Loading…
strong>The Liffey B [clear filter]
arrow_back View All Dates
Tuesday, October 29
 

11:00 GMT

I Can OIDC You Clearly Now: How We Made Static Credentials a Thing of the Past
Tuesday October 29, 2024 11:00 - 11:40 GMT
Iain Lane and Dimitris Sotirakis, Grafana Labs


At Grafana Labs, we tackled a thorny problem: managing secrets in an open-source CI/CD pipeline. Our journey from static secrets to OIDC-based access wasn't just about better security—it was about empowering our engineers. We'll walk you through how we leveraged OIDC and GitHub Actions to create a "secretless" system for accessing cloud resources, complete with shared jobs and abstractions that make secure access simple. But it wasn't all smooth sailing. We'll share war stories, including a security hiccup that taught us valuable lessons. If you're drowning in a sea of secrets or just want to sleep better at night, come and learn how we boosted security while cutting operational headaches. You'll walk away with practical strategies for implementing OIDC-based access that'll make your engineers happy and your security team even happier.


https://www.usenix.org/conference/srecon24emea/presentation/lane
Speakers
avatar for Iain Lane

Iain Lane

Grafana Labs
Iain is a senior software engineer at Grafana Labs. A member of the Platform team, his focus is on maintaining the infrastructure - Kubernetes clusters - which runs Grafana Cloud, and helping build tools and processes for engineers to deploy their software into this environment with... Read More →
avatar for Dimitris Sotirakis

Dimitris Sotirakis

Grafana Labs
Dimitris is a Senior Software Engineer with background in Backend, DevOps, Release and Platform Engineering. Specialized in CI/CD architecture, he has spent most of his career tackling the challenges of delivering software, tools and frameworks with quality. Currently he’s a member... Read More →
Tuesday October 29, 2024 11:00 - 11:40 GMT
The Liffey B

11:50 GMT

OMG WTF SSO: A Beginner’s Guide to Single Sign-On (Mis)configuration
Tuesday October 29, 2024 11:50 - 12:30 GMT
Adina Bogert-O'Brien


SSO protocols are just ways for an identity provider to share information about an authenticated identity with another service. Me having a way to tell my vendor “yeah, that’s Bob” doesn’t tell me what the vendor does with this information, or if the vendor always asks me who’s coming in the door. A bad SSO implementation can make you think you’re safer, while hiding all the new and fun things that have gone wrong.
To get the most out of implementing SSO, I need to know what I’m trying to accomplish and what steps I need to follow to get there. To illustrate why SSO needs to be set up carefully, for each of the things you need to do right, I’ll give you some fun examples of creative ways you and your vendor can do this wrong. We all learn from failure, right???


https://www.usenix.org/conference/srecon24emea/presentation/bogert-obrien
Speakers
avatar for Adina Bogert-O'Brien

Adina Bogert-O'Brien

I am incessantly curious, work in renewable energy, and sometimes find vulnerabilities when I’m bored. I co-founded a hackerspace over a decade ago but have only just accepted that security is more than a hobby. At work, I’m a business architect with security leanings working... Read More →
Tuesday October 29, 2024 11:50 - 12:30 GMT
The Liffey B

14:00 GMT

Achieving Excellence: SLO Thresholds That Transform Service Quality
Tuesday October 29, 2024 14:00 - 14:40 GMT
Thiara Ortiz, Netflix


At Netflix, ensuring exceptional quality for our streaming platform is crucial. Every time a Netflix member sits down, reclines in their chair, and turns on their TV, it's a moment of truth. It's our opportunity to deliver a spectacular service with amazing quality of experience. Misses, errors, or high latency—whether due to ISP configuration changes, code deployment, or catastrophic fallback—impact how our service is perceived.

In this talk, I'll share methods for defining thresholds for SLOs, ranging from intuition and industry best practices to advanced techniques like A/B experimentation. At Netflix, properly defining SLOs allows us to ensure industry-leading quality of experience for our members.


https://www.usenix.org/conference/srecon24emea/presentation/ortiz
Speakers
avatar for Thiara Ortiz

Thiara Ortiz

Netflix
Thiara is a Staff CDN Reliability Engineer at Netflix. Over the last four years, Thiara has been working on Open Connect, improving the resilience of the Netflix service for members around the world. Most recently, Thiara has been heavily involved with the introduction of Cloud Gaming... Read More →
Tuesday October 29, 2024 14:00 - 14:40 GMT
The Liffey B

14:45 GMT

Selective Reliability Engineering: There Is No Single Source of Truth
Tuesday October 29, 2024 14:45 - 15:05 GMT
Elise Burke, Datadog, Inc.


As engineers we design distributed architectures, define project scopes, and ensure that we have a single "source of truth". But what, exactly, do we mean by the phrase? Do we really have only one source of truth - and for that matter, how do we decide what it is?

We'll look at some well-known ambiguities in system design and data modeling and then consider more philosophical questions about truth, the sources of truth we accept, and why this ambiguity matters.


https://www.usenix.org/conference/srecon24emea/presentation/burke
Speakers
avatar for Elise Burke

Elise Burke

Datadog, Inc.
Elise's sixteen year career as a software and site reliability engineer includes supporting Google's internal distributed storage systems and Datadog's organization-wide production practices. Her interests include exploring the interconnectedness of both technology and the people... Read More →
Tuesday October 29, 2024 14:45 - 15:05 GMT
The Liffey B

15:10 GMT

Why You’re (Probably) Doing Service Catalogs Wrong
Tuesday October 29, 2024 15:10 - 15:30 GMT
Lisa Karlin Curtis, incident.io
Service catalogs promise a lot of things: powerful automations, insights into your technology estate.
But over the last few years, many of us have learned that setting up and maintaining a service catalog is really hard.
Building out a catalog from a standing start can take months, or even years. Too many people get stuck in a chicken-and-egg situation, where you can’t deliver value because you don’t have the data in your catalog, and you can’t convince anyone to spend time helping you because the catalog doesn’t do anything yet.
But there is another way...
https://www.usenix.org/conference/srecon24emea/presentation/curtis
Speakers
avatar for Lisa Karlin Curtis

Lisa Karlin Curtis

incident.io
Lisa started out as a consultant working with HMRC and then smart meters, before accidentally becoming a developer. She was a founding engineer at incident.io, building tooling to help your whole organization manage incidents better. She loves building stuff, but is also really interested... Read More →
Tuesday October 29, 2024 15:10 - 15:30 GMT
The Liffey B

16:00 GMT

SRE Stakeholders: A Spotter’s Guide
Tuesday October 29, 2024 16:00 - 16:40 GMT
Dave O'Connor


For Every SRE or SRE-adjacent team in any organisation, there are many kinds of stakeholders; people who care (or don't care!) about how your team operates, and the outcomes of that. They differ massively in how they view your team, and in how they, in turn, should be viewed, and managed.

In a timeline that doesn't contain a canonical book setting out what SRE is here for and how it achieves that, the sad and annoying answer is that "it depends". Because of this, we need to get good (or remain good) at stakeholder management and communications about why we're here, and what we do.

While primarily useful to SRE leadership, the kinds of stakeholders you run into can be useful to know for any SRE. Learn to spot the different stakeholders in your life, what they (generally) care about, and how you can help reduce misunderstandings and tension, no matter where you're sitting.


https://www.usenix.org/conference/srecon24emea/presentation/oconnor
Speakers
avatar for Dave O'Connor

Dave O'Connor

Dave is an SRE Leadership practitioner, Advisor and Coach based in Dublin. He's been working on SRE and SRE-adjacent organisations for over 20 years, primarily as an SRE Lead at Google from 2004-2021. Since then, he has spent time leading SRE, Security and Infrastructure teams at... Read More →
Tuesday October 29, 2024 16:00 - 16:40 GMT
The Liffey B

16:50 GMT

Panel Discussion: Is Reliability a Luxury Good?
Tuesday October 29, 2024 16:50 - 17:30 GMT
Moderator: Emil Stolarsky
Panelists: Niall Murphy, Stanza
https://www.usenix.org/conference/srecon24emea/presentation/stolarsky
Moderators
avatar for Emil Stolarsky

Emil Stolarsky

Increase
Emil is an engineer at Increase where he works on building modern banking infrastructure. Before that, he was at companies such as Wave Mobile Money, DigitalOcean, and Shopify, working on everything from building data centres in Sub-Saharan Africa to caching & performance optimizations... Read More →
Speakers
avatar for Niall Murphy

Niall Murphy

Stanza
Niall is the CEO of Stanza Systems, has occupied various engineering and leadership roles in Microsoft, Google, and Amazon, and is the instigator of the best-selling & prize-winning Site Reliability Engineering, which he hopes at some stage to live down. His most recent book is Reliable... Read More →
Tuesday October 29, 2024 16:50 - 17:30 GMT
The Liffey B
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -