Live data from Hacker News

DigitalOcean VPC

blog.digitalocean.com

161–169 of 169 posts

Re: DigitalOcean VPC

#161

Earlier quoted context omitted.

Hey, Kamal from DigitalOcean here. I'm sorry that happened to you! You're right, managed Redis Databases do not support backups[0] currently. I found the page on the website that says they do and let the team know. They will correct it asap. [0]: https://www.digitalocean.com/docs/databases/redis/#redis-lim...

Hey Kamal, good to see you here. I'm sorry to hijack this thread, but I'm hoping someone from DO could provide an official response to this often-cited post on HN regarding security issues on your K8S offering: https://news.ycombinator.com/item?id=22490390 Is there a chance you could poke someone into looking into this?

Hello,

I'm the tech lead for Kubernetes at DO. Just wanted to jump in and provide some clarification around the security issues you brought up.

The blog post you're referring to came out in December 2018, shortly after we released DOKS as a Limited Availability offering. By the time we announced our General Availability release in May 2019, we had done the following:

1. Changed our node bootstrapping process so that etcd information is no longer necessary in the metadata API, and removed said etcd information from metadata. 2. Firewalled off etcd so that it's accessible only inside the cluster. 3. Shifted how we run the CSI controller component so that a DO API token no longer needs to be stored as a secret in the cluster. 4. Switched from Flannel to Cilium as the CNI plugin, which allows users to configure network policies. We don't configure any network policies by default, but the option is there for users who want to use them.

These changes fix the vulnerabilities explained in the blog post. We do have further hardening measures planned, including limiting the scope of API tokens (one of the suggestions from the blog post, and also an often-requested feature from DO customers), but that's a big project so we can't provide a firm timeline for it at this point.

Hope this clarifies the current situation. If you or anyone else finds new security issues with DOKS (or other DO products) we would love to know about it. Our security team is always accepting vulnerability reports via their disclosure program: https://www.digitalocean.com/legal/contact-security/

Re: DigitalOcean VPC

#162
post #161

Earlier quoted context omitted.

Hey Kamal, good to see you here. I'm sorry to hijack this thread, but I'm hoping someone from DO could provide an official response to this often-cited post on HN regarding security issues on your K8S offering: https://news.ycombinator.com/item?id=22490390 Is there a chance you could poke someone into looking into this?

Hello, I'm the tech lead for Kubernetes at DO. Just wanted to jump in and provide some clarification around the security issues you brought up. The blog post you're referring to came out in December 2018, shortly after we released DOKS as a Limited Availability offering. By the time we announced our General Availability release in May 2019, we had done the following: 1. Changed our node bootstrapping process so that…

It does, thank you for the in-depth response! I'll refer to this comment if I ever see that post brought up again.

Re: DigitalOcean VPC

#163

Earlier quoted context omitted.

Hey Kamal, good to see you here. I'm sorry to hijack this thread, but I'm hoping someone from DO could provide an official response to this often-cited post on HN regarding security issues on your K8S offering: https://news.ycombinator.com/item?id=22490390 Is there a chance you could poke someone into looking into this?

Hey, I ran this by the DOKS team and they confirmed that this was taken care of a while back. Just to clarify, that issue existed while the product was in Limited Availability (think alpha). Nodes are now bootstrapped in a different way that eliminates the need to expose sensitive info in metadata or anywhere within the cluster itself.

Thank you!

Re: DigitalOcean VPC

#164
post #90
post #44

Earlier quoted context omitted.

We use Direct Connect to get traffic to edge nodes where we buy fixed 10Gbps links and pay a fraction of the AWS cost. AWS bandwidth costs are ridiculous.

Direct connect still charges per GB out. The cheapest listed location is $0.02/Gb.

Yes I said it’s a fraction of the cost. One fifth.

Re: DigitalOcean VPC

#165
post #44

Earlier quoted context omitted.

We use Direct Connect to get traffic to edge nodes where we buy fixed 10Gbps links and pay a fraction of the AWS cost. AWS bandwidth costs are ridiculous.

I'm not familiar with Direct Connect. Does it work out as AWS giving reduced bandwidth fees for certain providers?

It’s a private link to an external provider and you pay much less for transit to that provider.

Re: DigitalOcean VPC

#166
post #127

Earlier quoted context omitted.

Just a regular monthly plan. Some plans will claim it's an "unlimited texting plan" but really the charges are still there hidden. Maybe the provider has an agreement with other mobile phone providers to reimburse them for texts their customers send. My last provider refunded the cost if I forwarded the message to their spam department text number. We have pretty terrible mobile phone plans and rules here in Canada.

I live in Canada (Ontario) and have never heard of any plan doing something like this. I am on prepaid myself and have unlimited texting.

That sounds very generous for a pre-paid plan. Is it unlimited for all incoming phone numbers or do you choose specific phone numbers?

I've seen plans that you choose friends or pay more but in some way you are paying more for the free part a bit like insurance. Maybe plans with unlimited texting versus regular plans are more common so the extra cost is seen as normal?

Hopefully it's changing or maybe texting is becoming less of a thing due to more mobile Internet access.

Re: DigitalOcean VPC

#167

I didn't realise they offered Kubernetes as a managed service. Will seriously evaluate when our GCS credits are getting closer to running out. VPC, Kube and managed DB is all we need (and Terraform providers).

According to [0] there were serious security problems with their managed Kubernetes in the early days. May since have been fixed. [0] https://news.ycombinator.com/item?id=22490390

Yikes - only 60 days ago! Thanks.

Re: DigitalOcean VPC

#168

Earlier quoted context omitted.

I'm transferring out ~5TB/day and pay no charges for it. I'm using scaleway ( https://www.scaleway.com/en/pricing/ )

How are you finding the reliability. I've been hosting my personal website on ScaleWay, and there's been quite a bit of downtime (say 40 minutes every few weeks). Not a problem for my personal website, but I'm not sure I'd want to host production services on it.

this is indeed true earlier with C2* series instances. I used to face this problem daily, since I also used NAS. They have deprecated that dedicated box series now and currently using GP1-M which is reliable now.

Re: DigitalOcean VPC

#169
post #76

Earlier quoted context omitted.

I'm transferring out ~5TB/day and pay no charges for it. I'm using scaleway ( https://www.scaleway.com/en/pricing/ )

Would you mind sharing how much you’re spending at Scaleway each month (a ballpark would be enough)? I’m just generally wary of claims of unmetered resources at oversubscribed cloud providers — I mean if I’m paying $5/mo and transferring 150TB they probably have every incentive to cut me off. A clearly defined quota with moderate overage fees actually gives me peace of mind.

current monthly charges are around 300eur. totally running 3 servers.
Post reply on HN