248: A Public Service Announcement on Shared VPCs in AWS: Don’t!

Episode 248 March 02, 2024 01:15:09
248: A Public Service Announcement on Shared VPCs in AWS: Don’t!
The Cloud Pod
248: A Public Service Announcement on Shared VPCs in AWS: Don’t!

Mar 02 2024 | 01:15:09

/

Show Notes

Welcome to episode 248 of the CloudPod Podcast – where the forecast is always cloudy! It’s the return of our Cloud Journey Series! Plus, today we’re talking shared VPCs and why you should avoid them, Amazon’s new data centers ( we think they forgot about the sustainability pledge,) new threats to and from AI, and a quick preview of Next ‘24 programs – plus much more! 

Titles we almost went with this week:

A big thanks to this week’s sponsor:

We’re sponsorless this week! Interested in sponsoring us and having access to a specialized and targeted market? We’d love to talk to you. Send us an email or hit us up on our Slack Channel. 

AI is Going Great (or how ML Makes all Its Money)

01:24 Disrupting malicious uses of AI by state-affiliated threat actors

03:59  Ryan – “I do like that all these state-sponsored actors, they’re just like us, asking basic scripting questions.”

AWS

06:46 Announcing the Data Solutions Framework on AWS

17:43   Ryan – “…none of the things in this are new, but it’s the packaging of it all together, where you just sort of – with a few simple lines of SDK code – really have the full infrastructure for a full DataLake. And so, it’s super cool, because this is always what, as a customer, you’re sort of wanting, like give me the easy button.”

10:25 API Gateway now supports TLS 1.3 

10:45   Justin- “I assume this is also a prerequisite for them to be able to support mutual TLS on API Gateway, which would be probably the last big feature I think they’re missing on the API Gateway.”

11:36   Matthew – “…the one piece of it I don’t like is that they didn’t do it, which makes sense across the board on all the different flavors of API gateway, but that’s because CloudFront would need to actually handle 1.3 also. So I get why they’re slowly rolling it out, but you know, just doing a regional means someone’s going to go in there and try to do it on global and not understand why. And then you’re going to go bang your head on the wall until you really sit down and figure out, oh yeah, this is actually a CloudFront API gateway under the hood.”

12:40 Amazon GuardDuty Runtime Monitoring protects clusters running in shared VPC

13:57   Ryan – “I mean, even I’m glad they’re fixing this with GuardDuty. I hope that they’re not implementing too much complexity on the backend, making it either very complicated to run or changing the results. But like, today I learned that previously you couldn’t run GuardDuty and inspect those workloads, right? And so I’m sure that GuardDuty is one of many.”

18:18 One of Oregon’s smallest utilities is suddenly among the state’s biggest polluters. Why? Amazon data centers 

22:13   Matthew – “There was a podcast I listened to at one point where saying there’s a lot of these green initiatives. Everybody wants to do it. The problem comes down to the way all this works is like it has to come down to like transmission lines. And like, if you say, I’m going to build a wind farm over here, you got to pay for all the infrastructure after that to trans to do it. So you end up like, Hey, this 50,000, this hundred thousand dollar project now, it costs you a million dollars. You got to redo it. So like, it almost feels like we have to look at the way we kind of handle our electrical grid to support these. So a simple wind farm over here doesn’t end up costing billions of dollars.”

GCP

23:43  Google Cloud expands access to Gemini models for Vertex AI customers

25:29   Ryan – “This is moving way too fast for me. Like, Gemini 1.0 Pro used something like 32,000 tokens, right? Or maxed out at that? I can’t. I think that’s it. And now they’re scaling up to a million, like a week later, like it feels like. Like it’s crazy. You’re going to be able to run this against so many things.”

27:13 Feel the Next ‘24 love: Full session library is now live

33:21 Introducing vector search in BigQuery       

35:15   Justin- “I definitely see the advantage of it. Like, you know, I, my trick is I just like, I select SQL server row one. And if that’s the data I want, then I assume that row two is also similar to it. That’s how I do it. It’s not really the right way to do it. Yeah. There’s a wildcard. I just, yeah. Select all put it in an elastic search cluster, do a search, see what I come up with. All kinds of, all kinds of ways to solve this problem.”

35:40 Introducing Managed Instance Groups standby pool: Stop and suspend idle VMs

36:23   Matthew – “So this is the AWS auto scaling cold or whatever they called it, which is like a server that you can have on the side that like you can just boot up. And the only reason I ever saw to use this feature, was if you were auto scaling or MIG scaling in this case, I guess, Windows servers, just because they take so long to boot up. Because Windows…It was a nice feature. We set this up for one person at one point and it did dramatically help it, you know, Windows by default, I think it takes like 15 minutes to boot up. So just having the server there and essentially stopping it off hours; kind of lets you do fake auto scaling without actually doing auto scaling. So you’re stopping/starting servers. It’s a significant savings.”

Azure

37:54 Microsoft to invest $2.1B in Spain to expand AI and cloud infrastructure 

38:31   Justin – “I mean, if I were to be a betting man, they’re all trying to get ahead of the EU data center moratorium because they can only build for so long before they hit the moratorium limit. Because they also have power transmission problems in Europe, if you didn’t know.”

40:00 General Availability: Azure NetApp Files Standard Network Features – Edit Volumes

42:22   Matthew – “I just feel like it’s kind of also the way Azure is, is security and reliability. You always have to go to the higher tiers, which just drives me a little bit crazy. Like it’s not built in day one whereas with AWS, I feel like, you know, their motto is designed for failure. So like most of the managed services are by default and you don’t have an option. Like you can’t launch a load balancer without two subnets. You can’t launch, you know, your database without multiple subnets; they’re just there where Azure feels like you always have to think about it. I’m like, I don’t want to think about it. This is why I’m paying for a service – do it for me.”

Continuing our Cloud Journey Series Talks

50:35 Five key things to consider when building a cloud FinOps team 

52:17   Matthew – “…make sure you have executive buy in probably you’re starting this whole fin op started because your CFO is freaking out about the bill, but you know, making sure that not just the CFO, you know, your CTO and other organization members all agreed. This is something you’re going to do so you don’t have one side of the house fighting the other and you’re sitting there in the middle just going cool. We’re here.”

57:35   Ryan – “…it’s super fun to watch that transformation happen, from taking a dev team who hasn’t had any visibility into their costs to the initial stages of bewilderment of why is everything expensive, to actually making architecture choices based off of cost-driven data. And it’s not always comfortable, but almost every team that I’ve seen do that transformation, they’re excited by the end, right? It’s not like, oh, I had to do this and they’re jaded about it. And so like, it is one of those things where it allows some really cool decisions and it’s, you know, when you have the visibility, when you have that insight and, you know, like I said, access is clear and transparency is part of your culture.

Closing

And that is the week in the cloud! Just a reminder – if you’re interested in joining us as a sponsor, let us know! Check out our website, the home of the Cloud Pod where you can join our newsletter, slack team, send feedback or ask questions at theCloud Pod.net or tweet at us with hashtag #theCloud Pod

Other Episodes

Episode 0

March 25, 2020 00:48:18
Episode Cover

63: The Cloud Pod Stays Home to Enjoy the Fireworks

Ryan Lucas (@ryron01) fills in for Peter again as we practice social distancing on this week’s episode of The Cloud Pod. A big thanks...

Listen

Episode 0

February 23, 2020 00:38:36
Episode Cover

TCP Talks: Finops in the cloud with Rob Martin - Bonus Ep 2

The most terrifying part of moving to the cloud isn't security, migration techniques or learning new infrastructure as code tools, it is managing that...

Listen

Episode 155

March 10, 2022 00:53:40
Episode Cover

155: The Cloud Pod Shows Green in the New AWS Status Page

On The Cloud Pod this week, the team heads down a Cisco business model rabbithole. Plus cloud status pages struggle with reality, AWS is...

Listen