r/cloudcomputing

Do AI workloads really belong in the same cloud as everything else?

Something I've been thinking about a lot lately like regular web apps putting everything under one cloud account makes things pretty simple but AI workloads have very different needs like GPUs, high-speed storage, special networking setups, specific regions and different types of hardware.

I've seen people use services like AWS, Azure, GCP, CoreWeave, Lambda, Yotta Labs and others in all sorts of ways so just wanna know how people view this problem here

reddit.com
u/Fear73 — 20 hours ago

What diagramming tool are you using?

Hi everyone,

I am cloud engineer and looking for text to digram tool to integrate in my workflows. Is there any suggestion for text to diagram tool anyone used. Eraser I used but not getting much quality and limited free tier

reddit.com
u/Secret_Ad5249 — 2 days ago
▲ 51 r/cloudcomputing+7 crossposts

xFW - Open-Source eBPF Volumetric DDoS Protection

Hi Reddit,

DDoS attacks are becomeing larger and cheaper to launch, so we work on a scalable open source solution to mitigate them.

Tempesta xFW's core is XDP and TC eBPF programs implementing volumetric DDoS filtering. A user-space daemon handles gRPC requests from CLI tool or WebAPI (via C library).

It supports two packet-path architectures:

  • host-based protection, such as CDN edge or on-premises application delivery controller (ADC) cases, where the host is a TCP connection endpoint. This is good for protecting a local web or DNS server.

  • router-based protection, such as ISP, hosting, or IaaS provider cases, where the host routes IP packets to protected servers or networks.

Router-based deployment can be always-on/pass-through or on-demand/redirection protection. In the later case, a node may not "see" normal clean traffic and may receive only traffic containing a DDoS attack. Also, the node may receive only client-to-server traffic, as in direct server return (DSR) or some traffic scrubbing scenarios. In this mode a DDoS sensor and mitigation controllers are typically needed.

Traffic performance metrics are exported in Prometheus format.

DDoS incidents are aggregated per source IP and logged to Clickhouse for analysis.

A dry-run (evaluation) - mode allows you to observe all reported incidents and metrics without blocking traffic..

Single Xeon Gold 6348 with ConnectX-6 dual 100Gbps reach 196Mpps and 176Gbps of filtering capacity.

u/krizhanovsky — 8 days ago