Author: way0utwest

  • Deployment Failures

    Just Ship
    Shipping is good, but your deployment process needs to be solid.

    Years ago the company I worked for would patch the majority of our servers one Friday night each month. The Microsoft patches for the month, and other software patches, would be bundled up into SMS (Systems Management Server) packages and deployed to thousands of servers. We had an amazing administrator who built these packages, and it was quite an experience to walk into the data center and hear thousands of servers shut down and fans spin down for a moment before rebooting.

    That was the smoothest deployment system for vendor patches, but I worked in another place that deployed changes to a web application (the system that generated all our revenue and paid our salaries) every Wednesday night. We did this for over 18 months, over 70 deployments, pushing out changes on a consistent basis. We only rolled back three times, but we did roll back three times.

    Other jobs have had various levels of success at deploying changes. Many of the companies worked with the ad hoc, patch one machine at a time manually, process. Not very efficient, and probably not even possible at the numbers of systems many companies have today. I wanted to ask you this week how successful your company is.

    How often do you have problems during the deployment of some software change?

    Do you think that you have issues more often than not? Do you roll back when you have issues? I doubt that. In my experience, even broken deployments are often pushed forward, with the expectation that developers, vendors, or admins will fix things over the next few days. I’ve never thought that was a good plan, since we often fine broken features limping along for months or years, but organizational momentum can be hard to slow down.

    Let us know if you think you work inside of a smooth, strong deployment process, or one that’s more fragile and brittle.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.

  • The First Event of 2013 – SQL Saturday #183 – Albuquerque

    I’ll be delivering the Modern Resume presentation at SQL Saturday #183 in Albuquerque, NM on February 9, 2013. I got my acceptance today and replied that I’ll be there.

    This is the first SQL Saturday in New Mexico, which is a little exciting. I’ve been there a few times since my brother used to live there and thought it was a neat city. I’m looking forward to going back and wandering around for an afternoon before the event.

    If you’re anywhere nearby, register and come to the event. It should be a lot of fun.

  • Cloud Concerns

    cloud concerns
    The biggest concern with cloud computing isn’t security.

    When I get feedback about cloud computing from DBAs, the main concern seems to be data security, or the perception of problems with security from a cloud provider. That’s natural as sending your data to the cloud doesn’t necessarily remove the responsibility for security from the purview of the DBA, yet you don’t have complete control over the way the data is managed. Various providers are working on their security and passing certifications, though this doesn’t necessarily make many DBAs feel comfortable with databases in the cloud.

    However security may not be your number one concern. Outages and business continuity should be your primary concern. As noted in this article, cloud service outages have been more common than lost data. It’s much more likely that the service will go down, and if it does, what do you do? Contacting a cloud services company, and receiving fast answers aren’t likely when a cloud outage usually affects a large number of customers.

    However business continuity is important. If your database, or application server goes down, what would you do? In most cases you would sit in your office waiting for the cloud provider to come back online. That’s not much different from in-house failures where you may wait on the network or OS administrators to recover a host server. In a few of the disasters I’ve experienced, I only had slightly more control than I’d guess a cloud provider gives me.

    In either case, having good backups and a strategy to bring your system online in the event of an extended outage is important. I suspect that will mean hybrid public/private cloud applications that can function from an alternative location will need to be an architectural requirement for many businesses.

    Steve Jones


    The Voice of the DBA Podcasts

    We publish three versions of the podcast each day for you to enjoy.

  • You Need to Manage Passwords

    I saw a note this week from CNet about a system built to crack passwords (also on ArsTechnica). It reminded me of the story of the guy that cracked Googles DKIM key at 512bits. Not insignificant, until you get to the point of renting that power from AWS for tens of dollars.

    Here’s a great comic on the subject of passwords: Password Strength. It’s got some good advice, but there’s more to it than just having a good strong password. You need to manage your passwords, as in you need to have lots of them.

    Doubt that? Here’s a good piece from Troy Hunt.

    You need a password manager. Whether you use 1Password, KeePass, or PasswordSafe (my choice), choose one and set the defaults to something long. I’ve been using 12characers, but I’ve moved to 16 for my passwords. All of these work cross platform, and you can sync your files between devices.

    One more thing: you need to rotate passwords. Not just on your password manager, but on your various sites. If someone gets a copy of your password manager file, then it’s just a matter of time before they can crack it. Within months, they could have all the passwords in your file if they were determined.

    Lots of passwords I’m not overly worried about, but some I am. Banks, mail, a few of my profiles, these are important to me, and so I rotate the password periodically on them, using new passwords from my manager.

    Security is hard, and passwords aren’t going away anytime soon. Tell your friends, family, and make sure they all consider using some type of password manager and improving their security.