Category: Editorial

  • Automation is a Key Skill for the Modern DBA

    This month we had T-SQL Tuesday #130, hosted by Elizabeth Noble. Elizabeth and I had some good talks about database development and DevOps last year, and I managed to convince her to host one of the blog parties. I had expected that people might focus on the software development side of automation, but many of the posts cover administrative topics.

    The recap is coming next week, and I look forward to it, but I shouldn’t have been surprised. Good DBAs, as well as many sysadmins and Operations staff, have known that automation is important for years. It helps to ensure a smooth running environment and helps us cope with the volume of work that is thrust upon us.

    There were a few interesting posts. Greg Dodd talks about the advantages for his employer when he automates things, which is important to think about. Spending time automating things can slow down the initial closing of tickets, but it pays dividends in the future. It’s an investment, which is something to think about when you try to reduce repetitive work. Especially if your boss is concerned about the time taken to solve some tickets.

    One of the big advantages of DevOps, as well as general automation, is consistency. Taoib Ali explains how he enforces trace flags with automation, and Kevin Chant talks about SQL Server updates. Deepthi Goguri explains how to handle DBA work at scale. These are all situations where a little automation is not only useful, but perhaps essentially to reducing mistakes and human error.

    As we move to a larger number of versions to support, a great variety of platforms, including the cloud, it’s critical that a DBA not be required to click around in SSMS or connect to lots of systems to manage them. Learning to automate can produce some great blog posts for your brand, give you interesting conversation ice breakers at events (or on social media), and generate some stories that will impress interviewers.

    If you aren’t sure how to get started, consider reading Eitan’s Laws of Automation. It’s a look at what to automate, why, and a few ideas on implementing changes.

  • Remote Work Benefits

    It seems as though many of us that have been remote working will continue to do so. I see some offices opening, but not many. I had one friend that had everyone go back to their office in Denver, but they tend to all close their office doors so they don’t have to wear masks and they do their meetings over Zoom. Seems crazy to go into the office for that.

    The weight of this type of work continuing for the next six or more months has been a little tough for me at times. That sounds crazy, for someone that’s been a remote worker for over a decade, but I used to regularly go to offices, visit people, or even go work in Starbucks. Those types of things aren’t happening for me now. I am going to try and see if I can get a few more lunches with friends, especially when the weather changes a bit.

    If we are going to continue to work from home, some things likely need to change for some of us. On a call recently a friend asked about my Secret Lab chair, since this individual had an old chair and knew their organization wasn’t bringing them back until sometime in Q1 2021 at the earliest. They needed to get better set up at home to work.

    I saw an article that some companies are thinking about this new setup, how they might save money on office space and infrastructure, but also perhaps invest some of this in employees. There are companies that pay for phones, broadband, and some necessities, but some are thinking about doing more.

    They may not only invest in computer equipment, but might do a stipend to allow employees to better set up their home office, which may just be their new office. Perhaps some allowance for furniture or other equipment. I know some are considering monthly allowances for the additional expenses employees have, such as more electricity for equipment or heating/cooling. I know Redgate has offered some of this to our staff.

    Ultimately, we need to ensure we have an ergonomic, long term place to work, which is challenging for some. I continue to see people working from dining tables, sofas, and more, which are fine for some ad hoc typing, but not good for sustained periods of concentration. If your company isn’t planning on going back to an office, perhaps you want to ask about some benefits. At least a chair, as I think having a nice chair has made a big difference to my comfort across the last six months.

    I do think it’s important to get a good ergonomic setup if you are going to be here for a long time. Especially if there are others in your house and you all need to be sure you can work effectively and concentrate on what your employer expects you to do.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.

  • The Real Life Software Movie Plot

    It wasn’t that long ago that Firewall was released. In it, a security executive has his family taken hostage, with the plot being that the executive will help the criminals rob the bank that he’s spent years protecting or his family will be killed.

    While I haven’t heard of this extreme happening in the real world, I wonder how far away we are from this. Recently, there was a less violent attempt at hacking, with someone offering a Tesla employee over US$1mm to slip ransomware into their network. The idea would have been to threaten Tesla with data release unless they paid up. The details are interesting, and supposedly the ransomware cost US$250,000 to build, but another company paid US$4.5mm to criminals, so maybe this would have been very profitable.

    I’m sure there have been some shady offline attacks against companies and their executives or privileged staff. I hope there haven’t been any violent ones, but I am sure that something has happened somewhere in the world.

    Ultimately, I bet that the best defense might be to limit the knowledge of who can access sensitive data, and perhaps even ensure that no one can. Only systems, and that all queries, all access, and certainly all backups, are handled by some automated system, logging everything. This might not prevent this movie plot from coming true, but maybe you’d get a similar ending, with the criminals caught quickly because some system logged the action and alerted people.

    Security is a tough world to work in and think about constantly. Many of us know this, dealing with the stress and concern on a regular basis. Hopefully none of us add in the moral dilemma that might come from an actual criminal contacting us. If they did, hopefully all of us would be able to do the right thing.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.

  • The Best Security for Database Administrators

    A short while ago, Twitter got hacked. I wrote about this, as did Denny Cherry. I think Denny’s piece was more interesting, as he speculates about the security measures that Twitter may, or may not, have had in place.

    One of the things Denny brings up is air-gapping administrative machines. I’ve rarely seen this in organizations, and perhaps see this less and less in the pandemic world. There are some high security places that do this, but could your organization do this? How many of us use cloud or co-location facilities where we can’t even physically enter the premises?

    I suppose we can use some strong network security controls, perhaps even requiring static IP addresses for people at home and specific routes for certain administrators. I do know some companies that do require specific laptops for access, with limited software, but this certainly isn’t the norm. Too often a general laptop used for most work performs double duty as an administrative workstation with access to production data.

    Another thing Denny mentions is jump hosts, without any cut/copy/paste functionality from the remote machine to the host. This is something I am starting to see from customers, even smaller ones, as a way of limiting the chance of ransomware or some security breach. Multi-factor authentication gets an administrator onto a remote desktop session on a jump host, from which they can access production systems with limited tools. This certainly isn’t perfect, and it is annoying for administrators, but it is a good security layer, and it forces organizations to use good, compliant, database DevOps practices to deploy changes.

    Perhaps the best part of Denny’s article is the title of the last section: good security shouldn’t be user friendly. It shouldn’t be for administrators. While we might make things slightly easier for average users, anyone that can access bulk amounts of data, especially in a privileged fashion, should have strong security, which is a bit cumbersome. I think the hassles of strong security would be a good thing for more of us to have to deal with. Hopefully more organizations will start taking better precautions and reduce the chance of attack.

    Steve Jones

    Listen to the podcast at Libsyn, Stitcher or iTunes.