle.com/2019/01/14/microsoft-wins-1-76b-contract-supply-cloud-services-dod/ New AWS Services launch with HIPAA, PCI, ISO and SOC Certifications - https://aws.amazon.com/blogs/security/new-aws-services-launch-with-hipaa-pci-iso-and-soc/ GCP SpotInst Partnership - https://it.toolbox.com/blogs/technologynewsdesk/google-cloud-platform-announces-spotinst-elastigroup-011019 TriggerMesh brings AWS Lambda Serverless computing to k8 - https://www.zdnet.com/article/triggermesh-brings-aws-lambda-serverless-computing-to-kubernetes/ Lightning Round https://aws.amazon.com/about-aws/whats-new/2019/01/aws-step-functions-now-supports-resource-tagging/ https://aws.amazon.com/about-aws/whats-new/2019/01/aws-opsworks-stacks-now-supports-amazon-linux-2--amazon-linux-20/ https://aws.amazon.com/about-aws/whats-new/2019/01/aws-database-migration-service-adds-support-for-amazon-documentdb/ https://aws.amazon.com/about-aws/whats-new/2019/01/amazon-ec2-spot-now-supports-paginated-describe-for-spot-instance-requests https://aws.amazon.com/about-aws/whats-new/2019/01/aws-iot-core-now-enables-customers-to-store-messages-for-disconnected-devices/ https://azure.microsoft.com/en-us/blog/announcing-the-general-availability-of-azure-data-box-disk/ Cool Tools Git Explorer https://gitexplorer.com/ EC2types.io https://ec2types.io/home
Show Notes 1/8/18 * Amazon reportedly buys cloud endure for $250 million * Fargate Lowers prices by 50% * Cloudera/Hortonworks merger closes, takes aim at Amazon * Is this the worst S3 compromise? * Google Purchases DORA (DevOps Research and Assessment) * Github goes Free * AWS CLI Query JMES Path reference
Lightning Round * Windows Server 2019 AMI’s now available on AWS * Parallel Cluster now available in Sweden * Alexa announces Skill Builder Beta Example/Certification * WAF now includes a monitoring dashboard * MSFT Project Bali * EMR announces 99.9% Service Level agreement
Cool Tools * AWS CLI Builder * AWS Console Recorder
Sponsors * Foghorn Consulting - https://www.fogops.io/thecloudpod * Last week in AWS - https://www.lastweekinaws.com * Audible - http://www.audibletrial.com/thecloudpod
Show Notes Follow Up * Jedi Contract + Jedi Contract/AWS Bid Riddled with Conflicts of Interest * Community Licensing Issue + Adam Jacobs - Sustainable Free and Open Source Communities + https://sfosc.org/ + Stephen O'Grady - Cycle Circle of OSS + Copy Left and Community licenses are not without merit but are dead end
Show Topics * Introducing AWS Client VPN to Securely access AWS and On-Premises Resources * Blog Post: Exploring Container Security: let Google do the patching with new managed based images * 2019 Predictions from Justin, Jonathan and Peter
Lightning Round * https://cloud.google.com/blog/products/databases/cloud-spanner-adds-enhanced-query-introspection-new-regions-and-new-multi-region-configurations * https://azure.microsoft.com/en-us/blog/azure-backup-can-automatically-protect-sql-databases-in-azure-vm-through-auto-protect/ * https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-dynamodb-accelerator-adds-support-for-dynamodb-transactions/ * https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-transcribe-now-supports-speech-to-text-in-french-italian-and-brazilian-portuguese/ * https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-ec2-ntroduces-partition-placement-groups/ * https://aws.amazon.com/about-aws/whats-new/2018/12/introducing-workload-qualification-framework-to-plan-your-database-migration-projects/ * https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-route-53-adds-alias-record-support-for-api-gateway-and-vpc-endpoints/ * https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-connect-adds-real-time-customer-voice-stream/ * https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-rds-for-sql-server-now-supports-m5-instance-
The podcast has just started, but we've reached the end of 2018 already. To recap 2018 Justin, Jonathan and Peter scoured the AWS, Azure, GCP and General Cloud news to find their favorite stories, features and capabilities from 2018. Run through their top stories and see if you agree!
Honorable Mentions
Microsoft sponsors the Open Source Initiative - https://opensource.org/node/901Resource Based Pricing - https://cloud.google.com/compute/resource-based-pricing
K8 Takes over the WorldAzure K8 - https://azure.microsoft.com/en-us/services/kubernetes-service/Amazon EKS - https://aws.amazon.com/eksGKE on Premise - https://cloud.google.com/gke-on-prem/
Sponsors
Foghorn Consulting – www.fogops.io/thecloudpod – Your leading AWS premier partner helping companies move to the cloudLast Week in AWS – www.lastweekinaws.com – Your weekly dose of AWS Snark and announcements. The Cloud Pod - www.thecloudpod.net/sponsor
Clipart: ID 126311059 © Bulat Silvia | Dreamstime.com
Show Notes
AWS
Homework Assignment - Now Go Build E1 https://www.youtube.com/watch?v=a42kxHSX4Xw
Show Topic AWS ECS Container Roadmaphttps://github.com/aws/containers-roadmap
GCP
Google Cloud Next: https://cloud.google.com/blog/products/gcp/mark-your-calendar-google-cloud-next-2019?utm_source=DevOps%27ish&utm_campaign=3fc0c13de2-106&utm_medium=email&utm_term=0_eab566bc9f-3fc0c13de2-46450203 Save the date: April 9-11, 2019 at Moscone Center in San Francisco.Registration opened Dec 12th
Security Command Centerhttps://cloud.google.com/security-command-center/?utm_source=release-notes&utm_medium=email&utm_campaign=2018-december-release-notes-1-en
Azure
https://azure.microsoft.com/en-us/blog/automate-always-on-availability-group-deployments-with-sql-virtual-machine-resource-provider/ https://azure.microsoft.com/en-us/blog/a-fintech-startup-pivots-to-azure-cosmos-db/
Other
https://blogs.oracle.com/cloud-infrastructure/core-to-edge-security:-the-oracle-cloud-infrastructure-edge-network https://www.confluent.io/blog/license-changes-confluent-platform?utm_source=DevOps%27ish&utm_campaign=3fc0c13de2-106&utm_medium=email&utm_term=0_eab566bc9f-3fc0c13de2-46450203 https://www.zdnet.com/article/oracles-ellison-no-way-a-normal-person-would-move-to-aws/
Lightning Round
https://aws.amazon.com/about-aws/whats-new/2018/12/aws-transit-gateway-is-now-available-in-8-additional-aws-regions/ https://aws.amazon.com/about-aws/whats-new/2018/12/amazon-eks-adds-managed-cluster-updates-and-support-for-kubernetes/ https://aws.amazon.com/about-aws/whats-new/2018/12/aws-storage-gateway-announces-increased-throughput-and-adds-new-/ https://www.businesswire.com/news/home/20181212005251/en/Amazon-Web-Services-Launches-New-Region-Sweden https://www.infoq.com/news/2017/09/google-cloud-hashicorp https://azure.microsoft.com/en-us/blog/azure-backup-server-now-supports-sql-2017-with-new-enhanc
Enjoy our recap of AWS Re:Invent 2018
Topics:
Sponsors:
Foghorn Consulting - www.fogops.io - Your leading AWS premier partner helping companies move to the cloudLastweek in AWS - www.lastweekinaws.com - Your weekly dose of AWS Snark and announcements.