# 372: Welcome to Microsoft Patch-A-Palooza Duration: 83 minutes Speakers: A, C, B Date: 2026-09-24 ## Transcript [00:07] A: Welcome to The Cloud Pod, where the forecast is always cloudy. [00:10] C: We talk weekly about all things AWS, GCP, and Azure. [00:14] A: We are your hosts, Justin, Jonathan, Ryan, and Matt. [00:18] B: Episode 372, recorded for September 15th, 2026. Welcome to Microsoft Patchapalooza. Good evening, Ryan and Matt. How is your patching going? [00:29] A: Oh, oh, so good. Oh, so good. [00:31] C: You really should have like a cheers go off there, right when you said it, if we were playing properly. [00:36] B: That would require planning and, uh, preparation for the show that we don't always get to. [00:42] C: I was trying to find it on, on just on my laptop, so I couldn't find the things fast enough. [00:47] B: Yeah. Yeah. Uh, yeah, I saw him while I was on my trip, uh, a news article come across and I was like, ugh. I know that means that we have more patching to do when I get back. So much patching, so much patching. Someday I'll get better, right? I eventually will catch up with this glut in the backlog and it'll be better, right? Tell me, Matt, Ryan, or Matt, it'll be better. [01:06] C: You just need an image factory that creates images for you to deploy. [01:09] B: But then you have the problem of after the image factory, you had to get people to adopt the images, which takes just as much work in some cases. [01:16] A: I just did a presentation about just all of these things. Used this, uh, the, uh, spike of, of Microsoft vulnerability reported CVEs that they're patching as part of that thing and how it's like a 100x jump over the last few months. [01:32] B: I was seeing a chart that, you know, goes to the board and it was showing the vulnerabilities, you know, new vulnerabilities versus remediated vulnerabilities. And yeah, it's like the last like 4 months, it's just this up and to the right. Huge. [01:44] C: Yeah. [01:45] B: I mean, luckily we're, we're also, we're also patching it quite nicely too. So it's not like it's, we're not patching, but it's just like, it's so much volume right now. Then our customers are like, why is there so much stuff happening? It's like, oh yeah. [01:56] A: Well, I mean, that's the trick. It's just, it's hard to keep up with. And, and like, like you're saying with images, um, it's always been a problem with containers and, and patching Docker or, you know, updating Docker images. But now we've moved to immutable images, but you have to adopt those new images and rotating a VM's operating system is a little slower than in a Docker image. So it's difficult to keep up. And if we're gonna face the same or an exponential rate of vulnerabilities and fixing them, it's quite the challenge for operational teams. [02:28] C: I will say Azure's VMMS skillset automatically pull the latest one if you do it right. It's not bad, but even if you give it the new image with your maintenance window, it still does take time for it to occur. So like hitting an SLA that is contractual or whatnot becomes difficult because Microsoft just does it on their schedule, even as fast as you can, even if you're using custom image. If you're just using like the default latest, you know, server image, then it's somewhere like I've seen those take like 7, 8 weeks since the patch came out to occur. So, you know, OSes just take longer. [03:09] B: Yeah. [03:09] A: It's, it's much more overhead, right? It's not reusing the shared user space of the operating system of the underlying system. So it's, you know, it's always going to be more, more overhead, you know, because there's more layers to replace. [03:21] C: I feel like we just started with the security story at this point. [03:25] B: We could jump right to it. Uh, we should, we should. Uh, yeah. So, uh, this month in security this week. Why this month's Microsoft patch release is a doozy from Ars Technica. They patched 972 vulnerabilities in September. 112 were rated critical, surpassing prior records of 570 in July and 620 in August in consecutive months. Uh, year to date, Microsoft has fixed 2,760 vulnerabilities in 2026, more than double last year's total and on pace to exceed the combined totals of 2023 through 2025. Uh, over 100 companies including OpenAI, Anthropic, AWS, Google, and Microsoft signed an open letter warning that AI-enabled attacks are shrinking the window defenders have to patch before exploitation occurs. And zero-day initiative researcher Dustin Childs noted AI-assisted vulnerability discovery is accelerating patch volume, though active exploit rates have not yet spiked correspondingly as such. So do keep that in mind. So it's fear driving a lot of this behavior as well. [04:20] A: Well, it's fear and it's— there's the, the frontier models are discovering it, right? So there's the Project Glasswing and, and the two others that I just lost from my memory in line. Like real time. And so there's a bunch of discovery that's going on as people are running their source code through these things as, you know, like Mythos and the new OpenAI models that are purpose-built for finding these vulnerabilities are being run through codebases. And so it's interesting. And I was thinking back to your comment of like, it'll be over soon, right? And I'm just thinking about what it was only like last year where they found like a 20-year-old zero-day exploit. Was it in Bash or something real low level? And it was just like, yeah, maybe, or, or it's about to get real. [05:03] C: Kind of what I wonder with some of these also is where are they finding the vulnerabilities? Is it end users are finding them still or external people, or is it them doing it internally and finding them? And they don't really share those types of metrics. I think that'd be interesting to see. Is it something that's, you know, external facing or is it all internal? [05:25] B: I mean, I assume that if it was, it was mostly humans, you know, it would be tied to, you know, the similar numbers, but the fact that it's, it's double or triple the number tells me it has to be AI-assisted. [05:37] A: Yeah. Well, and, and Dustin's child's point, the Dustin child's point is that there, it's people running through their, their own code bases, running their own code bases through AI and discovering these things. [05:48] B: Right. [05:48] C: So is it Microsoft just finding all of it? Or is it Matthew Cohn running a test again, you know, with Claude code attacking a Windows OS locally? [06:00] A: Like, which way is Microsoft running Microsoft through Mythos and then publishing the CVE discovered by Mythos? [06:06] C: Because that to me feels less bad. While the vulnerability is higher and the count is currently higher, they're at least remediating it before it's actively getting attacked. You know, it's not a zero day in the— [06:19] A: And so that's the only good news. [06:21] C: Yeah, I look at the positive side of life. [06:24] A: CVs are being published at a crazy rate, but the exploit rates are not increasing at the same rate, although they are increasing. [06:30] C: What I did read a stat though, Ryan, this would probably interest you, is that when things are found and there are zero days, the amount of time it takes for a vulnerability to get attacked has decreased from days to hours. So vulnerabilities are getting attacked faster, which is why they signed the letter saying, you know, windows are shrinking. [06:53] A: Oh yeah, no, it's, it's definitely, you know, it, it's the, the exploit window for a single vulnerability is, is reducing. And then you can't sort of mitigate the risk like you used to because AI is able to chain so many of these low-level vulnerabilities together. To work around some pretty monumental barriers that you have for security. So it's, it's pretty tricky right now. [07:19] B: We'll see where, uh, it takes us over the next few months, but, uh, I hope it doesn't get worse. I hope it gets better, but I would not be shocked to see us talking next month about Patch Tuesday records again, because I think this is maybe the third month we talked about massive amounts of patch data, and it's in records for Red Hat, it's in records for um, all operating system manufacturers pretty much at this point. [07:41] A: Uh, I think we're cleaning up 20 years of stuff that's discovery, so I think it's going to be a while before it comes back down. [07:48] B: And some of them are, are not overly complicated, but they're like buffer overflows or different things that, you know, with the right testing harness you could have found them before. But again, without chaining, you maybe wouldn't have ran into some of them. So, uh, the AI is definitely helping. Uh, speaking of AI, it's, uh, how machine learning makes money. And, uh, we've got several features this week from OpenAI., as well as an interesting story from NVIDIA. Uh, first up, OpenAI has released two new features. First, the, uh, Agents API is now in public beta, exposing the same harness and infrastructure that powers Codex and ChatGPT for Work, letting developers create production-ready agents with a single API call specifying task, model, tools, environments. Developers get flexible compute options, an OpenAI-managed sandbox, self-hosted infrastructure, or partner-provided sandboxes from Blackcell, Cloudflare, Daytona, DigitalOcean, and many others, allowing selection based on the cost, performance, and cold start requirement that you may have. The new harness capabilities include automatic context compaction for long-running sessions, tool search to reduce token usage by loading only relevant tool definitions, and programmatic tool calling that lets agents run parallel calls and filter results in code before returning them to the context. Multi-agent support allows a main agent to delegate subtasks to parallel subagents, each maintaining independent context, useful for research, analysis, and coding workflows without requiring custom orchestration. Pricing follows standard token and tool usage costs, no additional API fees. I mean, this is nice. I appreciate the standardization. It's an area everyone's working on in GenTech development, I think, these days. And so having options here is good. Yeah. [09:17] A: I mean, this is, it's, it's kind of funny because this is what I thought sort of the, the Vertex AI agent SDK was going to be, but that was more of just a common way to define sort of these instructions and models. And then you still had to have that execution platform running somewhere. And so they, they did build that into Vertex. and I'm happy to see it being built out other places as well. I think Bedrock, you can do this in Amazon, and it's just more of like the, the runtime environment. And so I'm happy to see sort of harness definitions be more than just sort of agent instructions and agent tools and skill definitions, but also including that execution layer, because it is important. [09:57] C: Yeah, I think if they can standardize this execution layer, we can start to build you know, more secure ways to test them, to kind of do these things. So I think it's a nice initial soiree into that world of exposing what they've built internally to external people to start to test their code in. Because the last thing I ever really want to do is test my code locally with zero controls on it. Though I definitely do it, let's be honest. [10:22] B: Well, I mean, that's the reason why everyone doesn't— wasn't a big fan of Cowork and ChatGPT for work, because they were just running agents willy-nilly on corporate laptops, the corporate access. Um, and that's why, you know, not having API logging is such a big deal on those products, which they've now resolved. But, um, you know, that's what the fear was. And that's, you know, but that's been the problem, I mean, forever with, you know, with engineers. You can write any code you want to and run on your laptop because you're an engineer and you've been given that right to do that. So it was— it's not maybe an increase in threat scope, it's just an easier threat to now action than it used to be. [10:57] A: Yeah, it's, you know, like, it's, it, it just shines a light on, you know, sort of general user access and permission problems that have been around, you know, forever. It's just now they're— now you can scale them real fast. [11:10] B: Yeah, well, and also because everyone's now a developer, because everyone can use Cloud Code or Cloud Cowork, uh, you now also have a lot more people who never were doing things, and those people aren't trained in good practices or hygiene. So that's the risk. Uh, second feature from OpenAI this week, ChatGPT Images 2.5, its updated image generation model cutting generation latency by up to 50% compared to Images 2.0 while improving detail preservation, natural lighting, and multi-turn editing consistency. Two new API models are available with the GPT, uh, GPT Image 2.5 Flare, the default option offering 50% lower latency than GPT Image 2 for high-volume use cases like social content and product experiences. And GPT Image 2.5 Sunburst, aimed at premium workflows requiring tighter edit control, such as campaign and creative. New product features include Sketch, which lets users draw a reference directly in ChatGPT, templates for common formats like flyers and merch, in-image commenting for targeted edits, and the ability to share prompts alongside generated images. The model shows improved reference photo fidelity, better subject preservation across new settings and styles, and more reliable edit-only-what's-asked behavior. Which is relevant for developers and may be relevant for Ryan because our cover generator may actually properly represent him because he is not happy with the ChatGPT version of himself that exists in our show note covers. [12:28] C: I mean, yeah, we know that Justin's is accurate. He's happy with it because he did that feature and Matt and Ryan are not. [12:39] B: Matt's unhappy with it because he makes it more bald than he thinks he is. [12:42] C: Exactly. How did you know? [12:46] B: And then Ryan's is that it's his hair is all wavy and like, it's not, I mean, I guess it is like when I look at him right now, he does have kind of a wavy hair thing going on, but it's not as wavy as ChatGPT likes to make him or Gemini does. But we'll see. I am updating that in the background today to the new Gemini image model and the new OpenAI one. So we'll see how this shows topics go if we pick one with the images of the host or not. NVIDIA has launched a free tool that links your idle computers into a personal AI data center. And I look around my office at all the computers I have and I go, this might be great for me. NVIDIA's, uh, Pair is a free open-source software that networks idle home computers with NVIDIA GPUs and Apple M4 Plus chips to run local AI inference tasks together rather than a physical device despite its name. The tool targets underutilized compute in households with multiple devices using idle cycles for adjunctive workflows without disrupting active tasks like gaming. Security relies on a 6-digit pairing code plus mTLS encryption, addressing a key concern for distributed home computing setups. This reflects a broader industry push towards local and edge AI processing, reducing reliance on cloud inference and giving users more control over their data and costs. NVIDIA is also simplifying local GPU setup for third-party agent apps like Perplexity Portable Computer, Hermes Agent, and OpenClaw, signaling continued investment in lowering barriers to local AI adoption on Windows and Mac. [14:06] C: I feel like we're going in and out. I feel like this was back in the day of Folding@home, you know, where you would run that, it did cancer research, everything else, and then we kind of got away from that. And now I feel like we're just going back to using our home computers to distribute workloads across, just do the extra, you know, the needed capacity with these things. [14:29] B: Yeah. I mean, I was more of searching for aliens than for curing cancer, but you know, I was also a SETI@home. Yeah. [14:34] A: I didn't realize there was a cancer one or I would've— [14:36] B: Yeah, I knew there was both, but I chose Aliens, cuz I was way more excited about aliens than I was about solving cancer. Although I, I care about that too, but I just, uh, you know, in the '90s, my limited computer capacity was study at home all the way. Cause I was a teenager and didn't care about real world things. Now as an adult, I would've choose differently, but, uh, Matt was more humble than us. [14:55] C: Yeah. [14:56] A: I mean, it just shows the, you know, the, the resource constraint is driving force behind these, you know, it, it was CPU and, and the ability to sort of crunch numbers back in that, those days for, I guess a long, you know, long levels of protein chains for cancer or, you know, astronomical signals of whatever SETI was looking for. [15:17] B: Well, you know, Gemini has already mapped all the possible protein folds, so you don't even need to do, you know, that project anymore. Yeah. The other, is anyone using AI against the SETI data? Come on. Let's use some AI on alien searching. Yeah. You know, one of the things that's interesting is there's always been kind of this like model of compute. And I think we're just in one of the narrow cycles of it. So if you go back to the original compute, you know, with the large full laboratory-sized computers that, you know, have— a calculator today has more computing power of— you know, that was all very centralized. And then we kind of went through a couple iterations of that. And then we had mini computers, which was not really mini computer, but they said they were. And then went back to the mainframe and the mainframe to the desktop. And then we went to the internet, which was back to the server. And now we're kind of going back to the desktop again. Um, and I think it has to do with the cost of these things, right? And you can look at the cost of compute of GPUs, it's a very high cost. And so if you can minimize your cost to the just what you need and you can do that on your local computer, I think that's why there's such an interest for this. But as GPU costs drop in the future, hopefully, fingers crossed, um, you know, this, this may swing back the other way. But I think right now the reality is it's cheaper if you can run it locally than it is in the cloud and a lot of these use cases. And I mean, I'm looking at, you know, cost of Claude, cost of OpenAI versus DeepSeq and others. You know, you already are having that conversation. You're like, okay, well, if I can actually run DeepSeq on my laptop with my M4 GPU, uh, that's a pretty good trade-off. Or Quen 30B Coder, and I can do almost everything I'm doing, just maybe a little slower, or maybe not, depending on the model and what it's trying to do. [16:54] A: And it, for me, it's always been, uh, I guess, kind of an efficiency game. Like it's, I'd rather someone else run all my computers. So if it's, if it's cost efficient and I can do that, but, uh, because of the price for GPUs, just like, you know, um, you know, running kind of gaming or anything, it used to be like CPU stuff where it was like, you make sense to sort of have a console that connects back to a, uh, a server farm that's running your games. That's fine until like now for GPUs is that it makes more sense if I'm gonna just burn tokens in my terrible like developer workflow, I may as well, you know, be burning money that's recoverable in my home versus, you know, just paying through the nose through an internet bill. [17:38] C: Yep. I mean, I essentially hit some of that with like some personal projects with GitHub Actions. They were like, you used your 200 free minutes. And I was like, Well, I guess now I'm setting up a GitLab Actions at home on a spare computer I have and running it that way. Just trying to not become Jonathan and running, you know, entire server setup in my, in my house. [18:00] B: Is ever running a GitHub, your own GitHub Actions runner costs you money? It still costs you something on GitHub. So the question, it's a, it's an ROI trap. Like how many more minutes? [18:09] C: No, they never charged you. They rolled it out. Everyone freaked out about it. They dropped it off. And I don't think they've re-rolled it out because people were going to drop GitHub Actions too much, which I feel like at this point they probably want people to, but I don't, I don't get a bill from them for my projects. [18:30] B: Okay. Well, that's good. I remember when that first came out, I haven't really looked back at it, but maybe I'll set that up for my house because I have some extra capacity and I'm paying higher prices for GitHub. Than I really want to, especially with their availability these days. [18:44] A: Yeah. [18:44] C: So I definitely didn't just tell Claude to, here's a SageMaker, go set it up for me. [18:49] B: I mean, it's, it's super easy to set 'em up. I did it in AWS as a container and it was, you know, it's basically you give it a key, you run their little, you run their container baseline and you're done. Like that's all you have to do. So it's, it's not super hard. [19:01] C: And you can run a spot in AWS too. [19:05] B: Yeah, I've done that too. [19:05] C: And save some money there. [19:07] A: Yep. [19:09] B: Well, speaking of GitHub, good segue, guys. Cloud Tools this week, they have the August 22nd availability report detailing 5 incidents affecting service reliability incurring alongside an ongoing infrastructure migration to Azure. The company continues to prioritize availability and capacity work over new features in response to recurring capacity-related failures. And because everyone's going to cancel them if they don't fix the problem. Several incidents shared a common root cause pattern, services running too close to capacity or acting Kubernetes limits where routine deployments or traffic peaks triggered cascading failures across service mesh, Load Balancers, and databases. GitHub is adding headroom, autoscaling corrections, and circuit breakers to address this recurring theme, which is nice. This is a little bit more action, a little bit more what we asked for actually in the last RCA was like, can you actually tell me something tangible you're going to do? Make sure there's more headroom and you're not running your servers quite as hot to give you more wiggle room. Uh, that's a good move. That's, uh, I appreciate that one. [20:03] C: Yeah, the article has some interesting numbers where they say, you know, what they've moved off. So one of them was like authentication moved off the oldest shared database, and it's like a million queries per second from it, that from their replicas. It saved. So they, they go into detail in there about some of them, and some was like headroom that I was like concerned about, like before they were running, I don't remember what it was, uh, peak cache CPU utilization was at 98% before, and when they moved it over to Azure, they're at 80%. And I was just sitting there reading those numbers, and I was like, why was it okay that it was at 98%? Like, that's something that should have been flagging, I feel like, before. Or maybe they just couldn't get the hardware or something in their data center, or they were moving. [20:50] B: I mean, I'm always torn on that one, because if you can if you're going to run a system at 98% utilization and you have a way to prevent it from maxing out to 100%, uh, and you're not impacting user latency, I say congratulations, you're being a really good user of the dollars you're spending. [21:06] C: Um, but they were affecting end users. [21:08] B: Oh yeah, see, that's a different problem. Yeah, but again, like, I'm just saying there's a double-edged sword. Like, if you, you know, if you are able to maximize CPU on the system and not cause impact, then that's a great use of time and resources, but not really in this case. But, uh, yeah, I looked forward to seeing more of this and hopefully we're past the GitHub Actions, but I'm sure it'll be one tomorrow that I mentioned it out loud. [21:33] C: I still wish they went for each incident a little bit more like the Azure one, like minute by minute what occurred and what they did. But here they finally go into, okay, what went wrong? How do we respond? And they go into that in a lot more detail in this one. Um, and they show the charts of like failures and things like that in there too. So it's definitely more detailed, not where I would want it, but you know, I also just like the information because I find it really interesting. [22:04] B: Yeah, I, I always like to learn from other people and what they're doing too. So yeah, I agree. Uh, GCP Terraform now offers a metrics feature giving organizations visibility into run activity or workspace utilization and operational health across their Terraform estate aimed at platform teams managing infrastructure at scale. The dashboard surfaces data like run frequency, success and failure rates, and workspace activity trends, helping teams identify bottlenecks or problematic workspaces without manually auditing individual runs. Um, which is great. I'm mostly surprised it didn't exist because I feel like, yeah, if you're trying to show the ROI of why you have GCP Terraform, you should probably want to have metrics. That you can use to justify why you spent, you know, a bajillion dollars on HCP Terraform. So the fact this didn't exist kind of blows my mind, but I have never actually bought Terraform Enterprise or the Terraform HCP platform beyond an, you know, trial little project to see how it was. I don't really know what the problems are at enterprise scale, so I can't comment too much. [23:03] A: Well, your trial little project did make it to production, by the way. [23:06] B: Oh, you heard that? [23:07] A: You just didn't have to run it. I did. [23:09] B: Yeah. [23:10] C: I was like, I swear you were using it. Yeah. [23:14] B: Yeah. [23:14] A: Uh, yeah. And you know, it did have rudimentary things, but mostly for billing purposes, right? So number of like workspaces, which weren't Terraform workspaces, but what you know about 'em, they're different Terraform workspaces. But yeah, that level of runs and, and utilization metrics, like it's surprising cuz that was quite a while ago when I, you know, I was running Justin's production Terraform experiment. [23:38] B: Hey, that was a long, long time ago. So long ago that I forgot about it. Yeah. Until you just said it and I was like, oh yeah, I do remember that now. [23:46] A: So it's, it's sort of surprising. Yeah. That this is, that they, they didn't have anything built into this. Um, yeah, but pretty graphs of, you know, automated infrastructure. [23:56] C: Yay. [23:57] B: Yeah. I mean, I always like graphs. Executive in me loves a graph. Uh, all right. AWS introducing PizzaBot, an open source inbox for AI agents that works in the background and hopefully orders pizza because it's called PizzaBot. Uh, this is from the AWS open source release. Next, uh, open source team, uh, the self-hosted inbox application for background AI agents that starts internally at Amazon with over 2,000 users for tasks like meeting prep, email drafting, and CRM logging. The application addresses a specific gap. Instead of requiring users to watch a chat window while an agent works, PizzaBot uses an email-style interface with all unread and action queues, so agents surface results or approval requests only when needed. The architecture is a local server plus client model, uh, of course, Electron desktop app., with all data stored as SQLite database and files in a single user-controlled folder, supporting model providers including Anthropic, Amazon Bedrock, Google Gemini, OpenAI OpenRouter, or local models via LLM. Extensibility relies on existing standards rather than proprietary formats, the MCP server for tools and Anthropic's agent skills markdown convention for packaging specialist capabilities, meaning teams can reuse tooling they've already built. Uh, it is a community project under the Apache License 2.0, not an official AWS service, so there's no AWS support or SLA, so don't ask them for help, but, uh, use it at your own, uh, experimentation, which I downloaded it and that's as far as I got. So we'll play with it still, uh, but I have not gotten further than the download. [25:16] A: I mean, is it, is it very much tied towards sort of the, the employee sort of assistant or is it more general purpose? Like, I mean, you never see like OpenCLAR, Hermes, or sort of advertise as like helping you work, but they are sort of all personal assistant based, right? [25:33] B: Yeah, I mean, it's the same basic idea. Okay. Um, but I mean, the thing is, instead of having a chat prompt where you're constantly chatting and hard to change context, now you can send, it's just like sending an email. Like I sent an email to Ryan saying, hey, can you do this thing? I sent an email to Matt, hey, can you do this thing? And then like you guys came back to me later. Like now it's, it's more asynchronous in that way. So that's the kind of the advantage of it. At least how I read it and interpreted it. [25:55] A: So cool. [25:55] B: Again, I haven't, other than downloading it, that's as far as I've gotten. [25:58] C: Yeah. [25:58] A: So yeah. That's the most research any of us have done, so you can win. I mean, it makes sense to me, right? Like chatbots, it's, it's really the same thing at a, at a different speed, right? And you're seeing that happen with a lot of these coding agent harnesses, which is, you know, they're, they're responding to GitHub Issues or Jira Issues or, or that. And so it's all just points of input and then execute task and come back with, and you know, Chat's just a more real-time version of that, really. So it makes total sense. [26:36] B: Azure— AWS is launching the second-generation Single Rack Outpost, a self-contained 42U rack combining compute, storage, and networking, delivering up to 2,688 vCPUs and 100TB of EBS storage for on-premise deployments. The single rack form factor targets space and power constrained locations like manufacturing floors and gaming venues, offering a smaller footprint alternative to multi-rack Outposts for organizations needing low latency and local data processing. It supports multiple instance types including the M7, M8, C7, and C8, and the R7 and R8, uh, as well as accelerated networking instances including the BMNSF2E. And I don't know what those are, so I'm going to keep— skip that. Uh, matching capabilities available on multi-rack configurations, uh, maintains consistency with AWS regions through identical APIs, management console automation, and governance policies, allowing customers to extend existing cloud operations and security controls to on-premise environments without retooling work. Availability varies by country and territory, and customers should check with their Outposts RAG FAQs page for current regional support. So don't get too excited until you check the FAQ. [27:36] C: I'm more impressed that they've only had one section of AWS Outposts since they've released it. Because Outposts has been out for a long time, I feel like. [27:46] A: Well, this is Single Rack specifically, the second generation of Single Rack. [27:50] B: Yeah. [27:51] A: Oh, wait, so they're separate from Outposts in general, which is, yeah, which is all I realized. [27:56] B: Presumably. Okay. [27:58] C: I've clearly never had a use case to run Outposts before. [28:02] A: Uh, neither have I, but I, I like to nerd out at conferences when they have the rack, you know, out on the, on the expo floor. And so I have spent an exorbitant amount of time, like way, that's way more than is necessary for someone who's never used it or even had the use case where I would potentially use it. [28:16] C: I weirdly had a use case for it, but we were able to get enough power out of Snowball at the edge and do it that way versus trying to do the data hookup at remote locations for Outposts. Able to like essentially daisy chain multiple output, out Snowballs and then be able to then run the Lambdas at the edge on there. [28:42] A: So when we make fun of you for like the misuse of technology doing hacky stuff, this is one of those examples that, yeah, I'd point out, you probably— [28:49] C: To be fair, Amazon recommended that direction at the time, and we were working with the Snowball team because it was running this at like edge locations, like islands off of Alaska and stuff like that. [29:02] A: Chaining together Snowballs, but yeah, right, nothing. [29:06] C: Okay. Few ideas later, I'll talk about it. [29:11] A: It's like a glorified, like, uh, portable hard drive. [29:15] C: Like, that's crazy. But you can do the processing on them. [29:19] A: You can. [29:19] C: Because there's Lambdas there now. So you could do basic processing off there and send, I think it was basic notifications from it. [29:27] A: That's cool. [29:31] C: So it was conceptual. We handed it off to their internal team. I never finished it. But I did the, essentially the whole architecture of it. I gotta reach out and find out if they ever actually finished that. That was like 4 years ago now, so. [29:46] A: If I could have a, like a physical S3 bucket that also sent event notifications for, for, uh, to, uh, for integration, that would be awesome. I would, I would use that. Sounds like what that, that's what it is, which is pretty rad. [30:00] B: That's cool. Amazon API Gateway execution logs jump from 1,000 kilobytes to 1 megabit per event, finally giving developers actual visibility into full request and response payloads instead of truncated snippets. I mean, API Gateway logs from my experience were worthless at 1,000 kilobytes. Logs can now run to CloudWatch Logs, S3, or Data Firehose simultaneously, allowing streams to send JSON to CloudWatch real-time alerting while archiving Parquet-formatted logs S3 for cost-efficient long-term storage. And Athena analysis. This addresses a longstanding pain point for API debugging where truncated logs often cut off exactly the data needed to diagnose the issue of the stack trace. Availability across all AWS regions including GovCloud US with setup by console, CLI, or CloudFormation. So no waiting on regional rollouts. Build@CloudWatch vended log rates, meaning cost scale of log volume worth factoring in for high traffic APIs for enabling full Lambda logging broadly. And again, I think you should turn this on when you need to troubleshoot something. Not just leave it on all the time. [30:56] A: Yeah. Unless you, yeah, just have money to burn. [30:59] C: Right? Cause it's, it's, or you, what is that? [31:02] A: Is that a 1000x size of your, of your logging event? Sure. [31:07] B: Yeah. [31:07] A: Yeah. [31:07] B: What could go wrong? [31:08] C: If you hate your team that runs Elasticsearch, you do this. [31:11] B: Yeah. OpenSearch team, screw those guys. They don't know what they're doing. [31:15] A: And no one likes them. That's why they're running on OpenSearch. [31:18] B: Exactly. They probably replaced something loved like Splunk. Too soon, Justin. [31:25] A: I know it's been almost a decade. Still too soon. [31:27] B: But still too soon. Yeah, I know. And that's why I never support OpenSearch as a project anymore. Scars are deep. AWS is extending EBS volume clones to support cross-account copying, allowing customers to create point-in-time copies of EBS volumes in different AWS accounts with optional re-encryption using a KMS key in the target account. The workflow uses the AWS Resource Access Manager for sharing. The source account shares the volume via RAM. Target account accepts the resource share and then initiates the copy from their own EKS console. Key use cases is refreshing test and development environments with production data while maintaining isolation and applying different encryption keys. Useful for separating prod and non-prod AWS accounts. And title constraints include volume encrypted with AWS managed keys cannot be shared, only unencrypted or CMK encrypted volumes. And a custom copy must stay within the same availability zone as the source, and CMKs must also be shared if the source volume uses one. Pricing is a one-time fee based on volume size charged to the target account, plus standard EBS storage charges once the copy is created, shared, and Viya RAM itself is free. Now, this may sound cool to you, and I will tell you this is a sharp edge very quickly. Number one, you know, if you are able to get a hacker into your account, they could then share this volume with their account, and now your data has been exfiltrated and you have no logging. Where at least when they were in your account, you at least potentially, if they didn't turn off CloudTrail, know what they did with it. But worse, if you're just willy-nilly moving data from production to dev/test, you're going to have a bad time. Don't do that. You need to, you need to have scrubbing processes. There's reasons why we don't do that thing normally. And normally you keep your accounts isolated for this exact reason to make sure there is a hard barrier between them to make sure people who use the sanitation pipeline to not move customer data into a non-production environment. So you know, just little minor things that you should really keep in mind. [33:14] A: Yeah. More and more countries adopting data sovereignty is only going to complicate this, right? Because it's a lot of that is to prevent exactly this type of, you know, data movement. So like, I do think it's, I do think that this is very useful. And I do think if you had a scrubbing process in here from prod to dev, and this makes it incredibly useful to do, or this is how you enable your scrubbing process, this would be great. I hope it's point in time. Like, I know that like sharing of network resources via RAM has been very painful just because then you've got these weird inter-account dependencies that you can't clean up, um, from either side really. And so I hope that this doesn't sort of follow that pattern, but, but yeah. [33:55] C: I feel like I got burned on RAM early on, and every time I see a feature that discusses RAM, I'm like, this is a bad idea. Like, it's one of those things that like, It's just a red flag in my head. As soon as someone's like, you should use this, I'm like, there has to be a better way, or this should be— [34:11] B: It was shared VPC. [34:11] A: It was the same rough edge for all of us, and it was shared VPC. [34:14] C: Okay. [34:16] B: It's a great idea. I don't know what you're talking about. We'll share the Active Directory and the network between the accounts. What could go wrong? Yeah, no, it doesn't. Yeah, that was bad. [34:25] A: It broke all of us. [34:27] B: Yeah, and what do you mean you can't delete something from the shared VPC once it's created? Yeah, that's a limitation. [34:33] A: Oh, I'll delete it from the account that shared it. Nope, can't do that either. No, because there's something in it. [34:39] C: Was that the first shared resource they did? Is that why it spurred all of us so badly? [34:44] B: Yeah, yeah, I think so. [34:45] A: I think it was, it was the first one I remember anyway. [34:47] B: And it was, it was pre-organizations and like there was lots of, you know, weird IAM hacks you had to do to make it work. And we thought it was brilliant and then it wasn't. [34:55] A: Yeah, so it was what we were asking for for years and then we got it and didn't like it. Yeah. [35:01] B: And then they were mad that we didn't like it. They're like, what do you mean you don't want to use it? Like, well, because 'cause it sucks the way you implemented it. Like, oh, okay. Then they never, they didn't really do anything with it. Maybe AI has now fixed it though. [35:11] A: I haven't checked it out. I mean, RAM hasn't gone away. They've built it in for a lot of the organizations. So it's a big part of StackSets and some of the other CloudFormation things. [35:18] B: And so I don't know, they're sharing VPC, maybe it's not so bad now. Maybe they fixed it. [35:23] A: I don't know. Like, it's, I think the reasons why are bad are some fundamental things about Amazon. [35:28] B: Like, yeah, I mean, that's really what you kind of ran into very It's like, this is just a fundamental way that VPCs work inside AWS that this causes problems. So. [35:35] A: They're like, you wanna run multiple AWS accounts? That doesn't make any sense. Yeah. [35:41] B: You wanna share a single VPC? What? [35:43] A: I don't understand. What? [35:44] B: Yeah, well, RAM I think has potential, but definitely still some rough edges there too. The AWS DevOps Agent now supports two-way Slack communication, letting engineers run full incident investigations without leaving the chat thread that they're already using for team coordination. Update targets a common on-call pain point, context switching between Slack and separate investigation tools during high severity incidents, consolidating customer conversations, agent findings, or media steps into one thread. You mean into Jira? Uh, engineers trigger investigations by @mentioning the agent in a connected private Slack channel, and then query AWS resources, metrics, alarm status, deployment history, and incident pattern conversationally. The feature works across AWS, multi-cloud, and on-premise environments, positioning DevOps Agent as a unified operations layer. Hey, we should try this out, Matt, you and I, for Vault. Like, it'd be fun to play with. I was like, you had your issue today where you thought, uh, you thought it was lying and it wasn't. You just happened to send your response at the same time it did its thing. [36:38] C: So, wait, what was that? [36:40] B: That's what the LML— [36:41] C: oh, when I was putting the note in. Yeah. [36:45] B: Yeah. Well, you were— yeah, but it'd be interesting to play with this because I've been meaning to have a project and I feel like two-way Slack communication makes sense to try it now. So we should try this out. [36:54] C: Yeah, definitely. Because I don't— I believe now I do, but initially when I set up all that, I didn't have access to anything. So it was hard to debug it where if the AI bot does, I can just get more information. Next week's project. [37:10] B: Yeah, we can do that. All right. Uh, AWS integrates OpenSearch Serverless directly into v0, Vercel's AI-powered app builder. Let developers spin up a full text and vector search infrastructure using natural language prompts instead of manual configuration. The integration targets RAG workloads specifically, provisioning OpenSearch K8s collections, handling indexing, and configuring endpoints automatically so developers can focus on application logic rather than search infrastructure. This reflects a broader trend of AWS services embedding into third-party developer tools and AI coding platforms, meeting developers where they are already building rather than requiring a trip to the AWS console. So yeah, uh, for those of you who don't know, Vercel is a very popular frontend hosting language to have abstractions to AWS. So it's basically a service on top of AWS that you host your frontend application inside of, and you don't have to think about AWS at all. The dream of all developers everywhere. [37:59] A: And so is OpenSearch, I guess they're, the idea is that you can use OpenSearch Serverless natively inside your app as like the data layer for your application. [38:07] B: Yeah, probably for full-text search or for other other use cases that you may have because there's a lot of web apps. So if you think about like full-text search or being able to search a website, that all requires a search engine. OpenSearch is very popular for that. AWS Transform for .NET modernization now supports a CLI interface, adding to existing web app, Visual Studio IDE, KiroPower, and MCP agent options. CLI can be triggered with a single command and scripted into CI/CD pipelines for autonomous execution. This falls under AWS Transform Custom, which handles language version upgrades, framework migrations, performance optimization, and codebase analysis at scale. The transformations that improve through continuous learning across engagements. [38:45] A: All I've learned is that I do not know how to use this transform tool whatsoever. Like none of what they said this is. Like, wait, do I just like, is it like lifetime transform of my .NET application to a modern stack? Like where it's just like a shim layer? Like I thought this was gonna be like architectural guidance and like actually like generating resources. [39:06] B: It was back in the day. Then, and then everyone got AI agents and they're like, oh, now we can actually use you know, other things. And so that's what they're doing. [39:14] A: And so they have MCP and this is just so that you can have your AI agent run command line for you, I'm guessing? [39:19] B: Yeah. [39:19] A: Like fix my, fix my service. I mean, if something modernizes it, I guess I don't care. [39:25] B: Yeah. I mean, I'm, I'm more impressed that I think that developers are using, um, you know, any type of, uh, CLI. They're programming .NET. They're not, they're not. [39:35] A: Their, their IDE is under the covers, but they're not. Yeah. This is like they plugged it into VS Code. VS Code has a terminal in the backend and they even like in VS Code, it even hides it now. So you can't see it. [39:46] C: The whole transforms are just, these are just like prebuilt transform sets that they've built and they've essentially just added it for the .NET SDK. So like, you know, if you think back in the day it was like Boto 2 to Boto 3 or Python, you know, 3 to 4 or 2 to 3. You know, version upgrades. This is just a specific one for .NET, but what's interesting is it doesn't— I don't think it works in older SDKs. Like, I think it's limited too. So you can't go back to like Python 4— or sorry, .NET 4.6. It looks like you only might work on 8.0 and greater. So understanding .NET NET versus .NET Framework still baffles me. What their version numbers are for all these. [40:32] A: It's just so funny because I'm reading through the documentation now and I'm just like, okay, if I put this in a context of something that I would understand, so like Python version upgrade from like Python 2 to Python 3, which it can't actually do, but no, I'd say I was just— Python 2 is too fast. But, uh, but, uh, trying to understand like why I would use this from 3.8 to 3. I get how like in a large codebase, this would be this would be easy to do, or this would be enticing to do, like moving from like Python 3.7 to, I guess, Python 3.14, because you don't know which versions of which dependencies and which function names and different modules have changed names. But it is sort of, it is still something that I don't know that I would need a CLI tool to execute, but I guess maybe I, maybe I don't understand what this is or why you, how I would use it. [41:24] C: If you have a decent QA harness for your application, it's not a bad way to one-shot an upgrade. But with that being said, you still have to test and do everything afterwards because it's just doing a lot of the basic rule changes. [41:42] A: Mm-hmm. Well, and I'm sure it doesn't solve that either, right? Like, and so it's, it's just, yeah, I don't know. It's sort of like a trying to just understand how it's how you actually utilize the tool, like the hands-on keyboard sign portion of this for running a transformation, the transformation service. [41:58] B: Yeah, I, I never tried to play with it. I was in GCP world when this came out to try again. So, uh, maybe, maybe I'll try it out in a future company. I'll let you know. But we'll see. Uh, AWS is improving regional resiliency for root user sign-in features brought to you by Nova, uh, this week. Root user sign-in traffic is now distributed across 3 regions: US East North Virginia, US East Ohio, and US West Oregon, reducing dependency on a single region for this critical authentication path. Routing is automatic and transparent to users with no configuration changes or region selection needed to be on the customer side. The directive addresses a known failure mode where US East North Virginia outages could block root user access entirely, a scenario that has caused issues during past AWS service disruptions. Security and compliance teams need to update CloudTrail monitoring and alerting rules since console login events for root sign-ins will now appear in whichever of the 3 regions process the request, not just this normal default region. It would be nice if you guys just automatically pushed it to the same one, but that's not, it's against your multi-region isolation model. I get it, but it's sort of annoying. Yeah. [43:02] A: Well, hopefully you've got the security tooling set up where it will read CloudTrail in all the regions, not just the one region. [43:07] B: Well, I mean, first you had to, you had to know that when you enable this thing got enabled and if you didn't enable the CloudTrail logging, it could be logging you in right now and you would not know. And you wouldn't get any of it. [43:16] C: Yeah. [43:17] B: Yeah. That's, that's the kind of the maybe bad part of how they're rolling this out. Uh, that'd be my one critique, Amazon. [43:25] A: Yeah. I mean, it's, it's again, they're, they're handcuffed by their underlying, you know, architecture from forever ago, from the early 2000s, right? Like the single region and rolling it out. So it's, it is sort of, it's tricky when you've painted yourself into a bit of a corner there and trying to get your, dig your way out of it. And I think this is a pretty small rough edge to have to deal with because I think a lot of security and compliance configurations over time have grown to be multiple region aware. And I don't think there's a whole lot of, you know, automated playbooks or security logging that's going to only look at a single region. They might look at a single log source, but I doubt you'd see, a use case where they're only looking for console logins for root access in a single region in terms of their automation or their detections, hopefully. [44:16] C: I'm thinking about all the root login notifications I've set up over the years. I don't think I've ever locked it down in that way. You know, maybe tied to a specific CloudTrail ARN or something along those lines, but never down to that level. [44:32] A: It would be that, you know, incidental way, right? Yeah, exactly. I specified the ARN and that had a region in it and therefore like indirectly I tied it to a single region. So it's definitely something to go double check, but probably not intentionally. [44:46] B: And if you don't know how to actually analyze your CloudTrail events because it's hard. [44:51] C: Oh, okay. [44:51] B: And you don't know if you're missing it, you can now use Amazon Q Console, which is now fully integrated into CloudTrail, letting users query account activity, audit configurations, and troubleshoot issues using natural language instead of writing manual queries or parsing the log files, or writing Athena queries, which is always best. Practical use cases include checking trail configuration gaps, investigating IAM role access, tracing VPC changes, identifying unauthorized access attempts, and finding the source of unexpected billing spikes. Q pulls from CloudTrail trails, CloudWatch log groups, and EventBridge data stores directly, so answers are grounded in actual account activities. [45:24] A: Yeah, so this is going to be limited in time, right, to queries, just because of the same way that you're limited in the CloudTrail console today. Like you can only go back, I forget, what is it, like 2 weeks events, um, before you have to break down into doing it in Athena. [45:40] C: But this is still good for real-time debugging. Oh, for sure. Which is where I foresee this feature set up because essentially most of the time I use CloudTrail, I'm not, you know, running a security incident like you are. I'm trying to figure out why all of a sudden this new thing that I thought I had the right permission on isn't working. And that trying to find that random deny in the middle of everything. [46:04] A: You give me too much credit. I'm in CloudTrail trying to figure out what to undo, what I just did, whatever it was. [46:11] B: Someday you'll be in there trying to figure out how the AI removed your access rights. [46:14] A: Yeah, exactly. [46:15] C: Yeah. [46:16] A: They'd be like, all right, recreate what I just did. What, what things did I just delete that I shouldn't have? Which regions were those supposed to go into? I mean, this is, this is definitely an advantage. I, I, you know, going back, you know, using the CloudTrail console to sort of filter on events by, you know, API method name or, or username is, is great. And then you needed anything more granular than what you were provided directly in the console, you had to break out to Athena. So I'm hoping that the sort of deep access of Q will sort of have a little bit more than what the UI could provide. So I think it is. And then without the overhead of like having to set up an Athena table and, and manage the, the different schema changes that have drifted over the years. [46:59] B: All right, let's move to GCP. Uh, Goldman Sachs had a conference called the Communicopia and Technology Conference, which is the dumbest name. [47:11] A: It really is bad. [47:12] B: Yeah, it's so bad. Uh, but they had Thomas Kurian there, so it spiked my interest. Uh, and Thomas Kurian had 3 highlights., that were highlighted here in the blog post from Google. First up is a full-stack positioning. Google Cloud emphasized it's the only provider spanning the entire AI stack, citing 17 product lines exceeding $1 billion in revenue and over 300 customers with $100 million-plus contractual commitments, which again, I don't know if that's exactly what I see AWS and Azure doing, but okay. Uh, deal size growth. Kurian noted that more than 2x quarter-over-quarter and year-over-year growth in the number and value of $100 million to $1 billion deals, suggesting large enterprise AI commitments are accelerating. Uh, and then TPU economics. Google claimed a 2-year AI server playback period while TPUs offering faster playback with GPU than GPUs and knows most AI infrastructure contract values comes from committed 5-year deals, which is a specific cost and margin claim, uh, to look at. Gemini Enterprise apparently is adopting, uh, with much faster than, uh, other AI products with Google states customers using its AI products 1.8 times as many, uh, products overall compared to non-AI customers, framing AI as a driver of broader platform stickiness and cross-sell. Uh, so yeah, if you wanna check out the whole thing, there's a full slide deck and transcript from the September 8th Communicopia conference. Uh, if you wanna check that out. [48:26] A: I mean, you know, I don't trust any of these numbers cuz he like it, Gemini Enterprise, the, the, the IT tool Gemini Enterprise that was Vertex, uh, AI Gemini Enterprise that was like the Gemini model that was once Bard. Like they just rename these things and then move the things around. [48:41] B: Well, also they say there's Gemini Enterprise and then there's Gemini Enterprise and they're like, well, that's the same thing. [48:46] A: No, no, no, it's not the same thing. [48:47] B: When, when you contract it, it's different. Uh, because one costs more than the other does. So yeah. And it's feature things that you can't access unless you upgrade to the newer one. Yeah, it's crazy. [48:57] A: It's, yeah, it's the, and so it's, it, but you know, some of what he said is interesting with the, you know, the, the 2x quarter over quarter growth in the, in the deal size, which I think is interesting. I don't know if I agree with his positioning that, you know, Google Cloud is the only, you know, full stack of all the cloud providers just because there's the, the, Google owns the Gemini Frontier model, but okay. [49:19] B: Yeah, I mean, that— [49:19] A: see what you're doing there. [49:21] B: Yeah, I mean, like, do we care that— [49:23] C: that I, I don't— like, why does it matter? [49:25] B: Yeah, I mean, do we care that Azure's choice is OpenAI because they're the partner, and then Claude is really AWS's solution? Although, I mean, all those models are available on all the clouds now because they've all— they're all looking for growth across all of them. So I mean, I guess just eventually Gemini should be available inside of AWS and Azure in theory, because by not doing it, they're actually missing out on revenue potentially. So I wouldn't be shocked to hear them say Gemini is available on those clouds, just like OpenAI and Claude are available on theirs. [49:54] A: So we know it's possible because Google or Apple is using it in their data center. [49:58] B: In their own data center. Yeah. So, uh, we'll see. Uh, yeah, a little bit curious where that leads. Uh, but yeah, it's nice marketing for you to say we're the only fully stack integrated. Yeah. Okay. Thanks. [50:09] C: It's great marketing. Thing to say. [50:12] A: Uh, yeah, for sure. [50:14] B: Yeah, it's excellent marketing. Well done. Uh, Google Cloud launched a plugin system for AI coding agents that bundles related skills, documentation access, and MCP server configurations into a single installable package, addressing the complexity of managing individual agent skills separately. The flagship Google Cloud Developer Plugin handles core GCP workflows like authentication, authorization, project management, and gcloud CLI guardrails. And includes the developer knowledge MCP server for grounding agents in current official documentation. The plugin is built on the OpenAI Agents plugin specification, a vendor-neutral standard, meaning customers, uh, can use the same plugin across different AI coding environments like Claude Code, Codex CLI, and, and Antigravity CLI without maintaining separate configurations for each. Installation is handled through the Google Agent Skills Repository with straightforward setup commands provided for major coding agents, plus a codelab available for guided walkthroughs in anti-gravity. Yeah. [51:06] A: I mean, I, I, I love this. Uh, as I just completed my first sort of internal plugin, uh, for the company, um, using the same, uh, framework and it is just so much easier than trying to figure out all the different ways to configure your, the GitHub repo to point at your, you know, whether it be Cloud Code, your cloud agent or cloud app or your VS Code or now it's just an installable package that puts all the skills and the tools and and prompts in place, which is fantastic. And so having that be tailor-built for Google Cloud is great. Cause that was, you know, it was actually on my list to do is the things that I do using GCP all the time in my day job. Like how do I, you know, put some sort of like a wrangle all the random things that I do into something that's reusable and something I can get, you know, better results out of my agent. Interactions with. So this is, I'm glad to see they've already put that thought in and done the work, and I will try this out, get back to you. [52:07] C: We really need to track all the things we say we're going to get back to people on. [52:11] A: No, don't do, and our users, please, or listeners, please don't follow up on that. [52:16] B: We'll, I mean, this is a good task for, it's a good task for Bolt to maybe track them for us from the transcripts. [52:22] C: I know. [52:25] B: Yell at us when we haven't done it after week after week. [52:28] C: It's gonna be a long list. [52:29] A: Uh, that nagging will be turned off real quick. [52:33] B: Yeah, Bolt won't nag. It's not allowed. Where apparently Google is announcing that they're just exploring a potential data center in Lee County, New Mexico, uh, home of Ryan Lucas, uh, with the announcement framed as a community outreach effort ahead of formal project details. Company is emphasizing 3 commitments: responsible water resource management, paying for 100% of the energy used and covering infrastructure costs associated with the project. No technical specifications, capacity figures, timeline, or investment amount have been disclosed yet, making this more of an early-stage community engagement, which is, uh, gonna be the new thing because everywhere else they're trying to build data centers, people are revolting and protesting. Uh, and so this is their attempt to, uh, you know, reach out to the 10 people who live in Lee County, New Mexico. [53:14] A: Yeah, this is even by New Mexico standards, this is sparsely populated, uh, area. So I mean, which It does make it a good place for data centers, right? In terms of like that disruption that you could have. But there isn't much water or power infrastructure. So it is sort of data center building has that two-edged sword of like where the resources are is next to people. 'Cause that's where we build things like power grids and water utilities. But no one wants to live next to a big noisy, like light and noise-generating complex. So it's, it's double-edged sword. Anything that brings, you know, sort of money and resources in New Mexico, I'm a fan of just because that state's infrastructure is crumbling and not well funded. So it's good. I just, we'll see. [54:02] C: I don't know. [54:02] A: There's nothing there. They'd have to build everything. [54:05] B: Yeah, it's around the border of Texas, which makes me laugh because it reminds me of visiting Basel, Switzerland. Uh, which is on the border of Germany and France. Uh, and so, you know, the French put their nuclear power plants on their side of the river. The, the Germans put some other, you know, terrible thing. And then of course all of the drug manufacturing plants on the Switzerland side, you know, it's like, oh yeah, good. Just put those right next to your neighbor. Sort of like New Mexico saying, F you, Texas. Yeah. Yeah. [54:31] A: Right. If you have a big property and you don't like your neighbor, you just put it all over there. [54:34] B: It makes total sense. [54:35] C: Yep. They can get their power from the Texas power grid. I hear it's very stable. Yeah. [54:41] B: Yeah. Unless it's winter and then it's all over. [54:45] A: Or summer. [54:46] B: Yeah. Google's releasing the Filestore Agent Volumes. They provide fully managed dynamic provisioned file storage designed specifically for AI agent sandboxes, addressing storage lifecycle problems that emerge when scaling to thousands or millions of concurrent agent sessions. The service integrates with GKE Agent Sandbox and Agent Substrate on GKE, automatically attaching isolated workspaces in milliseconds when a sandbox launches. To removing the need for platform teams to manually provision or tear down storage volumes. Key technical features include per-workspace access isolation for security boundaries, sub-second attach and detach times to support suspending and resuming idle sandboxes, and native read-write many support with POSIX file locking for multi-agent collaboration on shared file trees. Pricing follows a pay-per-use model based on actual storage consumed rather than pre-allocated capacity, with automatic lifecycle tiering to shift idle data to lower-cost storage tiers. [55:38] A: Yeah, I mean, this, this is a problem I haven't run into yet, but I know it's in my future, like trying to figure out how to provide these execution runtime environments in a secure and safe manner and, and at scale. And so I'm glad that someone's running into these things, which is because hopefully all this will be solved by the time I have to do it. Things like this are perfect, right? Hoping for the idea of volumes that are pre-populated with data that you can sort of vend per different agent execution flows. Or just having the ability to keep them cloned and isolated and maintain changes to the upstream in a safe and sort of orchestrated way is great. And I do like that the attach and detach times are being thought of, because so many of my agent interactions are like, you know, it could be hours in between prompts, right? And so you don't want to be paying for that infrastructure the entire time while while whoever's on the other side of that agent is twiddling their thumbs waiting for the, you know, little ding from their platform that the agent's done. [56:40] B: Mm-hmm. Yeah. I think, uh, again, this is one of the biggest areas that I think we're going to see a lot of development, a lot of consolidation, because there's a lot of solutions for secure agent runtime. And then everyone's going to have a solution and everyone's going to have their things, and then they're going to start collapsing and compressing a little bit because they need to. There's too many options at the moment. [57:00] A: Market will have to sort of correct itself on that and standards will be adopted. [57:05] B: Yeah, yeah, exactly. For those of you who remember Agent Substrate, it's now available on GKE. It's an open source runtime designed specifically to run AI agent sandboxes at scale, claiming 10x higher density than standard containers and sub-500 milliseconds resume times over 500 activations per second. Talked about this when it first came out in beta, I believe. It's basically a Firecracker type, but like architecture for running a secure agent runtime. So now available to you on GKE in addition to servers. [57:34] C: Given that Google was the one that created this, I was kind of surprised it wasn't available day one on GKE. You know, it was, I guess, more if you ran your own, you could run it, but it's nice to integrate it. [57:46] B: I mean, I think Firecracker runs EKS, but you didn't, you had to have one before the other. And so I think you have to design the operating system first and then you can, you know, do the next step, which I think what you're saying here. That's just my take. [57:59] A: I haven't played around with this, so it's sort of, I was trying to figure out if this is just a, you know, a way to launch a whole bunch of containers that are each gonna sort of have an agent subsystem run on them, or if this is more of like a, you know, like in GKE, you have the workload concept, right? Which, you know, boils down to the underlying pods and everything associated with that pod. And I wonder if this was just a version of that where instead of a workload, that's like an app, typical application workload with this agent substrate be sort of a, a wrangling of Kubernetes resources around that. I don't know. [58:32] B: I don't know either. Uh, we'll have to see how that goes, but yeah, I'm sure it's just, you know, it doesn't fit with what I know of GKE, right? [58:40] A: Which is the, you know, like Kubernetes and containers, great. Yay. But, uh, you know, how do you, are you orchestrating you know, the little micro VMs, or is this, or is it more under the covers and you're launching VMs or containers on top of that, those micro VMs, you know? So it's sort of, I, you know, just depends on how they've, how they approach it. [58:58] B: Yeah. They're not really clear in their documentation about how they do that either. So, uh, well, in a sign of what Google requires their employees to work, uh, they have now completed the global rollout of a 16-hour default session length, uh, to make sure they cover their full 16-hour working day. For all customers who hadn't self-configured the setting, aimed at reducing credential theft and account takeover risk. Session controls are now generally available as part of the context-aware access with automation support via Terraform, gcloud CLI, and REST APIs, allowing policy management as code rather than manual UI configuration. Policies can now target Google Groups instead of organizational units, enabling different session lengths for different user types. For example, a 2-hour session for billing admins versus a 16-hour session for general developers. Regardless of org hierarchy and placement, which this is nice because I wish Amazon gave you this level of granularity. [59:43] C: That's a really nice feature. By type of user setup is really great. [59:52] B: This can be applied via the Cloud Console, the gcloud CLI, or individual OAuth groups, avoiding blanket policies that could disrupt BI tools or dashboard integrations. And a preview feature now lets admins manage session policies directly in the Google Cloud Console on other Access Context Manager settings. So it's all available to you. Yeah, this is nice. And I think Amazon had the 12-hour one they rolled out first, and you could change it to be up to 24 hours. I think it's the same kind of thing with Google. The default's 16, but I think you can go up to 24 hours or longer, maybe even, depending on what's allowed in the console and by your policies. [60:23] C: And actually, Justin, I think AWS, you can do it because in organizations, when you configure a role, it's a setting in each role. That you do. So you can, I think, configure it. Now I'll make her check, but I'm pretty sure it's configurable thing. [60:38] B: So I think it's configurable, but it's overwritten by the global. So you could say this one has, um, so if it's shorter than the global, then you, it works. But if it's longer than the global, it does not. Is if I recall the limitation of that feature. [60:50] C: Oh, it's been 4 years since I've really dug into that. [60:54] B: Yeah, and it's been a while since I looked at it too, but I remember that was like, it was like, oh, you were so close. So then you, fail at the last second because you wanted that in that way. But if you want less than the global, so then you, you basically either had to set the global to be really high and then you would set the individual roles less, which is kind of the solution they gave you, which is kind of BS answer. Um, but they might have fixed it by now. Again, like you said, it's been a few years since I looked at that one too. [61:16] A: It's interesting because it's, uh, this is the only— this— well, I guess it's because it's part of Google Workspace, so it is part of the identity provider sort of platform. The OAuth under— because it is sort of, it's a Google Cloud announcement, but like previously the only solutions I know that did this were Okta and Entra. So like, you can set sessions per different groups of people via policy. And so I imagine this is, this is very similar. It underpins that, which is great. Cause I mean, this is, I've had solutions where I couldn't use Google Workspace for, for certain things because it didn't meet compliance requirements required. In terms of having, you know, there are session length requirements that are different for administrators versus normal users. And that's, you know, that's a very standard federal regulation that you have to have. So it's either you blanket apply it to everyone or not at all, use a different solution. So this is great. [62:11] B: Moving on to Azure. Azure Front Door Edge Actions are now available to you. This supports Edge Actions, letting customers run JavaScript at the edge to inspect and manipulate requests before they hit the origin including header manipulation, origin override logic, and lightweight JWT claims checking. Edge Actions are managed as standalone Azure resources configured by Azure Portal, REST API, or PowerShell modules. The runtime is intentionally minimal with no outbound network access, no crypto libraries, and a 10-millisecond execution limit with fail-open behavior, meaning errors or timeouts result in requests passing through unprocessed. Not really the best default there. This makes it suitable for claims pre-filtering, but not full JWT signature validations. Because Edge Actions cannot cryptographically verify tokens, actual authentication must still happen at the origin or another trusted gateway. So, uh, good at beginning, uh, but somewhat limited still where Lambda on the edge is. [63:02] A: Yeah, that is an interesting limitation that you can only do sort of claims checking, but you can't do the full decryption. And I get that, I'm sure it's resources behind it, but, and be able to scale up to the you know, the execution that you would need for something like a, you know, a CDN. That is pretty, uh, fascinating. 'Cause I, you know, that was, you know, Cloud— when Cloudflare announced their version of this, that was the, the number one thing everyone wanted to do was the authentication at the end. [63:30] B: Well, yeah, 'cause if you can make that a faster round trip, then it's, it's a better scenario. [63:34] A: Yeah. [63:34] B: Plus you can then potentially keep it closer to the sovereign region. So like if they're in Europe and you did the authentication in Germany and then sent the data to another EU country, then like you could get through some of the compliance issues around GDPR. So there, there was definitely some use cases for it. So yeah, I expect this is maybe their way of keeping the people from rushing to use this feature while they test it and make sure it works. Because Azure Front Door, we know, is a very problematic service. [63:58] C: Yeah. [63:58] B: And so hopefully this can be tested and worked out and then they can expand to do full chat de-hook and signature validation and stuff there, which would be great. [64:06] C: So I wonder if they're going to have the same problem that AWS had with it when they first came out, was it's a full CloudFront or, you know, Front Door deployment, which meant your iteration time, if you did anything wrong in your Lambda or edge code, was, you know, a 20-minute cycle. [64:24] A: A 30-minute cache refresh. [64:26] C: Yeah. [64:26] A: Yeah. [64:26] C: Like, like you just hit these limits out of it. So like testing, I will say I've written one Node.js code and it was IP address filtering at the edge using Lambda at the edge, and it worked on the first try. I'm never writing Node.js by hand ever again because I did once. [64:42] A: We don't, we don't write code anymore anyway. [64:44] C: I was leaving off that part, you know, because I've written a lot of Node.js code with AI, but I manually written Node.js code once and it worked on the first try. [64:57] A: Wow. [64:58] B: Did you copy paste it from Stack Overflow? [65:01] C: I definitely copy and pasted a few sections of it. [65:03] A: I don't think I've ever written code that work on the first time, and that includes like hello world examples. [65:08] B: So you don't have to admit that. Yeah, I know. [65:12] A: Publicly too. What, what am I thinking? [65:14] B: Yeah. What are you doing? [65:16] C: Just edit that out, guys. Just edit that out. [65:18] B: Yeah. Just, yeah. Uh, uh, in a story that I do not understand, so Matt's gonna have to play Azure translator in chief. Uh, user-bound user delegation SAS is now generally available across Azure public regions, adding a new layer of security to Azure Storage authentication by tying SAS tokens to a specific Entra ID identity rather than just the delegator. This builds on the existing user delegation SAS feature, which already required Entra verification to generate tokens. The new capability restricts token usage further, so only the intended end user can actually use it, even if the token is intercepted or shared. Tokens remain valid for up to 7 days, consistent with existing user delegation SAS limits, but the added identity binding reduces risk from leaked or misused SAS tokens compared to account SAS or service SAS. Applies across Azure blobs, files, tables, and queues, giving customers a consistent security model across storage types for tightening access controls. Yeah, that was a lot. Matt? [66:15] C: Translator? Um, is pre-signed URLs. On AWS, but tied to the— which side was it that they released? The end user who's using it tied to their Entra ID. So pre-signed URL, anybody that gets that URL can use, but this is also verifying it with the identifier to say, Ryan, here's a pre-signed URL, you can use it for 2 hours, and it will verify your user along with that URL for the usage. [66:48] B: So because it's tied into Entra, it can do that. [66:50] C: Correct. [66:51] A: Got it. But do I have to supply my user identity credentials? Like that's the pre-signed URL is bypassing sort of that credentials, like it's pre-trusted sort of thing with these permissions. [67:01] C: It's an extra check. [67:02] A: Is this the same sort of concept, but it's tied to my permissions, my Entra ID permissions? [67:08] C: I don't think it's tied to your permissions. I think it's tied to your user. So are you Ryan? Yes or no? At least that's the way I read it. I haven't used this feature, but I think it's useful just because it's just that next level of protection with pre-signed URLs so that, okay, you know, if you're doing magic links or anything else like that, like in a, not specifically in this example, but if you're doing like a magic link, you're also saying here, the email is sent to Ryan and there's an extra verification that Ryan, that the email didn't get intercepted by sending it to sales@thecloudpod.net, that actually, and that Ryan is actually the person that received it on the other end. [67:48] B: I mean, again, 'cause you own the, you own the provider, I guess you can do that. Yeah. Yeah. [67:54] C: So they are, hold on, let me go back up in the show notes real fast. They are the only full stack Free site URL provider out there. [68:08] B: Yeah. I mean, Google could do it technically if they, if you're using them for your Workspace identity, but they don't yet. [68:14] C: So currently they're the only full stack provider. [68:16] B: Currently they're the only, yeah, they're doing the marketing on that. [68:18] A: I don't think they could actually, cuz the principals don't transfer. [68:21] B: Yeah. [68:22] A: The principal in a GCP cloud, uh, you, if you plug it in as cloud identity, Yeah, I know, your, your host could live it up. Yeah, I don't think he could. [68:31] B: Yeah. Uh, and then we have Oracle this week. Uh, they announced earnings last week. Infrastructure revenue jumped 121% year over year to $7.4 billion, driving a 30% overall revenue increase to $19.35 billion and beating Wall Street estimates on both revenue and EPS. Uh, good for them. Nearly half of Oracle's $664 billion backlog comes from a single OpenAI contract, tying Oracle stock performance closely to sentiment around OpenAI. Which is cool as Anthropic gains ground and OpenAI models pressure pricing across the industry. Financial red flags are noted, uh, negative free cash flow of $5.4 billion, uh, that's called buying GPUs. CapEx traveling to $28.5 billion, also GPUs, and total debt reaching $125 billion, uh, yes, also GPUs, raising questions about how sustainable this growth pace is without stronger cash generation. One counterbalancing signal is that customer prepayments now cover 40% of Oracle's CapEx, up from zero a year ago, suggesting customers have enough confidence in the buildout to help finance it directly rather than waiting capacity to come online. Uh, regional imbalance is an emerging concern, with Americas driving most growth while APAC and EMEA combined now generate just 40% of America's revenue, down from roughly 50% a year ago. Uh, Oracle's core software business actually declined 3% year over year. Uh, boo for them. Uh, but you know, they did win a new $7 billion Pentagon contract, so I'm sure they wiped their, their tears with dollar bills. Uh, and then after the earnings and their You know, everyone being super happy with what they did. Larry Ellison announced he wasn't going to sell $7.5 billion in stock and the crash— stock crashed on Monday. So nice. And then they also announced a 13% layoff of their staff. So even though they're making all this mass amounts of money, uh, they apparently don't like their margins. Uh, and so they're laying off 13% of their team. Yeah. [70:13] A: So, which is a bummer. I mean, the stock market and software companies right now, it's just bonkers. [70:17] B: It's, it's crazy town. Like all the fundamentals are out the window. It's You know, do you have growth? Yes. Is it a lot of growth? No. Is it AI-driven? Yes. You're good. Is it AI-driven? No. Nope. Nope. You're done. [70:29] A: You're done. [70:29] C: Yeah. [70:29] B: Yeah. So it's just, uh, it is crazy town on the stock market these days. [70:33] A: So, and then everyone, everyone's saying, oh no, it is AI-driven, but it's not, you know, like it's really, but it's not direct AI revenue. [70:39] B: It's, it's inferred AI revenue. And they're like, and then Wall Street goes, I don't know what that means. Penalized. [70:44] A: Yeah, exactly. Or Alternatively, they say AI, they don't know what it means, and they reward them. [70:49] B: Both happen. Yeah, yeah, both ways works. [70:52] C: Yeah. Whatever happened with the shoe company that turned into an AI company? [70:56] B: Oh yeah, yeah, I would look into them. I'll, I'll note that for a follow-up item. We, we followed it up at least one point. [71:02] A: I'm glad you keep bringing this up, but yeah, or the— we followed up on the, the Super Bowl commercial for AI that didn't turn into anything. [71:09] C: It still hasn't turned into anything. [71:10] A: It still hasn't turned into anything. Yeah. [71:12] C: Maybe that's what we need to do at the end of the year, you know, when we're already trying to figure out how to do all the shows in a terrible time frame between all the conferences. Oh yeah, it's like the follow-up of all the items. [71:23] B: Yeah, yeah. [71:23] C: But like, maybe it's the first of the next year, all the random follow-up things like that. [71:28] A: That's kind of a cool theme show idea. [71:30] C: I like it. [71:30] B: Yeah, I like it too. Uh, maybe we do that in January when it's really slow. [71:34] A: I like January, not, not end of year. [71:37] C: Yeah, that's what I going for. [71:39] A: Yeah. [71:39] C: But we actually need to be able to go through all the episodes. Yeah. No, it, it really, that's what Bolt's for. [71:44] A: Completely dependent on setting up the infrastructure for actually indexing and searching our shows. [71:48] B: You know, I mean, good thing Justin did that last year with the report. Yeah. Yeah. I'm, I'm ready to go. I already got the code written. We're, we're, we're off to the races. So nice. Uh, all right, gentlemen, I think we've reached the end of this week's show. Uh, and, uh, it was a long one as usual. So, but, uh, thanks again for joining us. [72:05] A: All right, bye everybody. Another week of cloud news wrapped up. Bolt will collect the news, Justin will get the notes, Jonathan will write some code, Ryan will watch the perimeter, and Matt will reluctantly watch Azure. Till next week for AI, Amazon, Google Cloud, and Azure, and hey, maybe even Oracle, who knows? Check out the The Cloud Pod.net for our newsletter. Join our Slack, message us on socials, or leave a review. [72:39] B: I have an after show for you guys. I was, uh, while I was, you know, polluting the Caribbean on a cruise boat, you know, by traveling through there, although it was, you know, as economically green as you can be, you know, they have some solar. They— there was an article across my desk as I was feeding you guys show notes for last week's episode, and then you guys decided not to talk about it last week, which Really excited me because now I get to talk about it with you guys instead. So it worked out for me. [73:03] C: Yeah. [73:04] B: But basically, you know, the headline was, uh, trialing AI-powered contrail mitigation technology. And that was where it started. And I was like, this is dumb. Why do we care about conspiracy theories and contrails and AI? What a waste of tokens and all of that. And then I actually read the article after I reacted to it. Uh, and apparently Google is expanding its contrail avoidance trials to Asia Pacific, partnering with Cathay Pacific on ultra long-haul flights. More than 80 of over 100 test flights followed contrail avoidance routes with an estimated 4% reduction in warming impact from contrails, which I did not know that a contrail has a warming impact, which is a global warming problem. So the system combines AI predictions, satellite imagery, and weather data to identify contrail-forming zones, then relays this to pilots via in-flight Wi-Fi and Cathay Pacific's electronic flight folder without altering standard cockpit workflows. This is a practical example of AI and data pipelines applied to real-time operational decision-making. Uh, one of the things they noted was a single route from Hong Kong to Singapore accounted for more than 50% of the trial's total emission reductions, suggesting that targeted interventions on high-impact corridors may be more efficient than broad network-wide changes. Contrails account for roughly one-third of aviation's total climate impact, and this approach requires no new aircraft or fuel technology, just altitude adjustments based on better data, making it a low-cost, near-term lever for emissions reductions. Google is also partnering with contrails.org, a nonprofit focused on contrail science, indicating a move towards open research collaboration rather than proprietary solution, which would accelerate industry-wide adoption. [74:31] C: So I went down a little bit of a hole before the episode started because I actually prepared for once because I'm in Seattle this week, and the contrails.org website's actually pretty cool where like there's a whole UI in there that you can like see the contrail and talks about like the plane type and everything else that was on and like how the contrail and why It's like 1% of the total global warming, I think the metric was, or whatever it was. Like, their website's really cool. It has a lot of like interactive stuff. You want to go kill, you know, 20 minutes of your life learning about things. [75:05] B: They can identify the airplane based on the type of contrail? That's— now we're nerdy and I'm super excited. Yeah. [75:14] C: I think they have the metadata from, I assume, like Flightradar or something like that. [75:18] B: Okay. [75:19] A: Um, that would be nuts cuz it's a moving cloud. [75:23] B: Yeah. Like how many satellites are you guys using up there for a nonprofit? [75:28] A: Yeah. [75:28] B: Who's funding you? This is a conspiracy, darn it. [75:30] C: Yeah. [75:30] A: I guess Cancer's Solved, like, here, satellite. [75:33] B: Yeah, exactly. They have a whole active like contrail map. I can see all the contrails in on the globe right now. [75:40] C: If they go— and like current ones, I think. [75:43] B: And then like, I mean, I assume it has to be based on the fact they know, they, they know the conditions that create a contrail. So I imagine it's more calculated contrail than actual. Actual contrails? Because I can tell you right now, if you were flying from the northeast of America to Europe and, uh, over Canada and Halifax, if there was that many contrails, we would hear about it, uh, because it's a pretty large population in this picture right now. [76:04] A: Yeah, well, I mean, I think that that's the— that's what the AI-powered thing is, is doing, is, is analyzing the conditions at which contrails form, right? [76:11] C: Because— [76:11] B: correct. [76:11] A: Yeah, from the, the, the article or news thing I was listening, it's just adjusting altitude is really all they're all the suggestions are to reduce contrails by, and so you can get rid of 50% of those contrails just by changing flight planes and, and by a couple thousand feet apparently. So it's kind of nuts. I had no idea the contrails were that impactful. [76:33] B: Like, I didn't know they were, I thought there was just a, I thought it was a cloud. I'm like, what? Like, and then, you know, people are like, oh, the, you know, the contrails are, you know, the, the government's poisonous. Yeah. The frogs are turning gay, you know, that kind of craziness., that I just can't stand. Like, I, we never really talked about that. I, I am not a conspiracy fan theory guy. Like, I, like, they drive me crazy. And my wife sometimes gets into them and is interested by them, and I'm just like, ah, yeah, it's just so ridiculous. But, uh, yeah. So anyways, anytime I saw Contra, I was, that was my immediate visceral reaction to it is like, this is dumb. What is Google doing? Yeah. Uh, which, you know, is its own form of, uh, You know, bias, I suppose, on my part. So I'll, I'll take it. You click through. I think, I think you can have the, the judgmental feelings as long as you click through and read the article. Yeah. [77:20] A: I think it's my own personal creed, I guess. But yeah, cuz I have the same thing. I did the exact response, like Contrail. I was like, oh, here we go. Like, government's poisoning us. [77:29] B: You know, like, but yeah, it's like, but yeah, it's the fact that it's. [77:35] A: There's that much, um, global emissions impa— it's not emissions impact, it's just global warming impact. And so it's separate from like the emissions from like the exhaust for the jet engine. Like, it's crazy to me. And I, it's all just about heat refraction, I guess. Like, what? [77:51] C: Who? [77:52] B: Yeah, it's interesting. And also, you know, if you listen to the crazy people online, no one knows how contrails are being made unless it's gotta be the government. It's not the engine. Like, oh, okay. Crazy people there. Yeah. We have science, we know how they're made. [78:04] C: Yeah. [78:04] B: But anyways. [78:05] A: Yeah, exactly. [78:07] B: Yeah. All right, gentlemen. Well, I, I'm glad we could get to the bottom of this contrail business. [78:11] C: Mm-hmm. [78:11] B: And, uh, I'm glad the, you know, that, you know, there's a benefit for us skating around contrails. Before I was like, I would just waste time, but it does impact the globe. And, uh, as we now know, I just, in the Caribbean on my vacation, it was hot. [78:22] A: Oh, I bet. [78:23] B: Uh, global warming is, uh, real people. Yeah. It's very hot. [78:27] A: Yeah. [78:27] B: And it's, uh, you know, I was I was very concerned about a hurricane at one point. I was like, this is gonna be bad. [78:31] C: I was gonna say, you're ballsy to go in the Caribbean this time of year. [78:34] B: It's early. I mean, like, I've, and I've dodged it. [78:37] A: Any later would be a problem. Yeah. [78:39] B: This is, yeah. And I've dodged enough hurricanes in my career, you know, of cruising. [78:43] C: Hurricane season starts May 1st, uh, I think it's October 1st or something. [78:47] B: But it really, it's really hottest in, uh, like August, September, October. [78:51] C: I know, I live there. [78:53] B: I know. Yes, it could be anytime. You know, we actually almost, uh, did it turn into a hurricane here on the West Coast? 'Cause I know almost like they were saying it could turn into a hurricane in LA. [79:02] A: There was, so it, it did not, uh, it was a hurricane technically, but it didn't hit anywhere. It didn't hit anywhere and it just caused high seas in LA. But then Hawaii, the one of the other, there was 3 storms all at once in the Pacific. [79:16] C: Yeah. [79:17] A: Yeah. [79:17] C: And one hit, but they're not hurricanes, they're typhoons, I thought. [79:19] A: Yeah. [79:20] B: Or so I thought that was the thing too. It was the Pacific Ocean. Pacific, it was a typhoon. [79:24] A: But now everyone's calling 'em hurricanes now, so now I'm confused. [79:26] C: Used? [79:26] A: Because what am I going to argue with my local news? [79:30] B: Yes. [79:30] C: What else do you have to do with life? Yeah, that, you know, that, that figures out that they're contrails from planes. Yeah. So I guess my other question is, how much AI computer are they using to actually solve the global warming? And is AI consuming enough power that it's— [79:50] B: is this, is this carbon neutral? Is that what you're asking? Yes. [79:53] C: Is it carbon neutral? Is it carbon negative because I'm more concerned about being— or sorry, carbon positive. Because I'm more concerned about being carbon positive at the end between doing all this. We're actually creating more pollution from this. [80:07] B: Yeah. I'm doing real-time research around hurricanes and typhoons because storms in the Pacific hurricane basin are called hurricanes because they form in the eastern or central parts of the Pacific Ocean east of the International Date Line. Hurricanes, typhoons, and cyclones are the exact same weather phenomenon, which is what we know as tropical cyclones. Only difference is where they happen in the world. Hurricanes form in the North Atlantic Ocean and eastern and central North Pacific Ocean, east of the 180-degree, uh, latitude line. [80:33] C: Storm understands where the time dateline is, and therefore that defines what it is. [80:38] B: That defines, yeah, yeah. Uh, typhoons form in the northwest Pacific Ocean, west of the International Date Line. So this is why I am mostly familiar with them being typhoons, because they were more of a Seattle thing and they hit Hawaii quite often. And then cyclones apparently form in the Indian Ocean and South Pacific Ocean. So we have all learned something today, folks. [80:52] A: Oh yeah, and these did form— the ones that we're talking about did form very southerly over by Mexico, so they formed over there. So that's why they're hurricanes. [80:59] B: That's why it's a hurricane. Hurricane. Yes, yes. All, all interesting. And, uh, this is also being impacted by the El Niño this year, which is— they're not calling it a super El Niño yet, which I'm surprised about because they're saying it's already the strongest El Niño on record. Um, so I'm surprised they're not calling it super El Niño, which I think we had before. So I don't know, I don't know how these weather people do things. [81:18] C: Yeah. [81:18] A: They're all, you know, I mean it. [81:20] B: Yeah. [81:20] A: I've definitely read articles about it being unprecedented. [81:22] B: So like, yeah. Well, and like apparently it's gonna be real, real wet here. So I look forward to the mudslides in California. [81:27] A: Mm-hmm. [81:27] B: 'Cause you know, that's coming. And then, uh, maybe that'll actually help out the Colorado River Basin because, uh, otherwise the Hoover Dam's gonna have to shut down soon. So maybe this is, uh, the world correcting itself or it's just gonna be bad for all of us. [81:38] A: I'm not sure. [81:39] B: Yeah. [81:39] C: Mm-hmm. [81:40] A: You know, humans are really, really good at dealing with change. [81:43] B: Yeah, yeah, we're real, real fast to react. I mean, I, I always— okay, now we're, now we're on a rat hole. Um, I remember when I was a kid in the '80s, uh, the ozone layer was a thing, and like, and like, we had to stop using certain types of spray cans that were causing, you know, had ozone and limiting gas, and we seem to change that and we fix that and the ozone hole's gone. Like, it was cool. But yeah, they have a global warming and they're like Yeah, screw that. It's all hoax and, and nonsense. I, I think it's a marketing problem. I think global warming was the wrong name. So I think the try to move to climate change was the right move, but it's too late. They already screwed it up. So it's, I don't know. [82:21] A: I think it was, I think it got politicized and by the time it got politicized it was totally lose. 'Cause no matter what side of the issue you were on, it just turned it into us versus them. [82:29] B: As everything in the world is these days, us versus them. [82:32] A: And I, I don't think that same divisiveness came with, uh, the ozone layer. Like, there are definitely people that are like, I like my styrofoam. But, uh, but it wasn't— you didn't get a political ideology assigned to you by saying that like you do today. [82:46] B: Yeah, that's fair. Yeah, it's crazy to me because like, yeah, we, we stopped global warming, that all worked, and then now— [82:52] A: it was a major shift, right? Like, every— we had to stop using all kinds of like propellants and VNCs. [82:57] B: Like, it was a big deal and everyone did it and they all agreed and it was like It's because, but you know, no one can see that hole either. So no one can see climate change technically. [83:06] C: Uh, that's what the contrails are. [83:08] B: The right, the contrails. Bring it full circle. [83:11] C: Sorry, it's bringing us back. [83:12] A: Yeah. Thank you. [83:12] B: All right. Thanks, Matt. I appreciate you guys out there at hole. All right, gentlemen, let's go before the next one. [83:17] A: Oh God, we're still recorded. I didn't know. [83:20] B: Later. [83:20] C: See you. [83:21] B: Bye.