Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
akadajet
Sep 14, 2003

why is this bitch rear end cloud flare always between me an my favorite websites?

Adbot
ADBOT LOVES YOU

Moo Cowabunga
Jun 15, 2009

[Office Worker.




because

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
:yayclod:flare

Sagebrush
Feb 26, 2012

buttflare

Moo Cowabunga
Jun 15, 2009

[Office Worker.




the forums are down again . net

akadajet
Sep 14, 2003

if cloudflare were any good they'd go out of their way not to call attention to themselves when poo poo breaks.

Agile Vector
May 21, 2007

scrum bored




saturday morning motherfuckers :smithcloud:

Moo Cowabunga
Jun 15, 2009

[Office Worker.




saturday afternoon bitches

Xaris
Jul 25, 2006

Lucky there's a family guy
Lucky there's a man who positively can do
All the things that make us
Laugh and cry

akadajet posted:

if cloudflare were any good they'd go out of their way not to call attention to themselves when poo poo breaks.

lol

one day i need to read up on ssl stuff and w/e it is and does. our hp windows server bugs our dam technicians everytime they remote desktop in to enter timesheets about some cert or something but idk im not a compouter toucher and :effort: to fix it

pram
Jun 10, 2001
its pretty good for the price honestly but I'd use Akamai for something serious

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
cloudflare said the forums broke and well, heck, i believe 'em

maskenfreiheit
Dec 30, 2004
cloudflare's chief dc policy wonk is named mike nelson, makes you think

qhat
Jul 6, 2015


the fact that internal certificates are not just automatically renewed and deployed well before the expiry date is what's bullshit

qhat
Jul 6, 2015


I remember I was once getting an MSSQL server setup with encryption and the windows team were all like "yep, we'll host and manage the servers for you, but you gotta remember to keep the cert updated". bollocks to that though, we pushed back and got them to manage it themselves like they should've been doing all along.

echinopsis
Apr 13, 2004

by Fluffdaddy

pram posted:

its pretty good for the price honestly but I'd use Akamai for something serious

is that what eirka ran on then

pram
Jun 10, 2001
no eirka used cloudflare too lol

echinopsis
Apr 13, 2004

by Fluffdaddy
i miss feeling like i was part of something

du -hast
Mar 12, 2003

BEHEAD THOSE WHO INSULT GENTOO
cloudflare is bad hth op

maskenfreiheit
Dec 30, 2004

du -hast posted:

cloudflare is bad hth op

av checks out

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast
i love when people talk about CDNs because they are my life

Asymmetric POSTer
Aug 17, 2005

Xaris posted:

our hp windows server bugs our dam technicians everytime they remote desktop in to enter timesheets

the most enterprise workflow

Asymmetric POSTer
Aug 17, 2005

Sniep posted:

i love when people talk about CDNs because they are my life

CDNs are cool & good

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

mishaq posted:

CDNs are cool & good

i work with most of them on a day to day basis

ama

Asymmetric POSTer
Aug 17, 2005

Sniep posted:

i work with most of them on a day to day basis

ama

the physical infrastructure/network side?

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

mishaq posted:

the physical infrastructure/network side?

its bad

next?

Asymmetric POSTer
Aug 17, 2005

Sniep posted:

its bad

next?

wots the worst outage uve ever seen

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast
o if you meant do i work on the infra side then not anymore, i did quite a bit with the level 3 cdn (formerly sandpiper then savvis) but now im just a customer of most all of them

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

mishaq posted:

wots the worst outage uve ever seen

never really a full outage, since these networks are so diverse and distributed, but i've seen major issues with capacity planning and upper mgmt that expects 90+% utilization before they'll augment (not naming names but these models fail) -- but regardless of that, big utilization spikes from clients will degrade performance for others on a fairly normal basis... and it's pretty universal, even huge networks like akamai fall for this at times - it's one of the biggest challenges out there i think is how to properly segment and safekeep customer A's properties from customer B's utilization. hard as gently caress.

Asymmetric POSTer
Aug 17, 2005

Sniep posted:

(then savvis)

glad you escaped before they fully went to hell

Sniep posted:

never really a full outage, since these networks are so diverse and distributed, but i've seen major issues with capacity planning and upper mgmt that expects 90+% utilization before they'll augment (not naming names but these models fail) -- but regardless of that, big utilization spikes from clients will degrade performance for others on a fairly normal basis... and it's pretty universal, even huge networks like akamai fall for this at times - it's one of the biggest challenges out there i think is how to properly segment and safekeep customer A's properties from customer B's utilization. hard as gently caress.

im surprised there arent more aws us-east-1 s3-esque outages that take out half the web because everyone puts all their eggs in of the few major cdn players baskets

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

mishaq posted:

glad you escaped before they fully went to hell
eh, i never worked for savvis, i just used their poo poo after level3 bought them back in the day. They had a really awesome DNS server called ITM that I wish I had the source to as I'd use it personally today. It owned.


mishaq posted:

im surprised there arent more aws us-east-1 s3-esque outages that take out half the web because everyone puts all their eggs in of the few major cdn players baskets

oh oh - on a per-customer basis? fuckin outages galore - i meant no network-wide outages to really report

as far as individual property outages are concerned, a lot are S3 or other control channel outages taking properties offline as a gatekeeper (the S3/origin front end dies, no users can get to the content on CDN, == outage) -- but really human error is more common... i for one have taken down 3 letter .gov agencies' public facing poo poo before by typoing a single number wrong on a config - it happens. most per-property outages though are human error i'd say. you can extend this to poo poo like SSL certs expiring and nobody preempted it, or what have you

again the big challenge isnt really outages since it's either not the CDN's responsibility or if it is, usually easily fixed

the hard party and million dollar question is how to keep performance up, and keep it up consistently.

akadajet
Sep 14, 2003

Sniep posted:

i work with most of them on a day to day basis

ama

why do they break all of the time and show ads for their service instead of the webpage i'm trying to visit??

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

akadajet posted:

why do they break all of the time and show ads for their service instead of the webpage i'm trying to visit??

awhat

i've never encountered any ad injection on any major CDN before

gimme an example

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)

Sniep posted:

awhat

i've never encountered any ad injection on any major CDN before

gimme an example

he means when lowtax breaks the forums and we get a cloudflare page

Asymmetric POSTer
Aug 17, 2005

carry on then posted:

he means when lowtax breaks the forums and we get a cloudflare page

cloudflare is more than a cdn tho, the ddos mitigation puts them in directly between you and sa's servers

Asymmetric POSTer
Aug 17, 2005

Sniep posted:

eh, i never worked for savvis, i just used their poo poo after level3 bought them back in the day. They had a really awesome DNS server called ITM that I wish I had the source to as I'd use it personally today. It owned.

what made it so good?

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)

mishaq posted:

cloudflare is more than a cdn tho, the ddos mitigation puts them in directly between you and sa's servers

whoosh

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

carry on then posted:

he means when lowtax breaks the forums and we get a cloudflare page

yeah that's not their fault when the origin dies and it's dynamic (non-cacheable) content

if it were me I'd not even keep cloudflare in the loop at all until the forums were getting ddos'd then flip DNS over to cloudflare to eat the attack reqs as needed

Asymmetric POSTer
Aug 17, 2005

Sniep posted:

if it were me I'd not even keep cloudflare in the loop at all until the forums were getting ddos'd then flip DNS over to cloudflare to eat the attack reqs as needed

why wont the attacker just attack sa's IPs they were able to figure out ahead of time then instead of the url? isnt part of the point of always-on ddos mitigation to obfuscate the servers themselves permanently to prevent that?

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

mishaq posted:

why wont the attacker just attack sa's IPs they were able to figure out ahead of time then instead of the url? isnt part of the point of always-on ddos mitigation to obfuscate the servers themselves permanently to prevent that?

a problem more cheaply solved for with a varnish or nginx proxy in front of the sa origins with separate addressing vs paying cloudflare rates but *shrugs*

idk I don't like the concept of always on proxy services for non critical things but I'm also cheap

Adbot
ADBOT LOVES YOU

akadajet
Sep 14, 2003

carry on then posted:

he means when lowtax breaks the forums and we get a cloudflare page

ya. i'd never know cloudflare existed if they didn't keep showing their poo poo to me when stuff breaks

  • Locked thread