⚗️⚗️⚗️ pnathan ⚗️⚗️⚗️

@pnathan
624 Followers
332 Following
7.1K Posts

hacker painter walker

love talking to random people.

Seattle

http://pnathan.com

Languages -
EN native
DE rusty
FR learning

@ me all day? slide into my DMS?Yes please!
alignmentchaotic nerd
politics?sure!
grad thesisi will read it

Afternoon, ya'll.

Reminder that I have moved the bulk of my fediverse presence to @ pnathan @ social.seattle.wa.us!

It's a #Seattle / Puget Sound local focused instance, which I have been graciously allowed to help moderate by @Finn . We hope to turn it into a coop once we have enough interested members.

Good evening!

Reminder that I have moved the bulk of my fediverse presence to @ pnathan @ social.seattle.wa.us!

It's a #Seattle / Puget Sound local focused instance, which I have been graciously allowed to help moderate by @finn . We hope to turn it into a coop once we have enough interested members.

Hi! Morning reminder that I am moving some 95% of my fediverse presence to pnathan @ social.seattle.wa.us.

@pnathan

I'm in the process of migrating most of my fediverse presence over to @pnathan , a #seattle local server that I got asked to help start up.
@baturkey @juliobiason
@[email protected] recommended Mastering Emacs to me, he's done a LOT of work there.

@tek That's *huge* news, if I'm not mistaken. First open non-straight in the NFL... it's going to cause an enormous firestorm among the Very Masculine of football fans.

I wish him 100% the best and hope he gets signed as he desires.

So I'm pondering how to figure out a way to get credentials into jenkins via cooking the credentials.xml files prior to bringup.

this shouldn't be this hard.

and yes.

Jenkins is old tech, and very Java Enterprise coding. Not a good thing. I like it, because it is flexible. But it's not well adapted for cloud work with proper automated bringup.

I've spent days looking at automating installing credentials post-bring up. But the CSRF protection system is... not designed for automation. Nor is there a RPC system for within-process environment (within-pod) for injecting secure information.

Digressive note:

I think that it'd be much closer to technically well done to roll up all needed functionality into your k8s cluster (logs, monitoring, builds, etc) without relying on cloud facilities (i.e., build your own cloud in k8s). But this requires substantial technical investment, documentation, and hiring. Probably a good +5 on your SRE team. And, worse, is this something *interesting*? Can you retain people for this?

Banging away on how to build a fully automated #Jenkins, including credential injection on bringup.

Fully automated bringup, including secrets, is one of the fiddlier bits of #SRE work. If you're on AWS, AWS IAM and SecretsManager serve as the trust root....

... but not everything integrates with that! Such as Jenkins.

One of the things businesses like a lot today is outsourcing, which is what Cloud is, particularly AWS. So here we are.

(hashtags for search)