
RPKI ASPA: a complement to RPKI/ROA that tackles BGP route hijacks through AS path manipulation. Why does BGP remain vulnerable? BGP was designed in an environment of mutual trust. Every…
The post RPKI ASPA: using AS-PATH to secure BGP appeared first on JTnetwork.io.
Every time we restarted Atlantis, the tool we use to plan and apply Terraform changes, we’d be stuck for 30 minutes waiting for it to come back up. No plans, no applies, no infrastructure changes for any repository managed by Atlantis. With roughly 100 restarts a month for credential rotations and unboarding, that added up to over 50 hours of blocked engineering time every month, and paged the on-call engineer every time.
This was ultimately caused by a safe default in Kubernetes that had silently become a bottleneck as the persistent volume used by Atlantis grew to millions of files. Here’s how we tracked it down and fixed it with a one-line change.
We manage dozens of Terraform projects with GitLab merge requests (MRs) using Atlantis, which handles planning and applying. It enforces locking to ensure that only one MR can modify a project at a time.
It runs on Kubernetes as a singleton StatefulSet and relies on a Kubernetes PersistentVolume (PV) to keep track of repository state on disk. Whenever a Terraform project needs to be onboarded or offboarded, or credentials used by Terraform are updated, we have to restart Atlantis to pick Continue reading
It’s episode 300, and it’s roundtable time. In this episode, Tom, Eyvonne, and Russ talk about how systems can be designed to prevent injection attacks, and then the perennial unpleasantness of layoffs.
download
Geoff Huston published an article supposedly describing the challenge of securing NTP, but as is usually the case, he couldn’t skip the prior art going all the way back (almost) to the formation of Earth.
Before coming to the how do we secure NTP section, you’ll learn everything about the wobbly Earth rotation, the changes in the Earth’s angular speed, the impact of tides, the smearing of leap seconds, the differences between UT1 and UTC, why we use quasars to measure time, and everything there is to know about NTP. Have fun!
Last September we introduced Code Mode, the idea that agents should perform tasks not by making tool calls, but instead by writing code that calls APIs. We've shown that simply converting an MCP server into a TypeScript API can cut token usage by 81%. We demonstrated that Code Mode can also operate behind an MCP server instead of in front of it, creating the new Cloudflare MCP server that exposes the entire Cloudflare API with just two tools and under 1,000 tokens.
But if an agent (or an MCP server) is going to execute code generated on-the-fly by AI to perform tasks, that code needs to run somewhere, and that somewhere needs to be secure. You can't just eval() AI-generated code directly in your app: a malicious user could trivially prompt the AI to inject vulnerabilities.
You need a sandbox: a place to execute code that is isolated from your application and from the rest of the world, except for the specific capabilities the code is meant to access.
Sandboxing is a hot topic in the AI industry. For this task, most people are reaching for containers. Using a Linux-based container, you can start up any sort of Continue reading
The never-ending “we will replace developers” (or networking engineers) pipe dream didn’t start with the latest bout of AI hype (or SDN). As Stephan Schwab explains in his Why We’ve Tried to Replace Developers Every Decade article, it started with COBOL, the magic high-level programming language that businesspeople would use to write their own programs.
At least some of us know how well that ended. I was also unfortunate to be there for the 5GL hype, the forms-driven programming hype, the “everyone will solve every problem out there with Excel macros” (it does work for networking inventory, doesn’t it?), and a few others. So please excuse me if I remain a bit skeptical about the latest fad, even though I find it (like all the previous ones) very useful when used conservatively in limited domains.
Daftar Pustaka
Pura Segara Kidul berdiri sebagai simbol kuat hubungan manusia dan alam laut. Pura ini berkembang dari tradisi leluhur Bali. Masyarakat pesisir membangun pura sebagai bentuk penghormatan spiritual. Selain itu, pura ini terhubung erat dengan konsep Tri Hita Karana.
Pada awalnya, masyarakat memanfaatkan pura sebagai tempat memohon keselamatan. Oleh karena itu, para nelayan sering melakukan persembahyangan sebelum melaut. Seiring waktu, peran pura semakin luas. Bahkan, pura menjadi pusat kegiatan keagamaan penting. Dengan demikian, Pura Segara Kidul memiliki nilai sejarah dan spiritual tinggi.
Makna spiritual Pura Segara Kidul sangat mendalam. Pura ini melambangkan keseimbangan antara manusia dan kekuatan laut. Selain itu, pura juga mencerminkan rasa syukur terhadap anugerah alam. Karena itu, umat Hindu rutin menggelar upacara khusus.
Selanjutnya, masyarakat meyakini laut sebagai sumber kehidupan. Oleh sebab itu, pura mengajarkan sikap hormat terhadap alam. Bahkan, filosofi ini menanamkan kesadaran lingkungan. Dengan kata lain, Pura Continue reading
Daftar Pustaka
Secara ilmiah, awan merupakan agregat tetesan air dan kristal es yang tersuspensi di atmosfer. Setiap tetesan memiliki diameter antara 10 hingga 50 mikrometer, namun jumlahnya bisa mencapai jutaan per meter kubik udara. Akibatnya, bobot satu awan cumulus rata-rata mencapai satu juta ton. Meskipun demikian, awan tetap melayang karena adanya gaya buoyancy yang dihasilkan oleh udara panas dan arus konveksi. Proses ini menyeimbangkan gaya gravitasi sehingga awan mampu tetap stabil di berbagai ketinggian.
Pergerakan awan dikendalikan oleh angin atmosfer dan perbedaan tekanan. Di lapisan troposfer, angin dapat mencapai kecepatan lebih dari 200 km/jam pada ketinggian tertentu, terutama di jet stream. Awan cirrus, yang berada di ketinggian 6–12 km, bergerak lebih cepat dibanding awan rendah karena dipengaruhi oleh aliran angin kuat di lapisan atas. Selain itu, konveksi lokal dan sistem tekanan rendah juga memicu pergerakan horizontal dan vertikal awan, memengaruhi distribusi hujan serta pola cuaca regional.
Warna awan tergantung pada interaksi cahaya matahari dengan tetesan air atau kristal es. Secara ilmiah, awan putih terjadi karena Continue reading
A few months ago, Cloudflare announced the transition to FL2, our Rust-based rewrite of Cloudflare's core request handling layer. This transition accelerates our ability to help build a better Internet for everyone. With the migration in the software stack, Cloudflare has refreshed our server hardware design with improved hardware capabilities and better efficiency to serve the evolving demands of our network and software stack. Gen 13 is designed with 192-core AMD EPYC™ Turin 9965 processor, 768 GB of DDR5-6400 memory, 24 TB of PCIe 5.0 NVMe storage, and dual 100 GbE port network interface card.
Gen 13 delivers:
Up to 2x throughput compared to Gen 12 while staying within latency SLA
Up to 50% improvement in performance / watt efficiency, reducing data center expansion costs
Up to 60% higher throughput per rack keeping rack power budget constant
2x memory capacity, 1.5x storage capacity, 4x network bandwidth
Introduced PCIe encryption hardware support in addition to memory encryption
Improved support for thermally demanding powerful drop-in PCIe accelerators
This blog post covers the engineering rationale behind each major component selection: what we evaluated, what we chose, and why.
Generation | Gen 13 Compute | Previous Gen 12 Compute |
Form Factor | 2U1N, Single Continue reading |