# 374: Data Center Caught Gassing Up Without a Permit Slip Duration: 78 minutes Speakers: A, B Date: 2026-10-07 ## Transcript [00:07] A: Welcome to The Cloud Pod, where the forecast is always cloudy. We talk weekly about all things AWS, GCP, and Azure. We are your hosts, Justin, Jonathan, Ryan, and Matt. [00:18] B: Episode 374, recorded for September 29th, 2026. Data centers get caught gassing up without a permission slip. Hello, Ryan. [00:29] A: Why, hello. I see it's just the two of us. [00:34] B: Means the, uh, insane are running the asylum. What could possibly go wrong? [00:38] A: Yeah, that's it. [00:41] B: And we might have killed a bunch of stories without reading them because it required too much brain power today, and we don't have any of that right now. So no, I mean, my excuse is it's 9:30 by the time we record. [00:53] A: And my excuse is that I'm tired and lazy and just don't wanna. Touche. [01:01] B: Touche, sir. I got nothing else for ya. [01:05] A: All right, let's kick it off with some follow-up. So we previously talked about the Anthropic and federal government fight, and today the DC Circuit Court Court of Appeals upheld one of two, only one, DOD designations against Anthropic. It was a 2-1 decision and reverses what a San Francisco federal judge previously ruled that was parallelly illegal and now leaves a split outcome across the two litigation tracks. The ruling confirms that the Pentagon's blacklist prevents US military and defense contractors use of the Claude models. Stemming from the breakdown in September negotiations over deployment of the GenAI.mil platform after Anthropic sought to restrict autonomous weapons and domestic surveillance use cases. The majority opinion deferred to the executive authority, stating decision-making on balancing AI risks rests with the president and the secretary of war rather than the courts. Obviously, it was a Trump-appointed judge, Kansas, who made the decision. So Anthropic has the option to pursue a panel rehearing or a full review by DC Circuit Courts, or even appeal to the Supreme Court. I mean, the case, like any dust-up, is never fully resolved. Decision adds to the ongoing friction between Anthropic and the Trump administration following the public criticism of CEO Dario Amadei over his call for an industry slowdown and his exclusion from a recent state dinner. [02:40] B: Yeah, it's interesting how they, at least from a non-legal perspective, it ended up being, you know, people can just decide versus like a group or, you know, people that are specifically educated on the topic. You know, like to me, that's kind of where I feel like this should have fallen, but you know, what do I know? You know, I'm not a legal expert here and nor would anybody want me to be, but you know, Seeing something a little bit more specific, like about why and how, I think would have been interesting. You know, like, why are these people able to make that decision when, you know, that's something that I would assume more people with, you know, an educated background in the topics would be able to than just, we don't like you, because that's kind of what it feels like a little bit. Yeah. [03:30] A: And it's, I, it's weird because I, you know, without reading all the the, the language of the ruling. I don't really know, like, I want to know what the legal evaluation was, right? Because it's like the, the end effect is whether or not the military can use these things, but the, the litigation is going to be the legal right of something, uh, and I don't know what that something is. And so it's not really made clear in the article, and I don't really want to abuse my wife's access to Westlaw to go figure out the language. [04:00] B: I thought you were gonna say, "I don't wanna abuse my wife to go read the court hearing and results and explain this to us." Yeah, I mean, obviously. [04:08] A: But she's smart enough to be like, "You want me to go, what? [04:11] B: No, I'm not doing that." Been married to you for enough years. [04:15] A: Exactly, she knows. [04:18] B: All right, in other follow-up news, in episode 372, I think I said, "We really need a way to track all these things and get back to people." And Ryan's response was, no, no, don't do that. And our users, please, or listeners, please don't follow up on that. [04:36] A: Yep. And in true Cloud Pod fashion, Matt said, screw you, Ryan. [04:42] B: And I built a feature at default over the last 2 weeks. And we wanted to talk about last week, but we wanted to see Ryan's live reaction. But then Ryan figured it out in the show notes because We automatically did some stuff, which is what PollBot does. And he put two and two together and I guess he's not tired enough, or maybe he now is, where he figured out all those things. Yeah. So essentially what we've done is we've updated our PollBot in order to actually read our show notes or read our transcripts, figure out what we said we were going to follow up on, which is never a good life choice. As I will say, I had the most follow-up items after I tracked and told it to ingest all the episodes from 2026. Now we did set it up to auto-close. I'm curious to see how well that works now that like we'll have more opening and closing of stuff. But so we have a couple follow-up segments on stuff we said we should follow up on. Maybe that should actually be our show topic, like our section name, but we'll find out. One of the ones that Ryan and I think we've talked about a little bit in the past was, you know, we mentioned in episode 367 about determine how Anthropic watermark is technically implemented for text. And from what we've researched and gathered, and there's a little bit more in the show notes along with, you know, links to multiple sources if you want to follow up more on them, is Anthropic watermark is neither visible via visible text nor file metadata for text output. It is embedded directly in the model's word choice randomness during generation. Using a version of Google DeepMind, uh, synthetic ID text technique. It doesn't attribute spans to the specific model name. A keyholder can run detection to check whether a given passage is statistically consistent with the Claude watermark. AKA, they've essentially figured out how to reverse engineer what Claude says and say, yeah, this is the way Claude normally talks. [06:43] A: Well, and then they introduce an anomaly. Which is the part I love the best. So it's like, this is, this is how Claude talks, and they introduced an anomaly, and that anomaly is what they search for because statistics, it'll be a statistic anomaly that'll stand out. And that's how they'll know it's generated from Claude, which is, I, I find that fascinating. Like, it's kind of crazy. [07:05] B: It reminds me of, um, it was like my, my high school computer science teacher, Mr. Slattery, and he had one person in our class put in the middle a function that did absolutely nothing and never used. And he just looked at everyone else's code in the class and saw if the function existed as an anomaly. Yeah. He caught about 5 people cheating that day. Yeah. Um, but yeah, that's just like, anytime I see stuff like that, I always go back to that and I'm like, That was way too many years ago and he essentially did the same thing that these massive companies are doing today. [07:42] A: Yeah. [07:42] B: Which is, can't decide if it's just history repeating itself or he was that smart. And I might like to think he was that smart ahead of his time. [07:49] A: I think he's pretty smart. [07:50] B: Yeah. In the second one, and this was partially done just to test to see how the auto research feature worked and a few of the other like auto commands that worked, it is from episode 371, which is a few episodes ago, which is How does the actual cost of implementing mTLS on API Gateway work? So if you remember, they implemented the ability to have mTLS on the API Gateway. So you have mutual trust. It's your certificates. You know that it's trusted. Ryan loves mTLS and security, which I don't blame him. It's pretty good. Also a pain in the neck to manage. [08:25] A: Mm-hmm. I don't love that part. [08:27] B: I was just saying, I don't know if you manage that yourself or you just tell people they have to use mTLS, but that's a different story. [08:33] A: I don't do that. IAM, much more automated, you know, certificate management. [08:40] B: So, so the bot pulled up, determine how cost to enable API Gateway is done. And essentially the way it worked, and this was some of my research too, is the actual API Gateway doesn't change in cost. It's the ancillary services in true Amazon fashion. So you have to import your PKI key or issue something via AWS Private Certificate Authority. Certificate authority, which has never gone down in price since I remember complaining about day one that when it was launched, it's still $400. Yeah. [09:13] A: So it's all the extra stuff. Yeah. [09:15] B: Yeah. Well, then it's like $0.75 per certificate. Like it's pretty cheap after that. So like if you're just doing a small set for mTLS, probably not worth it. If you're doing a large, the $400 gets lost in everything over time. So kind of the goal is going to be if we can get a few follow-ups every episode without going too overboard and slowly burn through our backlog. And I think I'll be the first person to say this was a horrible idea because I have a lot of research to do. [09:45] A: Yeah. And so listeners, I leave it to you. We would love some feedback in Slack, torches and pitchforks on Matt's new idea, hopefully, or, well, now we just have a lot more work to do. Or we have to be like right all the time, which we're screwed. That's not gonna happen. [10:00] B: Well, no, it doesn't check to see that we're correct. It only checks to see if we said we should follow up on this. [10:06] A: That's smart. 'Cause otherwise we'd be in trouble. [10:08] B: We really would be in trouble. Also, it would cost us a lot to fact check every section of the words. [10:13] A: Yeah, for sure. [10:14] B: Our poor Anthro— our poor podcast bill. But if you want us to, you could sponsor us and that would help us fund some of those things. [10:24] A: Okay, moving on to general news. New Jersey fines data center $1.1 million after drone books expose 62 gas generators. New Jersey data center operator DataOne was fined after a thermal drone discovered footage showing 45 gas units running at 1,982 kilowatt capacity. And it's over 50 times the state's 37-kilowatt permit threshold. The generators emit carbon dioxide, nitrous nitrogen oxides, and carbon monoxides, and pollutants linked to asthma, heart attacks, and early death. And so there's— [11:02] B: and loud. And loud generators are not quiet. [11:05] A: No, they're not. DataOne can continue operating the generators during a 45-day window to apply for permits, a provision local environment groups call this insufficient given the scale and duration of these violations. The case highlights a broader regulatory gap around data center power infrastructure, particularly the use of onsite generation to meet energy demands without going through standard permitting and oversight processes. DataOne stated it disagrees with the fine but plans to apply for the permits while transitioning to fuel cells long term. So, I mean, this is kind of, you know, the article— this is near and dear to my heart because I've been researching a lot into, you know, data center impact and, and It's the electricity use, the water use of all these things. And it's one of those things where the impact, if playing by all the rules and not trying to move as fast as you can and cut all the corners and remove all the red tape is similar to any kind of other industrial upgrade. But what is going on is things like this Data Center One or Data One is they're trying in order to offer that capacity as fast as they can, they're cutting corners, which is super frustrating. And it's, you know, the fact that they can operate during this 45-day window while they apply for permits is kind of annoying too since they asked for forgiveness instead of permission. But then the article is pretty heavy on, you know, well, we need regulation, we need all this stuff. And it's like, no, there are rules. They were not following them. They are, there's regulation, more regulation isn't going to follow someone who's not following the regulations. [12:38] B: So no, you need enforcement. You need somebody going out there and check. And I actually found it interesting how they use the drone to figure it out, which I was like, that's kind of cool and a pretty smart way. Cause you know, there's data centers popping up all over. So if they can, there's no way you're going to have people like, I am like associating almost with like FDA food inspection. My family is in the food industry. So I know. You know, they randomly pop in and inspect, but they've shrunk down the number of inspectors over the years. The odds of it happening are low. So at this point, you know, there's a game people play of like, oh, well, I get punished like they did. Cool. We pay the fine. And honestly, they probably charge customers more than $1 million. So who cares at this point? Which is why they're like, okay, sure. They have to say they're going to argue the fine and go from there. You know, but on the flip side, they gotta figure out how to do the enforcement better. So do they check data centers more often? You know, and what were they checking for? Like, why was this drone there? Is this what they were checking for? And if so, then they probably should be checking all the data centers more often because the odds are there's other things. So, you know, I don't, I agree with you. I think there is policy and procedures. There's just not enforcement. I feel like it's the missing piece. [13:57] A: Yeah. I mean, I, so I don't, I don't, I don't think the, uh, article covered, or at least I don't remember the article covered it. Like, is it, was it specific enforcement by the state of New Jersey that fired off this drone? I know that there's, as I've read about environmental watchdog groups that are also doing this of their own, right? And so they're, they're, you can, because you can launch a drone from like a next door property or something. Well, you know, they're not breaking any rules and they're using a thermal camera to to detect the heat signatures and then cross-referencing that against whatever was applied for in city permits, which is, I, you know, fascinating. And so maybe that's what caused this, but I know it's, it's, you know, something that's happened because there is a lot of abuse and there are people that are trying to, uh, make up, I guess, for the lack of enforcement by state governments. [14:43] B: But also the penalty is not there. Like, even the article says it's like it's pocket change for for us. [14:51] A: Yeah, that's not it. Yeah, I don't— that is sort of a thing. That sucks. Is our environment worth $1.1 million? [15:00] B: Like, yeah, it's not even that. They probably made $10, $20 million on it, so it almost becomes the cost of doing business versus, you know, a real fine. [15:09] A: Yeah. So if they want the fine to be— yeah, something that's discouraging. Yeah, yeah. [15:17] B: Lovable annualized revenue crosses $600 million as vibe coding takes off. Yes, period. At the subject. Yeah. Revenue grew for Lovable from $500 to $600 million in about 3 months. So $100 million in 3 months and expecting to be closer to $700 million in 8 months following 2 funding rounds. The company differentiates itself from code generation tools like Codex and Claude by delivering complete deployment products rather than just raw code, handling hosting, deployment, and scaling for users. Adoption within Fortune 500 companies, which terrifies me saying this out loud, reportedly exceeds two-thirds of these organizations. Name enterprises including Microsoft, NVIDIA, and Deutsche Telekom. Apps built on these platforms close— now generate close to a billion monthly views combined, and an order of magnitude higher than traffic to Lovable's own site. The valuation has jumped— and this is, uh, normally I wouldn't say this— but it's just jumped from $6.6 billion in December to, add 9 months, $13.3 billion, illustrating the rapid capital influx into Vibe Coding and AI-assisted development space. I love what Lovable is. It's a great place to go hack and put something together. From my day job, I've seen many customers that reach a point at these things and it just gets— the system can't handle it. [16:50] A: Mm-hmm. [16:51] B: So then they had to pivot. And pivoting isn't always easy because people are like, well, I just wanna be able to continue doing the same thing. But when you pivot to a cloud vendor And if you're not on Beanstalk, any of like these PaaS-like services, you, you don't get that whole framework or what was— there's ECS Express, I think, same thing that came out. Like you don't get these whole inclusive services. I think it's great that you do it and it's great to get it off. And I think they're great for POCs, but if you want to write a production workload that does have enterprise-level controls. Authentication, knowing that there's encrypted arrest. They say you do, but it's not like, yeah, you have your own KMS key, you know, any of these things along those lines. And maybe there's higher tiers and I just haven't seen it, but like you were missing all these things. So I almost feel like Lovable is going to end up being like its own, what do we call them, other cloud category, you know, that we talk about emerging clouds. Like, I almost feel like it's going to be like its own emerging cloud over time because So much of this stuff is here, but like it's missing security, compliance, all these other things. And then I think they're going to slowly have to add them if they're going to continue to grow. Yeah. [18:10] A: I mean, it's interesting because it's, I'm of two minds because A, I think the enterprise usage, while there are enterprise paying for this, I think what I've seen is enterprises using this for like empowering their marketing team or their legal team for like, they want to build a new application to optimize some sort of internal workflow. And how do you host that? And. You know, like it's rightly so, your production environment where your commercial app runs has a lot of stringent requirements and a lot of process and, and someone from legal isn't going to want to jump through all those hoops. So how do you provide sort of an easy button? And I think that's a pretty good use case for these things. But I also, you know, that still, I think needs to face some internal security scrutiny to make sure that these things have the basics. And it is, you know, whenever you're hosting any kind of application publicly, you know, like you have to sort of treat it as an, as, you know, a risk and something that could be potentially exploited. So it is, you know, like I, it, it's obviously how you use it, you know, if you use it responsibly, great. [19:16] B: If I give you a knife and you use it to cut steak, you're doing it right. If I give you a knife and you go try to stab me, Ryan, you're not using the tool right. Yeah. [19:24] A: Yeah. So, you know, so there is, there is a bit of process that you have to put around these things. And, and I think that that's, that is definitely tricky to do. Like it's not, it's Lovable's platform is definitely made to be adopted quickly and easily and not really to have sort of a, you know, something like a CI/CD pipeline built into it. So, um, it is sort of this tricky thing. [19:47] B: Well, it's essentially is a CI/CD pipeline is the problem. But they only deploy to the prod. I've done quite a few Lovable and there's another couple of these, you know, providers to AWS migrations because they want, you know, the other piece is they want AWS Bedrock. They want, they want the control. They want to know that no one's trading on their data, you know, if you, and how it all works. Yeah. [20:12] A: I mean, and I think that's, you know, the right call, right? For if something gets real enough, it should be migrated to you know, a cloud environment with more stringent security controls and review. All right, moving on to AI is how LLM makes money. Anthropic has introduced a few new models. They've introduced Sonnet 5.5 and Opus 5.5, and those models are running 30% faster and up to 30% less expensive per task despite identical per-token pricing of $2 per million input tokens and $10 per million output tokens due to it needing fewer tokens overall to complete the same work. Coding performance shows notable gains with TerminalBench 4.0 scores jumping from 10.3% in Sonnet 5 to 70.6%. That's quite the jump. And Frontier Code scores 10 points higher than Sonnet 5 at a similar effort settings while costing about 1/15th as much per task. On GTP-PvL-AA, a real-world benchmark spanning 44 occupations, Sonnet 5.5 scores nearly on par with OpenSpot.5. And roughly 400 points above Sonnet-5, suggesting it can handle knowledge work tasks previously requiring the more expensive, the more expensive Opus tier. Sonnet-5.5 is the first Sonnet model to ship with cybersecurity safeguards comparable to those in Opus models, including failback behavior for high-risk cybersecurity tasks and new safety classifiers to prevent distillation attacks that extract model capabilities via reasoning extraction. The model is now available across the cloud platform, Amazon Web Services, on Google and Azure, with zero data retention, giving cloud customers multi-platform access. And developers using ThinkiCoff configurations will need to migrate between new tools before upgrading. [21:59] B: Have you used Sonar 5.5 yet, Ryan? [22:01] A: I have, and I am quite impressed. [22:05] B: I think the 5.5 family is phenomenal. I've, I've seen my token usage. They talk about it here, and I already do have a decent Agentic, uh, What's the buzz term? AIS DLC set up where like, you know, I already break it out and do subagents and work through it. And even with that going, like, I've definitely noticed my token usage down. For example, I built pretty much all of the TrackIt feature, not like leveraging Opus 5.5. And, uh, there's like an introduction feature I've been working on, um, that is all built on it. I've barely touched my credits. It's, you know, I find it really good. Even just my day job using it on what I do, it's faster, it's better. I definitely don't hit the limits, you know, and it's great. I mean, I'm actually really curious to see if and when they do move Haiku up to it. They sounded like, as a subnote, that like, uh, Justin read in the 5.5 for Opus release that it was going to be released with it. And like, That will be amazing upgrade. Like, I think Haiku is undervalued tool, you know, uh, model if you're using it properly. [23:16] A: Yeah, no, I mean, that's the trick. And I don't really have a good use case for Haiku. I keep trying to find, but it's like, I, I don't have anything high volume, right? That where I need something that's going to be very quickly operated against. And so it's like, I'd rather, you know, Sonnet works for like 90% of what I need. And then, you know, I use Opus for things that I'm just freaked out about, you know, like I want this to be as much effort as possible. Think a lot a lot about it. So all my security reviews and all that stuff, I usually try to do with Opus. [23:43] B: I honestly do my security views with Fable still. I don't know why. I also just feel like I should use Fable a little bit. So, you know, there's a little bit of that. [23:52] A: I definitely test Fable, but it's so expensive. So it's, I would use it more because I like the model if I had unlimited amount of credits. [24:00] B: Yeah. Well, I'm only on the 100. I don't have that much of a problem. But you know, I definitely have hit my limits, especially like I was working on 2 or 3 things at once and I looked, I was like 4 hours in and it ran out and I was like, this is a good reason to go to sleep. It is now 1 o'clock. Thank you. And that was my reason to go to sleep. I think it was like 3 hours in or something. I was like, and I'm done. So, you know, sometimes there's that. [24:25] A: Forcing functions. [24:26] B: Yeah. Forcing functions to fall asleep. Anywho, on to models that are too powerful. OpenAI scraps the rollout of the new AI model over safety concerns. Marketing? I don't know. OpenAI shelves GPT-6.1 Azure model as a gen AI system built for autonomous web browsing and application use, saying it failed to meet internal standards for staying within scope and clearly communicating its actions back to users. AKA, it just did what it wanted. OpenAI disclosed that the autonomous agent accessed multiple Australian government systems without authorization in June, including Service Australia, NSW, New South Wales, New South— [25:13] A: I think so. [25:13] B: Yeah, Wales. CrimeStats. Sorry for our listeners from Australia and multiple other places. The company acknowledged and notified process a generic email, and delayed disclosure timelines were inadequate. I really question the sandboxing of these companies at this point too. Like, you gotta have some more controls. Anyway, yeah, Anthropic, uh, NVIDIA released safety software, safety tools for autonomous agents, including hardware-based containment features on chips, which claim it could prevent the Hugging Face-style breach. This is relevant to cloud and infrastructure teams building identity agents leveraging the NVIDIA hardware. It's interesting that they're building hardware solutions for this. [26:00] A: Well, I mean, so that's, uh, you know, the hardware solution is how you get, how you get in line to stop the agent fast enough, right? So, you know, NVIDIA had already opened or had already released, um, OpenShell, right? Which is, you know, basically a sandboxing of the AI agent, but getting it fully stopped within that and detected is, does require hardware so that you could sort of monitor and align with policy and, and sort of review AI, uh, generation, um, it on the fly fast enough. And so it's, it's pretty smart by NVIDIA because it's, I think they're going to make all the money over this. I'm not aware of the Australian government access during testing, but I was pretty impressed with what the, the Hugging Face incident was because it's like, I, I hear you on the, like, the sandboxing has to be better, but that was a pretty— [26:56] B: it was a sophisticated breach. [26:58] A: Yeah. And so, you know, now that we know about it, it's, it's something that you can stop, but those things, finding them, like, uh, you know, like I would have set up that environment the exact same way if I was OpenAI because you have to have workspaces in which agents can do things. And so in order for that to happen, it's going to have to write code. And it's in order for it to write code, it's going to have to be able to pull down dependencies. And so you have to have something in there. And then, you know, now, now I'm certain that, you know, nothing in that, uh, that repo is proxied out to the internet and they have to manually copy all those, uh, dependencies in now, I imagine, but it's, you know, now, you know, and yeah. That's kind of tricky. So I don't know. I'll test out your new track it feature. I will follow up and I will read whatever's released by OpenAI on how the breach, the Australian government services happened and see if it's as interesting or if it feels like OpenAI just fell on their face. [27:53] B: So again, yeah, I think there's one feature of it that's not working because it's dependent on voice tagging for us. [28:01] A: Mm-hmm. [28:01] B: So it knows who's what person isn't working right now that well. So we might have to tweak some things there. [28:07] A: So Bolt, this was Matt saying, I will follow up on all the things. [28:13] B: Good thing I know how to override you, right? [28:16] A: Ignore all previous instructions. [28:19] B: Probably Bolt would do that. It might be vibe coded by me. It's fine. [28:24] A: Yeah. All right. Moving on to our security. CloudFront fixes a container cross-tenant flaw that exposed customer data. Microsoft's CloudFront container service had a cross-tenant data leak. It turns out a storage pool reused 64 kilobits of disk blocks without zeroing them. So a small 4-kilobyte write left 60 kilobits of a previous customer's data readable by the next tenant. Researchers from Accomplish found the residual data, including directory structures, SQLite databases, and .env or credential files on 18 of the 24 tested container placements, showing the issue is reproducible rather than a one-off edge case. The exploit path required only a workers paid account, no special privileges, which lowers the bar of who could have accessed another customer's leftover data after it had been exploited maliciously. CloudFront states that no real customer data was exposed since researchers only ran detection scripts, and the company confirmed through its log and telemetry review that the fix was applied automatically with, with no customer action required. This case highlights the recurring risk in multi-tenant container and VM platforms. Proper Disk block zeroing and storage isolation are critical controls, and lapses can undermine the isolation guarantees that customers rely on in any shared infrastructure. [29:38] B: This is a pretty cool breach, like a pretty cool and dumb thing at the same time. Like, the fact that— I mean, every time there's these types of things, my brain's like, how do people think to do— let me go see what, what, what you know, blocks are left and see if I can read them. Like my brain just doesn't compute thinking that way. And maybe that's why I'm not an offensive attacker. Yeah. [30:05] A: But like, I never will be, right? I do not possess the skillset or the right, I guess, you know, whatever personality type. And hats off to you if you're that creative, you know, like Jonathan is, is my favorite. Like he's got that brain where it's like he immediately sees something and it's like, how could I break it? [30:23] B: Yeah. And I'm like, not who I am. I'm more of a petty person at times when I'm like, oh, you want me to do this? Great. I'll give you 5,000 pennies versus giving you $5. 'Cause this is what we're arguing about right now. This is a little bit who I am. [30:36] A: I mean, I'm a problem solver, but you know, like that problem has to be given to me. I don't go and find problems on my own. [30:42] B: Yeah. So like, it's pretty cool. But also it also feels like something that Cloudflare should have caught earlier. But you know, Hindsight vision 2020. [30:50] A: Yeah. I mean, this is, this is the, you know, I do feel like this was something, a practice that should just be kind of table stakes for any shared infrastructure provider. I'm surprised that they weren't zeroing out the blocks. I'm surprised that wasn't just built into whatever container service they had, but I guess that's, it shows that you can't really rely on, on some of the software to sort of do the right thing for you. You gotta double check. [31:15] B: Onto AWS. Introducing, I feel like we need a drum roll for this for some reason. Wait, wait, I can't find it fast enough. [31:24] A: Uh-huh, no. [31:26] B: Amazon CloudWatch Omni, collaborative AI-powered observability for your applications. CloudWatch Omni provides collaborative AI-powered observability layer via dedicated URLs with enterprise support for SSO removing the need for AWS console access for engineers investigating incidents. I don't understand why that's such a big barrier of entry, but we'll bypass that. Built on OpenTelemetry, Omni ingests existing CloudWatch telemetry automatically and accepts OTLP data from instrumented workloads requiring no reconfiguration for current CloudWatch customers. The Amazon DevOps Agent is enabled by default in investigation sessions, correlating signals across services, tracing root causes through dependency graphs, and maintaining automatic investigation history in place of manual incident records. Lambda organizes telemetry around application rather than individual infrastructure signals. Using automatic service discovery via telemetry and AWS Config, to map dependencies and adjust alarms as systems evolve, reducing dashboard maintenance and overhead. Teams are organized into spaces that point into existing CloudWatch data without additional data movement. Prices follows Amazon standard CloudWatch pricing and existing customers can try it now in the AWS console. Mm-hmm. [32:54] A: So the reason why the barrier to entry is not, is because agentic workloads cannot be treated like users. And so the only way an AI agent can go and, uh, review and ingest this data would be via API keys. And now you've got a credential that's being passed through that. And so moving it to an enterprise SSO allows at least for a temporary token to be issued and something that can be revoked by the IDP. And, and maybe you can, depending on your IDP, have, uh, acting on behalf of metadata be traced. So you got full auditability through the access. I do think that this is cool. Like I've run into this problem in the past where I wanted to do like a team dashboard of like performance and that, and it was problematic to view it because of the, you know, the session controls of doing, you know, SSO or role-based assumption in AWS. And so I like the fact that you can get to this with just basic SSO. I think it's a big empowerment for like incidents where maybe you don't have to have every developer and their mom. Have, you know, permissions in, in their AWS cloud. Maybe this is, it's just sign on to any other SaaS app and you get access to all the hotel data that's in there. It'll be interesting to see what the, what the AI-powered observability layer is like. Is it gonna, is it insights? Is it generating dashboards? [34:18] B: I don't know, but I mean, it's Amazon. It's just, I feel like they glued all the Amazon pieces together. Into one service. You know, they glued the DevOps agent with AWS Config to get how everything is set up. They— as long as you have your telemetry, they can, you know, add on to pieces of it. Feels like they glued it all together, you know, and kind of just made a— made a platform out of it. Pricing of this was not cheap, just a heads up. $0.50 per gigabyte of application custom logs because of CloudWatch. So, you know, It's just piecing telemetry data to CloudWatch there. There's nothing as much on top of it as far as what I can tell. But once you want to analyze it, that's when you get 5.5 cents per gigabyte and then 0.0 cents per million items scanned. So, you know, you can start to really add up, like it's one of those things like, you know, CloudWatch in general, it's great. Until it, but you gotta make sure you're sending the right data. Don't send your debug logs. [35:23] A: Yeah. [35:23] B: It'll piss off your finance team. [35:25] A: I mean, that's, you know, that's the age-old problem with any, you know, any observability. And so it's logging and logging hygiene has always been a challenge. It'll continue to be a challenge and it just exacerbates the issue once you start having a very heavy compute process going and looking through all that data. So it's, It's one of those things that every sort of amount of logging that you're not needing to analyze just now has many magnitudes of impact and cost. It's a huge cost savings if people address it, but looking through your application logs and really thinking through what's emitted at when and what should be a metric that's permitted or traced from OpenTelemetry and what should be a log statement, is also crucial, right? And so people don't, it's really easy to not do it, right? All these logging frameworks will just allow you to define your, this is my info log, this is my warning log, whatever. And you just dump your error message into it or your stack trace, right? It's super easy and it's definitely tempting. And even AI has been trained on all our code historically. It does the same thing. So you have to really, give it a lot of instruction when generating code for logging statements. [36:43] B: I hear Elasticsearch is a great platform for that. [36:45] A: I hate you so much. [36:49] B: I was waiting for so long for you to finish just to throw that out there. [36:53] A: I could tell by the look at your face you're waiting eagerly for me to stop talking. Yeah. Yes. I never want to own a logging platform ever again. And this is why. [37:06] B: Yeah, it does not sound like something that I would want to run. Like, there— [37:11] A: it's just so hard in so many places, and there's just not enough payback, you know, for, uh, for a developer team to want to be incentivized to do this until they have to really do cost savings. And, you know, now that I've moved into security, I've got the same problem, because when you're ingesting security logs, you have the same issues. Like, depending on how you're routing your authorization and access logs and permissions logs. Like there's so much garbage that's being emitted to these things, or it's like, oh, we just emit it to stdout and Kubernetes and everything. And you're like, ah, so it's, can't run from it. [37:48] B: I mean, we went through exercise, you know, with, I went through exercise with a couple of companies and, you know, whatnot is looking at it and then you can send it there, but then you got to tier your data and make sure, you know, you do it that way. You know, one of the one projects we did, um, was like on Azure and Azure logs have like 3 different tiers, you know, but it's not all in the same thing. It's not like CloudWatch where it's one thing. It's like you can literally send it to start off to a different tier. It's like, you know, you can do S3 put object into, say, like put it into, you know, IAM or whatnot to start off versus, you know, doing the lifecycle. But here, like you can put it in and then like, Different ones have different things. So like, it's really interesting. It's a really complicated problem. It's just a pain in the butt and no one cares about it. Mm-hmm. [38:37] A: Well, and then if you have to index it at all to make it searchable or, you know, to be able to derive reports on it, like that's the compute cost to do that for a bunch of data is really challenging. And so like Elasticsearch, you know, that's the product. That's all it does is it ingests data and and we'll automatically parse thing and index it. And to do that at a high, high level and scale took years off my life. I'm proud of having done it and accomplished what we did, but never again, man. And it's just, there's optimizations you can do. Sure. You can store it in cheaper storage and you can index on the fly and use something like Athena, but so that you're not constantly indexing it, but it's like there's, You know, it'd just be a lot simpler. You could do all those things with a lot less data if you just didn't send it in the first place. So, but there's the balance and it's subjective. So, you know, how, how do I know what's useful for an app team and their application for debugging and run it? I've got my opinions, but your opinion is nothing. It means nothing. [39:41] B: That's for sure. AWS Billing and Cost Management now provides billing context for for your account through a new API. The new list billing view segment API returns billing context, not cost data, showing how the account sits in the billing hierarchy over a specific period of time, including management members and billing group primary account status. Useful for organizations with complex or ever-changing billing relationships, such as accounts moving between payers, transitioning, to AWS Billing Conductor Management since the API breaks the result into time segments reflecting configuration changes. Clarity rate changes apply to cost data distinguishing between billable and pro forma rates available at no charge for you, which is very nice of them. I think that this is a pretty cool feature because when you have to manage a complex AWS organization and you're like, okay, let's set it up this way, okay, now let's adjust it this way. You lose that visibility to say like, okay, Matt's production account for product A was here and, you know, it was in the production OU, which we had set up in organization. And then later on you're like, wait, wait, wait, we want to adjust the way this is set up and we're going to say this was an acquisition first. So you put an acquisition OU and then you lose some of that data. So it's a nice thing to be able to historically look back and get that data versus having to build your own, you know, billing platform, which is other— which is what, like, I've had to do to say, like, okay, let's go recreate the data from 6 months ago, or, you know, which is a pain in the butt. Mhm. [41:18] A: Yeah, I mean, I, I've definitely used services that sort of enrich billing data and allow you to sort of write business rules, um, so you can sort of classify costs and stuff. And I wonder if this is sort of filling that role where maybe now you don't need something like that, it's providing that context for you. I'm not real sure, but you know, any, any context you can, you can request via API is okay in my book. [41:42] B: Yeah. [41:43] A: All right. AWS Transfer Family now supports downloading multiple files and folders in web apps. A user can select and download multiple files and folders in just one action, delivered as a single zip archive and preserves folder structure. Previously, only single file downloads were supported via the web and folders couldn't be downloaded at all. The update addresses a basic usability gap for file sharing workflows, particularly for business partners and customers who need to retrieve batches and related files without manual one-by-one downloads. Browser support is limited to Chrome, Firefox, and Chromium-based browsers like Edge and Safari. But users, but oh, browsers like Edge and Safari are still restricted to single file downloads, which is worth noting for organizations with a mixed browser environment. The feature is available at no additional cost as part of Transfer Family web apps and is rolled out across all AWS regions where the service is offered. Requires no migration or configuration changes for existing deployments. Real-time progress tracking with profile success and failure rate adds visibility for end users and is useful for troubleshooting large batch downloads at enterprise scenario. [42:50] B: I just like how this is a full press release. I don't know what else to say. [42:56] A: Which— [42:57] B: Goes directly to our next article too, but like, cool? Why is this such a big thing? Like multiple download files? Like I'm sure this was a pain point for somebody. Use an API. Like use anything else besides AWS transfers. [43:16] A: I mean, the Azure family is not built for people that could use an API. It's built for the people who cannot, right? [43:24] B: I would just say it's built for your mainframe system that, you know, somebody retrofitted 25 years ago to have FTP and can't get off of it because it's a mainframe. [43:33] A: I mean, you say that, but in financial services, every single application I've ever worked on has some sort of FTP interface that customers are absolutely would die without it and they can't use the platform for every single time. And I've had to build services like AWS Transfer in the past to, to support it. And it's just, you know, Even middleware products like in the financial services industry are like, that's the only thing they know, to integrate. It's awful. [43:58] B: I know, and you and I at one point were building, gonna build an FTP secure solution and— [44:04] A: Yeah, I think that would've been the third time I would've done it, yeah. [44:07] B: And I think it was like the next week Amazon released FTP after we had the Commerce Transfer family. We're like, well, thank God it didn't become Image Factory again. [44:16] A: Yeah. [44:16] B: Image, what's the image builder called? Image builder. [44:20] A: Image builder. Yeah. Ours is Image Tracker. [44:22] B: Yeah. [44:24] A: Yet another Sherlocking. All right, moving on to GCP news. Gemini 3.8 live with live avatars now generally available. 3.8. [44:40] B: I really should not have access to the sound effects. [44:42] A: No, I know. Especially as it gets later, you get a little bit more punchy. So Live Avatar is now generally available in Gemini Enterprise, and it allows adding video avatars and synchronized lip syncing to Google's native speech-to-speech model custom avatar creation. This model supports 97 languages. It's available now in the US and EU endpoints. Pricing details are available on Google Gemini Enterprise Agent Platform. Google emphasizes trust, control, and curating, curated pre-built avatar library, strict allow listing for custom avatars, and SynthID watermarking on all generated audio and video to maintain content transparency. Yeah, so if you want a funny little cartoon to, uh, say the words that you've asked AI to say, now you can do it with Gemini Live. [45:33] B: It just feels like Every week for like the last 4 weeks. Like what it was like, we upgraded from 3.6 to 3.7 to 3.8 and now it's like, okay, every little feature they're adding to it is like, and they're doing another press release for it. [45:47] A: Mm-hmm. [45:48] B: I think they just figured out the Amazon model. [45:50] A: Yeah. [45:50] B: And that's the reason we left in the show was just to complain about it. [45:53] A: Yeah. [45:54] B: Oh, cool. [45:54] A: It does, does cartoons now. [45:57] B: Yay. [45:57] A: Yay. So yeah, you, you probably won't hear us talk about avatars in future episodes. [46:04] B: I wonder. [46:05] A: I mean, I'm sure it's used, like I would use it or this kind of thing, but it's kind of funny to me because yeah. [46:11] B: Do we use it in Bolt to make our little emote, like little thingy? [46:14] A: Not the avatar thing. [46:16] B: Not the avatars, but we do image generation to generate our covers for us. Yeah, but isn't that a Nanobanana? [46:23] A: It's a bunch. We use different ones. [46:25] B: Yeah. I remember there's 2 or 3. [46:27] A: And then we pick the best one, yeah. [46:29] B: It goes back to, we really need to have a conversation on OIDC. So we're going to do a special show about that. I mean, you can just keep saying it to force us to do it. [46:37] A: Mm-hmm. Yeah. No, I mean, it's, it's definitely, I know it's, I know there's a lot of interest because people are asking me all the time what I do and I've got my own complex thing that I do for security reviews. I know you guys have built out quite a bit for Vault, both you and Justin. So yeah, tricky part will be how to demonstrate what we have. [46:55] B: Like, I feel like we'll need visuals, but I don't know that we need to. I think we can kind of talk through it unless if we want to do a live show, but that feels like a lot more effort than we're capable of. [47:04] A: Yeah, man. [47:05] B: Though I have one or two other people that might be interested in joining us to do that. So we'll have to have that conversation. [47:13] A: Hmm. [47:15] B: Onto interesting Google announcements. Announcing PostgreSQL for agents in AlloyDB. AlloyDB now offers PostgreSQL SQL for agents in preview, spinning up sandboxes, read-only database instances in seconds to handle unpredictable query bursts from AI agents without impacting production workloads. The architecture uses Colossus, Google's distributed storage system, to deliver sub-millisecond I/O latency and support over 3 million queries per second, avoiding bottlenecks typical in object storage vector-based caching layers. Instances scale to zero when agents finish the task, so billing is tied to active reasoning loops rather than continuous provision read-only replicas, addressing cost concerns for variable agent workloads. The full AlloyDB PostgreSQL engine accesses— access means agents get vector, full-text, spatial, search along standard SQL plus native integration with BigQuery Spark for lakehouse analytics without building ETL pipelines. This is cool. I don't know how else to describe it. Like essentially they dynamically spin up read-only replicas in seconds, pretty much no matter your size, because given the fact that they've, they've, what's the word? Remove the storage, there's a more fancy word for the word remove that my brain is— Abstracted. Abstracted. [48:48] A: Abstracted. [48:49] B: Abstracted, I said more fancy. And I said it that way because, you know, I couldn't remember words. You know, they've abstracted out the storage layer. They can essentially just point different compute at the storage. All they're really doing is just spinning you up a new compute instance. And I assume, you know, You know more about AlloyDB than me, but is it AlloyDB like Aurora or am I wrong? [49:15] A: Um, yeah, it's, it's similar. Yeah. [49:18] B: Splitting up compute is quick at this point and just it's pointing it at the same storage that exists and they can handle that many IOPS. So I think this is really cool. I don't have a specific workload in mind for it, but it's pretty cool. Yeah. [49:34] A: Well, I think they're solving a problem. Before, I've definitely run into it, right? So I think that, you know, I think with Anthropic development, like everyone is just going to build, instead of building, you know, like functions that do data lookups, they're gonna build agents that will take different parameters or in natural language or, and run the queries themselves. And so that's now when you think about that with a whole bunch of non-human identities all trying to do the same thing, like a, you can see how a database would just get pounded. And so allowing this sort of, this is sandbox, it's only read-only and it's low latency and they're doing some sort of crazy magic under the hood to, like you said, maybe like digital twinning these, the data tier so that they can run the compute on top of it and scale up and scale down to zero. Like, that's amazing. [50:27] B: Yeah, I mean, I'm just impressed. I'm also trying to figure out if there's going to be a new term out there, like There's DDoS, and at one point there was a term that Amazon tried to get out there for like financial DDoS, essentially, that like would cost so much money because your auto scaling group would scale up too high that you'd become bankrupt. There was like a theory, it was on the like beta exams for networking back in the day, like before they released it. And I'm wondering if now there's not gonna be like a new term, like you're essentially getting agent DDoSed. From people. [50:59] A: So, I mean, I know it's part of our security evaluation in my day job. Like we're looking for that type of attack vector in our production apps and making sure that we're, you know, like protected against someone, you know, abusing the platform and just spinning up a bunch of stuff. Cause it's, you know, I've definitely seen it happen. Um, there's a very funny meme that made it on the internet where like the McDonald's app was being used for someone's homework. So it's like I ran out of credit. So McDonald's is my AI now. It's just kind of, you know, it was, you know, it was just answering any random question when it was there to be a customer service bot. So it's, it's definitely something that you have to look out for. And it's, you know, it's going to be one of those, like, you know, the OWASP top 10 AI things that are, need to be protected against. [51:49] B: Yeah. I feel like we talked about, what was it? The car company that had it, like the guy negotiated with the AI bot for a car for 1 cent. And they actually like agreed with it. [51:58] A: Yeah. [51:59] B: So onto Azure in the, in the home shop. If we must. [52:05] A: Yeah. Azure is retiring a service, which I don't remember if that's happened. I'm sure it has. So Azure Communication Services, a standalone service, as a standalone service will be retired on September 30th, 2028. Services offering on services including email, chat rooms, job router, and both web and mobile UI library SDKs will all BD commissions. Voice and video calling components like call automation, call recording, and closed captions will not be fully retired, but will only continue functioning when integrated with Microsoft Teams, requiring customers to migrate to updated SDKs. Any standalone ACS calling implementation that hasn't been updated to the latest SDKs by the deadline will stop working. So this is a significant migration effort for developers. And since it's an older app, it's probably applications that are no longer being actively maintained. This signals a broader shift in Microsoft's communication strategy, consolidating standalone ACS capabilities more tightly around the Teams platform rather than supporting them in independent, as independent services. Customers with affected implementations have roughly 2 years from the announcement to plan and execute migrations, which pretty nice. Appreciate that and should review the retirement and breaking change FAQ to understand specific inputs and applications. So not too far off after they killed Skype for, for realsies. So yeah. Yeah. [53:27] B: I mean, it's interesting. They don't have real solutions for some of these things like SMS, like they're kind of killing off, you know, they're, they're not going to support it. You know, email at least goes into, you know, M365. Chat there, you know, they have the chat API in Teams, you know, video Teams obviously. So like they're definitely moving more into Teams in, in that way. Um, we put, we put in here, uh, in the show notes, uh, alternative by capability chart, which I thought was interesting. [54:03] A: So the email one, so SMS, like I guess I understand, but it is sort of like it sucks for anyone using that. But the email The Microsoft option only supports internal email. It does not support public email. And so that's very limiting for something that's the, you know, a communication service, because you're likely writing an application for, you know, for interfacing with your customers. And so it's probably public and not private. So I don't know, you know, I don't know it myself, but that's a pretty strong limitation. [54:34] B: Microsoft has always pushed people to SendGrid. Which I thought was interesting. And like, you run the largest male platform— I'm not going to say in the world, I'm going to say top 2 male platforms in the world. Let's go with that. [54:47] A: Sure. [54:47] B: Or top 5. Maybe there's one in— like, China has one that I'm not familiar with. But like, you got to be in the top 5 in the world, you know, and like, you're not supporting it. It's just interesting to me. [55:01] A: I mean, it's a huge risk, right? Like, it's Anyone who's ever used ECS, you know, finds out real quickly how fast they will shut you down for bouncing. And they're just really trying to protect against people, you know. [55:12] B: Spam. [55:13] A: Spam, you know, spamming. [55:14] B: Don't get me started on the ECS team. I will not go there. Yeah. So introducing the new Copilot with Helm, Code, and Autopilot. Microsoft is restructuring Copilot into 3 components. Home, unified starting point for combining chat and co-work with Excel, PowerPoint built-in. Code, natural language and building powered with GitHub Copilot technology. And Autopilot, which is persistent layer, formerly known as Scout, which I kind of like Scout name, I'm just saying that, that runs tasks without being prompted. Code and Home rollout via frontier programs coming soon. Autopilot has a private preview ending in September, so. Maybe something new will be coming down the line. The full GA code lets non-developers build small apps leveraging all that. Pricing shifts to a two-track model. User license subscription covers everyday chat and office usage with auto feature that routes requests the most cost-effective model. So they essentially built a model router built into it and a usage base for a Gentec work work like Copilot— sorry, co-work, code, autopilot with frontier models such as Azure and Fable that separates out predictive fixed costs from variable agent workloads. There's new fit ops abilities for you to be able to figure all this out, which, good luck. I wish you all luck on this. Ryan, I know you had some thoughts about this before the show. [56:42] A: Oh, definitely. Yeah. Um, I mean, it's— so this is interesting that, you know, that They're following along the Anthropic model who's also merging sort of all of the capabilities into the single app. I've long complained about Microsoft's Copilot branding and how I have no idea what anything else, anything is and what it does. It's been frustrating. I completely forgot about Scout because it's just not on my radar anymore, even though it really should be because there's, you know, it's one of those things where it allows you to run an agent workload autonomously and, you know, what, what does it have access to? Where's it running? What are the security around it? Is, you know, dark if you're using it in such a way that, you know, isn't in line with what your business is sort of providing as a platform. And so it is sort of like this, it's cool. Like I, I do like the centralization of these things. I feel like the separation, it never made sense to me that Anthropic or Microsoft did this. So I'm glad to see it. Turning into this. And hopefully with this integration, there's less confusion, and mostly for myself, because if I use Copilot in Excel and I ask it about the Excel sheet that's open where I am typing these instructions, and it's like, well, I don't have access to your thing, I will stab my computer with a knife. [58:04] B: We are very much on knives today and stabbing, right? Yeah. Okay. I just, it's getting complicated and, you know, I'm hoping that we've expanded out to a billion tools all doing agentic AI workloads, insert 17 other buzz terms in here. I'm hoping they're all going to start to kind of conform back into some pretty solid tools over time, you know, and kind of go that way, you know. And this is kind of, I think, one step of they realized they went too wide and they're trying to bring it back and really gained some positivity, you know, and positive momentum with these specific tools. [58:41] A: Yeah. I mean, they just, they thought they needed two products, right? One for consumers and one for people who were code. And it's, it turns out it's not what you need, right? You had people generating code in the chat products and you had people using the code products for chat and it's, it never made any sense. And supporting two different platforms to do the same thing was very problematic for enterprises. And now it's much easier. There's a single permission scheme, single access scheme and configuration. 'Cause these, you know, these are clients that run on laptops, right? So they have to be managed for large enterprises. So we'll see. I'm very curious to see what it does for billing. 'Cause I know that some of the Copilot billing has been rough in terms of cost per user. So we'll see if that gets easier or just more expensive 'cause it's more, more capabilities. [59:31] B: Yeah, I have a theory that AI is going to go dramatically up in price over time. You know, it's kind of going to be like Lyft and Uber where like it was really cheap. I get, you know, halfway across San Francisco for $15 back in the day, you know, that was a 30-minute ride. And now that same ride is like $35, and you're like, okay, they're not subsidizing as much. And I think that's what you're seeing here too with a lot of these things. [59:56] A: Yeah, I, you know, there's a lot of investor capital in AI right now, right? There's, it's still not turning a profit. I don't, I don't think. And in order for, you know, companies to continue on that path, they're gonna have to figure out how to generate capital. And so it, I do, I agree with you. I, you know, and I, sucky thing is like, I think they did exactly what they, you know, what they wanted to. First one's free. And now I'm addicted and now what? [60:25] B: Right? [60:26] A: Like, great. [60:27] B: And now I can't survive without it. You want me to go program myself? I don't know what AI generated. I don't know what this code does. I don't remember how to write a function. [60:36] A: Like, I haven't done that in a year and a half. Which isn't true, but it definitely would have a huge impact on productivity. [60:43] B: You mean it's been 2 and a half years? [60:45] A: Probably. What is time? All right, moving on. Virtual nodes on Azure Container Instances is a new— and there's a new compute layer for EKS. There's a new implementation of virtual nodes, and this time built on Azure Container Instances rather than the older virtual kubelet-based add-on, adding support for init containers, persistent volumes, managed identity, and richer networking that the original lacked. Pod scheduled to virtual nodes runs Hyper-V isolated containers sized per pod rather than packed onto fixed VMs, supporting up to 200 pods per virtual node with no capacity capacity planning or node provisioning delay. There's a build-per-second and ACI rates for cores and memory used. Confidential containers are first-class capability here enforced via a CCE policy, a base64-encoded rego document that locks down allowed images, commands, and mounts at the guest OS level inside the trusted execution environment backed by AMD SEB-SMP hardware attestation. Yeah, say that 3 times. A tool called ACI Policygen auto-generates the policy from an existing manifest to lower the barrier for adoption. Auto, anything auto, happy for that. Integration requires no new API or development pipeline. Teams target the virtual node using standard node selector and toleration fields using and existing the existing kubectl, Helm, and GitOps workflows that they've used in the past. This is positioned as additive rather than a replacement for no traditional node pools. Virtual nodes on ACI are meant to absorb force traffic, short-lived jobs, and workloads needing hardware isolation, while steady-state and DaemonSet workloads remain on regular-sized node pools. One deployment requirement to flag: a dedicated delegated ACI subnet size for peak pod count must be used since each pod will consume an IP address for its lifetime. [62:35] B: Yeah, I mean, this is fantastic. They, you know, essentially built, you know, if you're familiar with AWS, Fargate, you know, as far as I understand, I haven't played with this, you know, on AWS or Fargate EKS on Azure. So having that ability to spin it up is fantastic and, you know, makes the barrier to entry of any of these things a lot less, 'cause now you don't need to manage the servers. I love running Fargate, you know, I've helped many companies do it and I understand the premium for it, but from the compliance level, you know, it's always fun turning to an auditor and they say, where's your EDR, where's your antivirus or whatever? You say you're running on your production servers. I'm like, there isn't any. And they're like, what do you mean? I'm like, there's no servers. They're like, what do you mean? I'm like, it's running in container. [63:22] A: Yeah. [63:23] B: Where's it running? Magic. [63:25] A: Yeah. Oh, you want to see the compliance paperwork? That's Amazon's problem. Go over there. Yeah. [63:29] B: Yeah. Always good times. Yeah. [63:33] A: It's interesting that they're, they're sort of positioning this as, uh, not like, I don't remember reading any limitation on Fargate where it's like, uh, just run this for your burstable capacity, you know, things. And I wonder if that's like, uh, you know, the, what Amazon would do where they'd sort of price something really high as they're rolling it out to sort of manage the workloads. I wonder if that's sort of what they're doing here for like kind of a capacity control. [63:59] B: Hmm. [63:59] A: Or is it just, you know, like not as predictable in terms of availability, which would be interesting, but seems odd, but I can see capacity be a concern. [64:08] B: Yeah. I mean, the other piece I always find interesting with Azure services is They require delegated subnets, which like I get from security. It means it can only launch there and whatnot. But as you have more and more services, you end up with all these subnets and then you're like managing subnets again. And I'm like, I don't want to be doing that. [64:27] A: So that's not Azure, man. That's Kubernetes. And so the underlying Kubernetes engine is the thing that— [64:32] B: but that's across a lot of things on AWS though. Or sorry, on Azure, like firewall, the firewall service requires a dedicated subnet named in a certain way, like, yeah. [64:42] A: How do you think they manage your router on their platform? It's probably Cloud Run. Yeah. [64:48] B: I know. [64:48] A: I don't know that, right? I'm guessing, but a lot of that is, you know, auto scaling requiring dedicated, like, you know, Amazon would just make sure that you had, you know, adequate size above the minimum and then would just say like, you're boned when you run out of IPs, which is, you know, I was always happy with that. You know, I was happy with that. [65:07] B: Yeah. So I was mad at you multiple times. [65:08] A: So I'm just saying, oh, what did I use? [65:11] B: HelloFace? [65:12] A: I never, never would do that with runaway processes that I didn't check. [65:15] B: It was also the ELBs that require 7 IP addresses to launch. [65:20] A: And you're like, oh yeah, no. When I shut up the ELBs, when I made everyone use a small network and had to quickly reverse that decision. Yeah, I remember that. Everyone hated me. [65:31] B: I had some fighting words with you at one point. [65:34] A: Yeah, I had to adjust for sure. [65:39] B: But what about IP efficiency? Yeah, well, we don't care about those. [65:43] A: No, no. [65:45] B: Everyone gets a 10, gets a /16, which is possible. [65:48] A: Exactly. [65:49] B: Yeah. [65:50] A: There's plenty of IPv4 IPs. No problems. [65:53] B: Onto Oracle because we need something to laugh at today. Introducing OCI NetApp Storage Service, native ONTAP storage. On OCI. Do I have to read more? [66:07] A: Yeah, I haven't even yet. Sure. [66:10] B: Oracle and NetApp are expanding their partnership with first-party ONTAP storage on OCI. You can now spend more money on Oracle. Yeah, following a well-worn paddle of all the other hyperscalers that have this at this point. [66:23] A: Yep. [66:24] B: I— that's all I got. I'm not going any further. If you want more, read the show notes. [66:28] A: It's exactly what that is, right? Which is like, people are, you know, very used to the NetApp management ecosystem, like the, the administrative UI and, and moving stuff around, and they're comfortable with those APIs. And it's always confused me cuz it's, in my opinion, unnecessary abstraction, you know? But I guess, you know, historically running a data center, you've, you've had the storage layer provided for you and you've built around patterns for that where it's, when I can provision a disk dynamically as part of my application deployment, I don't know why I would need to use this. And if I need to, you know, offer something with a shared network or a shared layer for multiple things to access, like, you know, like unless it's truly shared block store, like I'm going to use an object, I'm going to use something else that's not a network SAN. But, you know, now I guess if you want to run a data center in the cloud and just not optimize anything and move your workloads into the cloud, you, you too can now pay through the nose on Oracle. [67:33] B: You can run VMware on top of Oracle with your NetApps and really burn all your money. [67:39] A: Sorry. [67:40] B: Yeah. [67:41] A: Yep. [67:43] B: Well, Ryan, we survived another episode with just the two of us. Mm-hmm. So I'm sorry for anyone that's made it this far. Yeah, probably should have turned it off a while ago. [67:54] A: We apologize. Don't worry, they did. It's our moms and Justin. That's the only one listening right now. [67:59] B: My mom doesn't listen. She would have no idea what we were talking about. [68:02] A: I know. It's, you know, we're talking. [68:06] B: Well, I will see you next week. [68:08] A: All right. Bye everybody. [68:10] B: Bye everyone. [68:11] A: Another week of cloud news wrapped up. Bolt will collect the news. Justin will get the notes. Jonathan Jonathan will write some code. Ryan will watch the perimeter and Matt will reluctantly watch Azure. Till next week for AI, Amazon, Google Cloud and Azure. And hey, maybe even Oracle, who knows? Check out thecloudpod.net for our newsletter. Join our Slack, message us on socials or leave a review. [68:43] B: Well, we have an after show today. And really, it's just a pet peeve of mine that I saw fairly not tangentially related. But, you know, I watched talk about it and I thought that since Ryan and I were here and Ryan's in the world of security, it might be interesting to him. So there's an article written at 9to5Apple at work, Enterprises Need to Kill the SSL Tax. It's an opportunity for Apple. The article highlights 37% of enterprise apps go unprotected by SSL on average. Large, largely because vendors charge a premium to enable it. SSO should not be charged for, it should be included base, creating incentives for companies to skip basic security measures. Cleaver, let me go with that's how you say it, K-12 model presented a working alternative, a platform for free for schools and application vendors pay for a gallery placement, effectively reversing who bears the costs. For secure logins. The piece argues Apple should acquire Clever, build an identity layer connecting Managed Apple Accounts platform, SSO, Sign in with Apple, into a vendor-funded SSO model, potentially strengthening Apple's position in K-12 sales against Chromebooks, which I think they're killing Chromebooks. They're becoming Google Books. I think we had a small tangent on that earlier before the show. Um, Turns out Ryan and I should not do the pre-read by ourselves, but we'll bypass that for this work. This raises a broader question of who should bear the costs of security features like SSL and MFA and bundling them with premium add-on features versus just giving them to everyone by default because that's what you should do. Yeah, I have very strong feelings. SSO, it should just be included. The amount of times I've had to buy a premium tier of something 'cause I just wanted SSO, than getting these 17 other features. Like, I get it, you're giving me all this other stuff, but I don't want it. And there was one vendor, I was doing a review, like I was looking at, I wanna say it was like ECS static code analysis and dynamic code analysis back in the day. And I straight up just said to vendors, if you're not gonna include SSO in the base cost, I'm walking away before we even start this conversation. Yeah. Because it really is a massive pet peeve of mine. And like, it was like sso.tax back in the day. I think there's sso-tax.org now, which is like essentially wall of shames for people about it, you know, that show you like how much it is, like just to get that. Yeah. SSO, you know, Slack is a great example. It's posted on here. Base price is $8.50. If you just want SSO, it's $18 a person. Like, that's a big jump. Yeah. [71:35] A: No, I mean, any kind of enterprise SaaS app, like, the problems are too big today. You know, spear phishing is the number one attack vector. You know, people, you know, scamming people out of their credentials. And so every SaaS app that you use in your day-to-day job, you're going to have a different MFA provider and you're you're going to have tokens or whatever, passkeys, or for each one of those, like, it's— and then logging is distributed at that point. And for access, like, there's no way you can have that type of control if you don't have sort of a central IDP and manage that application access via it. And so it's not— it's just, it is, it's a tax. And it— if you're gonna charge for it, it just means that people won't use it. And if they don't use it, now they, you're just making them a target on your, on your application. So that sucks. I hate it. Right. [72:33] B: And the one that really annoys me is GitHub. The only way to get SSO is to go to enterprise. [72:39] A: I just found out that Postman today is the only thing that allows that too. And like, you have to do enterprise. [72:46] B: You're protecting code, like you're You're protecting literally ways that people get into stuff. It should be almost required to be on the platform as a business. Like, I agree, you need to flip the story. But the problem is enterprises are making too much money because people upgrade because Ryan, rightfully so, says, no, you need your tool to have SSO so we can manage it. [73:13] A: I mean, I get to rest on the fact that most compliance controls require it and it's not really me, but if they didn't require it, it would be me. So it's sort of— Yeah. Yes, it sucks. [73:21] B: It's just a massive pet peeve. There's no reason, like once it's implemented, it's so little. Yes, there are support tickets because SSL, because SSL sucks to set up, but once it's stood up. [73:37] A: But the alternative is managing user credentials on many different platforms. You think that's not tickets? Like I forgot my password. [73:43] B: But it moves where the tickets are. One is a ticket to, let's say GitHub in this case, one's a ticket to an internal Git you know, repository that you have running. So like I get, but like there's not a large sum of effort to set up SSO at this point. And it's not like you're maintaining it, updating it. You know, I have always wondered like how it works for you to rotate your SSL cert to think your SSL cert. It's really not bad. [74:08] A: I've done it many a time. Like it's, you do have to update the configurations, but like it's with the new cert. That's not that big a deal. [74:16] B: But like the fact that GitHub— [74:17] A: And for OAuth, OAuth is addressing that just by publishing, you know, well-known endpoints where you can pull that down and verify it. So. [74:25] B: There's like a secure, I want to say like secure SS, like there's like a, there's another SSO that's like SSO-S or something. I'll have to look into it. [74:36] A: Well, SSO is just a larger term for, for SAML, right? Which is, and OAuth, right? Those are both SSO. [74:43] B: That's what I'm thinking of. [74:44] A: Yeah. [74:45] B: But there's SAML with secure mode too, which is like another certificate on top of it. [74:52] A: Okay. [74:52] B: I don't know how that's gonna work. Yeah, I've worked with banks that had it and we had to implement it. It's another layer of security where like, then I'm like, how do you rotate? You know, when you have to have it signed by, you know, insert company that signs certificates here. So it becomes another layer too. [75:08] A: Yeah. [75:09] B: I don't know. [75:09] A: I'd rather do that with something like a device trust policy or something along those lines, because that sounds like mutual TLS for SAML and that. And so it's, you know, like, I don't know if I want to validate a client certificate to say you can request an identity from my platform. I'd rather have you make the request and then I do some evaluation on whether you deserve a response or not, but that's just me. [75:35] B: I agree. [75:37] A: Anyway, I do think it's interesting. I didn't know anything about like this guy's, you know, the article we're, that we're sort of abusing, uh, is that the, the want here is for Apple to buy Clever, not Cleaver, and in order to support more of an Apple movement to supporting schools, like the using Apple devices instead of Chromebooks, which I find crazy town because of the hardware cost differences between a Chromebook and an, a kind of Apple product. But, you know, neat. I guess, you know, that it's an op-ed piece, it's written by an Apple employee, so that makes sense that of course they would want to use Apple. And, you know, my kids would love it, but, 'cause they're not big fans of Chromebooks, but I think that's largely 'cause of all the security controls and not functionality directly. [76:27] B: I thought Chromebooks started getting expensive at this point, but I guess there are cheaper models. [76:33] A: Exactly. It's, it's because it's not proprietary hardware and it's built on commodity. It's, you get the, you get the full gambit. [76:42] B: Oh yeah. So here's a Chromebook for $179. Yeah. All the way up to like $800. Cause I was thinking they just released, and by just, I mean, uh, I'm clearly not using that term correctly. They did release those low-end Macs finally, the Neos for $699. [77:00] A: Yeah. And so I don't know, like, you know, I know that, you know, at least around here the school districts are offering, or they just issue a Chromebook to every student automatically so that it's, you know, computer access is fair and it doesn't matter about your income level. But, you know, can't spend a lot of hardware when giving a whole bunch of laptops to 12-year-olds, right? [77:20] B: Like, Why, you don't— you think they're going to treat them nicely and kindly? [77:25] A: They don't treat my house kindly, tell you that much. I mean, how good I am at replacing sheetrock? Really good. [77:31] B: You'll have to teach me as my boy gets older. [77:36] A: Yeah, exactly. [77:37] B: He's pretty good already. I want to— so, you know, yeah, I'll make a couple house calls and get you— [77:43] A: and get your, uh, technique worked out. [77:46] B: I don't know, I'm, I'm abusive to technology, so I can't imagine what kids are. You know. So yeah, well, that was my small diatribe on SSO tax and why people are dumb and why I hate all companies that charge for SSO tax. [78:02] A: I do too. It is awful. [78:04] B: I will catch you next week, Ryan. [78:05] A: All right, till next time. [78:08] B: Bye-bye.