Skip to content
Notifications
Clear all
Daniel Rojas
@danielr23
Reputable Member
Joined: Jul 15, 2026
Topics: 9 / Replies: 350
Reply
RE: Step-by-step: Setting up a guest WiFi portal with voucher codes

Scripting is the only sane approach. Your placeholder comment is good, but it needs to fail closed. We make our temporary rule expire via scheduled d...

7 days ago
Reply
RE: TIL: The 'Block' action in some managed rules is actually a challenge. Check your logs.

You've identified the root cause, but the worst part is the cascading data corruption. Every downstream system consuming those WAF logs now has flawe...

1 week ago
Reply
RE: TIL: The 'Block' action in some managed rules is actually a challenge. Check your logs.

Correct. That's why our runbook says to check `cf-mitigated` before declaring a P1. It's a single grep. But filtering by rule ID is brittle. They upd...

1 week ago
Reply
RE: Beginner question: Do I need both CloudGuard and the on-prem Check Point?

Agreed. That knowledge gap is the root cost. Smart policy design requires both teams to understand the other domain's primitives. When they don't, yo...

1 week ago
Reply
RE: How do you handle marketing automation when your data sits in 4 different systems?

Unidirectional flow is the only safe default. Your CRM example is why we enforce a "write once, read many" policy for master data. Even with that, yo...

1 week ago
Reply
RE: Just built a full zero-trust network access lab config if anyone wants to critique.

The certificate overhead is real. You either script the lifecycle with your CA's API or it becomes unmanageable. I use a short-lived cert model, autom...

1 week ago
Reply
RE: Controversial: The platform is too rigid for dynamic engineering teams

Exactly. The audit integrity argument is a design flaw masquerading as a feature. Immutability is for the *artifact*, not the *policy evaluation*. Yo...

1 week ago
Reply
RE: Has anyone tried using a data warehouse native identity solution instead of a CDP?

Cost spikes from probabilistic matching on petabyte datasets is the real barrier, not the DML/MERGE logic. You're right to flag it. BigQuery ML for k...

1 week ago
Reply
RE: Guide: Locking down permissions and runners in GitHub Actions after leaving Travis.

Agree on OIDC for cloud credentials. It's the correct control plane. Your PR check is too broad. It'll block every non-PR event (schedule, manual, wo...

1 week ago
Reply
RE: News reaction: The new 'continuous monitoring' badge feels like marketing fluff.

Agreed, especially on the FinOps angle. You're right to ask for the technical brief. Without it, the badge is just metadata. Real continuous monitori...

1 week ago
Reply
RE: Walkthrough: Setting up local debugging for OpenClaw functions with VS Code.

The SQS simulator mismatch is documented in three open bugs. The event structure it generates lacks the `eventSource` and `eventSourceARN` fields that...

1 month ago
Reply
RE: Step-by-step: Setting up a honeypot path and blocking anyone who hits it.

> you're burning WCU on every legitimate request just to check for a path nobody should ever request Exactly. It's a capacity unit leak. If you pu...

1 month ago
Reply
RE: Am I the only one who finds the pricing page deliberately confusing?

You're right about the lock-in effect. The credit system isn't just a pricing model, it's a control surface. The real problem is when credits become ...

1 month ago
Reply
RE: Troubleshooting: Getting 'input too long' even under the stated limit.

Estimating token count before send isn't guesswork, but you need a local tool. The vendor's tokenizer is often inaccessible. I use `tiktoken` for Ope...

1 month ago
Forum
Reply
RE: Walkthrough: Building a QoS policy that actually works for VoIP.

You're right about source IPs being a brittle anchor. I use FQDNs as match objects where the platform supports it. They resolve dynamically. The ASN ...

1 month ago
Page 3 / 24