Skip to content
Artwork for Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News
Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News · Yesterday · 17 min

AWS GWLB TCP Reset, Azure DevOps Live Migrations to GitHub, GitHub Runner Enforcement, Docker Root Risk, Lambda IAM Updates, PostgreSQL Upgrade Traps, SonicWall Zero-Days & Better Incident Reviews

This week on Ship It Weekly: AWS Gateway Load Balancer gets TCP Reset, giving applications a faster way to recover when firewalls or other inline appliances fail instead of waiting minutes for TCP retries to time out. Microsoft puts Enterprise Live Migrations into public preview for moving Azure DevOps repositories to GitHub Enterprise Cloud with data residency while developers keep working. GitHub is beginning enforcement against outdated self-hosted Actions runners. And Omarchy fixes a Docker configuration that effectively gave normal desktop processes a path to root. The bigger theme this week is failure modes hiding inside infrastructure we already trust. A dead network path can look like a slow application. A repository migration involves far more than copying Git history. A self-hosted runner can quietly become unsupported while it continues looking healthy. And giving a developer access to the Docker socket may sound like convenience until you remember that the Docker group is effectively a root-level privilege. In the lightning round: Lambda gets full IAM resource-based policies, AWS warns that circular PostgreSQL role memberships can stall major RDS and Aurora upgrades, a researcher releases the FalconFlank CrowdStrike privilege-escalation PoC while CrowdStrike investigates, and SonicWall patches two SMA1000 zero-days after confirming active exploitation. Links AWS Gateway Load Balancer TCP Reset https://www.tellerstech.com/go/s-d7e609ab/ Azure DevOps Enterprise Live Migrations Public Preview https://www.tellerstech.com/go/s-ea05aff9/ GitHub Actions Self-Hosted Runner Minimum Version Enforcement https://www.tellerstech.com/go/s-6e8540c4/ Omarchy: Any User Process Can Escalate to Root https://www.tellerstech.com/go/s-d22971c3/ AWS Lambda Full IAM Resource-Based Policies https://www.tellerstech.com/go/s-ff2a04b5/ Fix Circular Role Dependencies Before Upgrading RDS and Aurora PostgreSQL https://www.tellerstech.com/go/s-e4578f52/ FalconFlank CrowdStrike Privilege Escalation PoC https://www.tellerstech.com/go/s-8c21b00b/ SonicWall SMA1000 Zero-Day Advisory https://www.tellerstech.com/go/s-559ffc8b/ Remote Incident Reviews: Async First, Live Later? https://www.tellerstech.com/go/s-68ca9f5e/ This Week’s On Call Brief https://tsn.io/L95NS Ship It Weekly https://www.tellerstech.com/go/siw/ On Call Brief https://www.tellerstech.com/go/ocb/

0:00-17:26

transcript

No transcript — this publisher did not publish one.

show notes

This week on Ship It Weekly: AWS Gateway Load Balancer gets TCP Reset, giving applications a faster way to recover when firewalls or other inline appliances fail instead of waiting minutes for TCP retries to time out. Microsoft puts Enterprise Live Migrations into public preview for moving Azure DevOps repositories to GitHub Enterprise Cloud with data residency while developers keep working. GitHub is beginning enforcement against outdated self-hosted Actions runners. And Omarchy fixes a Docker configuration that effectively gave normal desktop processes a path to root.

The bigger theme this week is failure modes hiding inside infrastructure we already trust. A dead network path can look like a slow application. A repository migration involves far more than copying Git history. A self-hosted runner can quietly become unsupported while it continues looking healthy. And giving a developer access to the Docker socket may sound like convenience until you remember that the Docker group is effectively a root-level privilege.

In the lightning round: Lambda gets full IAM resource-based policies, AWS warns that circular PostgreSQL role memberships can stall major RDS and Aurora upgrades, a researcher releases the FalconFlank CrowdStrike privilege-escalation PoC while CrowdStrike investigates, and SonicWall patches two SMA1000 zero-days after confirming active exploitation.

Links

AWS Gateway Load Balancer TCP Reset

https://www.tellerstech.com/go/s-d7e609ab/

Azure DevOps Enterprise Live Migrations Public Preview

https://www.tellerstech.com/go/s-ea05aff9/

GitHub Actions Self-Hosted Runner Minimum Version Enforcement

https://www.tellerstech.com/go/s-6e8540c4/

Omarchy: Any User Process Can Escalate to Root

https://www.tellerstech.com/go/s-d22971c3/

AWS Lambda Full IAM Resource-Based Policies

https://www.tellerstech.com/go/s-ff2a04b5/

Fix Circular Role Dependencies Before Upgrading RDS and Aurora PostgreSQL

https://www.tellerstech.com/go/s-e4578f52/

FalconFlank CrowdStrike Privilege Escalation PoC

https://www.tellerstech.com/go/s-8c21b00b/

SonicWall SMA1000 Zero-Day Advisory

https://www.tellerstech.com/go/s-559ffc8b/

Remote Incident Reviews: Async First, Live Later?

https://www.tellerstech.com/go/s-68ca9f5e/

This Week’s On Call Brief

https://tsn.io/L95NS

Ship It Weekly

https://www.tellerstech.com/go/siw/

On Call Brief

https://www.tellerstech.com/go/ocb/

links12