Keeping Latvia Connected with Zabbix and LMT

Post Syndicated from Michael Kammer original https://blog.zabbix.com/keeping-latvia-connected-with-zabbix-and-lmt/30834/

LMT is a mobile GSM/UMTS/LTE operator in Latvia. Founded on January 2, 1992, it was the first mobile network operator in the country. In addition to providing mobile network and ISP services, LMT uses innovative technologies and solutions to develop and maintain a variety of IT solutions for public and private organizations. Currently, LMT is the largest telecommunications service provider in the country, with over 1,660 base stations and over 1.5 million users as of 2024.

The challenge

LMT utilizes a variety of monitoring solutions for a variety of purposes – from tools performing and monitoring ping responses to vendor-specific solutions and all-in-one tools such as Zabbix. LMT has 2 data centers, and since the vast majority of services delivered by LMT can be considered critical, most of the relevant infrastructure is duplicated across them.

Multiple Zabbix instances are used in the environment, including Zabbix 5.0 with MySQL database backend, Zabbix 7.0 with PostgreSQL, and TimescaleDB. Over 3,000 hosts with approximately 500,000 items are monitored by Zabbix.

The solution

Here is one example of how Zabbix is used to monitor switch cabinets in LMT data centers. Switch cabinets contain devices to measure the electric current, which support Modbus protocol and which can in turn be used to collect data.

Modbus monitoring was achieved by using Zabbix agent2 with the official Modbus plugin. This was combined with NetBox and GraphQL. NetBox was used as the source of truth, providing information about power feed and various electrical characteristics, such as voltage, amperage, utilization, phase, and more. The data was collected from NetBox via HTTP agent checks and GraphQL, and a JSON result was created by utilizing Zabbix preprocessing features.

The information collected from NetBox is combined with Modbus data collection utilizing Zabbix agent2. The data collected by Zabbix agent2 is preprocessed after the collection. The collected data is normalized and used by Zabbix low-level discovery features to automatically create Zabbix items and triggers for the available resources. Finally, the resulting data is visualized on Zabbix dashboards.

The results

Monitoring with Zabbix has made reacting to changes in the monitored power feed (detecting spikes, observing gradual power feed changes, etc.) a much simpler proposition for LMT, which in turn improves service for its millions of users.

In conclusion

Zabbix has proven itself to be an ideal solution for telecommunications clients, making it easier than ever to keep track of network health and performance, driving a more positive customer experience and greater revenue growth in the process.

To learn more about what Zabbix can do for customers in telecommunications, get in touch with us.

The post Keeping Latvia Connected with Zabbix and LMT appeared first on Zabbix Blog.

I am thirty-eight years old

Post Syndicated from Eevee original https://eev.ee/blog/2025/07/21/i-am-thirty-eight-years-old/

There are several old, personal events that I’ve been rotating in my head for a very long time. I’m finally writing about them because I’ve just had the staggering realization that they all form one singular story. In some cases I’d never made the connection; in other cases I just plain forgot that things which happened within hours of each other were related.

This isn’t pleasant to write, and it won’t be pleasant to read. But I need it out of me.

I might have some of the details wrong, since I’m piecing together fragments from decades ago. This is a story, not a documentary. It’s about me, no one else.

content warning: underage sex; the active pursuit thereof by adults; bestiality mention.

I am five years old

My family moves from the UK (where my mother is from) to an American military base elsewhere (as my father is in the US military). In the switch from the UK to US school system, my parents push to have me put in second grade, on the grounds that I’ve been absorbing basically anything I’ve been exposed to since I was old enough to walk, and I’d be bored to tears in kindergarten.

This puts me two grades ahead for my age, which makes me two years younger than everyone around me, which will remain the case until I graduate from high school. I’m still quicker on the uptake than most everyone in my grade, and later get shifted a third year ahead in math. I never have school-age peers. This is normal.

I am eleven years old

I’m a picky eater. A lot of foods actively repulse me. My mother keeps making them for dinner anyway. I do my best to eat around them. Once she makes a quiche, and the taste of the cheddar makes me instantly want to vomit, so I can’t eat any of it. My father insists I sit at the table until I’m finished. I try a few bites but can’t bear it at all. I sit there for an hour, alone, before he gives up and lets me slink away.


I like computers. I don’t know much I can do with them besides toodle around in QBasic, but being able to write out instructions and have a thing happen feels like magic to me. I’m enamored. I’ll stay enamored for the rest of my life. I’m dimly aware that Windows and Office are also software, but they seem too incomprehensibly vast and complex to have been made, let alone made by fundamentally the same process I’m engaging in when I draw circles on the screen. I don’t consciously think about this, merely take for granted that they emerged fully-formed from a Company, which is somehow a different sort of entity from a person.

I think the Internet sounds cool but I don’t really know what there is to do on it besides download utilities I don’t need or read about The Microsoft Windows 95 Product Team! easter egg, which I only ever get to work once. I also find out that you can trick MS Paint into taking a screenshot of its own help window, which is cool because I don’t know how to take actual screenshots. That means I can make fake UIs, which is cool because I don’t know how to make real UIs, and I don’t know how to draw, either. Art, too, seems like some kind of foreign magic.

I’m really into Animorphs. I want to turn into a red-tailed hawk like Tobias and just fly away. I’m starting to do less well in school, and feel a budding hostility coming from my parents over it. I don’t have a lot of friends, don’t really have a sense of how to make them, and don’t think about it much. I feel a little out of place everywhere, but I always have, so it’s normal to me.

I hear about book 16, The Warning. It’s the one with Jake morphing into a rhino on the cover. I haven’t read it yet, but as I understand it, the plot centers around one of the protagonists typing “yeerk” or something into a search engine and finding exactly one result, which they then go investigate.

I think about this. I know about the Internet and search engines. But obviously, I think, entering “Yeerk” wouldn’t find anything, because Yeerks aren’t real. I try it anyway, just to see. I’m stunned to discover the world of fansites.

One of them has a forum and even a chat room attached. I join both and am stunned once more to discover that the Internet has other people on it, just hanging out. The other people are all teenagers, a little older than me, but I’m used to that. Half of them also have overbearing parents, and we bond over bitching about them. I can be kind of weird and awkward here and it’s fine. I’m really happy about having found this little sanctuary, and I start spending a lot more time online.

I am twelve or thirteen years old

I’m in ninth grade. My parents have put me in a private school, and it is fucking miserable. Homework is so tedious it feels akin to torture, so I just don’t do it, so my grades drop, so I get endlessly scolded and told I’m a disappointment. Chores, too, are agonizingly boring, and my mother regularly screams at me for not doing the dishes. None of the adults in my life — not parents, not teachers, not other school staff — suspect I have ADHD, perhaps because I’m smart and quiet, and I will eventually work it out myself some years later. Everyone else seems to believe their lecture will be the one to finally inspire me. My parents, who had once fought to save me from boredom, don’t recognize it happening in front of them.

I’m miserable at home from all the screaming, which makes me even more reclusive and less interested in school, which makes my grades all the more mediocre, which makes my parents yell more, which makes me more miserable.

Perhaps luckily, I don’t draw any conscious conclusions from any of this. I have no sense of how other people experience the world, and I haven’t really thought about, say, whether homework is easy for other people. I don’t even understand that I’m struggling, because I have nothing to compare it to. I don’t remember being a little kid very clearly, so as far as I can tell, it’s just always been like this. This is normal.

I have a little breakdown once and yell back at my mother, trying to convey… why I’m unhappy, without fully understanding it myself. She stands there, stunned. My father storms into the room, grabs me by my shirt collar, drags me upstairs to my bedroom, and throws me into it. He gets a utility knife and cuts through several random cables on my computer, then leaves without a word.

One of the cut cables is my keyboard, so to use my computer, I have to steal the keyboard from his computer and be sure to return it before he gets home and notices. Otherwise I would be completely isolated.

I learn a valuable lesson. Adults will hurt me, and this is normal. I hurt quite often, but I can’t do anything about it, and if I try, adults will hurt me more, so I just sit with it.

Sometimes I used to cry, but then my mother would hear and come tell me (in a caring voice) not to, because I’d give myself a headache. I took that to mean I just shouldn’t, so I’ve stopped.

My parents will later try to send me to a therapist a couple times — the problem is of course with me, not them, never them. I confide the encounter with my father, which makes it through some unseen grapevine, and I end up having to talk to some sort of military-HR person about it. Fearing that I might get put into the foster system and things will somehow end up worse, I lie that I had it coming. I hate lying, but I’ve learned that I have to lie to adults sometimes, so they won’t hurt me as much.

It isn’t mentioned again. My parents never say a word to me about it… until over a decade later, when my mother will tell me that I was physically imposing and physically threatened her. I will have no idea what she’s talking about — until that moment, the thought of attacking her in some way never crosses my mind. I’ll also be a late bloomer, insofar as I’ll bloom at all, and one of the few strong images I’ll remember from that day will be my mother looking down at me. But she will remain absolutely convinced that I was a threat, and that is why my father took the therefore-fully-justified actions he did, and I will be unable to disabuse her of this notion up through the end of her life. One day, many years later, she will die of cancer, having never believed me about my own motivations.

She will also, in the same conversation, chide me for not doing the dishes. I will be almost thirty years old.

I am fourteen years old

I’m in tenth grade, taking AP calculus. I’m good at it, but the homework is still mindnumbing.

I try to coast through my own life, attracting as little attention as possible from the adults around me who have the power to hurt me. I’m not fully successful. But when I’m hurt, it’s normal.


I’m still online a lot. I’ve gotten into doing, well, “web stuff”. It started out with posting little JavaScript snippets onto a small forum that doesn’t strip it out, or using a lot of <font> tags to make rainbow text. I’ve also gotten into Pokémon, and I feel a strong affection for tables and lists, so I start to make a Pokédex website. I don’t really know what I’m doing, and much of the effort comes from painstakingly retyping information from strategy guides or just other people’s websites, a process my future self will find comically rudimentary in hindsight. But it still feels like magic, and now I can share it with other people, too. I don’t know if anyone uses my website, but I’m delighted to have made it.

I’ve also hit puberty — several grades after everyone else, which has been a little awkward — and am starting to hear about this “sex” thing. It sounds pretty interesting. I end up combining my interests and joining an IRC channel dedicated to Pokémon porn. I’m probably the youngest person here, but no one cares, and I have no sense that there’s any reason anyone would care. There are some older teenagers here, as well as some adults, ranging all the way up to one 40-year-old — but he’s a completely regular cheerful guy who just genuinely enjoys writing fics about Sabrina having sex with an Alakazam or whatever.

But there’s also a guy who makes the occasional comment about “little girls”. There are at least one or two people who casually mention they have regular sex with their dogs. No one bats an eye at this, so I don’t, either. I have no basis for comparison, because I am fourteen years old. Maybe this is normal. Everyone else acts like it’s normal. It must be normal.

Sometimes people try to have cybersex with me. I’m not very good at it. I don’t really know anything about sex, but I start to pick it up from how other people describe it. It’s fun to write about this thing I’ve never done, this activity so mysterious that it almost feels like it must itself be fictional. It feels like it only exists in a bubble, completely detached from normal life.


Offline, I still barely know anyone. I’ve sort of gravitated to a couple other nerds at school, but outside of the fact that we are all vaguely aware how to make a website, we don’t have a lot in common. One of them is just kind of mean, even. This is normal. I’m two years into high school and just barely hitting the age when most people are starting it. I live in Hawai‘i at the moment, and almost everyone else has lived here their whole lives, but I’ve never even been to the same school for more than two years.

I find out about a little old-school website where furries can enter their location and find other furries nearby. I put in my zip code. Nobody else, it seems, lives in Hawai‘i.

I am still fourteen years old

We move, for the fourth time in my life, this time to the US mainland.

I update my zip code on the furry location website. Still nothing.

But then, out of nowhere, I get a message from someone I don’t know, who I’ll call 🐨. He’s eighteen, four years older than me, but that’s normal. He says he used to live in my town and he’s passing through for just a day or two, and would I like to meet up? I’m fucking ecstatic and say yes.

My mother drives me to where he’s staying. It has that 1970s wood panelling everywhere, which I might be seeing for the first time. It ultimately leaves me with a strange, otherworldly impression.

We talk a bit, and then he clearly wants to have sex. This hadn’t come up in our brief conversations beforehand. He seems surprised, but unswayed, that I haven’t had sex before. I don’t see any reason to turn him down — sex is supposed to be The Best Thing, after all.

We fool around some. It’s… fine. I don’t really like how he touches me. But hurting is normal, and this barely hurts at all, so I don’t say anything. I don’t even know how to say anything. People don’t show much interest in what I want. If anything, what I want seems to be an inconvenience to everyone else.

So I don’t say anything. It’s fine. This is normal.

Things peter out. I go home.

I’m no longer a virgin. It seems like something should be different. But nothing is. I don’t really think about it.

I try to keep in touch with 🐨, but he isn’t around much. He’s part of a little group of furries who all live in the same town and know each other, though, and they start to reach out, and I talk to some of them.

I am sixteen years old

[Hello, future Eevee here. Just letting you know, this is your last chance to back out. –ev]

I’ve just graduated high school. I’m so close to being away from my parents, to living on a college campus in a distant state. It’s exhilarating, but also terrifying, because I don’t really know how to live on my own. I’ve never done laundry or bought my own food. I don’t have a car or much money. I don’t really know how to do anything, other than make websites that look like they were made by a sixteen-year-old.

Over the past couple years, a number of guys have shown sexual interest in me. Almost all of them have been eighteen or older. I’ve met some of them at furry conventions and had sex with them. I didn’t really like any of it. But I’m desperately starved for affection and still assume the problem is with me, so I keep taking any opportunity I’m given. Maybe the next time will be better? I don’t know what else to do, so I keep doing what I’m doing.

I’m sufficiently self-aware of this inner turmoil to post about it. The only relevant comment I get is from someone I do not know and never otherwise speak to.

There is absolutely nothing wrong with giving it up for whoever wants it, especially at your age!

I am sixteen years old. This is normal. It can only be normal. No one else thinks anything of it, so I don’t either.

I attend another furry convention not long before I’m to move into a college dorm. My family’s situation is a little complicated at the moment — the house has been sold, my mother is in an apartment in our old town, my father is in an apartment in the new town, I’m off to a convention, and somehow this is all intended to coalesce later.

I have two sexual encounters that have… ramifications.


One is with 🐯, who I met somehow-or-other through 🐨’s group, despite not being local to them. [I have no memory whatsoever of how we met, why we started talking, or what we talked about. –ev]

He is twenty-six years old, a full decade my elder. He is openly interested in me because I’m underage. This is normal. After all, I am underage, and most of the people capable of travel are adults, so anyone who would have sex with me would at the very least have to find it acceptable that I’m underage.

We meet up at this con. He has sex with me. As usual, I don’t really know why I’m participating.

It’s the worst sex I will ever have in my life, deeply unpleasant and uncomfortable. I spend every single moment of it desperately wishing for it to be over, but I don’t know how to ask him to stop. I expect people to hurt me if I push back against what they want from me, but I’m not even cognizant of this — I see myself as just wanting to make people happy. Eventually I can’t take it any more and, in a flash of inspiration, offer to fellate him instead. I don’t really care for that, either, but it’s much less bad.

He gets me to promise I won’t tell anyone. I’m vaguely aware that this is the sort of thing he shouldn’t be doing, and I don’t want anyone in trouble on my behalf, so I agree.


There’s also 🐸, who I’m at least acquainted with, though we’re not exactly close. We hang out in a couple of the same IRC channels and have friends in common. Also, we’re the same age, almost exactly — we were born in the same month.

We also meet up and have sex. This time, at least, it seems like sort of maybe a good idea. At least it’s someone I know. It’s not great, but it’s not nightmarish, either.

He leaves his phone in my hotel room. I happen to catch a glance of him a little later, and so I run up to him to return his phone.

His father is with him, and is furious. He’s absolutely convinced I’m some kind of sex predator, despite that we’re exactly the same age and I look younger than 🐸. I go for my wallet but he sense my intentions and angrily insists he doesn’t care what kind of ID I have. He declares he’s placing me under citizen’s arrest, a thing I’ve never even heard of. But of course, I believe I have to go along with adults, or they’ll make things even worse.

He actually calls the police, who spend about two seconds checking my ID and say “yeah this is fine”. But then they want me to Make A Statement Down At The Station, so I go there, and I awkwardly describe a bland teenaged sexual encounter to someone who is a remarkably slow typist considering it seems to be their whole job.

And now I’m at a police station, and the police only want to release me into my parents’ custody, because I am sixteen years old. So they call my father, who is thankfully only a few hours’ drive away. And they put me in a chair and tell me that if I get up they’ll lock me in a cell. And I sit there, for two hours, while cops twenty feet away crack jokes with each other about the fact that two teenagers fucked. It may have been more or less than two hours, but I have undiagnosed ADHD, which has a way of stretching out activies like sitting in a chair doing nothing.

My father arrives, so silently furious that he accidentally drives into the wrong state on the way back to his apartment. He demands I log into my laptop, and he changes my password. Once I’m alone, because he’s off at his job as some sort of network administrator, I log into my laptop as admin, and change my password back. [Bright spot in this story. Fucking hilarious. Great job, li’l Eevee. –ev]

I then write a public post about the experience, which ends up linked on a now-defunct drama site. A bunch of people — who are we kidding here, more adult men — have a grand laugh about, again, two teenagers having sex. It probably doesn’t help that the post is written in an almost painfully cutesy affect, since I am sixteen years old. Several dramamongers approach me personally to be nasty, including one who calls me a “sick fuck” for “doing kids”. I am sixteen years old.

One of the convention staff also emails me with a brief rant, asking why I’m trying to destroy the convention by writing about things that happened to me, because now he’s fielding accusations that the con is full of pedophiles (presumably, again, because I had sex with someone my age). I have no idea what to say to this and never reply.

I do show it to 🐯, hoping for support. I happen to think that it’s absurd to blame someone for posting that they had sex at a con. But 🐯 insists I’m wrong and should apologize. I deflate.

My father later talks to me about the event. The conversation is extremely one-sided, because I know what happens if I push back against anything. He tells me I’m cold, calculating, manipulative, evil. He tells me I care only about myself. That I have no soul. That he doesn’t want me in the house.

I am sixteen years old.

All of this is normal.


The irony is, unfortunately, lost on me — because as requested, I erased mention of 🐯, the twenty-six-year-old who had sex with a sixteen-year-old, from my story. I erased it so thoroughly that I will forget these two encounters happened on the same weekend until many years later, even as I will continue to be lightly haunted by a memory of horrendous sex I felt trapped in.

Sometime in the next week and a half, I admit to someone that I had sex with 🐯. [I don’t know who, but I think I was pointedly asked, and I didn’t really know how to reject questions, and I’ve never liked lying, so I can extremely see how I would end up just saying it. –ev]

This makes it through some unseen grapevine, and suddenly 🐯 is furious with me, threatening to end the friendship [lol –ev] unless I fix it somehow, by convincingly lying to someone in this gossip chain that I don’t know. I make a half-hearted attempt, which I hate, and am (unsurprisingly) not believed.

Our relationship, such as it is, deteriorates, both because 🐯 himself deteriorates and because I don’t seem to have as much interest in trying to be friends with the person I had inescapable nightmare sex with. I must feel resentful of him without ever wanting to confront him directly, because I will later discover a few remaining scraps of one of our last conversations:

🐯: Gods eevee you’ve become such an annoying little bitch, I can’t beleive I was ever even nice to you. I wouldn’t have come within 20 feet of you had I known you were this kind of person.

I am sixteen years old. I am being spoken to by a twenty-six-year-old man.

🐯: gods, you and your stupid faces

I am sixteen years old, and I use emotes as punctuation o.o to a ridiculous degree ^o.o^ like multiple times per line o.o and the twenty-six-year-old man who was so eager to have sex with me is now sick to death of how juvenile I am. If only there were some way he could have foreseen this.

I am sixteen years old, but I begin to realize I do not give a shit about this loser who can only bed teenagers, nor about his big important opinion of me. He’s mad at me, but it doesn’t matter. Adults have been mad at me my entire life. What’s he going to do, type at me? I glaze over. I become laminated. I rebuff everything.

He only talks to me once more, to say he misses seeing me around. I don’t care.

I am sixteen years old. I start to wonder if this isn’t normal.

I am eighteen years old

Someone new joins the Pokémon porn IRC channel. They are fifteen years old. I don’t think anything of it, just as no one thought anything of it when I first entered. This is normal. Sort of.

I recognize their name from the artwork that decorates several Pokémon fansites. I find it fascinating that they were able to create any of that. It’s like magic to me.

There are a few artists here already, but this is the first whose art was truly captivating to me. Somehow it feels more impressive yet also more real, like I can believe it was done by a person. It plants the tiniest seed that maybe, one day, I can do it too.

I approach them to say hi, that I like their art. We have an actual conversation, then another. It’s like a breath of fresh air. So many people I’ve talked to have just wanted to hit on me way past the point of comfort and barely have a personality beyond that. But nothing like that happens here.

Instead we talk about actual things: Pokémon, and art, and our lives, and all the wrinkles they’ve had so far. They like cats. I like puzzles. Sometimes they struggle with pressure from overbearing commissioners, and something about that must resonate with me, so I try to be supportive. Later I’ll admit I’m still struggling with affection and my inability to tell people no, and they’ll be supportive of me, too.

It’s nice.

One day, it’ll even be normal.

I am thirty-two years old

I’m at the DMV. My best friend, someone I met a lifetime ago — in a Pokémon porn chat, of all places! — is here with me.

We live together, now, with our five cats, and we’ve recently escaped someone we both struggled to push back against. It feels like a small victory, but it was hard-earned.

We both sign the marriage certificate.

I am thirty-eight years old

I’m thinking back on a lot of things. It’s almost dizzying to see so many little threads of causality. My parents, even teachers, practically training me to think that whatever other people want is paramount. The deeply fucked-up culture of early-00’s Internet, where people could just openly announce their interest in doing sex crimes and no one batted an eye. Even the notion of a 14yo in a space dedicated to porn sounds unthinkable by today’s standards, but I poked my head in a lot of sex-themed places back in the day and not one of them cared how old I was.

I suppose I was well-spoken enough to sound older (aside from the hailstorm of o.o), but at the same time my social development was… almost non-existent. Hence how I had 20-somethings talking to me like I was an equal, all while I didn’t even understand how to say “I don’t like this”.

It took me a few more years to extricate myself from the weird little rut I’d dug for myself. It certainly helped that, around nineteen or twenty, vastly fewer random older men were interested in me. I’ll just, uh, try not to think too hard about that.

I don’t know what would have helped me avoid this. I keep thinking back to the vague ambient warnings about the Internet in the early 00s, which mainly focused on how anyone might be lying to you, might be pretending to be your age to trick you into sex later.

But that never happened to me. It was so unlike my experience that it almost feels laughable. Everyone I had sex with was pretty open that they wanted to have sex with me, and I agreed. No one ever warned me that sex without pretense could have emotional consequences. Everything in my (regular, offline) life that tried to tell me anything about sex was laser-focused on either pregnancy, STIs, or a guy in a van offering me candy. Like, hello, I was a deeply lonely sixteen-year-old. They didn’t need to offer me candy. They just offered me sex!

And there are lingering consequences — although now that I’m happily married and no longer on the radar of a bunch of people who really want to sleep with a teenager, they largely don’t matter in practice. But I had so much terrible, uncaring sex with men that I feel a little anxious even considering the thought of doing it again. There’s no one besides my spouse who I want to have sex with at the moment, but I still don’t like having that stuck in me. Like a shackle around my ankle that isn’t chained to anything, but it’s still there, and occasionally I feel it rattle.


But what really struck me, what really compelled me to write this down, was the realization of a strange pattern in the post-con sequence of events.

I think it’s fair to say that 🐯 used me for sex. I played along, but I think there’s at least a little bit of a responsibility gradient here.

But then, wait. Some group of people confirmed with me that I’d had sex with 🐯, and then I guess started gossipping about it, possibly even harassing him. Do you know how many people from that circle reached out to me, to see how I was doing?

Zero. Nada. I was useful only as long as it took to crystallize a nugget of Drama™, and then I was no longer needed.

So let me recap, this time with some editorializing:

  • A man ten years my elder used me for sex.
  • A bunch of adult men used me for laughs.
  • Some kind of gossip ring used me for, well, gossip.
  • A con staff member used me to vent about something that, frankly, furry conventions seemed to deal with a lot in the 00s.

Not one of these many adults reached out to see if I was okay. The con staff guy didn’t know about 🐯, of course, but they did know I’d had a harrowing experience and now was having at least one more — because those are what my whole fucking post was about! — and yet the only reason they went through the effort to find my email and reach out was to blame me for it again.

But it’s the gossip ring that I truly cannot excuse. The sole reason there was any gossip to be had at all was the idea that a twenty-six-year-old having sex with a sixteen-year-old is, in some sense, bad. But this clearly didn’t actually mean anything to them! It was “bad” only in the abstract, “bad” only in the sense that it gave them an excuse to ostracize the “bad” person, or laugh, or whatever the fuck they were doing.

It’s no different than that drama-site clown calling me a “sick fuck for doing kids” or whatever the hell. You could not possibly read a post about how I had to wait for my dad to pick me up because the cops wouldn’t release a minor and not grasp that I am a minor. Like, I AM “THE KIDS”! You, my fucking guy, right now, are being cruel towards the people you’re feigning concern for! But it just didn’t matter what happened or who was involved or who was hurt by it. Some asshole — almost certainly yet another adult — just wanted to be nasty, and they thought they saw someone they were allowed to be nasty to, so they were.

None of these people were interested in helping a sixteen-year-old. They only wanted to lash out at someone. The best I got was a tiny apology from 🐯, of all fucking people, who eventually caught on that I had not fully enjoyed our time together. But he can, of course, shove that entirely up his ass.


For many, many years, I’ve avoided making any mention of the thing with 🐸, my first exposure to the Internet “Drama” Circuit. I feared it would happen again, or that I’d be called a pedophile some more by people who just conveniently forget that we were the same age. I’d completely forgotten that 🐯 happened at the same time — because he’d basically asked me to detach him from the rest of it! Rediscovering that little tidbit has sure cast this story in a different light.

But like, fuck that, regardless? I will talk about my own life in whatever goddamn way I please. As soon as I decided to write this down, I couldn’t even remember why I’d ever been scared to do it. I guess I had been pretty thoroughly punished for writing it down the first time.

And sure, with decades’ worth of hindsight, it was perhaps not a good idea to have described my underage sex life — or the brief entanglement of the police with it — in public. But I still reject the idea that it was wrong to do so, or that any subsequent ragging on the convention was my fault. The actual story here (once 🐯 was stripped from it) was that Some Fucking Guy overreacted and called the cops because his teenaged kid got laid and he didn’t like that. That is fucking bananas behavior for a grown-ass man, but somehow fingers ended up pointed at literally everyone else. Clown world.


And various people have been calling me a pedophile ever since anyway. I’m often not privy to why. Like, as best as I could discern, the Something Awful Pokémon crowd branded me a pedo at one point because I had some cutesy, non-sexual, unremarkable artwork of myself (i.e., an Eevee person) as the background of my website for a while. Like that’s it, that’s the whole thing. Conspicuously, I am not attracted to, or otherwise interested in, teenagers or children, but that just doesn’t seem to factor in. You’d think it would be kind of important, right? But there’s this weird chain of semantic implications that lets you suggest someone actively molests children based purely on vibes, without ever having to identify any concrete child, and that seems kind of bad to me, but if I try to explain it I’ll probably be called a pedophile, because why would anyone but a pedophile defend pedophiles by nitpicking the definition of “pedophile”, huh?

Meanwhile, I was actively pursued by much older adults! 🐯 isn’t even the oldest guy who had sex with me when I was sixteen! But I’ve spent half a lifetime nervous about even admitting that, out of some nebulous fear of the reaction, all while I get lumped in with the sort of people who did it to me because my website background doesn’t have a suit and tie or what the fuck ever. What a joke.

It makes me feel fucking crazy, sometimes, to watch our culture obsess over rooting out anyone with a whiff of “pursues sex with a minor” with the same furor and accuracy as we once rooted out people possessed by Satan, but with “the minor” — a person — reduced to a sort of… fantasy hypothetical? Or just dropped entirely, I guess. “Pedophile” is the thing you call someone that makes you win, because that’s the worst thing, and they can’t prove you wrong. Even the richest man in the world does it.

Sometimes I think about what might happen in another timeline, where I’m sixteen now and I post this story. I’m sure 🐯 would be absolutely roasted right off the Internet — but how many people would still check on me for anything other than more sordid details?

…But then, who have I checked on? How many times have I had the opportunity, and not taken it?

I can definitely think of one or two. But that’s a whole other rabbit hole.


This sucks. I feel like basically every adult in my teenaged life let me down, and I have no idea what to do with that information.

I guess all I can do is try to reach back in time with the power of blogging and say what I desperately needed to hear.

If you are a teenager reading this — I don’t know how or why, but I am functionally powerless to stop you — and even a little bit of it has resonated with you, then let me impress upon you this: how you feel matters. Even if it doesn’t seem to matter to the people around you, the people with power over your life, it should still matter to you. Hold onto it, even if you have to hide it, and do not let go for anyone.

I’m sorry for whatever you may feel trapped in. I’m sorry if it’s hard. It might keep being hard for a little while. But if you keep looking, you will find people who care about what you want, who will have your back when you struggle to stand up for yourself, and who won’t punish you for hurting.

Please take care of yourself.

P.S.: Sex is an amplifier, not an automatic good time. It’s like Mario Party: a hilarious chaotic mess with the right people, but a horrible fucking slog with the wrong people.


I am thirty-eight years old.

I still think about what happened to me when I was sixteen. Not all the time. But sometimes.

Maybe after today, I can finally stop.

Beyond IAM access keys: Modern authentication approaches for AWS

Post Syndicated from Mitch Beaumont original https://aws.amazon.com/blogs/security/beyond-iam-access-keys-modern-authentication-approaches-for-aws/

When it comes to AWS authentication, relying on long-term credentials, such as AWS Identity and Access Management (IAM) access keys, introduces unnecessary risks; including potential credential exposure, unauthorized sharing, or theft. In this post, I present five common use cases where AWS customers traditionally use IAM access keys and present more secure alternatives that you should consider.

AWS CLI access: Embrace CloudShell

If you’re primarily using access keys for AWS Command Line Interface (AWS CLI) access, consider AWS CloudShell—a browser-based CLI that minimizes the need for local credential management while providing the same powerful CLI capabilities that you’re accustomed to.

AWS CLI with enhanced security: IAM Identity Center

If you need a more robust solution, AWS CLI v2 combined with AWS IAM Identity Center offers a superior authentication approach. This integration enables:

  • Centralized user management
  • Seamless multi-factor authentication (MFA) integration
  • Enhanced security controls

Configuration is straightforward using the AWS CLI documentation, and MFA can be enabled following the IAM Identity Center MFA guide.

Local development: IDE integration

For developers working in local environments, modern integrated development environments (IDEs) such as Visual Studio Code, with AWS Toolkit support offer secure authentication through IAM Identity Center. This alleviates the need for static access keys while maintaining a smooth development experience. Learn more about AWS IDE integrations.

AWS compute services and CI/CD access

When your applications and automation pipelines need AWS resource access, whether running on AWS compute services (Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Container Service (Amazon ECS), or AWS Lambda) or through continuous integration and delivery (CI/CD) tools, IAM roles can provide the ideal solution. These roles automatically manage temporary credential rotation and follow security best practices.

  • For AWS compute services: Use standard IAM roles with your compute resources. Review the EC2 IAM roles documentation for implementation details.
  • For AWS-hosted CI/CD: When using AWS CodePipeline or AWS CodeBuild for example, use service-linked roles to manage permissions securely.
  • For CI/CD tools self-hosted on Amazon EC2: If you’re running tools such as Jenkins or GitLab on AWS resources, use the instance profile roles the same as you would with other compute services.

For third-party CI/CD services (such as GitHub Actions, CircleCI, and so on), see External access requirements.

External access requirements

For scenarios involving third-party applications or on-premises workloads, AWS offers three methods:

  • Third-party applications: Implement temporary security credentials through IAM roles instead of static access keys. Never use root account access keys. See third-party access documentation.
  • On-premises workloads: Use AWS IAM Roles Anywhere to generate temporary credentials for non-AWS workloads. For more information, see Access for non AWS workloads.
  • CI/CD software as a service (SaaS): For cloud-based CI/CD services, use OpenID Connect (OIDC) integration with IAM roles to minimize the need for long-term credentials. This allows your CI/CD pipelines to obtain temporary credentials through trust relationships. See the AWS OIDC provider documentation for implementation details.

Best practice: Principle of least privilege

Regardless of your authentication method, always implement the principle of least privilege. This helps make sure that users and applications have only the permissions they need. For guidance on crafting precise IAM policies, see Techniques for writing least privilege IAM policies.

Note: AWS also offers policy generation based on AWS CloudTrail logs, helping you create permission templates based on actual usage patterns. Learn about this feature in the IAM policy generation documentation.

Conclusion

As you’ve seen, there are numerous secure alternatives to IAM access keys that you can use to enhance your AWS authentication strategy while reducing security risks. By using tools such as CloudShell, IAM Identity Center, IDE integrations, IAM roles, and IAM Roles Anywhere, you can implement robust authentication mechanisms that align with modern security best practices.Key takeaways:

  • Prefer temporary credentials over long-term access keys
  • Choose the authentication method that best fits your use case
  • Implement the principle of least privilege across all access methods
  • Take advantage of the built-in tools provided by AWS for policy generation and management
  • Regularly review and update your authentication methods as new solutions become available

By making these changes, you can not only improve your security posture but also streamline your authentication processes across your AWS environment. Start small by identifying your current IAM access key use cases and gradually transition to these more secure alternatives. Your future self—and your security team—will thank you.

If you have feedback about this post, submit comments in the Comments section below.

Mitch Beaumont

Mitch Beaumont

Mitch is a Principal Solutions Architect for Amazon Web Services based in Sydney, Australia. Mitch works with some of Australia’s largest financial services customers, helping them to continually raise the security bar for the products and features that they build and ship. Outside of work, Mitch enjoys spending time with his family, photography, and surfing.

Building resilient multi-tenant systems with Amazon SQS fair queues

Post Syndicated from Maximilian Schellhorn original https://aws.amazon.com/blogs/compute/building-resilient-multi-tenant-systems-with-amazon-sqs-fair-queues/

Today, AWS introduced Amazon Simple Queue Service (Amazon SQS) fair queues, a new feature that mitigates noisy neighbor impact in multi-tenant systems. With fair queues, your applications become more resilient and easier to operate, reducing operational overhead while improving quality of service for your customers.

In distributed architectures, message queues have become the backbone of resilient system design. They act as buffers between components, allowing services to process work asynchronously and at their own pace. When a sudden traffic spike hits your application, queues prevent cascading failures by buffering work and ensuring that downstream services aren’t overwhelmed. Amazon SQS has long been a go-to solution for developers building scalable applications because it’s a fully managed serverless solution that can seamlessly scale to ingest millions of messages per second.

In this post, you learn how to use Amazon SQS fair queues and understand their inner workings through a practical example.

Overview

Many modern applications follow a multi-tenant architecture, where a single application instance serves multiple tenants. A tenant is any entity that shares resources with others. It could be a customer, client application, or request type. This approach reduces operational costs and simplifies maintenance through efficient resource utilization. One example of such shared resources are queues and their associated consumer capacity.

However, multi-tenant systems face challenges when one tenant becomes a noisy neighbor. This tenant impacts others by overutilizing your system’s resources. With queues, this tenant causes a backlog by sending a large volume of messages or by requiring longer processing time. Regular queues deliver older messages first, which increases message dwell time for all tenants in such scenarios. This makes it difficult to maintain quality of service and forces teams to over-provision resources or build complex custom solutions.

Amazon SQS fair queues help maintain low dwell time for other tenants when there is a noisy neighbor. This happens transparently without requiring changes to your existing message processing logic. You define what constitutes a tenant in your system, and Amazon SQS handles the complex orchestration of mitigating noisy neighbor impact.

How it works

Amazon SQS continually monitors the distribution of messages received but not yet deleted (in-flight) by consumers across all tenants. When the system detects an imbalance:

  1. It identifies the noisy tenant, the one causing the queue to build a backlog.
  2. It automatically adjusts message delivery order to prioritize messages belonging to quiet (non-noisy) tenants.
  3. It maintains overall queue throughput.

Consider the following example that consists of a multi-tenant queue and four different tenants (A, B, C, and D).

In the steady state condition, the queue has no backlog, and in-flight messages are evenly distributed among tenants. All messages are consumed immediately when they land in the queue. The dwell time of messages is low for all tenants. Notice that not all consumer capacity is fully utilized in this steady state. The steady state condition is illustrated in the following diagram.

Figure 1: A multi-tenant queue in steady state condition

Figure 1: A multi-tenant queue in steady state condition

Now consider a noisy tenant scenario in which the number of messages of tenant A increases significantly and creates a backlog in the queue. Consumers are busy processing the messages mostly from tenant A, and messages from other tenants are waiting in the backlog, leading to a higher dwell time for all tenants. This noisy tenant scenario is illustrated in the following screenshot.

Figure 2: A multi-tenant queue with a noisy tenant

Figure 2: A multi-tenant queue with a noisy tenant

When a single tenant starts to occupy a significant portion of consumer resources, Amazon SQS fair queues considers this tenant as a noisy neighbor and prioritizes returning messages belonging to other tenants. This prioritization helps maintain low dwell times for quiet tenants (B, C, D), while the dwell time for tenant A’s messages will be elevated until the queue backlog is consumed—but without impacting other tenants. Fair queues are illustrated in the following diagram.

Figure 3: A multi-tenant queue with fair queues

Figure 3: A multi-tenant queue with fair queues

Amazon SQS doesn’t limit the consumption rate per tenant. Consumers can receive messages from noisy neighbor tenants when there is consumer capacity and the queue has no other messages to return. Like Amazon SQS standard queues, fair queues allow virtually unlimited throughput, and there are no limits on the number of tenants you can have in your queue.

How to use

The following is a quick overview of how to get started with Amazon SQS fair queues in your applications. See the feature documentation for a detailed walkthrough. These are the high-level steps the walkthrough follows:

  1. Enable Amazon SQS fair queues by adding a tenant identifier (MessageGroupId) to your messages
  2. Configure Amazon CloudWatch metrics to monitor Amazon SQS fair queues behavior
  3. You can use the example application to observe the Amazon SQS fair queues behavior with varying message volumes

Enable Amazon SQS fair queues by adding a tenant identifier (MessageGroupId) to your messages

Your message producers can add a tenant identifier by setting a MessageGroupId on an outgoing message:

// Send message with tenant identifier
SendMessageRequest request = new SendMessageRequest()
    .withQueueUrl(queueUrl)
    .withMessageBody(messageBody)
    .withMessageGroupId("tenant-123");  // Tenant identifier
sqs.sendMessage(request);

The new fairness capability will be applied automatically in all Amazon SQS standard queues for messages with the MessageGroupId property. It’s important to mention that it doesn’t require any change in the consumer code. It has no impact on API latency and doesn’t come with any throughput limitations.

Configure Amazon CloudWatch metrics to monitor Amazon SQS fair queues behavior

You can monitor Amazon SQS fair queues with Amazon CloudWatch metrics. The following terms are important in this context:

  • Noisy groups – A noisy message group represents a noisy neighbor tenant of a multi-tenant queue.
  • Quiet groups – Message groups excluding noisy groups.

When you use fair queues, Amazon SQS now emits the following additional metrics:

  • ApproximateNumberOfNoisyGroups
  • ApproximateNumberOfMessagesVisibleInQuietGroups
  • ApproximateNumberOfMessagesNotVisibleInQuietGroups
  • ApproximateNumberOfMessagesDelayedInQuietGroups
  • ApproximateAgeOfOldestMessageInQuietGroups

The new ApproximateNumberOfNoisyGroups metric gives the number of message groups (tenants) that are considered noisy in a fair queue. This metric helps identify the number of potential noisy neighbors in multi-tenant environments by tracking message groups consuming disproportionate resources. Use this metric to set alarms that trigger when the number of noisy groups exceeds your acceptable threshold, indicating potential queue fairness issues.

Amazon SQS already provides several standard queue-level metrics that offer approximate insights into the queue’s state, message processing, and potential bottlenecks. These metrics look at all messages in a queue. With fair queues, there’s a new set of four equivalent metrics, shown in the preceding list, that allow the exclusion of messages from noisy neighbor groups and target only quiet groups (non-noisy tenants). Hence, they all have the InQuietGroups suffix.

To monitor the effect of Amazon SQS fair queues you can compare metrics that have the InQuietGroups suffix with standard queue-level metrics. During traffic surges for a specific tenant, the general queue-level metrics might reveal increasing backlogs or older message ages. However, looking at the quiet groups in isolation, you can identify that most non-noisy message groups or tenants aren’t impacted, and you can estimate the total number of impacted message groups.

The following graph shows how the standard queue backlog metric (ApproximateNumberOfMessagesVisible) increases due to a noisy tenant while the backlog for non-noisy tenants (ApproximateNumberOfMessagesVisibleInQuietGroups) remains low.

Figure 4: Queue backlog for noisy and quiet groups

Figure 4: Queue backlog for noisy and quiet groups

While these new metrics provide a good overview of Amazon SQS fair queues behavior, it can be beneficial to understand which specific tenant is causing the load. Use Amazon CloudWatch Contributor Insights to see metrics about the top-N contributors, the total number of unique contributors, and their usage. This is especially helpful in scenarios where you’re dealing with thousands of tenants that would otherwise lead to high-cardinality data (and cost) when emitting traditional metrics. The following screenshot shows an example of a Contributor Insights dashboard on the AWS console that visualizes the top 10 contributors based on MessageGroupId.

Figure 5: Container Insights ReceivedMessagesPerMessageGroupId dashboard

Figure 5: Container Insights ReceivedMessagesPerMessageGroupId dashboard

Contributor Insights creates these metrics based on data from your application log output. Let your code log the number of messages being processed, and the corresponding MessageGroupId within your application. You can find a full example in the sample application in the next section.

Example application

To make it even more straightforward to get started, we’ve prepared an example application that you can use to observe the Amazon SQS fair queues behavior with varying message volumes. You can find the source code repository, infrastructure as code (IaC), and the instructions to run the sample on the sqs-fair-queues repository on GitHub.

The example application includes a load generator to simulate multi-tenant traffic and provides an Amazon CloudWatch dashboard that displays the most important metrics to visualize fair queue behavior. The following screenshot shows an example of the dashboard.


Figure 6: CloudWatch FairQueuesDashboard

Conclusion

Amazon SQS fair queues automatically mitigates the noisy neighbor impact in multi-tenant queues. Even when one tenant generates high message volumes or requires longer processing times (that is, becomes a noisy neighbor), the feature maintains consistent message dwell times for other tenants. When you add a tenant identifier to your messages, Amazon SQS fair queues will automatically detect and mitigate noisy neighbor impact, providing fair access to the queue for other tenants.

We recommend reviewing the Amazon SQS Developer Guide to get started and exploring the sample applications to test the behavior with varying message volumes.

Optimizing vector search using Amazon S3 Vectors and Amazon OpenSearch Service

Post Syndicated from Sohaib Katariwala original https://aws.amazon.com/blogs/big-data/optimizing-vector-search-using-amazon-s3-vectors-and-amazon-opensearch-service/

NOTE: As of July 15, the Amazon S3 Vectors Integration with Amazon OpenSearch Service is in preview release and is subject to change.

The way we store and search through data is evolving rapidly with the advancement of vector embeddings and similarity search capabilities. Vector search has become essential for modern applications such as generative AI and agentic AI, but managing vector data at scale presents significant challenges. Organizations often struggle with the trade-offs between latency, cost, and accuracy when storing and searching through millions or billions of vector embeddings. Traditional solutions either require substantial infrastructure management or come with prohibitive costs as data volumes grow.

We now have a public preview of two integrations between Amazon Simple Storage Service (Amazon S3) Vectors and Amazon OpenSearch Service that give you more flexibility in how you store and search vector embeddings:

  1. Cost-optimized vector storage: OpenSearch Service managed clusters using service-managed S3 Vectors for cost-optimized vector storage. This integration will support OpenSearch workloads that are willing to trade off higher latency for ultra-low cost and still want to use advanced OpenSearch capabilities (such as hybrid search, advanced filtering, geo filtering, and so on).
  2. One-click export from S3 Vectors: One-click export from an S3 vector index to OpenSearch Serverless collections for high-performance vector search. Customers who build natively on S3 Vectors will benefit from being able to use OpenSearch for faster query performance.

By using these integrations, you can optimize cost, latency, and accuracy by intelligently distributing your vector workloads by keeping infrequent queried vectors in S3 Vectors and using OpenSearch for your most time-sensitive operations that require advanced search capabilities such as hybrid search and aggregations. Further, OpenSearch performance tuning capabilities (that is, quantization, k-nearest neighbor (knn) algorithms, and method-specific parameters) help to improve the performance with little compromise of cost or accuracy.

In this post, we walk through this seamless integration, providing you with flexible options for vector search implementation. You’ll learn how to use the new S3 Vectors engine type in OpenSearch Service managed clusters for cost-optimized vector storage and how to use one-click export from S3 Vectors to OpenSearch Serverless collections for high-performance scenarios requiring sustained queries with latency as low as 10ms. By the end of this post, you’ll understand how to choose and implement the right integration pattern based on your specific requirements for performance, cost, and scale.

Service overview

Amazon S3 Vectors is the first cloud object store with native support to store and query vectors with sub-second search capabilities, requiring no infrastructure management. It combines the simplicity, durability, availability, and cost-effectiveness of Amazon S3 with native vector search functionality, so you can store and query vector embeddings directly in S3. Amazon OpenSearch Service provides two complementary deployment options for vector workloads: Managed Clusters and Serverless Collections. Both harness Amazon OpenSearch’s powerful vector search and retrieval capabilities, though each excels in different scenarios. For OpenSearch users, the integration between S3 Vectors and Amazon OpenSearch Service offers unprecedented flexibility in optimizing your vector search architecture. Whether you need ultra-fast query performance for real-time applications or cost-effective storage for large-scale vector datasets, this integration lets you choose the approach that best fits your specific use case.

Understanding Vector Storage Options

OpenSearch Service provides multiple options for storing and searching vector embeddings, each optimized for different use cases. The Lucene engine, which is OpenSearch’s native search library, implements the Hierarchical Navigable Small World (HNSW) method, offering efficient filtering capabilities and strong integration with OpenSearch’s core functionality. For workloads requiring additional optimization options, the Faiss engine (Facebook AI Similarity Search) provides implementations of both HNSW and IVF (Inverted File Index) methods, along with vector compression capabilities. HNSW creates a hierarchical graph structure of connections between vectors, enabling efficient navigation during search, while IVF organizes vectors into clusters and searches only relevant subsets during query time. With the introduction of the S3 engine type, you now have a cost-effective option that uses Amazon S3’s durability and scalability while maintaining sub-second query performance. With this variety of options, you can choose the most suitable approach based on your specific requirements for performance, cost, and accuracy. For instance, if your application requires sub-50 ms query responses with efficient filtering, Faiss’s HNSW implementation is the best choice. Alternatively, if you need to optimize storage costs while maintaining reasonable performance, the new S3 engine type would be more appropriate.

Solution overview

In this post, we explore two primary integration patterns:

OpenSearch Service managed clusters using service-managed S3 Vectors for cost-optimized vector storage.

For customers already using OpenSearch Service domains who want to optimize costs while maintaining sub-second query performance, the new Amazon S3 engine type offers a compelling solution. OpenSearch Service automatically manages vector storage in Amazon S3, data retrieval, and cache optimization, eliminating operational overhead.

One-click export from an S3 vector index to OpenSearch Serverless collections for high-performance vector search.

For use cases requiring faster query performance, you can migrate your vector data from an S3 vector index to an OpenSearch Serverless collection. This approach is ideal for applications that require real-time response times and gives you the benefits that come with Amazon OpenSearch Serverless, including advanced query capabilities and filters, automatic scaling and high availability, and no administration. The export process automatically handles schema mapping, vector data transfer, index optimization, and connection configuration.

The following illustration shows the two integration patterns between Amazon OpenSearch Service and S3 Vectors.

Prerequisites

Before you begin, make sure you have:

  • An AWS account
  • Access to Amazon S3 and Amazon OpenSearch Service
  • An OpenSearch Service domain (for the first integration pattern)
  • Vector data stored in S3 Vectors (for the second integration pattern)

Integration pattern 1: OpenSearch Service managed cluster using S3 Vectors

To implement this pattern:

  1. Create an OpenSearch Service Domain using OR1 instances on OpenSearch version 2.19.
    1. While creating the OpenSearch Service domain, choose the Enable S3 Vectors as an engine option in the Advanced features section.
  2. Sign in to OpenSearch Dashboards and open Dev tools. Then create your knn index and specify s3vector as the engine.
PUT my-first-s3vector-index
{
  "settings": {
    "index": {
      "knn": true
    }
  },
  "mappings": {
    "properties": {
        "my_vector1": {
          "type": "knn_vector",
          "dimension": 2,
          "space_type": "l2",
          "method": {
            "engine": "s3vector"
          }
        },
        "price": {
          "type": "float"
        }
    }
  }
} 
  1. Index your vectors using the Bulk API:
POST _bulk
{ "index": { "_index": "my-first-s3vector-index", "_id": "1" } }
{ "my_vector1": [2.5, 3.5], "price": 7.1 }
{ "index": { "_index": "my-first-s3vector-index", "_id": "3" } }
{ "my_vector1": [3.5, 4.5], "price": 12.9 }
{ "index": { "_index": "my-first-s3vector-index", "_id": "4" } }
{ "my_vector1": [5.5, 6.5], "price": 1.2 }
{ "index": { "_index": "my-first-s3vector-index", "_id": "5" } }
{ "my_vector1": [4.5, 5.5], "price": 3.7 }
{ "index": { "_index": "my-first-s3vector-index", "_id": "6" } }
{ "my_vector1": [1.5, 2.5], "price": 12.2 }
  1. Run a knn query as usual:
GET my-first-s3vector-index/_search
{
  "size": 2,
  "query": {
    "knn": {
      "my_vector1": {
        "vector": [2.5, 3.5],
        "k": 2
      }
    }
  }
}

The following animation demonstrates steps 2-4 above.

Integration pattern 2: Export S3 vector indexes to OpenSearch Serverless

To implement this pattern:

  1. Navigate to the AWS Management Console for Amazon S3 and select your S3 vector bucket.

  1. Select a vector index that you want to export. Under Advanced search export, select Export to OpenSearch.

Alternatively, you can:

  1. Navigate to the OpenSearch Service console.
  2. Select Integrations from the navigation pane.
  3. Here you will see a new Integration Template to Import S3 vectors to OpenSearch vector engine – preview. Select Import S3 vector index.

  1. You will now be brought to the Amazon OpenSearch Service integration console with the Export S3 vector index to OpenSearch vector engine template pre-selected and pre-populated with your S3 vector index Amazon Resource Name (ARN). Select an existing role that has the necessary permissions or create a new service role.

  1. Scroll down and choose Export to start the steps to create a new OpenSearch Serverless collection and copy data from your S3 vector index into an OpenSearch knn index.

  1. You will now be taken to the Import history page in the OpenSearch Service console. Here you will see the new job that was created to migrate your S3 vector index into the OpenSearch serverless knn index. After the status changes from In Progress to Complete, you can connect to the new OpenSearch serverless collection and query your new OpenSearch knn index.

The following animation demonstrates how to connect to the new OpenSearch serverless collection and query your new OpenSearch knn index using Dev tools.

Cleanup

To avoid ongoing charges:

  1. For Pattern 1:
  1. For Pattern 2:
    • Delete the import task from the Import history section of the OpenSearch Service console. Deleting this task will remove both the OpenSearch vector collection and the OpenSearch Ingestion pipeline that was automatically created by the import task.

Conclusion

The innovative integration between Amazon S3 Vectors and Amazon OpenSearch Service marks a transformative milestone in vector search technology, offering unprecedented flexibility and cost-effectiveness for enterprises. This powerful combination delivers the best of both worlds: The renowned durability and cost efficiency of Amazon S3 merged seamlessly with the advanced AI search capabilities of OpenSearch. Organizations can now confidently scale their vector search solutions to billions of vectors while maintaining control over their latency, cost, and accuracy. Whether your priority is ultra-fast query performance with latency as low as 10ms through OpenSearch Service, or cost-optimized storage with impressive sub-second performance using S3 Vectors or implementing advanced search capabilities in OpenSearch, this integration provides the perfect solution for your specific needs. We encourage you to get started today by trying S3 Vectors engine in your OpenSearch managed clusters and testing the one-click export from S3 vector indexes to OpenSearch Serverless.

For more information, visit:


About the Authors

Sohaib Katariwala is a Senior Specialist Solutions Architect at AWS focused on Amazon OpenSearch Service based out of Chicago, IL. His interests are in all things data and analytics. More specifically he loves to help customers use AI in their data strategy to solve modern day challenges.

Mark Twomey is a Senior Solutions Architect at AWS focused on storage and data management. He enjoys working with customers to put their data in the right place, at the right time, for the right cost. Living in Ireland, Mark enjoys walking in the countryside, watching movies, and reading books.

Sorabh Hamirwasia is a senior software engineer at AWS working on the OpenSearch Project. His primary interest include building cost optimized and performant distributed systems.

Pallavi Priyadarshini is a Senior Engineering Manager at Amazon OpenSearch Service leading the development of high-performing and scalable technologies for search, security, releases, and dashboards.

Bobby Mohammed is a Principal Product Manager at AWS leading the Search, GenAI, and Agentic AI product initiatives. Previously, he worked on products across the full lifecycle of machine learning, including data, analytics, and ML features on SageMaker platform, deep learning training and inference products at Intel.

AWS Weekly Roundup: Kiro, AWS Lambda remote debugging, Amazon ECS blue/green deployments, Amazon Bedrock AgentCore, and more (July 21, 2025)

Post Syndicated from Donnie Prakoso original https://aws.amazon.com/blogs/aws/aws-weekly-roundup-kiro-aws-lambda-remote-debugging-amazon-ecs-blue-green-deployments-amazon-bedrock-agentcore-and-more-july-21-2025/

I’m writing this as I depart from Ho Chi Minh City back to Singapore. Just realized what a week it’s been, so let me rewind a bit. This week, I tried my first Corne keyboard, wrapped up rehearsals for AWS Summit Jakarta with speakers who are absolutely raising the bar, and visited Vietnam to participate as a technical keynote speaker in AWS Community Day Vietnam, an energetic gathering of hundreds of cloud practitioners and AWS enthusiasts who shared knowledge through multiple technical tracks and networking sessions.

What I presented was a keynote titled “Reinvent perspective as modern developers”, featuring serverless, containers, and how we can cut the learning curves and be more productive with Amazon Q Developer and Kiro. I got a chance to discuss with a couple of AWS Community Builders and community developers, who shared how Amazon Q Developer actually addressed their challenges on building applications, with several highlighting significant productivity improvements and smoother learning curves in their cloud development journeys.

As I head back to Singapore, I’m carrying with me not just memories of delicious cà phê sữa đá (iced milk coffee), but also fresh perspectives and inspirations from this vibrant community of cloud innovators.

Introducing Kiro
One of the highlights from last week was definitely Kiro, an AI IDE that helps you deliver from concept to production through a simplified developer experience for working with AI agents. Kiro goes beyond “vibe coding” with features like specs and hooks that help get prototypes into production systems with proper planning and clarity.

Join the waitlist to get notified when it becomes available.

Last week’s AWS Launches
In other news, last week we had AWS Summit in New York, where we released several services. Here are some launches that caught my attention:

Console to IDE Integration

ECS Blue-Green Deployments

AWS Free Tier Enhanced Benefits

  • Monitor and debug event-driven applications with new Amazon EventBridge logging — Amazon EventBridge now provides enhanced logging capabilities that offer comprehensive event lifecycle tracking with detailed information about successes, failures, and status codes. This new observability feature addresses microservices and event-driven architecture monitoring challenges by providing visibility into the complete event journey.

EventBridge Enhanced Logging

S3 Vectors Overview

  • Amazon EKS enables ultra-scale AI/ML workloads with support for 100k nodes per cluster — Amazon EKS now supports up to 100,000 worker nodes in a single cluster, enabling customers to scale up to 1.6 million AWS Trainium accelerators or 800K NVIDIA GPUs. This industry-leading scale empowers customers to train trillion-parameter models and advance AGI development while maintaining Kubernetes conformance and familiar developer experience.

EKS Ultra-Scale Performance Improvements

From AWS Builder Center
In case you missed it, we just launched AWS Builder Center and integrated community.aws. Here are my top picks from the posts:

Upcoming AWS events
Check your calendars and sign up for upcoming AWS and AWS Community events:

  • AWS re:Invent – Register now to get a head start on choosing your best learning path, booking travel and accommodations, and bringing your team to learn, connect, and have fun. If you’re an early-career professional, you can apply to the All Builders Welcome Grant program, which is designed to remove financial barriers and create diverse pathways into cloud technology.
  • AWS Builders Online Series – If you’re based in one of the Asia Pacific time zones, join and learn fundamental AWS concepts, architectural best practices, and hands-on demonstrations to help you build, migrate, and deploy your workloads on AWS.
  • AWS Summits — Join free online and in-person events that bring the cloud computing community together to connect, collaborate, and learn about AWS. Register in your nearest city: Taipei (July 29), Mexico City (August 6), and Jakarta (June 26–27).
  • AWS Community Days — Join community-led conferences that feature technical discussions, workshops, and hands-on labs led by expert AWS users and industry leaders from around the world: Singapore (August 2), Australia (August 15), Adria (September 5), Baltic (September 10), and Aotearoa (September 18).

You can browse all upcoming AWS led in-person and virtual developer-focused events.

That’s all for this week. Check back next Monday for another Weekly Roundup!

— Donnie

This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!


Join Builder ID: Get started with your AWS Builder journey at builder.aws.com

[$] When free-software communities unite for privacy

Post Syndicated from jzb original https://lwn.net/Articles/1029769/

At DebConf25 in Brest,
France, the
talk
“When Free Software Communities Unite: Tails, Tor, and the
Fight for Privacy” was delivered by a man who introduced himself only
as intrigeri. He delivered an overview of the Tor Project, its mission, and
the projects under the umbrella. He also spoke about how the
organization depends on Debian, and plans for the software it
delivers.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/1030774/

Security updates have been issued by AlmaLinux (java-1.8.0-openjdk), Debian (angular.js and batik), Fedora (chromium, pypy, screen, unbound, wine, and wine-mono), Mageia (djvulibre, quictls, and redis), Red Hat (avahi, gnome-remote-desktop, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-21-openjdk, kernel, kernel-rt, python-setuptools, redis, and valkey), SUSE (chromedriver, coreutils, cosign, docker, FastCGI, ffmpeg-4, fractal, gimp, glib2, ImageMagick, iputils, java-17-openjdk, java-24-openjdk, jq, kubelogin, kubernetes1.23, kubernetes1.24, kubernetes1.26, python-requests, python3, rmt-server, rustup, and thunderbird), and Ubuntu (apache2).

Streamline DevOps troubleshooting: Integrate CloudWatch investigations with Slack

Post Syndicated from Paige Broderick original https://aws.amazon.com/blogs/devops/streamline-devops-troubleshooting-integrate-cloudwatch-investigations-with-slack/

Infrastructure alerts pose a challenge for DevOps teams, particularly when they occur outside of regular business hours. The complexity isn’t merely in receiving notifications, it lies in rapidly assessing their severity and determining the root cause. This challenge is compounded when upstream service disruptions cascade into multiple downstream alerts, creating a confusion of notifications that mask the true source of the problem. DevOps teams find themselves working backwards through a complex web of interconnected services, unsure whether to start investigating at the application, network, or infrastructure level.

To reduce resolution time and alert root cause analysis, AWS introduced CloudWatch Investigations, a generative AI-powered capability within Amazon CloudWatch. Powered by Amazon Q Developer, a generative AI–powered assistant for software development, CloudWatch investigations analyzes multiple metrics, logs, and deployment events to provide suggestions for remediation and root-cause analyses, reducing alarm resolution time. A key advantage of this feature is the ability to integrate these findings directly into Microsoft Teams and Slack, making sure developers and stakeholders receive immediate alerts when issues arise. This centralized collaboration approach enables teams to work together efficiently, reducing duplicate efforts and facilitating consistent problem-solving across the organization.

In this blog post, we will walk through how to integrate CloudWatch Investigations with Slack channels and demonstrate how to interact with investigations in Slack.

Overview of the solution

CloudWatch Investigations can be started in multiple ways, like from existing Amazon CloudWatch log insights, metrics, or alarms. To demonstrate CloudWatch Investigations functionalities, we will use CloudWatch alarms in a sample web application available in the aws-samples GitHub repository. Steps on how to deploy this web app in your AWS environment, via a CloudFormation template, can be found here. You can learn more about the architecture of the resources deployed in the AWS One Observability workshop. If you choose to deploy the sample web application, you will be responsible for all service charges associated with the CloudFormation template deployment. Alternatively, you can use existing CloudWatch alarms in your environment. Examples of common Amazon CloudWatch alarms include: MemoryUtilization, CPUUtiliziation, 5xxErrors and 4xxError. A full list of available alarms can be found here.

For this blog, we will utilize a pre-configured alarm to monitor when one of the website services, backed by an Application Load Balancer, experiences abnormal response times. When the alarm triggers, CloudWatch Investigations automatically initiates an investigation, analyzing both the current alarm state and 90 days of CloudTrail event history to generate hypotheses and determine potential root causes. The investigation insights are published to a Slack channel via Amazon Q Developer in Chat Applications and Amazon Simple Notification Service (SNS).

Figure 1. Architecture diagram of the services involved in the investigation integration in Slack

Prerequisites

  1. Launch the Amazon CloudFormation template associated with the One Observability lab outlined in the AWS Samples GitHub.
  2. Set up a Standard Amazon SNS topic by following the instructions outlined here. To enable CloudWatch investigations to send notifications to Slack, you must add an access policy to the Amazon SNS topic, an example can be found here.
  3. When the topic configuration is complete, navigate to Amazon Q Developer in Chat Applications (formerly AWS Chatbot) to configure the integration between Amazon Q and Slack by following the instructions outlined here. To allow channel members to interact with the investigation in Slack, add the following permission templates to the Channel role settings: Notification Permissions, Amazon Q Permissions, and Amazon Q Operations assistant permissions. More details on these permissions can be located here.

Setting up CloudWatch Investigations

To get started, navigate to the Amazon CloudWatch console. Choose AI Operations and then Configuration.

Figure 2. Configure for this account button within the AWS Console

Before we can set up an investigation, we need to create an investigation group. This is an organizational structure to manage common properties of the investigation like retention requirements, encryption, access permissions and the SNS topic linked. Click Configure for this account and follow the prompts in the console to set up the investigation group. Detailed explanations for each prompt are located in the documentation here. For this demo, we left the default options for steps 1 and 2 of the prompts. In step 3, please select the existing SNS topic created in the prerequisites section.

Figure 3. Select SNS topic for Q Developer Operational Insights

For the investigation trigger, we will use an existing alarm created by the CloudFormation deployment mentioned at the beginning of this blog. The sample alarm is named:

ApplicationInsights/Services/AWS/ApplicationELB/TargetResponseTime/app/Servic-lista-... 

and it goes into ALARM state when one of the website services, backed by an Application Load Balancer, experiences abnormal response times.

To configure this alarm to automatically start an investigation when it goes into an ALARM state:

  1. In the CloudWatch console, choose Alarms, All alarms
  2. Search for the alarm name and click on it
  3. Choose Actions, Edit
  4. Choose Next once to skip the metrics and conditions section
  5. Choose Add investigation action and then select your investigation group as outlined in figure 4
  6. Choose Skip to Preview and create, then choose Update alarm

Figure 4. Configure alarm to automatically start investigations

Testing the solution

At this point, we are ready to test the solution. To simulate a website traffic overload and trigger the alarm, we are going to use Amazon ECS tasks deployed as part of the sample web application. Open up CloudShell and run the following command:

PETLISTADOPTIONS_CLUSTER=$(aws ecs list-clusters | jq '.clusterArns[]|select(contains("PetList"))' -r)

TRAFFICGENERATOR_SERVICE=$(aws ecs list-services --cluster $PETLISTADOPTIONS_CLUSTER | jq '.serviceArns[]|select(contains("trafficgenerator"))' -r)

aws ecs update-service --cluster $PETLISTADOPTIONS_CLUSTER --service $TRAFFICGENERATOR_SERVICE --desired-count 5

The command will launch 5 instances of the Amazon ECS traffic generator container task. Once the tasks are running (after about 5 minutes), the ALB will become overloaded with requests, forcing the alarm into ALARM state as shown below. You should also see a new investigation created.

Figure 5. CloudWatch Alarm in ALARM state

Interacting with the investigation via Slack

Once the alarm is triggered, an investigation is initiated. Since we associated the investigation with an Amazon SNS topic and subscribed our Slack client to it, we can see a message in our Slack channel from Amazon Q as seen in figure 6.

Figure 6. Slack notification for open investigation

Within Slack, channel members can accept useful hypotheses and discard unhelpful ones by clicking on the Accept or Discard button. They can also add text-based notes of observations or evidence to the investigation by clicking on the Add Note button. Amazon Q will respond to messages within the same thread as the original investigation message. Channel members will be able to track who has accepted or discarded messages, as well as notes made about the investigation. This emphasizes the power of Slack integration, as teams can collaborate on the investigation and track who is actively working on it. It is important to note that CloudWatch Investigations uses Generative AI and may provide suggestions different from those below based on your specific account environment.

Figure 7. Accept or discard investigation suggestions from Slack

When integrated with Slack, CloudWatch Investigations can provide suggestions and root-cause hypotheses. Channel members with appropriate permissions can access metrics, charts, and additional information related to the investigation by clicking the blue header at the top of the investigation message. This link will direct users to the CloudWatch Investigations feed in the AWS console as shown below in figure 8.

Figure 8. CloudWatch Investigations in CloudWatch console.

Integrating CloudWatch Investigations with Slack or Teams channels improves developers’ visibility of arising issues and provides targeted recommendations to reduce alarm resolution time. The Accept and Discard buttons make it straightforward to track who is actively working on an investigation, fostering a culture of collaboration. The best part? The integration is quick to set up, especially with existing alarms.

Clean Up

If you launched the CloudFormation template mentioned at the beginning of this blog, the services will continue to run unless you delete them. To make sure that you are not charged for use of the resources after the demo, please follow the below steps to delete the resources created as part of the steps performed on this blog.

  1. Remove the Amazon Q in Chat Applications Slack integration by clicking on Remove Workspace Integration and policy as explained here.
  2. Delete Amazon SNS topic and subscription as explained here.
  3. Remove the CloudWatch Investigations as explained here.
  4. Delete the images under the Amazon ECR repository named cdk-…-container-assets… as explained here.
  5. Open the CloudShell console or AWS CLI and execute the two commands below:
curl https://raw.githubusercontent.com/aws-samples/one-observability-demo/main/PetAdoptions/cdk/pet_stack/resources/destroy_stack.sh | bash

aws cloudformation delete-stack –stack-name CDKToolkit

After executing the above command, the resources of the demo should be destroyed. Look at the CloudFormation console in case of potential errors.

Conclusion

The new CloudWatch Investigations feature reduces alarm resolution time for development teams by providing actionable insights and recommendations. It is straightforward to connect investigations to a team’s primary form of communication, such as Teams or Slack, to improve notification awareness and interaction. To learn more about the capabilities of CloudWatch Investigations check out the feature announcement and documentation.

Happy investigating!

Another Supply Chain Vulnerability

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2025/07/another-supply-chain-vulnerability.html

ProPublica is reporting:

Microsoft is using engineers in China to help maintain the Defense Department’s computer systems—with minimal supervision by U.S. personnel—leaving some of the nation’s most sensitive data vulnerable to hacking from its leading cyber adversary, a ProPublica investigation has found.

The arrangement, which was critical to Microsoft winning the federal government’s cloud computing business a decade ago, relies on U.S. citizens with security clearances to oversee the work and serve as a barrier against espionage and sabotage.

But these workers, known as “digital escorts,” often lack the technical expertise to police foreign engineers with far more advanced skills, ProPublica found. Some are former military personnel with little coding experience who are paid barely more than minimum wage for the work.

This sounds bad, but it’s the way the digital world works. Everything we do is international, deeply international. Making anything US-only is hard, and often infeasible.

EDITED TO ADD: Microsoft has stopped the practice.

Площадки за дронове и медицински хеликоптери

Post Syndicated from Боян Юруков original https://yurukov.net/blog/2025/dronove-i-helikopteri/

Сагата с медицинските хеликоптери върви от много години. В последните две има сякаш някакъв напредък към устойчив модел на работа. Правителството се похвали дори с десетина хеликоптерни площадки в болници и ключови места. Те са детайл, който остана на заден план покрай несигурността дали хеликоптерите въобще са изрядни или безопасни да летят, дали пилотите са обучени и прочие.

Покрай разкритието, че комплекс Диана в София е „отцепено“ за дронове от НСО само защото Бойко Борисов рита там мач преди да вечеря в „офиса“ на Сталийски в ресторант 101, се поинтересувах къде има такива зони и как се създават. Разбира се, въпреки че след скандала зоната пазеща мачлетата на Борисов беше махната, миналата година ми беше отказана информация какви са били точно аргументите на НСО. Причината беше, че НСО не давали. В действително премахването на зоната предполага отпаднала необходимост, което от своя страна означава, че рискът за това не съществува и причините не следва да са засекретени. Добър пример е за това как се укрива неправомерни действия чрез засекретяване. Често такива се укриват допълнително чрез блокиране на изслушвания в НС.

По същото време – април 2024-та – попитах ГД ГВА защо няма обозначени ограничения за използване на дронове покрай обявените тогава четири площадки в София. Това е важно, защото дроновете са особено опасни за хеликоптерите, а в градска среда се използват често. Бяха тъкмо пуснати или в процес на сертифициране и вече имаше полети, включително на пациенти. Отговориха ми, че процесът е сложен и са на финалната права да добавят такива ограничения.

Интересното в случая е, че в някои случаи има подобни площадки, които са защитени. Пример са кулите до НДК, където явно навремето доста бързо са ограничили дроновете. В същото време площадката в седство в Св. Екатерина, която отдавна съществува, все още няма такова ограничение. Това виждаме на интерактивната карта на дирекцията. Те публикуват ограниченията в единен формат, който е неразделна част от заповедите.

Наскоро ги попитах отново защо хеликоптерните площадки не са покрити с ограничения. Повече от година по-късно не само няма промяна в картата и документацията им, но и вече площадките са 10 (изключвайки спряната в Русе). Виждаме ги в списък на страницата на дирекцията.

  • БВЛ „Уни Хоспитал“
  • БВЛ „СВЕТА АННА“
  • БВЛ „ЛОЗЕНЕЦ“
  • БВЛ „СВЕТА ЕКАТЕРИНА“
  • БВЛ „МОБАЛ Д-р Стефан Черкезов – В. Търново“
  • БВЛ „ТУНЕЛ ЖЕЛЕЗНИЦА“
  • БВЛ „Д-р Стамен Илиев“
  • БВЛ „УМБАЛ СВЕТИ ГЕОРГИ“
  • БВЛ „МБАЛ – ШУМЕН“
  • БВЛ МБАЛ „Д-Р Атанас Дафовски“

Отбелязал съм ги на тази карта. Три са в София. Няма такива в Стара Загора, Бургас или Варна.

Тук виждате снимки на интерактивната карта на дирекцията към началото на юли. Виждате, че няма отбелязани ограничения. Виждат се маркирани в близост ограничения на други обекти, включително примера, с който започнах.

Този път ми отговориха, че процесът е много сложен и все още върви година по-късно, независимо, че ми бяха казали, че са на финалната права за първите площадки. Посочиха обаче, че нямало проблем, защото нямало такова изискване за пускане на площадките в експлоатация.

Поради технологични особености и ограничения, процесът по публикуване на информация за географските зони на БЛС изисква време. Независимо от това, действащите регулаторни механизми за експлоатация на БЛС осигуряват необходимото ниво на авиационна безопасност при текущото използване на болничните вертолетни площадки.

При експлоатация на БЛС в неограничена категория, определена в чл. 4 от Регламент за изпълнение (ЕС) 2019/947, дистанционно управляващият пилот поддържа визуален контакт с БЛС, което му позволява прецизен контрол върху траекторията на полета и предотвратяване на сблъсъци с други въздухоплавателни средства, хора или препятствия. При експлоатация в специфичната категория, определена в чл. 5 от Регламент за изпълнение (ЕС) 2019/947, операторът на БЛС следва процедура за издаване на разрешение, която включва предварителна оценка на риска и определяне на подходящи мерки за намаляване и управление на риска, съгласувани с ГД ГВА.

Следва да се отбележи, че към настоящия момент няма действащи нормативни изисквания, които да обвързват въвеждането в експлоатация на болнични вертолетни летища с предварително установяване на географски зони на БЛС около тях.

Отговорното лице за обработване на информация за географските зони е началник отдел “Безпилотни летателни системи, международна дейност и иновации”, дирекция „Авиационна безопасност“ в ГД ГВА.

Може би се питате защо едни кръгчета на карта на сайт на дирекция имат значение когато всеки може да вдигне дрон. Би следвало да се използва здрав разум в такива случаи и да не се излагат на риск медицинските хеликоптери. Още повече, че вече има ограничения покрай летища и пак биват затваряни защото дронове се забелязват в близост. При липса на такива ограничения обаче съвсем няма причина да се санкционират неразумните. Такива би били например медиите ни гонещи кадри на кръв за новинарските си емисии или други търсачи на сензации. Дори да не се стигне до инцидент, забелязването на дрон може да забави кацане или излитане, което да изгуби ценни минути. Търсенето на отговорност дори при кадърен прокурор, би била трудно затруднена. Отделно по-тежките и сложни машини имат изисквания автоматично да избягват такива ограничителни зони, което прави този списък важен.

За сега според дирекцията проблем няма, но се работи все още по въвеждането на такива ограничения. Т.е. решаването на проблема. Ще питам след година отново или когато някой забие дрон във витлата – което дойде по-рано.

The post Площадки за дронове и медицински хеликоптери first appeared on Блогът на Юруков.

The collective thoughts of the interwebz