Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)L
Posts
5
Comments
79
Joined
3 yr. ago

  • I mean, the person in question had "hardening EKS" on their CV. EKS still means that the whole data plane is your responsibility. How can you harden a cluster without understanding the foundation of container security (isolation primitives, capabilities, etc.)? Workload security is very much part of the job.

    I mean the moment some pod will need to run with some privilege (say, a log forwarder which gets host logs), and you need to "harden" the cluster, what do you do if you don't understand the concept of capabilities? I will tell you what, because I asked this very question, and the answer was "copy the logs elsewhere", which is the "make it work with the hammer solution" that again shows the damage of not understanding.

    I am with you about different scopes, skillsets etc. But here we were interviewing people with a completely matching skillset on paper.

  • Thanks, indeed I think there are many parallels with other areas. I will check it out.

  • I totally agree with you, but I don't think this is the specific case. Most of the rejections in our case (which I can see) on the preliminary screening were based on lacking CV skills. Which is stupid in its own way, but at least makes sense assuming we are looking for those skills specifically.

    For the rest, the company is a remote company paying good salaries for the European market, I would say slightly above market average in many metrics.

    I will sift more into the rejections, but from what I have seen, almost all those who had the screening phone call made it to the interview (I.e., rejections were mostly cv-based).

  • But those are absolutely not the only 2 levels. Server rental can be managed easily by the same infra team who manages the cloud, for a fraction of cost.

    I will say more, the same exact team that spends time managing EKS clusters could manage self-managed clusters and have money to spare for additional hires.

  • Mind you that my take and experience is specifically in the context of security.

    I struggle to make the parallel that you suggest (which might work for some areas) with a security engineer.

    Say, a person learned to brainlessly parrot that pods need to have setting x or z. If they don't understand them, they can't offer meaningful insight in cases where that's not possibile (which might be specific), they can't provide a solid risk analysis etc.

    What is the counterpart to this gap? Because I struggle to see it. Breadth of areas where this superficial knowledge is available is useless, IMHO.

  • Ahaha yes, that might be the case, but I started to lose hope if the top of the applicants (out of hundreds of rejected!) all exhibits this behavior. I can't help but feel that now we are looking for people with a mindset and skillset that is simply disappearing in the industry.

    And as I said in another post, I perfectly acknowledge that if I stopped reading and investigating stuff on my own, I could absolutely keep my job by just mindlessly administering a few services and rephrasing CIS benchmarks...

  • This is quite a trite argument from my point of view. Also, this is from the perspective of the business, which I don't particularly care about, and I tend to look from the perspective of the worker.

    Additionally, the cloud allows to scale quickly, but the fact that it allows to delegate everything is a myth. It's so much a myth that you see companies running fully on cloud with an army on people in platform teams and additionally you get finops teams, entire teams whose job is optimizing the spend of cloud. Sure, when you start out it's 100% reasonable to use cloud services, but in the medium-long term, it's an incredibly poor investment, because you still need people to administer the cloud plus, you need to pay a huge premium for the services you buy, which your workforce now can't manage or build anymore. This means you still pay people to do work which is not your core business, but now they babysit cloud services instead of the actual infra, and you are paying twice.

    Cloud exploded during the times of easy money at no interest, where startups had to build some stuff, IPO and then explode without ever turning a single dollar of profit. It's a model that fits perfect in that context.

  • Not when the skillset is essentially outsourced and you are left consuming the product of that skillset.

    Understanding is nonnegotiable in security, IMHO.

    You can't fail to understand how signature attestation works, if you are implementing it, to make one example I made in the post. Otherwise you end up verifying the signature in the CI (like that person claimed it should be done) and waste the whole effort. You can definitely still outsource the whole infra and scripting to Github, but you still need to understand. The problem is that when you can outsource everything, at some point understanding becomes an extra step.

  • That's the thing! I think it wouldn't be conceivable that your "principal engineer" (real position for one of the people) doesn't understand the basic theory of the stuff they are implementing. Now it feels you can instead work years and years just shuffling configuration and pressing buttons, leading to "senior" people who didn't gather actual years of experience.

    I don't want to pretend I am outside this logic. I am very much part of this problem myself, having started my career 10 years ago. I do despise cloud services though (if anything, they are super boring), so I tend to work with other stuff. But I could 100% just click buttons and parrot standard and keep accruing empty years of experience...

  • Kubernetes is not really meant primarily for scaling. Even kubernetes clusters require autoscaling groups on nodes to support it, for example, or horizontal pod autoscalers, but they are minor features.

    The benefits are pooling computing resources and creating effectively a private cloud. Easy replication of applications in case of hardware failure. Single language to deploy applications, network controls, etc.

  • Yes if single node, kinda if 2-3 nodes, no for anything above that IMHO.

  • That takes courage to say, after 90% of your comments have to do with (speculations on) me.

    Anyway, good riddance.

  • I specifically quoted the part that I considered bad faith. I am OK with you thinking I am an apologist. I don't consider it bad faith (although I consider it wrong). What was bad faith was purposefully misinterpreting a sentence that was in a clear context so that you could use it for that patronizing statement.

    This was a objectively true from my viewpoint

    Nothing to say, it just sounds ironic to me. Again, I have no problem with your subjective judgment.

    He was simply wrong for this statement.

    And I respect your opinion.

    that did more harm than good.

    Now we ended up in an argument that has to do with result? I have never said that it was a good move. That it benefit the company or anything like that. What argument are you trying to challenge? I am judging the action based on my own morality, not based on whether it benefit him or his company.

    You are just learning, and pointing out your own words is not bad faith

    Strike two. Go re-read the sentence. I said that I didn't know anything about him before this debacle and that I ended up learning about him whole informing myself about it. For your convenience I will quote my own words:

    I actually can't care less about him, and I barely know anything about him. My involvement is very limited to this case, and that is because wanting to understand inevitably forced me to learn certain things and inform myself.

    This behavior (patronizing, intentionally misunderstanding other person sentences) for me is clearly a demonstration of bad faith. As usual, your accusation of bad faith did not specify any reason or quoted any part and i challenge you to do that.

    Not that it matters to you, but next similar behavior and I will block you and move on.

  • I agree with you on the principle. In this case I disagree with the premise. Years of actions I think easily out weight that tweet. If that's the only reason to be suspicious, then I don't think it's warranted.

  • I start to perceive a pinch of bad faith, and an excessive amount of paternalism. Your arguments are mostly ad hominem, so far you didn't produce much coherent criticism of ideas.

    Anyway, you seem to have missed the point that understanding that "leaders" (BTW, you seem to use this term seriously like if we were on LinkedIn) keep their mouth shut is different from understanding my (ours) role into this dynamic.

    I don't need any proof, that was just an example, from a very limited sample of my life which is this alias and that blog. I have nothing to prove or anything to defend from baseless accusations of a random internet person with lacking knowledge (about myself, which I hope you will agree).

    You state yourself you are just learning about this which is very clear.

    Here is the bad faith I was talking about. A sentence which clearly is out of context used for a very patronizing ad hominem.

  • If they choose to expose themselves as politically ignorant and supporting positions that are indefensible the consequences is they will lose business. This is all I am pointing out.

    Very easy to understand. But why should we (the customers, citizens, etc.) care? My interest is to have that knowledge, it's the shareholder interest to have the business succeeding, and they take care of that. So why from your words you seem to imply that it's "better" if they keep their mouth shut (and therefore protect the businesses)?

    I get you want to hear their opinions and then play devil’s advocate about them because that is just what you do.

    Unnecessary ad-hominem, which is also easily proved wrong. I hear the opinions of Musk, of Bezos (but also of Zuckerberg, of the Nvidia guy, of Altman and many others) and I am happy because with that information I can (and do) distance myself from their companies. In this case, I feel differently and therefore I take another decision. I like to think that I can critically evaluate situations, but if the conclusion I end up with is different from yours it doesn't mean that mine is wrong by definition.

    You are clearly technically minded but you are also clearly not politically minded.

    You are clearly wrong about this. I have nothing to prove obviously, but you can easily also see that by just browsing through other posts on my blog, for example this. I will even go a step further and say that the purism and localism (as defined in this book) that emerges from your words is something I explicitly want to distance myself from, because it has proved to be a complete failure in terms of political battles.

    I am referring at things like:

    It is clear no matter what corner of the Internet we run to as long as it is into the open arm of corporations it is a mistake.


    Clearly you feel a kinship with this man because you are also heavily invested in the tech world. You defend him because you also admire him.

    I don't. I actually can't care less about him, and I barely know anything about him. My involvement is very limited to this case, and that is because wanting to understand inevitably forced me to learn certain things and inform myself. Please don't assume other people's positions.

  • Thanks, I appreciate it.

  • I felt that was really uncalled for. The whole post elaborates quite a lot in thousands of words, and I feel like your summary is not really accurate. Unfortunately, I have no way to debate accusations that follow a circular logic, so I won't attempt to do so.

    Otherwise please keep that shit to yourself and keep it out of your business if you ever want my money.

    I reiterate that I find curious that you seem to prefer ignorance of those positions, as if the reality is suddenly better if you don't know a problem exists. You would rather pay for Proton not knowing that Andy Yen thinks what he thinks than having more information so that you can choose to stop paying. Obviously just an example, same thing applies to the WaPo or Tesla, or any other similar case.

  • I think I can agree with that. Unfortunately PGP is the only alternative we have for emails (i.e., the client-side tools would still be doing PGP encryption), which is also the reason why it shouldn't be used for really delicate communication. The fact that - whatever setup you use - there will always be metadata showing that person X communicated with person Y alone is a nonstarter for certain types of communication.

    Signal would be my recommendation.