"The company formalized the idea that defects could be fixed through human intervention on live production systems" (From Part 5). Uh...yeah. I think we all realized that years ago.
Decisions that eroded trust in Azure – by a former Azure Core engineer
191–200 of 697 posts
Re: Decisions that eroded trust in Azure – by a former Azure Core engineer
#192The post is so dramatized and clearly written by someone with a grudge such that it really detracts from any point that is trying to be made, if there is any. From another former Az eng now elsewhere still working on big systems, the post gets way way more boring when you realize that things like "Principle Group Manager" is just an M2 and Principal in general is L6 (maybe even L5) Google equivalent. Similarly Sev2 i…
Before the days of title inflation across the industry, a a Principal at Microsoft was a rare thing. When I was there, the ratio was maybe 1 principal for every 30 developers. Principals were looked up to, had decades of experience, and knew their shit really well. They were the big guns you called in to fix things when the shit really hit the fan, or when no one else could figure out what was going on.
Re: Decisions that eroded trust in Azure – by a former Azure Core engineer
#193What an epic takedown. Microsoft should have promoted this guy instead of laying him off. Did Microsoft really lose OpenAI as a customer?
Re: Decisions that eroded trust in Azure – by a former Azure Core engineer
#194Earlier quoted context omitted.
It is kind of a fundamental risk of IMDS, the guest vms often need some metadata about themselves, the host has it. A hardened, network gapped service running host side is acceptable, possibly the best solution. I think the issue is if your IMDS is fat and vulnerable, which this article kind of alludes to. There’s also the fact that azure’s implementation doesn’t require auth so it’s very vulnerable to SSRF
You could imagine hosting the metadata service somewhere else. After all there is nothing a node knows about a VM that the fabric doesn’t. And things like certificates comes from somewhere anyway, they are not on the node so that service is just cache.
Re: Decisions that eroded trust in Azure – by a former Azure Core engineer
#195The first couple of paragraphs felt like a parody of a guy who goes to a diner and gets upset the waitress doesn’t address him as Dr. It didn’t get any better.
His writing style is fairly over the top (he is Swiss, and I have seen this before, but not most of the time), but most of the technical content seems true to me.
Re: Decisions that eroded trust in Azure – by a former Azure Core engineer
#196Earlier quoted context omitted.
In our case this was only a month ago, and now we're stuck because management thought it was a good idea to sign a hefty spend commitment.
Don't they have an SLA? You can break that open if they don't perform.
Re: Decisions that eroded trust in Azure – by a former Azure Core engineer
#197Earlier quoted context omitted.
Don't they have an SLA? You can break that open if they don't perform.
To what end? I've never seen an SLA which is clear cut enough to be worth pursuing if you want more than a free t-shirt.
I have, regularly. I am not sure what kind of business you are running but parties that rely on service providers for critical (primary business process driving) components routinely agree to SLAs with large penalties and the ability to open up an existing contract in case of non-performance. Obviously you would have to be willing to pay for such a service in the first place otherwise there is no point in setting up an SLA, this won't be cheap. But we're definitely not talking about 'free t-shirts' here, more about direct liability, per hour penalties and so on.
Re: Decisions that eroded trust in Azure – by a former Azure Core engineer
#198Re: Decisions that eroded trust in Azure – by a former Azure Core engineer
#199What are we reading here? These are extraordinary statements. Also with apparent credibility. They sound reasonable. Is this a whistleblower or an ex employee with a grudge? The appearance is the first. Is it? They’ve put their name to some clear and worrying statements. > On January 7, 2025… I sent a more concise executive summary to the CEO. … When those communications produced no acknowledgment, I took the customa…
I am sort of confused how NDA and such agreements employees sign would allow for an employee to post such an article without being sued by Microsoft?
Re: Decisions that eroded trust in Azure – by a former Azure Core engineer
#200I interviewed with a Dutch energy company migrating infra from AWS -to- Azure and I have no idea what would make them do that (aside from inertia, but then why use Azure in the first place?)
And for some reason Azure usage is rampant in Europe.