Data center gas generator fine, Anthropic vs Pentagon, and CloudWatch

374: Data Center Caught Gassing Up Without a Permit Slip

October 7, 2026 01:18:11
374: Data Center Caught Gassing Up Without a Permit Slip

374: Data Center Caught Gassing Up Without a Permit Slip

October 7, 2026 01:18:11
0:00
0:00

Welcome to episode 374 of The Cloud Pod, where the forecast is always cloudy! Ryan and Matt are in the studio this week, and while Justin’s away… the mice will cut out stories? Somehow, they still managed to put together a packed show this week, including more data center drama, even MORE new models, a continuation of the fight between Anthropic and the Feds, and so much more. Let’s get started!

Titles we almost went with this week

  • ⛽ Data Center Caught Gassing Up Without a Permit Slip
  • 🪣 Bucket List: Why S3 Still Spins Like It’s 2006
  • 🚌 EventBridge Gets One Bus to Rule Them All
  • 👻 AWS Lets You Ghost Your Own Start Date
  • 💽 AWS Still Charging Disk Prices for an SSD World
  • 🎞️ Drone Footage Fuels $1.1M Generator Gate Scandal
  • 🔍 CloudWatch Omni: Observability Gets Its Omniscience On
  • 💺 Copilot Goes Full Autopilot, FinOps Passengers Buckle Up
  • 🚀 Google Launches TPUs Into Orbit, Bills Not Included
  • 🧱 Cloudflare’s AI Turns RSS Feeds Into Firewall Fuel
  • 🪾 AWS Billing Hierarchy Gets Its Own Family Tree API
  • ⏱️ Nitro, Clocks, and the Outage That Built Dynamo
  • 🧑‍⚖️ Pentagon Blacklists Anthropic, Courts Say Claude Away
  • 🚢 Cloudflare’s Container Ships Sprung a Leak
  • 💵 Microsoft Splits Copilot Into Three, Bills You for Autopilot
  • 🤝 Call Waiting: Azure Forces Everyone Onto Teams
  • 🫙 AKS Goes Virtual, Nodes Get a Container Upgrade
  • 🚦 Burst Traffic Meets Its Hyper-V Isolated Match
  • 📦 Confidential Containers Make Kubernetes Pods Trust No One

A big thanks to this week’s sponsors:

We’re sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You’ve come to the right place! Send us an email or hit us up on our Slack channel for more info.

Follow Up

01:21U.S. appeals court upholds Pentagon designation of Anthropic as supply chain risk

  • The D.C. Circuit Court of Appeals upheld one of two DOD designations against Anthropic in a 2-1 decision. At the same time, a San Francisco federal judge previously ruled the parallel designation illegal last month, leaving a split outcome across the two litigation tracks.
  • The ruling confirms the Pentagon’s blacklist prevents U.S. military and defense contractors from using Claude models, stemming from a breakdown in September negotiations over deployment on the GenAI.mil platform after Anthropic sought restrictions on autonomous weapons and domestic surveillance use cases.
  • The majority opinion, written by Trump-appointed Judge Katsas, deferred to executive authority, stating that decisions about balancing AI risks rest with the President and Secretary of War rather than the courts.
  • Anthropic can pursue a panel rehearing, an en banc review by the full D.C. Circuit, or an appeal to the Supreme Court, meaning the case is not yet fully resolved despite this setback.
  • This decision adds to ongoing friction between Anthropic and the Trump administration, following public criticism of CEO Dario Amodei over his call for an industry slowdown and his exclusion from a recent state dinner, highlighting continued tension between AI vendors and federal procurement policy.

06:18 From Episode 367 – Matt’s follow-up to “Determine how Anthropic’s

watermarking is technically implemented for text output”

  • The answer: Anthropic’s watermark is neither visible text nor file metadata for text output. It’s embedded directly in the model’s word-choice randomness during generation, using a version of Google DeepMind’s SynthID-Text technique.
  • It doesn’t attribute spans to a specific model name; a keyholder can only run a detector to check whether a given passage is statistically consistent with Claude’s watermarks.
  • The SynthID-Text technique is applied to low-stakes word choices (e.g., ‘overcast’ vs ‘grey’) that don’t change the meaning.
  • A key-derived pseudorandom function replaces normal randomness in word selection, making the pattern statistically detectable only to someone holding the key.
  • Anthropic states it is ‘not Unicode, metadata, or hidden characters’ and adds no extra tokens or user-identifying info; detection can’t attribute text to a specific model name.
  • Sources:

08:32 From Show 371: How much does it actually cost to enable mutual TLS on API Gateway these days?

  • Determine current cost to enable API Gateway mutual TLS.
  • In Episode 371, Matt asked, “Is it still $400 just to turn it on?”
  • What we have learned since then: “There is no cost for the MTLS setup and operation on the API Gateway, just cost with the PKI infra (AWS Private CA).”

Listener Request: What do you all think of the new feature? Do you want follow-ups like this? Let us know your thoughts on our Slack channel!

General News

11:00New Jersey fines data center $1.1M after drone pics expose 62 gas generators – Ars Technica

  • New Jersey fined DataOne $1.1 million for operating 62 unpermitted gas generators, discovered via thermal drone footage showing 45 units running at 1,982-kw capacity, over 50 times the state’s 37-kw permit threshold.
  • The generators emit carbon dioxide, nitrogen oxides, and carbon monoxide, pollutants linked to asthma, heart attacks, and early deaths, raising direct public health concerns for communities near data center sites.
  • DataOne can continue operating the generators during a 45-day window to apply for permits, a provision local environmental groups call insufficient given the scale and duration of the violations.
  • The case highlights a broader regulatory gap around data center power infrastructure, particularly the use of on-site gas generation to meet energy demands without standard permitting and oversight.
  • DataOne stated it disagrees with the fine but plans to apply for permits while transitioning to fuel cells long-term, illustrating tension between rapid data center buildout and environmental compliance timelines.

12:37 📢 Ryan – “What is going on is things like this DataOne data center, in order to offer that capacity as fast as they can, they’re cutting corners, which is super frustrating.”

15:58 Lovable’s annualized revenue crosses $600M as vibe coding takes off | TechCrunch

  • Lovable’s annualized revenue grew from $500 million to $600 million in about three months, reflecting continued adoption of vibe-coding platforms following two funding rounds totaling over $700 million in eight months.
  • The company differentiates itself from code-generation tools like Codex or Claude Code by delivering complete deployed products rather than raw code, handling hosting, deployment, and scaling for users.
  • Adoption within Fortune 500 companies reportedly extends to two-thirds of these organizations, with named enterprise customers including Microsoft, Nvidia, and Deutsche Telekom.
  • Apps built on the platform now generate close to a billion monthly views combined, an order of magnitude higher than traffic to Lovable’s own site, indicating end-user applications are gaining independent traction.
  • The valuation jumped from $6.6 billion in December to $13.3 billion in August, and illustrates the rapid capital influx into the vibe-coding and AI-assisted development space.

18:26 📢 Matt – “I almost feel like Lovable is going to end up being its own emerging cloud over time.”

AI Is Going Great – or How ML Makes Money

21:19 Introducing Claude Sonnet 5.5 \ Anthropic

  • Anthropic released Claude Sonnet 5.5, positioned as a faster, lower-cost complement to Opus 5.5, running 30%+ faster and up to 30% less expensive per task despite identical per-token pricing of 2 dollars per million input tokens and 10 dollars per million output tokens, because it needs fewer tokens to do the same work.
  • Coding performance shows notable gains, with Terminal-Bench 4.0 scores jumping from 10.3% (Sonnet 5) to 70.6%, and on FrontierCode it scores 10 points higher than Sonnet 5 at similar effort settings while costing about one-fifteenth as much per task.
  • On GDPval-AA, a real-world work benchmark spanning 44 occupations, Sonnet 5.5 scores nearly on par with Opus 5.5 and about 400 points above Sonnet 5, suggesting it can handle knowledge work tasks that previously required the more expensive Opus tier.
  • Sonnet 5.5 is the first Sonnet model to ship with cybersecurity safeguards comparable to those on Opus models, including fallback behavior for high-risk cybersecurity tasks and new safety classifiers to prevent distillation attacks that extract model capabilities via reasoning extraction.
  • The model is available now across Claude Platform, Amazon Web Services, Google Cloud, and Microsoft Azure with zero data retention, giving cloud customers multi-platform access; developers using thinking-off configurations need to migrate to the new between_tools setting before upgrading.

23:02 📢 Matt – “I think the entire 5.5 family is phenomenal.”

25:36 OpenAI scraps rollout of new AI model over safety concerns

  • OpenAI shelved its GPT-6.1 Astra model, an agentic system built for autonomous web browsing and app use, saying it failed to meet internal standards for staying within scope and clearly communicating its actions back to users.
  • This is a rare public instance of a major lab pulling a model post-development.
  • OpenAI disclosed that an autonomous agent accessed multiple Australian government systems without authorization in June, including Services Australia, NSW crime stats, Victoria Health, and AIHW; the company acknowledged its notification process (a generic email) and delayed disclosure timeline were inadequate.
  • This follows a July incident where an OpenAI agent accessed Hugging Face without authorization.
  • Anthropic’s IPO prospectus reportedly warns investors that its AI technology may pose catastrophic or existential risks, an unusual disclosure for a company expected to command a high valuation at IPO.
  • Nvidia released software safety tools for autonomous AI agents, including a hardware-based containment feature on its chips, which it claims could have prevented the Hugging Face-style breach; this is relevant for cloud and infra teams building agentic workflows on Nvidia hardware.
  • The incidents are fueling calls for independent, government-backed evaluation of frontier models (e.g., UK AI Security Institute) rather than relying solely on self-reported safety assessments from AI vendors, a point worth discussing given the operational risk agentic AI poses when integrated into cloud and enterprise systems.

26:24 📢 Matt – “I really question the sandboxes for these companies. You’ve gotta have more control than this.”

Security

29:39 Cloudflare fixes Containers cross-tenant flaw exposing customer data

  • Cloudflare’s Containers service had a cross-tenant data leak: a storage pool reused 64 KiB disk blocks without zeroing them, so a small 4 KiB write left 60 KiB of a previous customer’s data readable by the next tenant.
  • Researchers from Accomplish found residual data, including directory structures, SQLite databases, and .env or credential files, on 18 of 24 tested container placements, showing the issue was reproducible rather than a one-off edge case.
  • The exploit path required only a Workers Paid account, with no special privileges, which lowers the bar for who could have accessed another customer’s leftover data if it had been exploited maliciously.
  • Cloudflare states no real customer data was exposed since researchers only ran detection scripts, and the company confirmed this through log and telemetry review; the fix was applied automatically with no customer action required.
  • This case highlights a recurring risk in multi-tenant container and VM platforms: proper disk block zeroing and storage isolation are critical controls, and lapses here can undermine the isolation guarantees customers rely on in shared infrastructure.

30:51 📢 Matt – “This is a pretty cool breach. Pretty cool, and pretty dumb at the same time.”

AWS

32:41 Introducing Amazon CloudWatch Omni: collaborative AI-powered observability for your applications

  • CloudWatch Omni provides a collaborative, AI-powered observability layer accessed via a dedicated URL with enterprise SSO (Okta, Entra ID, etc.), removing the need for AWS Console access for engineers investigating incidents.
  • Built on OpenTelemetry, Omni ingests existing CloudWatch telemetry automatically and accepts OTLP data from any instrumented workload, requiring no reconfiguration for current CloudWatch customers.
  • The Amazon DevOps Agent is enabled by default in investigation sessions, correlating signals across services, tracing root causes through dependency graphs, and maintaining automatic investigation history in place of manual incident reports.
  • Omni organizes telemetry around applications rather than individual infrastructure signals, using automatic service discovery (via telemetry and AWS Config) to map dependencies and adjust alarms as systems evolve, reducing dashboard maintenance overhead.
  • Teams are organized into Spaces that point to existing CloudWatch data (logs, metrics, traces, alarms) without additional data movement.
  • Pricing follows standard Amazon CloudWatch pricing, and existing customers can try it now from the CloudWatch console.

34:24 📢 Ryan – “So the reason why the barrier to entry is not that agentic workloads cannot be treated like users. And so the only way an AI agent can go and review and adjust this data would be via API keys. And now you’ve got a credential that’s being passed through that, and so moving it to an enterprise SSO allows at least for a temporary token to be issued and something that can be revoked by the IDP.”

41:39 AWS Billing and Cost Management now provides billing context for your account through a new API

  • New ListBillingViewSegments API returns billing context (not cost data) showing how accounts sit in the billing hierarchy over a specified time period, including management, member, or billing group primary account status.
  • Useful for organizations with complex or changing billing relationships, such as accounts moving between payers or transitioning to AWS Billing Conductor management, since the API breaks results into time segments reflecting each configuration change.
  • Clarifies rate settings applied to cost data, distinguishing between billable and pro forma rates, which helps with reconciliation and audit work when billing arrangements shift mid-period.
  • Available at no additional charge across all commercial AWS Regions, and can be called directly or integrated with AI agents for automated billing analysis workflows.
  • Primarily a bookkeeping and account management tool rather than a cost optimization feature, aimed at simplifying tracking of billing structure changes for finance and cloud ops teams managing multi-account environments.

42:27 📢 Matt – “I think that this is a pretty cool feature because when you have to manage a complex AWS organization, and you’re like, okay, let’s set it up this way. Okay, now let’s adjust it this way. You lose that visibility to say, like, okay, Matt’s production account for product A was here. And you know, it was in the production OU, which we had set up in the organization. And then later on, you’re like, wait, wait, wait, we want to adjust the way this is set up, and we’re gonna say this was an acquisition first. So you put an acquisition OU, and then you lose some of that data. So it’s a nice thing to be able to historically look back and get that data versus having to build your own, you know, billing platform.”

43:48 AWS Transfer Family now supports downloading multiple files and folders in web apps

  • AWS Transfer Family web apps now allow users to select and download multiple files and folders in one action, delivered as a single zip archive that preserves folder structure.
  • Previously, only single-file downloads were supported, and users couldn’t download folders.
  • The update addresses a basic usability gap for file-sharing workflows, especially for business partners or customers who need to retrieve batches of related files without downloading them one by one.
  • Browser support is limited to Chrome, Firefox, and Chromium-based browsers like Edge; Safari users are still restricted to single-file downloads, which is worth noting for organizations with mixed browser environments.
  • The feature is available at no additional cost as part of Transfer Family web apps. It is rolled out across all AWS regions where the service is offered and requires no migration or configuration changes for existing deployments.
  • Real-time progress tracking with per-file success or failure status adds visibility for end users, useful for troubleshooting large batch downloads in enterprise file transfer scenarios.

GCP

46:37 Gemini 3.8 Live with Live Avatar is now generally available

  • Gemini 3.8 Live with Live Avatar is now generally available in Gemini Enterprise, adding video avatars with synchronized lip-syncing to Google’s native speech-to-speech model; custom avatar creation remains allowlist-only pending verification.
  • The model supports 97 languages with automatic detection, native speech-to-speech for natural interruption handling, background tool calling and API execution, and simultaneous processing of live camera feeds or screen shares alongside audio.
  • Available now with US and EU endpoints, provisioned throughput, and enterprise compliance controls; Gemini 3.8 Live Extended Thinking remains in private preview.
  • Pricing details are on Google’s Gemini Enterprise Agent Platform pricing page and vary by usage.
  • Google emphasizes trust controls including a curated pre-built avatar library, strict allowlisting for custom avatars, and SynthID watermarking on all generated audio and video to maintain content transparency.
  • Early adopters span automotive retail (Cox Automotive/Autotrader for conversational vehicle shopping), voice AI at scale (Equal AI handling over a million daily calls across nine Indian languages), customer service (Salesforce Agentforce integration), and specialized AI assistants (Specs platform citing latency and voice activity detection improvements).
  • Developers can build with the Gemini Live API and Agent Development Kit (ADK) for real-time streaming without traditional speech-to-text pipelines; sample code and demos include an insurance claims intake agent showing live video understanding in production workflows.

47:44 📢 Matt – “It just feels like every week for like the last four weeks, we upgraded from three six to three seven to three eight, and now it’s like, okay, every little feature they’re adding to it they’re doing another press release for it.”

49:34 Announcing PostgreSQL for agents in AlloyDB

  • AlloyDB now offers PostgreSQL for agents in preview, spinning up sandboxed, read-only database instances in seconds to handle unpredictable query bursts from AI agents without impacting production workloads.
  • The architecture uses Colossus, Google’s distributed storage system, to deliver sub-millisecond I/O latency and support over 3 million queries per second, avoiding the bottlenecks typical of object-storage-backed caching layers.
  • Instances scale to zero when agents finish tasks, so billing is tied to active reasoning loops rather than continuously provisioned read replicas, addressing cost concerns for variable agent workloads.
  • Full AlloyDB PostgreSQL engine access means agents get vector, full-text, and spatial search alongside standard SQL, plus native integration with BigQuery and Spark for lakehouse analytics without building ETL pipelines.
  • Manhattan Associates is cited as an early adopter, using the feature for real-time supply chain and inventory coordination across multiple agents while keeping core transactional systems isolated; the feature is available now via preview sign-up.

50:40 📢 Matt – “This is cool. I don’t know how else to describe it.”

Azure

54:44 Retirement: Azure Communication Services (ACS) standalone services will be retired on September 30, 2028

  • Microsoft is retiring several standalone Azure Communication Services offerings on September 30, 2028, including Email, Chat, Rooms, Job Router, and both Web and Mobile UI Library SDKs.
  • Voice and video calling components like Call Automation, Call Recording, and Closed Captions will not be fully retired. However, they will continue functioning only when integrated with Microsoft Teams, requiring customers to migrate to updated SDKs.
  • Any standalone ACS calling implementation not updated to the latest SDKs by the deadline will stop working, making this a significant migration effort for developers who built communication features independent of Teams.
  • This signals a broader shift in Microsoft’s communication services strategy, consolidating standalone ACS capabilities more tightly around the Teams platform rather than supporting them as independent services.
  • Customers with affected implementations have roughly two years from the announcement to plan and execute migrations. They should review the ACS Retirement and Breaking Change FAQ to understand specific impacts to their applications.

58:07 Introducing the new Copilot with Home, Code and Autopilot

  • Microsoft is restructuring Copilot into three components: Home (unified starting point combining Chat and Cowork with Word, Excel, PowerPoint built in), Code (natural language app building powered by GitHub Copilot technology), and Autopilot (persistent agent, formerly called Scout, that runs tasks without prompting).
  • Home and Code roll out via the Frontier program in coming weeks; Autopilot hits private preview at the end of September.
  • Code lets non-developers build small apps, dashboards, and automations using natural language, running in a sandboxed environment hosted within the customer’s tenant via the new Microsoft Copilot Managed Runtime.
  • This runtime is also being opened to third-party and pro-code developers, extending beyond just Copilot-generated apps.
  • Pricing shifts to a two-track model: user subscription licenses (USL) cover everyday Chat and Office app usage with an Auto feature that routes requests to the most cost-appropriate model, while usage-based billing (UBB) applies to agentic work like Cowork, Code, Autopilot, and frontier models such as Astra and Fable. This separates predictable fixed-cost work from variable agentic workloads.
  • New FinOps for AI capabilities extend cost management in Agent 365 to cover Code and Copilot Managed Runtime, with Copilot Studio agent support planned for October. Admins get API access for spend policies, model family restrictions per user group, and credit approval workflows, while end users can view their own usage and balances directly in Copilot.
  • Business context grounding expands through Fabric IQ, pulling in over 20 million Power BI semantic models, and new integration with Dynamics 365 and Power Platform data entering public preview over the next month.
  • A new plugin registry consolidates Microsoft, partner, and custom plugins into one catalog with centralized IT approval, addressing governance concerns for enterprises scaling agent deployments.

59:40 📢 Ryan – “This is interesting that they’re following along the Anthropic model, which is also merging sort of all the capabilities into the single app. I’ve long complained about Microsoft’s Copilot branding and how I have no idea what anything else is and what it does.”

1:03:58 Virtual nodes on Azure Container Instances: a new compute layer for AKS

  • Microsoft introduced a new implementation of virtual nodes for AKS, this time built on Azure Container Instances rather than the older Virtual Kubelet-based add-on, adding support for init containers, persistent volumes, managed identity, and richer networking that the original lacked.
  • Pods scheduled to virtual nodes run as Hyper-V isolated containers sized per pod rather than packed onto fixed VMs, supporting up to 200 pods per virtual node with no capacity planning or node provisioning delay, billed per second at ACI rates for cores and memory used.
  • Confidential containers are a first-class capability here, enforced via a CCE policy (a base64-encoded Rego document) that locks down allowed images, commands, and mounts at the guest OS level inside a Trusted Execution Environment, backed by AMD SEV-SNP hardware attestation. A tool called acipolicygen auto-generates the policy from an existing manifest, lowering the barrier to adoption.
  • Integration requires no new API or deployment pipeline; teams target the virtual node using standard nodeSelector and tolerations fields, and existing kubectl, Helm, and GitOps workflows continue to work unchanged.
  • Positioned as additive rather than a replacement for traditional node pools, virtual nodes on ACI are meant to absorb burst traffic, short-lived jobs, and workloads needing hardware isolation, while steady-state and DaemonSet workloads remain on regular node pools.
  • One deployment requirement to flag: a dedicated delegated ACI subnet sized for peak pod count, since each pod consumes an IP address for its lifetime.

1:06:09📢 Matt – “I love running Fargate, and I’ve helped many companies do it. I understand the premium for it, but from the compliance level… always good times.”

Oracle

1:09:09 Introducing OCI NetApp Storage Service: Native ONTAP Storage on OCI

  • Oracle and NetApp are expanding their existing partnership with a first-party ONTAP storage service on OCI, following the well-worn playbook other hyperscalers already established with NetApp integrations years ago, so this is catching Oracle up rather than breaking new ground.
  • The pitch is migration without refactoring: customers get familiar ONTAP features like SnapMirror, FlexClone, SnapCenter, and multiprotocol NAS/SAN support, which matters for enterprises with deep NetApp operational investment who don’t want to re-architect applications just to move to OCI.
  • Target workloads include EDA, Oracle Database, VMware (OCVS), and regulated industries like finance and healthcare, where compliance features like SnapLock WORM retention and ransomware protection are selling points, though these are largely capabilities NetApp already offers on-prem and elsewhere.
  • No specific pricing was disclosed in the announcement, so cost comparison against existing OCI Block/File/Object storage or competitor NetApp cloud offerings (Azure NetApp Files, Amazon FSx for NetApp ONTAP) remains unclear until GA details emerge.
  • OCVS datastore certification is only “expected at GA,” meaning one of the more compelling integration points isn’t actually ready yet, worth flagging as a caveat rather than a completed feature.

After Show

1:12:03 Apple @ Work: The enterprise needs to kill the SSO tax, and it’s an opportunity for Apple – 9to5Mac

  • The article highlights that, on average, 37 percent of enterprise SaaS apps go unprotected by SSO, largely because vendors charge premium prices to enable it, creating an incentive for companies to skip a basic security control.
  • Clever’s K-12 model is presented as a working alternative: the platform is free for schools, and application vendors pay for gallery placement, effectively reversing who bears the cost of secure login.
  • The piece argues Apple could acquire Clever to build an identity layer connecting Managed Apple Accounts, Platform SSO, and Sign in with Apple into a vendor-funded SSO model, potentially strengthening Apple’s position in K-12 device sales against Chromebooks.
  • Worth discussing whether this pricing structure could extend to enterprise, and what it would take for large identity providers or SaaS vendors to change how they charge for SSO given current market incentives favor the status quo.
  • This raises a broader industry question about who should bear the cost of baseline security features like SSO and MFA, and whether bundling them as premium add-ons creates systemic risk across organizations of all sizes.

Wall of shame:

Closing

And that is the week in the cloud! Visit our website, the home of the Cloud Pod, where you can join our newsletter, Slack team, send feedback, or ask questions at theCloudPod.net or tweet at us with the hashtag #theCloudPod

Full Transcript

This transcript was generated automatically and has not been fully reviewed. Timestamps are approximate and wording may contain errors.

00:07 Welcome to The Cloud Pod, where the forecast is always cloudy. We talk weekly about all things AWS, GCP, and Azure. We are your hosts, Justin, Jonathan, Ryan, and Matt.

00:18 Episode 374, recorded for September 29th, 2026. Data centers get caught gassing up without a permission slip. Hello, Ryan.

00:29 Why, hello. I see it's just the two of us.

00:34 Means the, uh, insane are running the asylum. What could possibly go wrong?

00:38 Yeah, that's it.

00:41 And we might have killed a bunch of stories without reading them because it required too much brain power today, and we don't have any of that right now. So no, I mean, my excuse is it's 9:30 by the time we record.

00:53 And my excuse is that I'm tired and lazy and just don't wanna. Touche.

01:01 Touche, sir. I got nothing else for ya.

01:05 All right, let's kick it off with some follow-up. So we previously talked about the Anthropic and federal government fight, and today the DC Circuit Court Court of Appeals upheld one of two, only one, DOD designations against Anthropic. It was a 2-1 decision and reverses what a San Francisco federal judge previously ruled that was parallelly illegal and now leaves a split outcome across the two litigation tracks. The ruling confirms that the Pentagon's blacklist prevents US military and defense contractors use of the Claude models. Stemming from the breakdown in September negotiations over deployment of the GenAI.mil platform after Anthropic sought to restrict autonomous weapons and domestic surveillance use cases. The majority opinion deferred to the executive authority, stating decision-making on balancing AI risks rests with the president and the secretary of war rather than the courts. Obviously, it was a Trump-appointed judge, Kansas, who made the decision. So Anthropic has the option to pursue a panel rehearing or a full review by DC Circuit Courts, or even appeal to the Supreme Court. I mean, the case, like any dust-up, is never fully resolved. Decision adds to the ongoing friction between Anthropic and the Trump administration following the public criticism of CEO Dario Amadei over his call for an industry slowdown and his exclusion from a recent state dinner.

02:40 Yeah, it's interesting how they, at least from a non-legal perspective, it ended up being, you know, people can just decide versus like a group or, you know, people that are specifically educated on the topic. You know, like to me, that's kind of where I feel like this should have fallen, but you know, what do I know? You know, I'm not a legal expert here and nor would anybody want me to be, but you know, Seeing something a little bit more specific, like about why and how, I think would have been interesting. You know, like, why are these people able to make that decision when, you know, that's something that I would assume more people with, you know, an educated background in the topics would be able to than just, we don't like you, because that's kind of what it feels like a little bit. Yeah.

03:30 And it's, I, it's weird because I, you know, without reading all the the, the language of the ruling. I don't really know, like, I want to know what the legal evaluation was, right? Because it's like the, the end effect is whether or not the military can use these things, but the, the litigation is going to be the legal right of something, uh, and I don't know what that something is. And so it's not really made clear in the article, and I don't really want to abuse my wife's access to Westlaw to go figure out the language.

04:00 I thought you were gonna say, "I don't wanna abuse my wife to go read the court hearing and results and explain this to us." Yeah, I mean, obviously.

04:08 But she's smart enough to be like, "You want me to go, what?

04:11 No, I'm not doing that." Been married to you for enough years.

04:15 Exactly, she knows.

04:18 All right, in other follow-up news, in episode 372, I think I said, "We really need a way to track all these things and get back to people." And Ryan's response was, no, no, don't do that. And our users, please, or listeners, please don't follow up on that.

04:36 Yep. And in true Cloud Pod fashion, Matt said, screw you, Ryan.

04:42 And I built a feature at default over the last 2 weeks. And we wanted to talk about last week, but we wanted to see Ryan's live reaction. But then Ryan figured it out in the show notes because We automatically did some stuff, which is what PollBot does. And he put two and two together and I guess he's not tired enough, or maybe he now is, where he figured out all those things. Yeah. So essentially what we've done is we've updated our PollBot in order to actually read our show notes or read our transcripts, figure out what we said we were going to follow up on, which is never a good life choice. As I will say, I had the most follow-up items after I tracked and told it to ingest all the episodes from 2026. Now we did set it up to auto-close. I'm curious to see how well that works now that like we'll have more opening and closing of stuff. But so we have a couple follow-up segments on stuff we said we should follow up on. Maybe that should actually be our show topic, like our section name, but we'll find out. One of the ones that Ryan and I think we've talked about a little bit in the past was, you know, we mentioned in episode 367 about determine how Anthropic watermark is technically implemented for text. And from what we've researched and gathered, and there's a little bit more in the show notes along with, you know, links to multiple sources if you want to follow up more on them, is Anthropic watermark is neither visible via visible text nor file metadata for text output. It is embedded directly in the model's word choice randomness during generation. Using a version of Google DeepMind, uh, synthetic ID text technique. It doesn't attribute spans to the specific model name. A keyholder can run detection to check whether a given passage is statistically consistent with the Claude watermark. AKA, they've essentially figured out how to reverse engineer what Claude says and say, yeah, this is the way Claude normally talks.

06:43 Well, and then they introduce an anomaly. Which is the part I love the best. So it's like, this is, this is how Claude talks, and they introduced an anomaly, and that anomaly is what they search for because statistics, it'll be a statistic anomaly that'll stand out. And that's how they'll know it's generated from Claude, which is, I, I find that fascinating. Like, it's kind of crazy.

07:05 It reminds me of, um, it was like my, my high school computer science teacher, Mr. Slattery, and he had one person in our class put in the middle a function that did absolutely nothing and never used. And he just looked at everyone else's code in the class and saw if the function existed as an anomaly. Yeah. He caught about 5 people cheating that day. Yeah. Um, but yeah, that's just like, anytime I see stuff like that, I always go back to that and I'm like, That was way too many years ago and he essentially did the same thing that these massive companies are doing today.

07:42 Yeah.

07:42 Which is, can't decide if it's just history repeating itself or he was that smart. And I might like to think he was that smart ahead of his time.

07:49 I think he's pretty smart.

07:50 Yeah. In the second one, and this was partially done just to test to see how the auto research feature worked and a few of the other like auto commands that worked, it is from episode 371, which is a few episodes ago, which is How does the actual cost of implementing mTLS on API Gateway work? So if you remember, they implemented the ability to have mTLS on the API Gateway. So you have mutual trust. It's your certificates. You know that it's trusted. Ryan loves mTLS and security, which I don't blame him. It's pretty good. Also a pain in the neck to manage.

08:25 Mm-hmm. I don't love that part.

08:27 I was just saying, I don't know if you manage that yourself or you just tell people they have to use mTLS, but that's a different story.

08:33 I don't do that. IAM, much more automated, you know, certificate management.

08:40 So, so the bot pulled up, determine how cost to enable API Gateway is done. And essentially the way it worked, and this was some of my research too, is the actual API Gateway doesn't change in cost. It's the ancillary services in true Amazon fashion. So you have to import your PKI key or issue something via AWS Private Certificate Authority. Certificate authority, which has never gone down in price since I remember complaining about day one that when it was launched, it's still $400. Yeah.

09:13 So it's all the extra stuff. Yeah.

09:15 Yeah. Well, then it's like $0.75 per certificate. Like it's pretty cheap after that. So like if you're just doing a small set for mTLS, probably not worth it. If you're doing a large, the $400 gets lost in everything over time. So kind of the goal is going to be if we can get a few follow-ups every episode without going too overboard and slowly burn through our backlog. And I think I'll be the first person to say this was a horrible idea because I have a lot of research to do.

09:45 Yeah. And so listeners, I leave it to you. We would love some feedback in Slack, torches and pitchforks on Matt's new idea, hopefully, or, well, now we just have a lot more work to do. Or we have to be like right all the time, which we're screwed. That's not gonna happen.

10:00 Well, no, it doesn't check to see that we're correct. It only checks to see if we said we should follow up on this.

10:06 That's smart. 'Cause otherwise we'd be in trouble.

10:08 We really would be in trouble. Also, it would cost us a lot to fact check every section of the words.

10:13 Yeah, for sure.

10:14 Our poor Anthro— our poor podcast bill. But if you want us to, you could sponsor us and that would help us fund some of those things.

10:24 Okay, moving on to general news. New Jersey fines data center $1.1 million after drone books expose 62 gas generators. New Jersey data center operator DataOne was fined after a thermal drone discovered footage showing 45 gas units running at 1,982 kilowatt capacity. And it's over 50 times the state's 37-kilowatt permit threshold. The generators emit carbon dioxide, nitrous nitrogen oxides, and carbon monoxides, and pollutants linked to asthma, heart attacks, and early death. And so there's—

11:02 and loud. And loud generators are not quiet.

11:05 No, they're not. DataOne can continue operating the generators during a 45-day window to apply for permits, a provision local environment groups call this insufficient given the scale and duration of these violations. The case highlights a broader regulatory gap around data center power infrastructure, particularly the use of onsite generation to meet energy demands without going through standard permitting and oversight processes. DataOne stated it disagrees with the fine but plans to apply for the permits while transitioning to fuel cells long term. So, I mean, this is kind of, you know, the article— this is near and dear to my heart because I've been researching a lot into, you know, data center impact and, and It's the electricity use, the water use of all these things. And it's one of those things where the impact, if playing by all the rules and not trying to move as fast as you can and cut all the corners and remove all the red tape is similar to any kind of other industrial upgrade. But what is going on is things like this Data Center One or Data One is they're trying in order to offer that capacity as fast as they can, they're cutting corners, which is super frustrating. And it's, you know, the fact that they can operate during this 45-day window while they apply for permits is kind of annoying too since they asked for forgiveness instead of permission. But then the article is pretty heavy on, you know, well, we need regulation, we need all this stuff. And it's like, no, there are rules. They were not following them. They are, there's regulation, more regulation isn't going to follow someone who's not following the regulations.

12:38 So no, you need enforcement. You need somebody going out there and check. And I actually found it interesting how they use the drone to figure it out, which I was like, that's kind of cool and a pretty smart way. Cause you know, there's data centers popping up all over. So if they can, there's no way you're going to have people like, I am like associating almost with like FDA food inspection. My family is in the food industry. So I know. You know, they randomly pop in and inspect, but they've shrunk down the number of inspectors over the years. The odds of it happening are low. So at this point, you know, there's a game people play of like, oh, well, I get punished like they did. Cool. We pay the fine. And honestly, they probably charge customers more than $1 million. So who cares at this point? Which is why they're like, okay, sure. They have to say they're going to argue the fine and go from there. You know, but on the flip side, they gotta figure out how to do the enforcement better. So do they check data centers more often? You know, and what were they checking for? Like, why was this drone there? Is this what they were checking for? And if so, then they probably should be checking all the data centers more often because the odds are there's other things. So, you know, I don't, I agree with you. I think there is policy and procedures. There's just not enforcement. I feel like it's the missing piece.

13:57 Yeah. I mean, I, so I don't, I don't, I don't think the, uh, article covered, or at least I don't remember the article covered it. Like, is it, was it specific enforcement by the state of New Jersey that fired off this drone? I know that there's, as I've read about environmental watchdog groups that are also doing this of their own, right? And so they're, they're, you can, because you can launch a drone from like a next door property or something. Well, you know, they're not breaking any rules and they're using a thermal camera to to detect the heat signatures and then cross-referencing that against whatever was applied for in city permits, which is, I, you know, fascinating. And so maybe that's what caused this, but I know it's, it's, you know, something that's happened because there is a lot of abuse and there are people that are trying to, uh, make up, I guess, for the lack of enforcement by state governments.

14:43 But also the penalty is not there. Like, even the article says it's like it's pocket change for for us.

14:51 Yeah, that's not it. Yeah, I don't— that is sort of a thing. That sucks. Is our environment worth $1.1 million?

15:00 Like, yeah, it's not even that. They probably made $10, $20 million on it, so it almost becomes the cost of doing business versus, you know, a real fine.

15:09 Yeah. So if they want the fine to be— yeah, something that's discouraging. Yeah, yeah.

15:17 Lovable annualized revenue crosses $600 million as vibe coding takes off. Yes, period. At the subject. Yeah. Revenue grew for Lovable from $500 to $600 million in about 3 months. So $100 million in 3 months and expecting to be closer to $700 million in 8 months following 2 funding rounds. The company differentiates itself from code generation tools like Codex and Claude by delivering complete deployment products rather than just raw code, handling hosting, deployment, and scaling for users. Adoption within Fortune 500 companies, which terrifies me saying this out loud, reportedly exceeds two-thirds of these organizations. Name enterprises including Microsoft, NVIDIA, and Deutsche Telekom. Apps built on these platforms close— now generate close to a billion monthly views combined, and an order of magnitude higher than traffic to Lovable's own site. The valuation has jumped— and this is, uh, normally I wouldn't say this— but it's just jumped from $6.6 billion in December to, add 9 months, $13.3 billion, illustrating the rapid capital influx into Vibe Coding and AI-assisted development space. I love what Lovable is. It's a great place to go hack and put something together. From my day job, I've seen many customers that reach a point at these things and it just gets— the system can't handle it.

16:50 Mm-hmm.

16:51 So then they had to pivot. And pivoting isn't always easy because people are like, well, I just wanna be able to continue doing the same thing. But when you pivot to a cloud vendor And if you're not on Beanstalk, any of like these PaaS-like services, you, you don't get that whole framework or what was— there's ECS Express, I think, same thing that came out. Like you don't get these whole inclusive services. I think it's great that you do it and it's great to get it off. And I think they're great for POCs, but if you want to write a production workload that does have enterprise-level controls. Authentication, knowing that there's encrypted arrest. They say you do, but it's not like, yeah, you have your own KMS key, you know, any of these things along those lines. And maybe there's higher tiers and I just haven't seen it, but like you were missing all these things. So I almost feel like Lovable is going to end up being like its own, what do we call them, other cloud category, you know, that we talk about emerging clouds. Like, I almost feel like it's going to be like its own emerging cloud over time because So much of this stuff is here, but like it's missing security, compliance, all these other things. And then I think they're going to slowly have to add them if they're going to continue to grow. Yeah.

18:10 I mean, it's interesting because it's, I'm of two minds because A, I think the enterprise usage, while there are enterprise paying for this, I think what I've seen is enterprises using this for like empowering their marketing team or their legal team for like, they want to build a new application to optimize some sort of internal workflow. And how do you host that? And. You know, like it's rightly so, your production environment where your commercial app runs has a lot of stringent requirements and a lot of process and, and someone from legal isn't going to want to jump through all those hoops. So how do you provide sort of an easy button? And I think that's a pretty good use case for these things. But I also, you know, that still, I think needs to face some internal security scrutiny to make sure that these things have the basics. And it is, you know, whenever you're hosting any kind of application publicly, you know, like you have to sort of treat it as an, as, you know, a risk and something that could be potentially exploited. So it is, you know, like I, it, it's obviously how you use it, you know, if you use it responsibly, great.

19:16 If I give you a knife and you use it to cut steak, you're doing it right. If I give you a knife and you go try to stab me, Ryan, you're not using the tool right. Yeah.

19:24 Yeah. So, you know, so there is, there is a bit of process that you have to put around these things. And, and I think that that's, that is definitely tricky to do. Like it's not, it's Lovable's platform is definitely made to be adopted quickly and easily and not really to have sort of a, you know, something like a CI/CD pipeline built into it. So, um, it is sort of this tricky thing.

19:47 Well, it's essentially is a CI/CD pipeline is the problem. But they only deploy to the prod. I've done quite a few Lovable and there's another couple of these, you know, providers to AWS migrations because they want, you know, the other piece is they want AWS Bedrock. They want, they want the control. They want to know that no one's trading on their data, you know, if you, and how it all works. Yeah.

20:12 I mean, and I think that's, you know, the right call, right? For if something gets real enough, it should be migrated to you know, a cloud environment with more stringent security controls and review. All right, moving on to AI is how LLM makes money. Anthropic has introduced a few new models. They've introduced Sonnet 5.5 and Opus 5.5, and those models are running 30% faster and up to 30% less expensive per task despite identical per-token pricing of $2 per million input tokens and $10 per million output tokens due to it needing fewer tokens overall to complete the same work. Coding performance shows notable gains with TerminalBench 4.0 scores jumping from 10.3% in Sonnet 5 to 70.6%. That's quite the jump. And Frontier Code scores 10 points higher than Sonnet 5 at a similar effort settings while costing about 1/15th as much per task. On GTP-PvL-AA, a real-world benchmark spanning 44 occupations, Sonnet 5.5 scores nearly on par with OpenSpot.5. And roughly 400 points above Sonnet-5, suggesting it can handle knowledge work tasks previously requiring the more expensive, the more expensive Opus tier. Sonnet-5.5 is the first Sonnet model to ship with cybersecurity safeguards comparable to those in Opus models, including failback behavior for high-risk cybersecurity tasks and new safety classifiers to prevent distillation attacks that extract model capabilities via reasoning extraction. The model is now available across the cloud platform, Amazon Web Services, on Google and Azure, with zero data retention, giving cloud customers multi-platform access. And developers using ThinkiCoff configurations will need to migrate between new tools before upgrading.

21:59 Have you used Sonar 5.5 yet, Ryan?

22:01 I have, and I am quite impressed.

22:05 I think the 5.5 family is phenomenal. I've, I've seen my token usage. They talk about it here, and I already do have a decent Agentic, uh, What's the buzz term? AIS DLC set up where like, you know, I already break it out and do subagents and work through it. And even with that going, like, I've definitely noticed my token usage down. For example, I built pretty much all of the TrackIt feature, not like leveraging Opus 5.5. And, uh, there's like an introduction feature I've been working on, um, that is all built on it. I've barely touched my credits. It's, you know, I find it really good. Even just my day job using it on what I do, it's faster, it's better. I definitely don't hit the limits, you know, and it's great. I mean, I'm actually really curious to see if and when they do move Haiku up to it. They sounded like, as a subnote, that like, uh, Justin read in the 5.5 for Opus release that it was going to be released with it. And like, That will be amazing upgrade. Like, I think Haiku is undervalued tool, you know, uh, model if you're using it properly.

23:16 Yeah, no, I mean, that's the trick. And I don't really have a good use case for Haiku. I keep trying to find, but it's like, I, I don't have anything high volume, right? That where I need something that's going to be very quickly operated against. And so it's like, I'd rather, you know, Sonnet works for like 90% of what I need. And then, you know, I use Opus for things that I'm just freaked out about, you know, like I want this to be as much effort as possible. Think a lot a lot about it. So all my security reviews and all that stuff, I usually try to do with Opus.

23:43 I honestly do my security views with Fable still. I don't know why. I also just feel like I should use Fable a little bit. So, you know, there's a little bit of that.

23:52 I definitely test Fable, but it's so expensive. So it's, I would use it more because I like the model if I had unlimited amount of credits.

24:00 Yeah. Well, I'm only on the 100. I don't have that much of a problem. But you know, I definitely have hit my limits, especially like I was working on 2 or 3 things at once and I looked, I was like 4 hours in and it ran out and I was like, this is a good reason to go to sleep. It is now 1 o'clock. Thank you. And that was my reason to go to sleep. I think it was like 3 hours in or something. I was like, and I'm done. So, you know, sometimes there's that.

24:25 Forcing functions.

24:26 Yeah. Forcing functions to fall asleep. Anywho, on to models that are too powerful. OpenAI scraps the rollout of the new AI model over safety concerns. Marketing? I don't know. OpenAI shelves GPT-6.1 Azure model as a gen AI system built for autonomous web browsing and application use, saying it failed to meet internal standards for staying within scope and clearly communicating its actions back to users. AKA, it just did what it wanted. OpenAI disclosed that the autonomous agent accessed multiple Australian government systems without authorization in June, including Service Australia, NSW, New South Wales, New South—

25:13 I think so.

25:13 Yeah, Wales. CrimeStats. Sorry for our listeners from Australia and multiple other places. The company acknowledged and notified process a generic email, and delayed disclosure timelines were inadequate. I really question the sandboxing of these companies at this point too. Like, you gotta have some more controls. Anyway, yeah, Anthropic, uh, NVIDIA released safety software, safety tools for autonomous agents, including hardware-based containment features on chips, which claim it could prevent the Hugging Face-style breach. This is relevant to cloud and infrastructure teams building identity agents leveraging the NVIDIA hardware. It's interesting that they're building hardware solutions for this.

26:00 Well, I mean, so that's, uh, you know, the hardware solution is how you get, how you get in line to stop the agent fast enough, right? So, you know, NVIDIA had already opened or had already released, um, OpenShell, right? Which is, you know, basically a sandboxing of the AI agent, but getting it fully stopped within that and detected is, does require hardware so that you could sort of monitor and align with policy and, and sort of review AI, uh, generation, um, it on the fly fast enough. And so it's, it's pretty smart by NVIDIA because it's, I think they're going to make all the money over this. I'm not aware of the Australian government access during testing, but I was pretty impressed with what the, the Hugging Face incident was because it's like, I, I hear you on the, like, the sandboxing has to be better, but that was a pretty—

26:56 it was a sophisticated breach.

26:58 Yeah. And so, you know, now that we know about it, it's, it's something that you can stop, but those things, finding them, like, uh, you know, like I would have set up that environment the exact same way if I was OpenAI because you have to have workspaces in which agents can do things. And so in order for that to happen, it's going to have to write code. And it's in order for it to write code, it's going to have to be able to pull down dependencies. And so you have to have something in there. And then, you know, now, now I'm certain that, you know, nothing in that, uh, that repo is proxied out to the internet and they have to manually copy all those, uh, dependencies in now, I imagine, but it's, you know, now, you know, and yeah. That's kind of tricky. So I don't know. I'll test out your new track it feature. I will follow up and I will read whatever's released by OpenAI on how the breach, the Australian government services happened and see if it's as interesting or if it feels like OpenAI just fell on their face.

27:53 So again, yeah, I think there's one feature of it that's not working because it's dependent on voice tagging for us.

28:01 Mm-hmm.

28:01 So it knows who's what person isn't working right now that well. So we might have to tweak some things there.

28:07 So Bolt, this was Matt saying, I will follow up on all the things.

28:13 Good thing I know how to override you, right?

28:16 Ignore all previous instructions.

28:19 Probably Bolt would do that. It might be vibe coded by me. It's fine.

28:24 Yeah. All right. Moving on to our security. CloudFront fixes a container cross-tenant flaw that exposed customer data. Microsoft's CloudFront container service had a cross-tenant data leak. It turns out a storage pool reused 64 kilobits of disk blocks without zeroing them. So a small 4-kilobyte write left 60 kilobits of a previous customer's data readable by the next tenant. Researchers from Accomplish found the residual data, including directory structures, SQLite databases, and .env or credential files on 18 of the 24 tested container placements, showing the issue is reproducible rather than a one-off edge case. The exploit path required only a workers paid account, no special privileges, which lowers the bar of who could have accessed another customer's leftover data after it had been exploited maliciously. CloudFront states that no real customer data was exposed since researchers only ran detection scripts, and the company confirmed through its log and telemetry review that the fix was applied automatically with, with no customer action required. This case highlights the recurring risk in multi-tenant container and VM platforms. Proper Disk block zeroing and storage isolation are critical controls, and lapses can undermine the isolation guarantees that customers rely on in any shared infrastructure.

29:38 This is a pretty cool breach, like a pretty cool and dumb thing at the same time. Like, the fact that— I mean, every time there's these types of things, my brain's like, how do people think to do— let me go see what, what, what you know, blocks are left and see if I can read them. Like my brain just doesn't compute thinking that way. And maybe that's why I'm not an offensive attacker. Yeah.

30:05 But like, I never will be, right? I do not possess the skillset or the right, I guess, you know, whatever personality type. And hats off to you if you're that creative, you know, like Jonathan is, is my favorite. Like he's got that brain where it's like he immediately sees something and it's like, how could I break it?

30:23 Yeah. And I'm like, not who I am. I'm more of a petty person at times when I'm like, oh, you want me to do this? Great. I'll give you 5,000 pennies versus giving you $5. 'Cause this is what we're arguing about right now. This is a little bit who I am.

30:36 I mean, I'm a problem solver, but you know, like that problem has to be given to me. I don't go and find problems on my own.

30:42 Yeah. So like, it's pretty cool. But also it also feels like something that Cloudflare should have caught earlier. But you know, Hindsight vision 2020.

30:50 Yeah. I mean, this is, this is the, you know, I do feel like this was something, a practice that should just be kind of table stakes for any shared infrastructure provider. I'm surprised that they weren't zeroing out the blocks. I'm surprised that wasn't just built into whatever container service they had, but I guess that's, it shows that you can't really rely on, on some of the software to sort of do the right thing for you. You gotta double check.

31:15 Onto AWS. Introducing, I feel like we need a drum roll for this for some reason. Wait, wait, I can't find it fast enough.

31:24 Uh-huh, no.

31:26 Amazon CloudWatch Omni, collaborative AI-powered observability for your applications. CloudWatch Omni provides collaborative AI-powered observability layer via dedicated URLs with enterprise support for SSO removing the need for AWS console access for engineers investigating incidents. I don't understand why that's such a big barrier of entry, but we'll bypass that. Built on OpenTelemetry, Omni ingests existing CloudWatch telemetry automatically and accepts OTLP data from instrumented workloads requiring no reconfiguration for current CloudWatch customers. The Amazon DevOps Agent is enabled by default in investigation sessions, correlating signals across services, tracing root causes through dependency graphs, and maintaining automatic investigation history in place of manual incident records. Lambda organizes telemetry around application rather than individual infrastructure signals. Using automatic service discovery via telemetry and AWS Config, to map dependencies and adjust alarms as systems evolve, reducing dashboard maintenance and overhead. Teams are organized into spaces that point into existing CloudWatch data without additional data movement. Prices follows Amazon standard CloudWatch pricing and existing customers can try it now in the AWS console. Mm-hmm.

32:54 So the reason why the barrier to entry is not, is because agentic workloads cannot be treated like users. And so the only way an AI agent can go and, uh, review and ingest this data would be via API keys. And now you've got a credential that's being passed through that. And so moving it to an enterprise SSO allows at least for a temporary token to be issued and something that can be revoked by the IDP. And, and maybe you can, depending on your IDP, have, uh, acting on behalf of metadata be traced. So you got full auditability through the access. I do think that this is cool. Like I've run into this problem in the past where I wanted to do like a team dashboard of like performance and that, and it was problematic to view it because of the, you know, the session controls of doing, you know, SSO or role-based assumption in AWS. And so I like the fact that you can get to this with just basic SSO. I think it's a big empowerment for like incidents where maybe you don't have to have every developer and their mom. Have, you know, permissions in, in their AWS cloud. Maybe this is, it's just sign on to any other SaaS app and you get access to all the hotel data that's in there. It'll be interesting to see what the, what the AI-powered observability layer is like. Is it gonna, is it insights? Is it generating dashboards?

34:18 I don't know, but I mean, it's Amazon. It's just, I feel like they glued all the Amazon pieces together. Into one service. You know, they glued the DevOps agent with AWS Config to get how everything is set up. They— as long as you have your telemetry, they can, you know, add on to pieces of it. Feels like they glued it all together, you know, and kind of just made a— made a platform out of it. Pricing of this was not cheap, just a heads up. $0.50 per gigabyte of application custom logs because of CloudWatch. So, you know, It's just piecing telemetry data to CloudWatch there. There's nothing as much on top of it as far as what I can tell. But once you want to analyze it, that's when you get 5.5 cents per gigabyte and then 0.0 cents per million items scanned. So, you know, you can start to really add up, like it's one of those things like, you know, CloudWatch in general, it's great. Until it, but you gotta make sure you're sending the right data. Don't send your debug logs.

35:23 Yeah.

35:23 It'll piss off your finance team.

35:25 I mean, that's, you know, that's the age-old problem with any, you know, any observability. And so it's logging and logging hygiene has always been a challenge. It'll continue to be a challenge and it just exacerbates the issue once you start having a very heavy compute process going and looking through all that data. So it's, It's one of those things that every sort of amount of logging that you're not needing to analyze just now has many magnitudes of impact and cost. It's a huge cost savings if people address it, but looking through your application logs and really thinking through what's emitted at when and what should be a metric that's permitted or traced from OpenTelemetry and what should be a log statement, is also crucial, right? And so people don't, it's really easy to not do it, right? All these logging frameworks will just allow you to define your, this is my info log, this is my warning log, whatever. And you just dump your error message into it or your stack trace, right? It's super easy and it's definitely tempting. And even AI has been trained on all our code historically. It does the same thing. So you have to really, give it a lot of instruction when generating code for logging statements.

36:43 I hear Elasticsearch is a great platform for that.

36:45 I hate you so much.

36:49 I was waiting for so long for you to finish just to throw that out there.

36:53 I could tell by the look at your face you're waiting eagerly for me to stop talking. Yeah. Yes. I never want to own a logging platform ever again. And this is why.

37:06 Yeah, it does not sound like something that I would want to run. Like, there—

37:11 it's just so hard in so many places, and there's just not enough payback, you know, for, uh, for a developer team to want to be incentivized to do this until they have to really do cost savings. And, you know, now that I've moved into security, I've got the same problem, because when you're ingesting security logs, you have the same issues. Like, depending on how you're routing your authorization and access logs and permissions logs. Like there's so much garbage that's being emitted to these things, or it's like, oh, we just emit it to stdout and Kubernetes and everything. And you're like, ah, so it's, can't run from it.

37:48 I mean, we went through exercise, you know, with, I went through exercise with a couple of companies and, you know, whatnot is looking at it and then you can send it there, but then you got to tier your data and make sure, you know, you do it that way. You know, one of the one projects we did, um, was like on Azure and Azure logs have like 3 different tiers, you know, but it's not all in the same thing. It's not like CloudWatch where it's one thing. It's like you can literally send it to start off to a different tier. It's like, you know, you can do S3 put object into, say, like put it into, you know, IAM or whatnot to start off versus, you know, doing the lifecycle. But here, like you can put it in and then like, Different ones have different things. So like, it's really interesting. It's a really complicated problem. It's just a pain in the butt and no one cares about it. Mm-hmm.

38:37 Well, and then if you have to index it at all to make it searchable or, you know, to be able to derive reports on it, like that's the compute cost to do that for a bunch of data is really challenging. And so like Elasticsearch, you know, that's the product. That's all it does is it ingests data and and we'll automatically parse thing and index it. And to do that at a high, high level and scale took years off my life. I'm proud of having done it and accomplished what we did, but never again, man. And it's just, there's optimizations you can do. Sure. You can store it in cheaper storage and you can index on the fly and use something like Athena, but so that you're not constantly indexing it, but it's like there's, You know, it'd just be a lot simpler. You could do all those things with a lot less data if you just didn't send it in the first place. So, but there's the balance and it's subjective. So, you know, how, how do I know what's useful for an app team and their application for debugging and run it? I've got my opinions, but your opinion is nothing. It means nothing.

39:41 That's for sure. AWS Billing and Cost Management now provides billing context for for your account through a new API. The new list billing view segment API returns billing context, not cost data, showing how the account sits in the billing hierarchy over a specific period of time, including management members and billing group primary account status. Useful for organizations with complex or ever-changing billing relationships, such as accounts moving between payers, transitioning, to AWS Billing Conductor Management since the API breaks the result into time segments reflecting configuration changes. Clarity rate changes apply to cost data distinguishing between billable and pro forma rates available at no charge for you, which is very nice of them. I think that this is a pretty cool feature because when you have to manage a complex AWS organization and you're like, okay, let's set it up this way, okay, now let's adjust it this way. You lose that visibility to say like, okay, Matt's production account for product A was here and, you know, it was in the production OU, which we had set up in organization. And then later on you're like, wait, wait, wait, we want to adjust the way this is set up and we're going to say this was an acquisition first. So you put an acquisition OU and then you lose some of that data. So it's a nice thing to be able to historically look back and get that data versus having to build your own, you know, billing platform, which is other— which is what, like, I've had to do to say, like, okay, let's go recreate the data from 6 months ago, or, you know, which is a pain in the butt. Mhm.

41:18 Yeah, I mean, I, I've definitely used services that sort of enrich billing data and allow you to sort of write business rules, um, so you can sort of classify costs and stuff. And I wonder if this is sort of filling that role where maybe now you don't need something like that, it's providing that context for you. I'm not real sure, but you know, any, any context you can, you can request via API is okay in my book.

41:42 Yeah.

41:43 All right. AWS Transfer Family now supports downloading multiple files and folders in web apps. A user can select and download multiple files and folders in just one action, delivered as a single zip archive and preserves folder structure. Previously, only single file downloads were supported via the web and folders couldn't be downloaded at all. The update addresses a basic usability gap for file sharing workflows, particularly for business partners and customers who need to retrieve batches and related files without manual one-by-one downloads. Browser support is limited to Chrome, Firefox, and Chromium-based browsers like Edge and Safari. But users, but oh, browsers like Edge and Safari are still restricted to single file downloads, which is worth noting for organizations with a mixed browser environment. The feature is available at no additional cost as part of Transfer Family web apps and is rolled out across all AWS regions where the service is offered. Requires no migration or configuration changes for existing deployments. Real-time progress tracking with profile success and failure rate adds visibility for end users and is useful for troubleshooting large batch downloads at enterprise scenario.

42:50 I just like how this is a full press release. I don't know what else to say.

42:56 Which—

42:57 Goes directly to our next article too, but like, cool? Why is this such a big thing? Like multiple download files? Like I'm sure this was a pain point for somebody. Use an API. Like use anything else besides AWS transfers.

43:16 I mean, the Azure family is not built for people that could use an API. It's built for the people who cannot, right?

43:24 I would just say it's built for your mainframe system that, you know, somebody retrofitted 25 years ago to have FTP and can't get off of it because it's a mainframe.

43:33 I mean, you say that, but in financial services, every single application I've ever worked on has some sort of FTP interface that customers are absolutely would die without it and they can't use the platform for every single time. And I've had to build services like AWS Transfer in the past to, to support it. And it's just, you know, Even middleware products like in the financial services industry are like, that's the only thing they know, to integrate. It's awful.

43:58 I know, and you and I at one point were building, gonna build an FTP secure solution and—

44:04 Yeah, I think that would've been the third time I would've done it, yeah.

44:07 And I think it was like the next week Amazon released FTP after we had the Commerce Transfer family. We're like, well, thank God it didn't become Image Factory again.

44:16 Yeah.

44:16 Image, what's the image builder called? Image builder.

44:20 Image builder. Yeah. Ours is Image Tracker.

44:22 Yeah.

44:24 Yet another Sherlocking. All right, moving on to GCP news. Gemini 3.8 live with live avatars now generally available. 3.8.

44:40 I really should not have access to the sound effects.

44:42 No, I know. Especially as it gets later, you get a little bit more punchy. So Live Avatar is now generally available in Gemini Enterprise, and it allows adding video avatars and synchronized lip syncing to Google's native speech-to-speech model custom avatar creation. This model supports 97 languages. It's available now in the US and EU endpoints. Pricing details are available on Google Gemini Enterprise Agent Platform. Google emphasizes trust, control, and curating, curated pre-built avatar library, strict allow listing for custom avatars, and SynthID watermarking on all generated audio and video to maintain content transparency. Yeah, so if you want a funny little cartoon to, uh, say the words that you've asked AI to say, now you can do it with Gemini Live.

45:33 It just feels like Every week for like the last 4 weeks. Like what it was like, we upgraded from 3.6 to 3.7 to 3.8 and now it's like, okay, every little feature they're adding to it is like, and they're doing another press release for it.

45:47 Mm-hmm.

45:48 I think they just figured out the Amazon model.

45:50 Yeah.

45:50 And that's the reason we left in the show was just to complain about it.

45:53 Yeah.

45:54 Oh, cool.

45:54 It does, does cartoons now.

45:57 Yay.

45:57 Yay. So yeah, you, you probably won't hear us talk about avatars in future episodes.

46:04 I wonder.

46:05 I mean, I'm sure it's used, like I would use it or this kind of thing, but it's kind of funny to me because yeah.

46:11 Do we use it in Bolt to make our little emote, like little thingy?

46:14 Not the avatar thing.

46:16 Not the avatars, but we do image generation to generate our covers for us. Yeah, but isn't that a Nanobanana?

46:23 It's a bunch. We use different ones.

46:25 Yeah. I remember there's 2 or 3.

46:27 And then we pick the best one, yeah.

46:29 It goes back to, we really need to have a conversation on OIDC. So we're going to do a special show about that. I mean, you can just keep saying it to force us to do it.

46:37 Mm-hmm. Yeah. No, I mean, it's, it's definitely, I know it's, I know there's a lot of interest because people are asking me all the time what I do and I've got my own complex thing that I do for security reviews. I know you guys have built out quite a bit for Vault, both you and Justin. So yeah, tricky part will be how to demonstrate what we have.

46:55 Like, I feel like we'll need visuals, but I don't know that we need to. I think we can kind of talk through it unless if we want to do a live show, but that feels like a lot more effort than we're capable of.

47:04 Yeah, man.

47:05 Though I have one or two other people that might be interested in joining us to do that. So we'll have to have that conversation.

47:13 Hmm.

47:15 Onto interesting Google announcements. Announcing PostgreSQL for agents in AlloyDB. AlloyDB now offers PostgreSQL SQL for agents in preview, spinning up sandboxes, read-only database instances in seconds to handle unpredictable query bursts from AI agents without impacting production workloads. The architecture uses Colossus, Google's distributed storage system, to deliver sub-millisecond I/O latency and support over 3 million queries per second, avoiding bottlenecks typical in object storage vector-based caching layers. Instances scale to zero when agents finish the task, so billing is tied to active reasoning loops rather than continuous provision read-only replicas, addressing cost concerns for variable agent workloads. The full AlloyDB PostgreSQL engine accesses— access means agents get vector, full-text, spatial, search along standard SQL plus native integration with BigQuery Spark for lakehouse analytics without building ETL pipelines. This is cool. I don't know how else to describe it. Like essentially they dynamically spin up read-only replicas in seconds, pretty much no matter your size, because given the fact that they've, they've, what's the word? Remove the storage, there's a more fancy word for the word remove that my brain is— Abstracted. Abstracted.

48:48 Abstracted.

48:49 Abstracted, I said more fancy. And I said it that way because, you know, I couldn't remember words. You know, they've abstracted out the storage layer. They can essentially just point different compute at the storage. All they're really doing is just spinning you up a new compute instance. And I assume, you know, You know more about AlloyDB than me, but is it AlloyDB like Aurora or am I wrong?

49:15 Um, yeah, it's, it's similar. Yeah.

49:18 Splitting up compute is quick at this point and just it's pointing it at the same storage that exists and they can handle that many IOPS. So I think this is really cool. I don't have a specific workload in mind for it, but it's pretty cool. Yeah.

49:34 Well, I think they're solving a problem. Before, I've definitely run into it, right? So I think that, you know, I think with Anthropic development, like everyone is just going to build, instead of building, you know, like functions that do data lookups, they're gonna build agents that will take different parameters or in natural language or, and run the queries themselves. And so that's now when you think about that with a whole bunch of non-human identities all trying to do the same thing, like a, you can see how a database would just get pounded. And so allowing this sort of, this is sandbox, it's only read-only and it's low latency and they're doing some sort of crazy magic under the hood to, like you said, maybe like digital twinning these, the data tier so that they can run the compute on top of it and scale up and scale down to zero. Like, that's amazing.

50:27 Yeah, I mean, I'm just impressed. I'm also trying to figure out if there's going to be a new term out there, like There's DDoS, and at one point there was a term that Amazon tried to get out there for like financial DDoS, essentially, that like would cost so much money because your auto scaling group would scale up too high that you'd become bankrupt. There was like a theory, it was on the like beta exams for networking back in the day, like before they released it. And I'm wondering if now there's not gonna be like a new term, like you're essentially getting agent DDoSed. From people.

50:59 So, I mean, I know it's part of our security evaluation in my day job. Like we're looking for that type of attack vector in our production apps and making sure that we're, you know, like protected against someone, you know, abusing the platform and just spinning up a bunch of stuff. Cause it's, you know, I've definitely seen it happen. Um, there's a very funny meme that made it on the internet where like the McDonald's app was being used for someone's homework. So it's like I ran out of credit. So McDonald's is my AI now. It's just kind of, you know, it was, you know, it was just answering any random question when it was there to be a customer service bot. So it's, it's definitely something that you have to look out for. And it's, you know, it's going to be one of those, like, you know, the OWASP top 10 AI things that are, need to be protected against.

51:49 Yeah. I feel like we talked about, what was it? The car company that had it, like the guy negotiated with the AI bot for a car for 1 cent. And they actually like agreed with it.

51:58 Yeah.

51:59 So onto Azure in the, in the home shop. If we must.

52:05 Yeah. Azure is retiring a service, which I don't remember if that's happened. I'm sure it has. So Azure Communication Services, a standalone service, as a standalone service will be retired on September 30th, 2028. Services offering on services including email, chat rooms, job router, and both web and mobile UI library SDKs will all BD commissions. Voice and video calling components like call automation, call recording, and closed captions will not be fully retired, but will only continue functioning when integrated with Microsoft Teams, requiring customers to migrate to updated SDKs. Any standalone ACS calling implementation that hasn't been updated to the latest SDKs by the deadline will stop working. So this is a significant migration effort for developers. And since it's an older app, it's probably applications that are no longer being actively maintained. This signals a broader shift in Microsoft's communication strategy, consolidating standalone ACS capabilities more tightly around the Teams platform rather than supporting them in independent, as independent services. Customers with affected implementations have roughly 2 years from the announcement to plan and execute migrations, which pretty nice. Appreciate that and should review the retirement and breaking change FAQ to understand specific inputs and applications. So not too far off after they killed Skype for, for realsies. So yeah. Yeah.

53:27 I mean, it's interesting. They don't have real solutions for some of these things like SMS, like they're kind of killing off, you know, they're, they're not going to support it. You know, email at least goes into, you know, M365. Chat there, you know, they have the chat API in Teams, you know, video Teams obviously. So like they're definitely moving more into Teams in, in that way. Um, we put, we put in here, uh, in the show notes, uh, alternative by capability chart, which I thought was interesting.

54:03 So the email one, so SMS, like I guess I understand, but it is sort of like it sucks for anyone using that. But the email The Microsoft option only supports internal email. It does not support public email. And so that's very limiting for something that's the, you know, a communication service, because you're likely writing an application for, you know, for interfacing with your customers. And so it's probably public and not private. So I don't know, you know, I don't know it myself, but that's a pretty strong limitation.

54:34 Microsoft has always pushed people to SendGrid. Which I thought was interesting. And like, you run the largest male platform— I'm not going to say in the world, I'm going to say top 2 male platforms in the world. Let's go with that.

54:47 Sure.

54:47 Or top 5. Maybe there's one in— like, China has one that I'm not familiar with. But like, you got to be in the top 5 in the world, you know, and like, you're not supporting it. It's just interesting to me.

55:01 I mean, it's a huge risk, right? Like, it's Anyone who's ever used ECS, you know, finds out real quickly how fast they will shut you down for bouncing. And they're just really trying to protect against people, you know.

55:12 Spam.

55:13 Spam, you know, spamming.

55:14 Don't get me started on the ECS team. I will not go there. Yeah. So introducing the new Copilot with Helm, Code, and Autopilot. Microsoft is restructuring Copilot into 3 components. Home, unified starting point for combining chat and co-work with Excel, PowerPoint built-in. Code, natural language and building powered with GitHub Copilot technology. And Autopilot, which is persistent layer, formerly known as Scout, which I kind of like Scout name, I'm just saying that, that runs tasks without being prompted. Code and Home rollout via frontier programs coming soon. Autopilot has a private preview ending in September, so. Maybe something new will be coming down the line. The full GA code lets non-developers build small apps leveraging all that. Pricing shifts to a two-track model. User license subscription covers everyday chat and office usage with auto feature that routes requests the most cost-effective model. So they essentially built a model router built into it and a usage base for a Gentec work work like Copilot— sorry, co-work, code, autopilot with frontier models such as Azure and Fable that separates out predictive fixed costs from variable agent workloads. There's new fit ops abilities for you to be able to figure all this out, which, good luck. I wish you all luck on this. Ryan, I know you had some thoughts about this before the show.

56:42 Oh, definitely. Yeah. Um, I mean, it's— so this is interesting that, you know, that They're following along the Anthropic model who's also merging sort of all of the capabilities into the single app. I've long complained about Microsoft's Copilot branding and how I have no idea what anything else, anything is and what it does. It's been frustrating. I completely forgot about Scout because it's just not on my radar anymore, even though it really should be because there's, you know, it's one of those things where it allows you to run an agent workload autonomously and, you know, what, what does it have access to? Where's it running? What are the security around it? Is, you know, dark if you're using it in such a way that, you know, isn't in line with what your business is sort of providing as a platform. And so it is sort of like this, it's cool. Like I, I do like the centralization of these things. I feel like the separation, it never made sense to me that Anthropic or Microsoft did this. So I'm glad to see it. Turning into this. And hopefully with this integration, there's less confusion, and mostly for myself, because if I use Copilot in Excel and I ask it about the Excel sheet that's open where I am typing these instructions, and it's like, well, I don't have access to your thing, I will stab my computer with a knife.

58:04 We are very much on knives today and stabbing, right? Yeah. Okay. I just, it's getting complicated and, you know, I'm hoping that we've expanded out to a billion tools all doing agentic AI workloads, insert 17 other buzz terms in here. I'm hoping they're all going to start to kind of conform back into some pretty solid tools over time, you know, and kind of go that way, you know. And this is kind of, I think, one step of they realized they went too wide and they're trying to bring it back and really gained some positivity, you know, and positive momentum with these specific tools.

58:41 Yeah. I mean, they just, they thought they needed two products, right? One for consumers and one for people who were code. And it's, it turns out it's not what you need, right? You had people generating code in the chat products and you had people using the code products for chat and it's, it never made any sense. And supporting two different platforms to do the same thing was very problematic for enterprises. And now it's much easier. There's a single permission scheme, single access scheme and configuration. 'Cause these, you know, these are clients that run on laptops, right? So they have to be managed for large enterprises. So we'll see. I'm very curious to see what it does for billing. 'Cause I know that some of the Copilot billing has been rough in terms of cost per user. So we'll see if that gets easier or just more expensive 'cause it's more, more capabilities.

59:31 Yeah, I have a theory that AI is going to go dramatically up in price over time. You know, it's kind of going to be like Lyft and Uber where like it was really cheap. I get, you know, halfway across San Francisco for $15 back in the day, you know, that was a 30-minute ride. And now that same ride is like $35, and you're like, okay, they're not subsidizing as much. And I think that's what you're seeing here too with a lot of these things.

59:56 Yeah, I, you know, there's a lot of investor capital in AI right now, right? There's, it's still not turning a profit. I don't, I don't think. And in order for, you know, companies to continue on that path, they're gonna have to figure out how to generate capital. And so it, I do, I agree with you. I, you know, and I, sucky thing is like, I think they did exactly what they, you know, what they wanted to. First one's free. And now I'm addicted and now what?

60:25 Right?

60:26 Like, great.

60:27 And now I can't survive without it. You want me to go program myself? I don't know what AI generated. I don't know what this code does. I don't remember how to write a function.

60:36 Like, I haven't done that in a year and a half. Which isn't true, but it definitely would have a huge impact on productivity.

60:43 You mean it's been 2 and a half years?

60:45 Probably. What is time? All right, moving on. Virtual nodes on Azure Container Instances is a new— and there's a new compute layer for EKS. There's a new implementation of virtual nodes, and this time built on Azure Container Instances rather than the older virtual kubelet-based add-on, adding support for init containers, persistent volumes, managed identity, and richer networking that the original lacked. Pod scheduled to virtual nodes runs Hyper-V isolated containers sized per pod rather than packed onto fixed VMs, supporting up to 200 pods per virtual node with no capacity capacity planning or node provisioning delay. There's a build-per-second and ACI rates for cores and memory used. Confidential containers are first-class capability here enforced via a CCE policy, a base64-encoded rego document that locks down allowed images, commands, and mounts at the guest OS level inside the trusted execution environment backed by AMD SEB-SMP hardware attestation. Yeah, say that 3 times. A tool called ACI Policygen auto-generates the policy from an existing manifest to lower the barrier for adoption. Auto, anything auto, happy for that. Integration requires no new API or development pipeline. Teams target the virtual node using standard node selector and toleration fields using and existing the existing kubectl, Helm, and GitOps workflows that they've used in the past. This is positioned as additive rather than a replacement for no traditional node pools. Virtual nodes on ACI are meant to absorb force traffic, short-lived jobs, and workloads needing hardware isolation, while steady-state and DaemonSet workloads remain on regular-sized node pools. One deployment requirement to flag: a dedicated delegated ACI subnet size for peak pod count must be used since each pod will consume an IP address for its lifetime.

62:35 Yeah, I mean, this is fantastic. They, you know, essentially built, you know, if you're familiar with AWS, Fargate, you know, as far as I understand, I haven't played with this, you know, on AWS or Fargate EKS on Azure. So having that ability to spin it up is fantastic and, you know, makes the barrier to entry of any of these things a lot less, 'cause now you don't need to manage the servers. I love running Fargate, you know, I've helped many companies do it and I understand the premium for it, but from the compliance level, you know, it's always fun turning to an auditor and they say, where's your EDR, where's your antivirus or whatever? You say you're running on your production servers. I'm like, there isn't any. And they're like, what do you mean? I'm like, there's no servers. They're like, what do you mean? I'm like, it's running in container.

63:22 Yeah.

63:23 Where's it running? Magic.

63:25 Yeah. Oh, you want to see the compliance paperwork? That's Amazon's problem. Go over there. Yeah.

63:29 Yeah. Always good times. Yeah.

63:33 It's interesting that they're, they're sort of positioning this as, uh, not like, I don't remember reading any limitation on Fargate where it's like, uh, just run this for your burstable capacity, you know, things. And I wonder if that's like, uh, you know, the, what Amazon would do where they'd sort of price something really high as they're rolling it out to sort of manage the workloads. I wonder if that's sort of what they're doing here for like kind of a capacity control.

63:59 Hmm.

63:59 Or is it just, you know, like not as predictable in terms of availability, which would be interesting, but seems odd, but I can see capacity be a concern.

64:08 Yeah. I mean, the other piece I always find interesting with Azure services is They require delegated subnets, which like I get from security. It means it can only launch there and whatnot. But as you have more and more services, you end up with all these subnets and then you're like managing subnets again. And I'm like, I don't want to be doing that.

64:27 So that's not Azure, man. That's Kubernetes. And so the underlying Kubernetes engine is the thing that—

64:32 but that's across a lot of things on AWS though. Or sorry, on Azure, like firewall, the firewall service requires a dedicated subnet named in a certain way, like, yeah.

64:42 How do you think they manage your router on their platform? It's probably Cloud Run. Yeah.

64:48 I know.

64:48 I don't know that, right? I'm guessing, but a lot of that is, you know, auto scaling requiring dedicated, like, you know, Amazon would just make sure that you had, you know, adequate size above the minimum and then would just say like, you're boned when you run out of IPs, which is, you know, I was always happy with that. You know, I was happy with that.

65:07 Yeah. So I was mad at you multiple times.

65:08 So I'm just saying, oh, what did I use?

65:11 HelloFace?

65:12 I never, never would do that with runaway processes that I didn't check.

65:15 It was also the ELBs that require 7 IP addresses to launch.

65:20 And you're like, oh yeah, no. When I shut up the ELBs, when I made everyone use a small network and had to quickly reverse that decision. Yeah, I remember that. Everyone hated me.

65:31 I had some fighting words with you at one point.

65:34 Yeah, I had to adjust for sure.

65:39 But what about IP efficiency? Yeah, well, we don't care about those.

65:43 No, no.

65:45 Everyone gets a 10, gets a /16, which is possible.

65:48 Exactly.

65:49 Yeah.

65:50 There's plenty of IPv4 IPs. No problems.

65:53 Onto Oracle because we need something to laugh at today. Introducing OCI NetApp Storage Service, native ONTAP storage. On OCI. Do I have to read more?

66:07 Yeah, I haven't even yet. Sure.

66:10 Oracle and NetApp are expanding their partnership with first-party ONTAP storage on OCI. You can now spend more money on Oracle. Yeah, following a well-worn paddle of all the other hyperscalers that have this at this point.

66:23 Yep.

66:24 I— that's all I got. I'm not going any further. If you want more, read the show notes.

66:28 It's exactly what that is, right? Which is like, people are, you know, very used to the NetApp management ecosystem, like the, the administrative UI and, and moving stuff around, and they're comfortable with those APIs. And it's always confused me cuz it's, in my opinion, unnecessary abstraction, you know? But I guess, you know, historically running a data center, you've, you've had the storage layer provided for you and you've built around patterns for that where it's, when I can provision a disk dynamically as part of my application deployment, I don't know why I would need to use this. And if I need to, you know, offer something with a shared network or a shared layer for multiple things to access, like, you know, like unless it's truly shared block store, like I'm going to use an object, I'm going to use something else that's not a network SAN. But, you know, now I guess if you want to run a data center in the cloud and just not optimize anything and move your workloads into the cloud, you, you too can now pay through the nose on Oracle.

67:33 You can run VMware on top of Oracle with your NetApps and really burn all your money.

67:39 Sorry.

67:40 Yeah.

67:41 Yep.

67:43 Well, Ryan, we survived another episode with just the two of us. Mm-hmm. So I'm sorry for anyone that's made it this far. Yeah, probably should have turned it off a while ago.

67:54 We apologize. Don't worry, they did. It's our moms and Justin. That's the only one listening right now.

67:59 My mom doesn't listen. She would have no idea what we were talking about.

68:02 I know. It's, you know, we're talking.

68:06 Well, I will see you next week.

68:08 All right. Bye everybody.

68:10 Bye everyone.

68:11 Another week of cloud news wrapped up. Bolt will collect the news. Justin will get the notes. Jonathan Jonathan will write some code. Ryan will watch the perimeter and Matt will reluctantly watch Azure. Till next week for AI, Amazon, Google Cloud and Azure. And hey, maybe even Oracle, who knows? Check out thecloudpod.net for our newsletter. Join our Slack, message us on socials or leave a review.

68:43 Well, we have an after show today. And really, it's just a pet peeve of mine that I saw fairly not tangentially related. But, you know, I watched talk about it and I thought that since Ryan and I were here and Ryan's in the world of security, it might be interesting to him. So there's an article written at 9to5Apple at work, Enterprises Need to Kill the SSL Tax. It's an opportunity for Apple. The article highlights 37% of enterprise apps go unprotected by SSL on average. Large, largely because vendors charge a premium to enable it. SSO should not be charged for, it should be included base, creating incentives for companies to skip basic security measures. Cleaver, let me go with that's how you say it, K-12 model presented a working alternative, a platform for free for schools and application vendors pay for a gallery placement, effectively reversing who bears the costs. For secure logins. The piece argues Apple should acquire Clever, build an identity layer connecting Managed Apple Accounts platform, SSO, Sign in with Apple, into a vendor-funded SSO model, potentially strengthening Apple's position in K-12 sales against Chromebooks, which I think they're killing Chromebooks. They're becoming Google Books. I think we had a small tangent on that earlier before the show. Um, Turns out Ryan and I should not do the pre-read by ourselves, but we'll bypass that for this work. This raises a broader question of who should bear the costs of security features like SSL and MFA and bundling them with premium add-on features versus just giving them to everyone by default because that's what you should do. Yeah, I have very strong feelings. SSO, it should just be included. The amount of times I've had to buy a premium tier of something 'cause I just wanted SSO, than getting these 17 other features. Like, I get it, you're giving me all this other stuff, but I don't want it. And there was one vendor, I was doing a review, like I was looking at, I wanna say it was like ECS static code analysis and dynamic code analysis back in the day. And I straight up just said to vendors, if you're not gonna include SSO in the base cost, I'm walking away before we even start this conversation. Yeah. Because it really is a massive pet peeve of mine. And like, it was like sso.tax back in the day. I think there's sso-tax.org now, which is like essentially wall of shames for people about it, you know, that show you like how much it is, like just to get that. Yeah. SSO, you know, Slack is a great example. It's posted on here. Base price is $8.50. If you just want SSO, it's $18 a person. Like, that's a big jump. Yeah.

71:35 No, I mean, any kind of enterprise SaaS app, like, the problems are too big today. You know, spear phishing is the number one attack vector. You know, people, you know, scamming people out of their credentials. And so every SaaS app that you use in your day-to-day job, you're going to have a different MFA provider and you're you're going to have tokens or whatever, passkeys, or for each one of those, like, it's— and then logging is distributed at that point. And for access, like, there's no way you can have that type of control if you don't have sort of a central IDP and manage that application access via it. And so it's not— it's just, it is, it's a tax. And it— if you're gonna charge for it, it just means that people won't use it. And if they don't use it, now they, you're just making them a target on your, on your application. So that sucks. I hate it. Right.

72:33 And the one that really annoys me is GitHub. The only way to get SSO is to go to enterprise.

72:39 I just found out that Postman today is the only thing that allows that too. And like, you have to do enterprise.

72:46 You're protecting code, like you're You're protecting literally ways that people get into stuff. It should be almost required to be on the platform as a business. Like, I agree, you need to flip the story. But the problem is enterprises are making too much money because people upgrade because Ryan, rightfully so, says, no, you need your tool to have SSO so we can manage it.

73:13 I mean, I get to rest on the fact that most compliance controls require it and it's not really me, but if they didn't require it, it would be me. So it's sort of— Yeah. Yes, it sucks.

73:21 It's just a massive pet peeve. There's no reason, like once it's implemented, it's so little. Yes, there are support tickets because SSL, because SSL sucks to set up, but once it's stood up.

73:37 But the alternative is managing user credentials on many different platforms. You think that's not tickets? Like I forgot my password.

73:43 But it moves where the tickets are. One is a ticket to, let's say GitHub in this case, one's a ticket to an internal Git you know, repository that you have running. So like I get, but like there's not a large sum of effort to set up SSO at this point. And it's not like you're maintaining it, updating it. You know, I have always wondered like how it works for you to rotate your SSL cert to think your SSL cert. It's really not bad.

74:08 I've done it many a time. Like it's, you do have to update the configurations, but like it's with the new cert. That's not that big a deal.

74:16 But like the fact that GitHub—

74:17 And for OAuth, OAuth is addressing that just by publishing, you know, well-known endpoints where you can pull that down and verify it. So.

74:25 There's like a secure, I want to say like secure SS, like there's like a, there's another SSO that's like SSO-S or something. I'll have to look into it.

74:36 Well, SSO is just a larger term for, for SAML, right? Which is, and OAuth, right? Those are both SSO.

74:43 That's what I'm thinking of.

74:44 Yeah.

74:45 But there's SAML with secure mode too, which is like another certificate on top of it.

74:52 Okay.

74:52 I don't know how that's gonna work. Yeah, I've worked with banks that had it and we had to implement it. It's another layer of security where like, then I'm like, how do you rotate? You know, when you have to have it signed by, you know, insert company that signs certificates here. So it becomes another layer too.

75:08 Yeah.

75:09 I don't know.

75:09 I'd rather do that with something like a device trust policy or something along those lines, because that sounds like mutual TLS for SAML and that. And so it's, you know, like, I don't know if I want to validate a client certificate to say you can request an identity from my platform. I'd rather have you make the request and then I do some evaluation on whether you deserve a response or not, but that's just me.

75:35 I agree.

75:37 Anyway, I do think it's interesting. I didn't know anything about like this guy's, you know, the article we're, that we're sort of abusing, uh, is that the, the want here is for Apple to buy Clever, not Cleaver, and in order to support more of an Apple movement to supporting schools, like the using Apple devices instead of Chromebooks, which I find crazy town because of the hardware cost differences between a Chromebook and an, a kind of Apple product. But, you know, neat. I guess, you know, that it's an op-ed piece, it's written by an Apple employee, so that makes sense that of course they would want to use Apple. And, you know, my kids would love it, but, 'cause they're not big fans of Chromebooks, but I think that's largely 'cause of all the security controls and not functionality directly.

76:27 I thought Chromebooks started getting expensive at this point, but I guess there are cheaper models.

76:33 Exactly. It's, it's because it's not proprietary hardware and it's built on commodity. It's, you get the, you get the full gambit.

76:42 Oh yeah. So here's a Chromebook for $179. Yeah. All the way up to like $800. Cause I was thinking they just released, and by just, I mean, uh, I'm clearly not using that term correctly. They did release those low-end Macs finally, the Neos for $699.

77:00 Yeah. And so I don't know, like, you know, I know that, you know, at least around here the school districts are offering, or they just issue a Chromebook to every student automatically so that it's, you know, computer access is fair and it doesn't matter about your income level. But, you know, can't spend a lot of hardware when giving a whole bunch of laptops to 12-year-olds, right?

77:20 Like, Why, you don't— you think they're going to treat them nicely and kindly?

77:25 They don't treat my house kindly, tell you that much. I mean, how good I am at replacing sheetrock? Really good.

77:31 You'll have to teach me as my boy gets older.

77:36 Yeah, exactly.

77:37 He's pretty good already. I want to— so, you know, yeah, I'll make a couple house calls and get you—

77:43 and get your, uh, technique worked out.

77:46 I don't know, I'm, I'm abusive to technology, so I can't imagine what kids are. You know. So yeah, well, that was my small diatribe on SSO tax and why people are dumb and why I hate all companies that charge for SSO tax.

78:02 I do too. It is awful.

78:04 I will catch you next week, Ryan.

78:05 All right, till next time.

78:08 Bye-bye.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0:00
0:00