| |
| 🔗 Stories, Tutorials & Articles |
| |
|
| |
| The best tools for bare metal automation that people actually use |
| |
| |
Bare metal ops aren’t what they used to be. The game’s gone full stack: API-driven provisioning, declarative workflows, and config convergence now run the show.
Tools like MAAS, Foreman, Ironic, and Tinkerbell treat physical servers as programmable units. Real hardware, real APIs. Meanwhile, Kubernetes-native models bring physical gear into the cluster fold using Custom Resources (see: Bare Metal Operator). It’s a weirdly elegant mashup - metal meets manifest. |
|
| |
|
| |
|
| |
| Keeping Secrets Out of Logs |
| |
| |
A new writeup lays out a layered plan to keep secrets out of logs, no silver bullets here, just ten solid "lead bullets" that actually stack. Think of it as defense in depth for log hygiene.
Highlights include: Type-safe domain primitives for secrets, Taint-based static analysis, Read-once secret wrappers, and smart log preprocessors (like Vector) that redact and sample before anything hits disk. |
|
| |
|
| |
|
| |
| SSH has no Host header |
| |
| |
A dev built a custom SSH proxy that punches through IPv4 limits without handing out public IPs like candy. Their trick: shared IPv4s with per-user relative IP mapping.
It maps incoming SSH traffic to the right VM using the source IP and public key combo. No Host header? No problem. They sidestep that hole cleanly. |
|
| |
|
| |
|
| |
| What came first: the CNAME or the A record? |
| |
| |
| A recent change to 1.1.1.1 accidentally altered the order of CNAME records in DNS responses, breaking resolution for some clients. This post explores the technical root cause, examines the source code of affected resolvers, and dives into the inherent ambiguities of the DNS RFCs. |
|
| |
|
| |
|
| |
| Preparing for Post-Quantum Cryptography ✅ |
| |
| |
NIST locked in its Post-Quantum Cryptography (PQC) standards in August 2024. The countdown’s on: U.S. federal systems need to make the leap by 2035.
Wiz jumped early with a PQC Security Framework. It scans for shaky encryption, maps your crypto assets, and flags what’s PQC-ready, all cloud-wide, using hybrid cryptography and metadata sleuthing. |
|
| |
|
| |
|
| |
| How we built an AI SRE agent that investigates like a team of engineers |
| |
| |
Datadog just dropped Bits AI SRE, an autonomous agent that thinks more like an SRE than a chatbot. It doesn't just regurgitate summaries - it investigates. It builds hypotheses, tests them against telemetry, and chases down actual root causes.
Older tools leaned hard on LLMs to summarize alerts. That got noisy fast. Bits AI SRE flips the script. It crawls through evidence step by step, like a real engineer, connecting dots across services to isolate the real issue. |
|
| |
|
| |
👉 Got something to share? Create your FAUN Page and start publishing your blog posts, tools, and updates. Grow your audience, and get discovered by the developer community. |