Episode 378 – Azure Compute Fleet
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Jun 6, 2024 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 378 of the Microsoft cloud It pro podcast recorded live. On 05/31/2024. This is a show about Microsoft 3 65 in Azure from the perspective of It pros and end users where we discuss a topic or news and how it relates to you. Today, we're diving into a new preview feature that was recently announced at Microsoft build, Microsoft compute. Scott and Ben dive into what exactly the services is and some of the intricacies of what it entails. They also discuss what a deployment involves and what some of the possible use cases they see of the service based on the features implemented within the preview. You wanna get in a smash or adventures today? Yes. Like fleets, Azure fleets, boat fleets, helicopter fleets. Compute fleets of what? Azure compute fleets, fleets of computers. Yeah. III figured it's been a hot minute since we talked about Smash stuff and it's only fair that we get back to it. And this is a new preview feature that came out or was announced in the build time frame. What was that? Week ago, 2 weeks ago. Something like that. I don't know. Time has no meeting to me anymore. Could've have been, like, a month ago. A But it recently at Microsoft built. Yeah. May 20 24 is when this 1 publicly came out. And landed in public preview. So I figured between virtual machines, virtual machine scale sets or Vms s, virtual machines scale sets, flex or Vms s Flex, which we've talked about in the past. And now compute fleet. We've got yet another perm mutation for at scale deployment of virtual machines. And I think this 1 is kind of interesting when it comes to the quote unquote scale aspect of it because it goes a little bit above and beyond what things like Vms do today, just with the units of compute that can be deployed, like, if you're thinking, like individual Vm counts, things like that. So real quick just to kinda ground everybody. So compute, like I said is this new thing. It's effectively a new infrastructure service within Azure around compute. And it's meant to kinda just streamline end to end that whole provisioning and management aspect of provisioning compute... Compute capacity across a whole bunch of different Vm types, potentially at the same time, availability zones, kinda of mix and match to your pricing model. Also that you can get to Vm deployments at scale that are performance because let's be honest, it's a little bit hard to do like multi vm deployments today, especially if you're doing, like, a scripted deployment or something, say with, like, powershell and just en, like, Hey. I'm gonna spin up a Vm, and then I'm gonna wait, and I'm gonna spin up another Vm, and I'm gonna spin up another Vm. It's a lot of Api calls. It's a lot of potential polling operations, things like that. So the cool thing about this is we need to kinda talk about it as, like, a infrastructure service or an infrastructure component. It's a single Api call to do an Azure compute fleet deployment, which is really kind of a cool thing, especially when you think about the scale of it. So you can deploy up to 10000 vms, in a single call through compute fleet. You've got a bunch of different settings in there where you can prioritize things like deployment speed, you could prioritize operational costs, say, like spot compute versus regular, pay go, compute, you can kinda have a mix and match model, potentially balance both those dimensions together because you're deploying different units of compute and those different units of compute the Skews underlying Skus and compute. They all have different costs associated with them. You've also got to, kinda cost management aspects. And being able to mix and match pricing models in a wide swath single Api call deployment. What else Oh? You can also... Because you're deploying potentially so many virtual machines at a time. Like, but deploying 10000 Vms at once isn't necessarily a small ask. When it comes to things like quotas, availability of that compute in a region, anything along that dimension as well. So it's kinda nice from the fire in forget aspect to say, hey, fire off an Api call and kinda load me up based on what my quota is for my subscription. A given region things like that along the way. So it looks like a kind of fun nifty new feature. It is definitely not an f for everybody feature, I think, given the scale aspect of it. I don't know that many people are looking to deploy deploy 10000 vms at once, at least not broadly. But there's definitely customers out there that would love to deploy 10000 and frankly, more than 10000 virtual machines at a given and go to get through some of the stuff. So you think about, like, customers with a large Ai training workload kind of thing. That's a ton of compute, ton jeep can be fairly ep. So, you know, you might not wanna run the thing the whole time. But, like, yeah, Definitely, while we're training a model, we need to get that. Those units have compute up and running and those Vms configured all those kinds of things along the way. So looks like a fun 1. Yeah. This was interesting and you first brought it up me We're like, hey, ben. Go check this 1 out because can't remember. It was a couple months ago. We were talking about Av. And I was creating some maybe the environments where we were actually, like, destroying and rebuilding or tearing down and recreating Vms on a nightly basis, and we were only doing... I mean, we're only doing like, 30 or 40 Vms. But we were running into issues where when we did all 30 of them at once. Again, it was a bunch of single Api calls. Not all of them are coming back up. We split it up into 5 or 05:10 vms at once. And it worked better. And you're were like, hey Ben, now you can do complete. Compete and do, like, do compute fleet and do, like, a whole bunch from that once. And it led to a little bit of like that use case where this is very much, like, when you stand up a compute fleet, go to play a bunch of them, but then you have to continue managing it through the fleet. And that was 1 thing I was curious about when you told me to go check it out is it's like, can I use a fleet to go deploy 30 vms? And then like, in the case of Av, if I wanna scale up or scale down, how does that look within a compute fleet? Like, can I go? Turn Vms off or delete them or how do I manage these museums once it's the fleet. And this is not really for that use case. Like you said, this is I'm gonna go deploy a bunch of Vms, but then you continue to manage that capacity of Vms within the fleet, and it's not something that you could easily... I would say it's not something you can easily scale. It's like what you said. We wanna go spin up 10000 vms. We're gonna go spin 5000 vms for a workload and we were even talking probably more of like an a a ep type workload where it's... We're gonna go train something for a week or train something for a month or... I mean, certain industries have certain times a year where it's busy and they're spinning up a huge number of Vms. Think of shopping sites over the month of November and December where... Mh. They need a massively scale up. For a short period of time, and then they scale back down or they just frankly, like blow them away. It's like, we hit the middle of January, nobody's shopping anymore because everybody spends their Christmas money and has done shopping. Let's just delete everything. Like, this is very much spin up a bunch of Vms for a short period of time and then get rid of them all. Is kinda how I interpret this. It's the Nuance potentially of that statement of compute fleet is kind of like an infrastructure service versus a holistic compute management service. Right? So I think about things maybe, like, the Vms s or Vms Flex as being a little bit more feature rich there. Like, 1 of the things with compute fleet, at least I haven't seen a way to do it. It's not documented nor, like, that I see, like, an easy way to do it through the Api surface or the portal or anything like that. But, like, 1 of the big differences is is when you deploy a compute, you're deploying compute, you're not necessarily configuring that compute. So when I think about, like, a traditional single Vm deployment or, like, a Vms fast deployment things like that. It's not just about deploying the compute. It's also about configuring and managing that compute throughout its life cycle. So I don't know. Maybe I'm standing up, like that, you know, traditional multi tier web application thing where, you know, I've got a front end, some middle wear and a back end. I might do that in S flex, and then within my deployment configuration, I would say, hey for this Ubuntu based front end deploy Ng x on it. And load these Ssl cert and do this configuration for Ng x. My middle aware, do this kinda configuration for my Api hosting on my data side, like, with my sql server. Like, Sam doing, like, my sequel or something like that. Well, go ahead and actually spin up my sequel install it on the box for me or even deploy that as a bad service like whatever it happens to be. And you don't have that same flexibility within compute. Compute is literally, like, fire and forget I want to create just a ton of virtual machines at the same time. I'm gonna have, like, min and Max targets for how much I want to deploy. And and of what type I want to deploy. But then once it's deployed, it's up to you to go and stand up your applications, do all that kind of management on top of it. So it's kinda nice in that it's got a single Api, fire and forget for the at scale deployment piece. It'd be interesting to see where this goes in the future, like, if they bring in, like, at scale management as well. Like, I would love to have a way. And if it's possible today, maybe the docs just need to be updated. I would love to have a weighted to say, like, go in and create an arm template to do a compute fleet deployment. And then within that fleet, as I'm defining my Vm skus, and I'm saying, okay, you know, I want 10 of this spot, up to a hundred of this spot. I want 10 of these, you know, ds s 96, up to, you know, 50 of them, whatever happens to be. Like, in that same arm template, having, like, further child properties that I can call out to so that I can do things, like, execute boot automations, so maybe, like, cloud in it scripts, things like that on a Linux box just to get them up and running. But that stuff's kind of not there today. The other thing is it's a little bit different and I do think of as maybe a little bit more of an ep thing. So when you fire off a request to instant initiate a compute fleet. So you go in fire off this Api surface. And again you do that through arm template. You do it through the portal. You do it through the Arm Apis. Like, however you do it? You fire off that request. That request can take... It's effectively asynchronous compute deployment at that point, like, it all happens in the background it just churn and churn and churn. These are, like, super long running jobs. So, like, an initial compute fleet request can be active for up to a year. 365 days. If you need to clear a request, like, hey I I did the fire and forget saying of that Api, and now there's a bunch of async stuff happening in the background. Your only option is, like, you can't really, like, pause it. You can just delete the compute fleet request. And if you do that, all the Vms inside that compute fleet come down at the same time. So, yeah. I... It's a little bit weird. In that it doesn't have parity with things like, Flex. It's its own new weird thing. Like, whether you wanna think about it as potentially, like, a new Api surface, like, as a new infrastructure service, built on top of existing constructs like virtual machines, things like that. The public docs refer to it as a building block. So it's just kinda like this foundational little block or, like Lego brick. That's going to accelerate your access to compute capacity in a region. So if you think about it that way, like, hey, I just need to secure a bunch of compute. Really good for that. I need to secure a bunch of compute, and I need to configure it, and I need all this post configuration. I need down level management and all this other stuff. I don't know. It might not be the best thing for that, but it's not, like Vms or those other things are going away. You might have to kinda mix and match to or it just very well could not be the right thing for you along the way. I'm curious, and I don't know that you have an answer because we talked about this a little bit, and this is in the Faq. The 365 day thing you brought up. Is if you go in and look at the Faqs for compute fleet. It says how long does my compute fleet request active, compute fleet requests are active for 365 days. If you delete it, it deletes all the Vms. If I don't delete it, it continues the Vms continue to run and charge you. Does this mean that if I request or maybe I already know what you're gonna answer. I'm curious how this plays out is could it actually take 365 days to provision all 10000 vms? Or does this mean that, like, you put in a request And within that request, you're setting, I need certain amounts of Vms, and you can go in and update your fleet, I believe to change that number of Vms, Like, do you only have a year to change it and after a year, a complete fleet or a compute fleet is like. Stock or locked, I'm I can't imagine anybody would wanna spin up 10000 vms and not know if it's gonna complete in a week in a year. Like, the whole what is our active request mean? Don't know. Right? Like, I I... So a couple of things. So it's in preview. I I think you've gotta kinda look at it from that lens of, hey, it's all not gonna be there, and I think as questions or answer or, like, as questions or asked those will get added and and build some of that out over time. You know, do you wanna wait a year to deploy your 10000 Vms? No, Probably not, but that's why you're gonna have men's and max. Like, so you had the portal up earlier. I was gonna say we should walk through that and just talked through what a deployment looks like. Yeah. I think that gives you a little bit of kind of a a view into that. World and what some of the dimensions are that you're looking at. So, like, any other arm deployment. Right? Subscription, resource groups, that's pretty easy. You're gonna have a resource name, your fleet name, what region are you deploying into which this is limited right now in preview. It's East. East Us 2 west 2 west 2 and West Us. So really East and West, the original and 2 are the only 4 options at this point in time. Effectively some Us hero regions in Azure. Yeah. So you've got that availability zones is your next 1. So do you wanna use Az z's for your Vm as to deploy and then just like a regular Vm, you know, zone 1, zone 2, zone 3 kind of thing. What is your security type for those virtual machines? So I think we discussed this a couple episodes back. Trusted launch Vms or the default everywhere right now, but you can revert to standard, or you can do confidential computer on the way. Know, trusted launch are the ones that give you, like, you've got the screen up now. Those are the ones that give you secure boot. They give you virtual T pms. And then some of the integrity monitoring around, like, memory things like that coming in from the hyper visor. Single image that you're gonna choose. So it... It's kind of interesting. Like, again, this isn't like Has flex. Where you would say, hey. Maybe I have this Vm. That's on a Ubuntu. I have this 1 that's on windows, things like that. That doesn't occur over here. So you just kinda pick a single image, and then you're lining up the units of compute that are all gonna use that image underneath it. Yep. And you can do with that image, you can do your custom images to you. So you still get that option like Go see marketplace images, see other images, where you can go select my images, shared images. You can do ubuntu Red hat, oracle windows, like you have all of your normal images that you would expect. So this isn't limiting in that aspect. It's just limiting and that you could only pick 1 for your entire fleet. Correct. Yeah. Yep. Do you feel overwhelmed by trying to manage your Office 3 65 environment are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running, intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an as of several thousand employees. They want to partner with you to implement and administer your Microsoft cloud technology. Visit them at intelligent dot com slash podcast that's INTELLIGINK dot com slash podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud, so you can focus on your business. Next up for you is the types virtual machines. So I think this is an interesting 1 Like I I'm Mentioned in kinda of the opening that you can do mix and match. For cost optimizations. So being able to mix and match regular Vms and spot Vms. And then you can select the sizes or the Vm series that you wanna use. Along the way for those specific components. So I think it's a minimum today of 3 Vm series that you have to select and you can go up to 15. I'm gonna spin up some big ones, Scott. I'm gonna go do 10000 d 96 b fives. Yeah. Go for it. That's a beef you bill. So, yeah, shooting can do us select a bunch of those. Like you said, spot regular. So... And then after that, you start picking capacity. This is the 1 where it gets interesting for me. Like, after you select all your sizes, now you can go choose these capacity preferences. So you can maintain a capacity, and this is once the target is matte, replace evicted vms to maintain target capacity. So it sounds like once you spin this up, you can set a capacity. So target capacity is a number between 1 and 10000, and it sounds like once you spin these up, you must be able to kick Vms out. Like you could essentially go in and say, I'm missed guessing eviction is essentially deleting that Vm saying this Vm isn't part of this this fleet anymore. It's a spot compute thing. 1 of the things that you run into with spot compute is it's kinda based on availability. And it's based on demand shaping within the region. So if you're doing spot, spot can be evicted, at any time. So it's really good for kinda, like, state workloads. If you have state full things, you know, you kinda make sure like, hey, that you're responding to things like eviction notices, so you're potentially persisting state and, like, object storage or off to disc someplace else. Things like that. So basically, what it's saying is if you wanna maintain your capacity, like, let's say you did a thousand spot vms, and you tell it to maintain. Well, over time, once you've turned those spot vms off, they're gonna get evicted just naturally through the life cycle as other customers come in and out of the region and the elasticity there. So what you're telling it to do is saying, like, hey, I need a thousand vms all the time. So if any get evicted, so it avail a hundred Vms and you go down to 900, the async engine in the background that's deploying that compute for you, will come in and request another hundreds spot Vms to get you back up to a thousand. And if you can't get you to a thousand, it'll kinda keep churning away in the back end. And keep trying to get you to where you need to be, or you can say don't maintain that capacity. Like, hey, I wanna start at, like, a thousand, and then stuff's just naturally gonna get it over time. And once it gets evicted, I don't really need it back or maybe I spun up another compute fleet or something else along the way. So you can kinda let it go naturally kinda downhill that way if you want to. This would get interesting then with the 365 days because as it technically then like, no longer active after 365 days and if something gets evicted, it isn't active to maintain capacity. There is my question. I guess so. I don't know. Preview service, there's no Sla, anything like that. Figure it out. I imagine some of this like just to be brutally honest is kinda like a shot in the dark from folks going like, hey, how long do we need to do this? Is, like, a year sounds like a long time for a long running async job just to kinda keep sitting in the background. It's like a job scheduler. Especially when you consider that at least as of today for compute fleet, it doesn't have any cost. So it's kinda like Ak and that, you know, you're getting the management piece for free, but you're paying for the underlying compute along the way and and all the constructs that that come with that. So you're You're paying for the virtual machines. You're not paying for the ability to deploy those virtual machines and manage them via compute fleet. I don't know if part of it is maybe, like, a little bit of, like, just a cost thing, even like, internally. Like, hey, how many these jobs do we need to run? How long do they need to pull for? What does that look like and how does it manifest? I imagine a lot of that stuff gets cleaned up be before it go was to a production state. I would assume so because there's a lot of I have a lot of questions. Like, how some of that works that aren't answered. I think some of the the questions you have. You know, if folks are kinda sitting in the background and they're asking these same questions. A, lot of it is... This might not be the service for you. Like, that's true. There are other things out there. Like, this definitely, like, has a use case and a place. And if you're looking at it, and you're going, like, yeah, I don't really see the use case. Right I don't see place, like, that's okay. That's why things like Vm and everything else exists out there. Because like I said, this isn't Vms, So even though you can do the capacity deployment through a single Api call, you've still got the potential, like, configuration concerns and all the other stuff that comes along the way with it. So you have this little trade off there that you're kinda balancing between do I want to deploy a lot of compute or do I want to deploy a little less compute and then have all the manage ability aspects that come with it? Continuing down? Setting maintain capacity don't maintain, what is your target capacity? So what are you gonna set this at? And then you can set the eviction policy. So... That's all spot stuff, spot specific. Delete, allocation strategies, max hourly, price per spot is all the spot stuff, and then you get down to the Vm capacity so non spot Vms, and you lose some of those extra settings because now it's just regular compute where it's your capacity, and this one's... I don't know if this is spot. Yeah. Maybe you can help me out with this. Like, you can set a capacity for these normal Vms of say a thousand. And then you set your minimum starting capacity of something like 10, and this minimum starting capacity is essentially saying that Vm in the fleet our provision gradually. It starts with your desired in capacity if you specify it, so it could start with 10, and then it's gonna slowly grow up to 100. It doesn't say how slow, but this is not something you have with spot Vms. Like spot vms you just set the capacity, and I'm guessing it's does it all out once versus regular Vms where if you want to use set a minimum and slowly ramp up to your capacity. I think it's implied that spot is also going to ramp because by nature of spot via. By nature of spot. Like, you're basically saying with spot compute. Give me your extra compute in the region, and I'm gonna pay a little bit less for that compute, but the reason that I'm paying less is because you, Microsoft as the as the host and hyper scaler can rip that compute away from me. I can be evicted. And when you've ripped that compute away from me, you're gonna go give it to another customer. So let's say in this case, like, I'm the 1 who's consuming a lot of spot, and you come in and you say, hey. I'm here as a as a customer and I don't need spot compute. I need real non ep compute, and it's in the same series that I have in spot. It's in Microsoft best interest to e me out of there and just let it go. So I I think a lot of it is just kinda, like, sitting and and trying to balance that nature of spot versus everything else that's they're and available for you. The other interesting thing about this too is like, you said earlier, you can select up to 15 different sizes. So you could go in and select 15 different d series Vms, z e series Vm spot Vms, but you can't set capacity on a per sku level. I can go in here, and I can say, I want my target capacity to be 3000, my minimum is a hundred, but I've selected 5 different sizes. It's gonna go... Well, it's technically gonna break the way I have it now. If I'm spinning up 5 different sizes with 3000 capacity. I believe it's spinning up 3000 of each or is it taking? Now I'm questioning myself. Total capacity. So this is total capacity. It's taking 3000 dividing it by 5 probably and spinning up 600 of each Skew that I've selected, doing that math in the background versus 3000 of each sku that I've selected. Again, very unclear from the documentation, even from the sense of, like, hey, self documenting code. If you go look at, like, the arm templates for these or, like, the actual arm endpoint that sits out there. I don't have, you know, 10000 course that I can go play with in my in my Pe go subscription. So, like, I wasn't even able to to 1 of these at scale, like, even, you know, even getting yourself lifted beyond, like, the default core limits and, like, a visual studio sub is pretty rough these days for how that stuff comes together. But, yeah, you're basically doing your allocations that way, and it's gonna split amongst them. It's unclear how it divides things up. So the interesting thing is it's not exposed in the portal really or at least it is a math back clearly between with the options in the portal. But in the arm template, if you go look at the arm template. So Mh. The spot profile and the regular priority profile. They have this property that's called allocation strategy. And allocation strategy can be capacity optimized, or it can be lowest priced. So that's kind of interesting because then what it's doing, if I'm reading it the right way based on the Api, is it using the logic of, hey, you selected 5 d series Vms. What are you phonetic clicking on over there? So so you've nuts. Yes. You've selected 5 d series Vms, you can go in and you can make your Alex vacation strategy to be lowest price. And then what it'll do based on that is, I... It would literally choose the lowest price Vm series. And it would start with deploying those first and then come behind it, like, it would just keep kinda incrementally stepping up the ladder based on the price. Or like I said, the other dimension is capacity optimized. So what I was clicking and I was trying to see what a... I can't find small Vms. That's another weird thing with this. Like the smallest Vm I was able to find to select was 8 cores. I was curious if I just selected 2 small ones and set it to 4. If I get 8 Vms or if I get 2 of each. Okay. Not to service for you if you're looking for small tabs. If I'm looking for small Vms, I know. I was trying to test it out to answer my questions. This very much does seem geared towards, like Ai training scenarios, Hp scenarios, where I'm gonna spin up a bunch of compute to run some kind of some kind of job on top of things. It's just going above and beyond, like, the click stops of some of the scale out capabilities of things like, you know, the current Hp offerings, current Vms offerings, but, yeah. It's a little bit of weird nuance there. So then once you set your capacities, it's really, after that, it's just what's my admin username password for all these vms, again, set it once, get it for everything. If you wanna do hybrid benefit, if you're doing windows, and then networking is just virtual network subnet, and then you can go in and tweak network interfaces. Really, if you wanna do Ns msg or accelerated networking. They do have an option 2 to do a new load balance in front of it with networking. So relatively basic, you're essentially just saying dump all these vms in a network. Use an ns msg if you want to... And if you're gonna do any type of load balancing. Yeah. I believe you have to create a load balance. I don't think it's optional Do you? I'm gonna try it? Oh, basics. What did I fail on? Oh, field name? Benz test fleet. Who it validated without a load balance or Scott? Create gonna initialize the deployment. So I tried to spin it up through an arm template, and I just pulled their default arm template. So the default arm template at least as it's documented today. Includes a V handle load balance in it. So, yes. I just said V subnet, no load balance. So it doesn't look like it's required. We'll see what this actually creates when it goes and deploy everything. Well, mean if I have to come back and check in a year. Yeah. It's What else? There's that Faq out here. I'm trying to think if there was anything else in here that we wanted to cover, start and stop time. Yeah. No start and stop time. You spin it up? It's running. It will be interesting like you said, do they change some of the stuff going forward, but also like you said it's not for me. This is not a service I would use, the only use I kinda thought of it, but even as we've looked at it is if you wanted to do it for a lab. If you're spinning up, like a large lab for a learning environment. But even that, given you'd have to do an image and that there's no start and stop time, you're probably better off going other routes even for labs. Like you said it does tend to be... It appears to be more Hp Ai training based stuff that you were mentioning. I'd go back to you there are services to do those kinds of things. Right? Like, there there's literally lab services. Lab services. We've talked about that 1 before, which does sit out there. There's Dev. So there's kinda all these different constructs. So you do have to kinda go through and pick the right functionality, like, underlying deployment model, all all those things that that are gonna work for you within there. The only thing I'd call out is, like, if folks are watching this, and they're like, trying to get hands on with it and if you are more of, like, an arm template deployment person, versus a go and click in the portal to do your first deployment. You do have to register the resource provider. For this 1. So there's a little bit of a flag that needs to be cleared, register the resource provider and then you can go ahead and do your deployments. You didn't have to register the resource provider because you initiated through the portal and then that registration happens automatically. And then it broke because My subscription is not registered to use the name base Microsoft dot compute. You've never deployed a vm in there. Apparently not. That's a weird 1. I thought I had. Now I'm gonna go look. Oh, this is gonna be annoying. Yeah. We'll go look later. That wraps that'll be for another time. Yes yes. Yeah. So kind of a interesting service to go look at explore play with. If you wanna go spin up a whole lot of vms. Compute fleet. Get it done. Alright. As always. Thank you, Ben. Thank you. Enjoyed it. Enjoy your weekend. Try to stay cool in this. Florida got hot really fast this year. We went from summer to summer, like that yes. In an instant. So enjoy, we will talk to you again soon. Alright. Thanks, Ben. If you enjoyed the podcast, Go leave us a 5 star rating in itunes. It helps to get the word out so more It pros can learn about Office 3 65 in Azure. If you have questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 378 – Azure Compute Fleet
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 34:08 — 23.5MB)
Subscribe: Spotify | Amazon Music | Pandora | iHeartRadio | Email | RSS
Welcome to Episode 378 of the Microsoft Cloud IT Pro Podcast. In this episode we discuss Azure Compute Fleet, a new Preview service announced at Microsoft Build 2024. Azure Compute Fleet is a new Azure infrastructure service that lets you deploy Azure compute capacity across different virtual machine SKUs, availability zones, and pricing models. It’s all about acquiring VM capacity at scale. If you’re familiar with AWS EC2 and Spot fleet, this is effectively the equivalent in Azure.
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 357 – Community galleries for Azure Compute Gallery
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Oct 26, 2023 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 357 of the Microsoft Cloud IT Pro podcast recorded live on October 16th, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we discuss a topic or recent news and how it relates to you today. Ben and Scott run through the recently announced community gallery capability that has been added to the Azure Compute Gallery service. We also spend a little time talking about the table level RAC read access control for log analytics workspace. Scott, you've had questions for me in the past. I have a question for you this morning. It kind of ties into. Tables are turning. I'm. Okay. Tables are turning. We were talking before we started recording and you made a comment about you need to find more time to use your green egg in your Blackstone to grill .And it tied into an article I saw this morning about a survey of workers that would take pay cuts for these top tier perks and the biggest perks. I'm curious what you think about these. This survey found that most workers would take some kind of a pay cut for a four day work week consisting of four eight hour days pay cut of 16 to 20%. So essentially you're giving up a day's salary, right? 20% for four days of work. Large number of workers would also take a pay cut from our vacation time. Same thing. 16 20% doesn't say how much more vacation time And then fully remote workers was obviously one of the top ones. 61% of people saying they would take a pay cut for remote work. I think those were the big three more vacation, four hour workday remote work. I'm curious, some people were like, I would know that wasn't a pay cut one. Curious your thoughts. Would you take a pay cut for any of those? Not that your employee could listen or should do it for. More vacation? No, I think generally the thing to do is like when you're walking into a new position is know your worth and negotiate for it. Right? That's my thought. Even. Companies with very fixed policies, I think there's ways to come to agreement there. Like you might land in a band say with two weeks of vacation, but really you need like, you need three and that's what you're used to and what you've had in the past. And I've run into that from some places like having worked overseas where you just end up naturally with more in a vacation time. Another interesting one is I've worked at a bunch of law firms and law firms tend to have pretty generous vacation policies, like three to four weeks. Interesting. For all employees regardless of level. So I got used to that pretty early on in my career by doing some of that stuff. Like working with law firms where I was like, Ooh, I just need three weeks .And now at Microsoft we do the DTO thing, discretionary time off, which is effectively unlimited time off but you know, you have to get, still get your manager's approval and things like that. So no, I I don't think vacation time is one that would be worth taking it for remote work. Yeah, absolutely. What you do, if you are, if you think about it, if you're grinding away for say like half an hour to an hour of commute one way each day, that's gonna be your eight hours right there anyway . So,so just take the, take the pay cut and do it. You were already putting the time in. It is what it is. And generally you do come out ahead in those deals just with the savings on mileage wear and tear gas. You might up some more things at home. You might find that you go absolutely crazy and end up with like microphones and fancy webcams, and all the other stuff. But I,I think it all course fills the gap pretty decently. The 40 workweek one is interesting. I would not want to do 32 hours I think for a 20% pay cut. I would rather do 40 hours like we tend to do a standard in in the United States, but just let me do my 40 hours in four days in four days and then I'm done. I can still do the same things and I'll arguably have the same if not more output. So just let me, let me do that and float through. Right. Especially I can see the four and 40, especially if you're combining that with the remote work because if you're doing eight to five and you're just doing a quick lunch that's already nine hours. Lunch. What's lunch .Exactly. I. Don't, I don't get lunches anyway so it it, yeah it's. The snacks sitting on my desk here. So I have mixed feelings about remote work and if that should be a pay cut. So I've always had this theory too if you're going into the office, how much money is the company actually spending for you to be in the office because they're paying for the real estate, the electricity, the office supplies. There may be a lot of office supplies that you actually get if you're in the office in terms of chairs and desks and all of that. Should you actually be getting a pay cut if you're working remotely or should the company actually be investing some of that money back into you for you to provide some of that stuff as you're working remotely? Pick. The company. ,there's lots of companies even today with the whole rigmarole about returned office RRTO and all that stuff that are carrying large chunks of their books in commercial real estate. I think it's hard to make that flip. If you went to a company today and that company didn't have offices and they said, oh, but we pay 20% less, that smells a little fishy. But if they have a bunch of offices other places and they go, well we let some people come into the office and they make this much and they let some people stay from home, like there's trade-offs there. I think that's a negotiation that you can potentially like rationalize your way through as a remote work from home employee. I would take that trail. I don't know that I could go back to an office, let's put it that way. If somebody came and said you have to go back to an office or take a 20% pay cut, I would take a 20% pay cut, I think. Take the pay cut and stay at home. I'm not gonna sell my house and move someplace else and do all those things. And I also get what you're saying about long commutes. Like if, to your point, if you're driving an hour a day spending X number of dollars on gas and oil changes and maintenance on your car or whatever those additional expenses are that do come with commuting, just even from a time perspective, there is something to be said for that too. But I'm with you. I don't know that I could ever go into an office. I. Don't, I don't know that people always think about it that way. like and you have to have, I I think it helps.Like I've worked places where I've had to do the long commute thing. Like when I lived in outside Washington DC when I had to go down into the district for customers, Uhhuh ,that was a two hour one way commute. There were some days where it was taking me three hours to go one way just because of traffic timing for things like I lived 35 miles outside of dc which meant that for me to get down into the district, like you can't drive on the hve lanes as a single driver in the morning. So you had to find it potentially a different way to get in, but you didn't want to drive in all the way to the district and have to deal with the traffic actually down there. So I would drive my car to a park and ride. I would go from the park and ride to the train and then I would take the train to where I need to be and maybe catch another bus, right? If there wasn't a train that got you within a walkable distance of the place that you were going. So it was a little ridiculous sometimes. And I would get home at eight at night , what did I do?. Yeah.So in cases like that, it's a totally worthwhile trade off and it's not a trade off that everybody can make, but if you can make it, I think it's, yeah, it's worthwhile doing. Like it is a quality of life thing. It. Was interesting, there was just an interesting survey and I'd say we'd post a link to it but it was on the Jacksonville Business Journal and it's a paid link so if we post a link you can't really get to it anyways. ,it was interesting just to see what some of those top things were. That and the four, I'm with you, the four day, eight hours a day surprised me. It was like, so people just wanna work 32 hours instead of 40 hours. There. Are people that do that. So I've definitely worked in organizations and and come across folks that do those kinds of things. Uh, we did a, I attended maybe last year and a half ago a seminar that was put on by one of our more junior employees who decided to take that trade off like totally negotiated down and said you are gonna do 32 hours a week and that's it. And for a whole bunch of reasons, right? They're just like work life balance, mental health, this is a better model for me kind of thing. Uhhuh, and there's a lot of that in there.Like everybody is situationally different. Like not everybody is built to do 40 hours of continuous context switching the entire time. So I can I get that respect it, know what you want, go for it and grab it if it's an option. That was my question for the day outside of, and I also saw an article in there about mansions for sale in Jacksonville, but we don't need to talk about $25 million mansions in Jacksonville .No. No, no we don't. So news, there's a few news things. We were just talking before this too. News feels like it's slowed down, but Ignite is now one month away I think ish give. Or take. Yes. From one we're recording this. We're about, we're we're about a month and a week away, so maybe just about five. Weeks. By the time people hear this it'll be like two, two and a half weeks away. But. Something like that. Yeah. As a result Microsoft has said we announce news as it comes up now and we've definitely seen a lot more news come out, but it is also very apparent that once you would get within a month of ignite, the news kinda slows down and Microsoft is definitely holding some stuff back to announce that Ignite in a month. So there's a few things that have trickled out that we figured we'd talk about today. So do you wanna take the first? Yeah, what do you wanna start with? I don't know. You have a tab highlighted here in the browser. Do you wanna start with the, the one you're on? This was an interesting one that I did not see. Let's start with sharing images using community galleries like. Pictures, right? ., yeah sort of I guess maybe if we consider A-V-H-D-A picture,do we consider V HD's pictures? A vhd is a picture of a virtual machine. They certainly tell a story. No. So in Azure there has been this thing kicking around for a while now, which is the Azure Compute Gallery. So for a long time you've been able to take a virtual machine in Azure or even potentially like a virtual machine from your, from another environment. Not the best idea. But typically we'd start with an Azure one just for the best experience. But you can take those images and you can customize them. So say it's like a Windows image and you want to cis prep that image, take it back to an out of the box experience for running it through. You maybe wanna lay down your own bits on top of it just to give you an accelerator, like whatever it is. So you've had the ability for a long time to take those images and let start it out as oh just grab AVHD, then you would create like an image your next VM from that VHD that's a pain. And then they introduce this thing called a commute gallery. So effectively take your images and have your images with things like versioning associated with them. So okay great. I've got my golden image for Windows server 2022, I've got my golden image for my Ubuntu 20.0 0.4 LTS version that I run in my environment, Myre, whatever it happens to be. Take those and then be able to like version them as you patch them, update your applications, all those kinds of things. Compute galleries have traditionally been private. So there's been like the Azure marketplace, hey go out to the marketplace from an official publisher, be it Microsoft or one of the other vendors that's in the marketplace that's been vetted by Microsoft and grab your VDS from there or your images that you spin up. So a third party example would be something like Kemp, like you wanna spin up a load balancer from Kemp, you need like a NetScaler, that kind of thing. Great, you can go spin those up and those are vendor supported images from those companies And now there's a new flavor that's kicking around which within the community gallery now you can or so within the compute gallery, Azure Compute Gallery, you can now have private galleries which is traditionally what you've had. And you can also have a community gallery and community galleries are interesting. So private galleries as they've existed you could do rback sharing within your tenant. You could also do a what was known as a direct shared gallery potentially over to other users within your tenancy, other subscriptions, things like that. But generally like your tenant, your Azure ad intra ID tenant was a boundary for you for identity. So you couldn't really share those things publicly with other Azure users if you wanted to do that. Let's say you didn't, I don't know, you didn't meet the bar to go into the public marketplace, you just didn't even know it was the thing. You didn't wanna deal with it. Like you could just spin up one of these community galleries Now because what community galleries allow you to do is you can still do rback. So you can still do things like your share your images using world based access control to a service principle, anything like that. People, groups, whatever it happens to be. But it's not locked down to a specific tenant. So a community gallery lets you break the boundary of a single tenant and get out there to more of the marketplace or you can just share things publicly. You can say hey I've got this community image and I want to push it out for everyone out there to be able to see and get hands on with. So it's another mechanism or another way for publishers to share things potentially outside of the Azure marketplace. And that's got like pros and cons to it. I think as consumers of images, like we need to be pretty careful there 'cause now there's maybe some additional vetting or things that you'll want to have in place. 'cause like marketplace images are certified, they go through a certification process both for Microsoft images and like Microsoft as the vendor who's publishing them or you know Kemp, Citrix NetScaler, all those kinds of things. Those all go through a certification process. They're all good. Vetted, verify, run 'em with your production workloads. You can do that with confidence, they'll be supported. There's a slew of first party, third party images, like all the, all that stuff just is there. But I think the biggest thing is they are supported. is probably the biggest thing. Uh, for marketplace images,community images, there's a certain degree of trust that you're going to have with the publisher. 'cause like you or I could just go create a community gallery today and spin up an image and put it out there. So you're trusting that A, we know what we're doing when we build that image. B we are licensed to build and distribute that image. Like there could be software licensing or other things that come into play there. So this is really good for open source stuff potentially depending on the license associated with that. I don't know how well or how much it gets used for commercial stuff. It's also great for testing. Like I could see like a bunch of marketplace vendors potentially using this as a path to test their images and get them out there. There's no like billing model, anything like that. Community images are just free. So it really is like a, I think like an apple like test flight kind of thing. Like it is very test kind of thing. And then that support angle is a rough one I think in that images published through a community gallery are supported by the owner of the image. So who's the person who made the image that is who is ultimately responsible for support on top of that thing. And Microsoft calls this out in the documentation. Okay, like this is potentially an area you could be interested in, but if you are a consumer of community gallery images, like you're not just a publisher but you're also using them in your environment. Like you should exercise a degree of caution there becauseyou really do have more work to do. Like you have to go verify the source again, there's no like certification scanning, anything like that that happens on the way. Like there could be malware in these things. Like it's really on you to go and figure it out and, and there's mechanisms for folks to report nefarious images to Microsoft. Like all that stuff's in place but it doesn't stop it from getting out there as quickly the way it might do in something like the regular Azure marketplace. Yeah. I was just looking through it. So if you go out to Azure and you browse for resources, you can go look up and I'm, I think these are all community galleries. You can go look for the community images in Azure and just start browsing through them. So in community images right now there are 4,600 images and you're right, you don't know what any of them are. So one of them in here is from some guy named Pete and the gallery is Pete Specialized and it's a Windows 11 and they have AURLfor the publisher's website, which just goes to his public blog. It's Peter and it's a software engineer's log book. But to your point, it's what is actually in this Windows 11 specialized image. Because one thing I don't see on any of these is for all of these community images, they have a name location, architecture publisher, but there's no description on any of these. I don't even see a description field where someone could go in and specify what this image actually is or what's contained in it or why I might want to use it. And I'm wondering if. It's a little rough. So if you go look at the way to deploy from a community image today, uh, lots of the examples like they, they start right off with CLI and and and rest even over the, the portal deployment experience. But if, if you dig down in and you go, okay, hey let's look and see how you deploy this in the CLI, it's effectively do discovery, go out and list the images that are available, list the community images that are available. Funny enough, not a global resource, right? This is still a a regional service. So go out and list the community images that exist in this region. Show me all the community images in east US in North Europe, like whatever happens to be where you're deploying. Once you have that, the resource ID to that image. So,so effectively the string, here's the gallery name and the GUI associated with that image. All that stuff all the way down to the version that becomes like what you pass into a VM creed command to get things, get things spun up and get them running. So yeah, it's new thing that's out there. I, I'd be interested to see what the uptick on it is and if you do see like MSRC reports on these over time of, I, I could totally see a vendor coming in and doing something like a, a bad actor vendors maybe a bad choice word. A bad actor comes in and you know, slams a bunch of images into 60 regions or you've gotta play like whack-a-mole trying to figure out like which region which bad actor is in and and where they've published in images, things like that. There's more vetting for you to do as a customer here. Like you really do have to trust where these things come from because say you're using like a virtual machine scale set and we're doing like VMSS and we're scaling things out. The way you're gonna do this is community images aren't just like a, it's like a docker image in that it's got like a version associated with it. So yeah like if the docker image, you might always do like docker on image name and then a tag of latest like always give me the latest one every time I run this. You can do the same kinds of things and you'll see that if you dig into the resource U MRIs and the image definition ur urs in that you're actually pointing down to version and version could just be like latest it could be a tag and the next VMSS instance that you bring up could potentially be running something different than the rest of it. There could have been something bad that happened along the way. Whatever ear mileage may vary. Yes, I'm having fun going through here and just going, HP has some stuff out here. Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees they want to partner with you to implement and administer your Microsoft cloud technology, visit them at intelligent.com/podcast. That's I-N-T-E-L-L-I-G-I-N k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud so you can focus on your business. So there's some good stuff. There's some an HP HPE ES morale software documentation. So they have an image out there for their ESM morale. I don't even know what it is but they have some images out there for that. It looks like it's primarily different vendors that have built their services, bundled them into a VM and pushed 'em out there. But then you do have these random ones like Pete's specialized VM image, huh. It will be interesting to see the uptake too. And I feel like at some point in time you need better sorting or maybe you don't necessarily go to the community image to find it but if you have a specific vendor that you buy software from that you're using it from, it gives them an option to put it out there and maybe trust them to point you to the right image. It's an interesting model of how do you figure out if there's something out there you wanna use. I would almost wanna see it where you could browse by publisher and that's a little hard to do maybe today like it, it'd even be nice if you could just maybe browse by like publisher URI. So there's a couple extra fields if you load one of these up. Say you push the community image out there and and you sort of see the metadata associated with it. So there's name of the resource that makes sense, what location does it live in? What's its architecture X 86, X 64, that kind of thing. But there's also a publisher URI and a legal agreement URL. So if you go look today, like there's a bunch of stuff even that appears to be published by Microsoft where like they've just skipped those fields. and publishing URI is ww www.example.comkind of thing. If you go out and browse it, I don't know if you were noticed but like all the by default it's sorted by the public gallery name. Yep. So a bunch of stuff that shows up there is for actual like Microsoft services, there's a ton of AKS images that just fill up the first couple of screens, like different versions of Ubuntu running different versions of container DA FIPs compliant container D and then they have all like the permutations of that. So you see each image like published globally. So okay there's one image but rather than being in one one region it's in 60 regions .Yes And just pushed all over the place to prevent egress charges from eating up too much and things like that. But there's tons of just variants of different things out there. Yeah, you'd have to go through the list and see and I imagine most of this would be like very much like a test flight ish kind of thing. Like a vendor comes to you and says hey here's the image definition URI so that you don't have to go searching for it this way. Yeah because even like the way it is today, like grouping by like the public gallery name and things like that, like it's a messy way to get in there and view things a. Hundred percent. So definitely has potential I I agree it needs some work to be able to sort filter, make it usable. If you wanna start in community images versus a vendor telling you hey we have all these community images out here. Here's our public gallery name or here's the link like you said directly to that image we have published for you. If you want, if you're up in the portal. So something you can do is in the upper right if you're in the list view, go click on the list view and change over to the summary view and then do something like summarize by location. We'll show you a map and the number of deployed images out at out at each location. But you can then go in, there's a summary view for a gallery name and you can just say hey show me like the top 10 publishers in the gallery. Things like that. Hey. Scott, did you try clicking on the summary view by location and then actually clicking on a location? I did not click on a location. I mean they came up Oh yeah. , they're, they're still working on that. They're.Broken some underlying APII think. Yeah that was my first one. I'm like oh it's deployed in East US two and I got an error. So it's not just me , that's a, it's interesting.Maybe we should create a podcast gallery Scott of all of our VMs of nothing 'cause I don't have that many customized ones. I've done a few for like dev box and AVD where I've done some gold images but nothing that I don't know that I'm pushing any public galleries anytime soon. I'd be super scared to publish most stuff. Like I think you'd have to be a little bit of illegal eagle to get some of that out there, right? Like I would not want to publish a Windows 11 image. Lemme put it that way for Pete's special image gallery over there. That doesn't seem . Something could be off there. Well.But you'd still have to license it, right? So it's not on you to necessarily license the OSS or from a legally standpoint in terms of somebody doing something on your image and it somehow coming back on you. You. Just don't know. So in my mind, let's put it this way, like given the choice between going and getting like an Ubuntu image from the marketplace, Azure marketplace, okay that that certified scanned publicly verifiable thing versus a community gallery. I'm either gonna go to the marketplace or I'm gonna build my own. That's it. I'm not gonna go to the community gallery and deal with deal with that kind of thing. Especially for a base image in my head it would be like, ooh, base images marketplace, great, we can get those And then if whatever you need in a base image isn't there in a base image like what's my overhead to add it and maintain it, I bet that's gonna be like right in line if not lower than dealing with something from a community gallery. Yeah. And then I, I would think a lot of the community gallery over time turns into probably what it looks like the AKS team is doing where there are a bunch of like test images and variants and things like that that you can go out and run with. So if I'm Citrix and I'm publishing NetScalers out, I might have my marketplace images for NetScalers and then maybe I have an entire test bed set of images that I can let customers get on like early days for a new release to go vet something. Yeah, I think that's where I'd see a lot of benefits to it 'cause looking through it, I did see a couple, let's see if these come back up. Yeah there's some here that you have nightly builds net service who are these by edgeless systems has something out there. I don't know what they do. Any cloud always encrypted open source solutions for confidential computing. But if you go look for like nightly you will see some of these images where there's nightly builds of stuff or dev builds or beta builds and I agree with you there where if you have some of those production workloads and you do wanna have give customers the option to go test on a nightly build or a lab build or something like that, this could be a good place for it. But again I think then you're coming through the vendor's website. You're not necessarily out here browsing for edgeless systems nightly builds because. .I don't know why. Yeah. So fascinating. More services see where it goes. But with that I have meetings coming up Scott we have some more topics. Yeah we have more topics but we might have to punt those for next week unless you had another quick one you wanted to talk through. So we're talking galleries and rback and sharing and things like that. So one that crossed my radar, we've talked a bunch about log analytics and custo and things like that in the past table level AC in custo clusters. Have you seen this one out there and kicking about. You sent this one to me a few weeks ago 'cause we were talking about it from a sentinel deployment perspective of what if I want to have a log analytics workspace and layer sentinel on it but I don't necessarily want everybody to have access to everything in my log analytics where maybe those users using Sentinel doing it for those SIM workloads need access to the entire log analytics workspace. But my app developers only need access to certain data in there like the app services they're working on where they're using it for app insights or something like that. And it was how do you secure your logs if you're using a single instance of log analytics for these different workloads? And you sent this to me when we were talking about that 'cause up in before I had not seen this one. Yeah. So this is a capability that is in preview uh, as far as being able to use like Azure R back in this manner. Yep. TLDR is you end up with a log analytics workspace where you're gonna create some some new roles around that log analytics workspace. So you're gonna have a new role at the workspace level like all up here's my deployed resource and all the tables within it and what that role does, it's a kinda limited permission role that has access to read workspace details and it has the ability to run a query but it does not have the ability to read any data from any tables in there. So that kind of gives you the ability to go in and see hey what's out there But then if you actually wanna run against it, you need additional permissions to get at it And then you have a table level role which effectively becomes a reader role and those are just scoped down at the table level to let folks in on that side. So in combination like when you have both the roles and they both line up the right way, then you get this magical super set where not only can you see the table and you have the ability to run queries but now you have the additional grant and additional permission to be able to execute a query, uh I guess execute a query, read data out of the table. Yeah. It's. Weird because the permission is like workspaces slash query slash read and it's really, it should be like WordSpace slash query slash execute and read or whatever it happens to be, something like that.But because these are are back rolls, you can do things like action have a not action. So you could say like for this user they're not allowed to do this thing on this table, anything like that up and down. So it's pretty familiar once you know what the roles are that are out there. So that customer role that you created at the top and then the reader role for each table, it's just going ahead and applying RAC at that point to get it out there. So I've been having to play around with it like it's pretty seamless like I mean it's, it really does just bring your scope for RAC down to a lower level down to that table level within a log analytics resource. So there still might be some weird things in there like you mentioned like Sentinel is one of those things that really should have access to all the tables that are out there. So you need to think your way through that one and what that looks like and maybe even like where users execute queries from, do they execute them from Sentinel which is running on say like a managed identity and it has access to everything or do you give them access to the log analytics workspace where then they're coming in as their user principle and all that kind of stuff to get to where they need to be. And it. Also looks like you talked about permissions but it also has a couple different access control modes. Going back to kind of the example that I had talked about where you can set workspace permissions where it doesn't allow granular RAC and you essentially have access to everything but they also have a user or a user resource or workspace permissions where it's not even going and it looks like and setting it up the table. But if you use that control mode you can do granular RAC granted based on the resource they can view versus just a let's go set it on this table or this table and going down that route. This. Will be the new mode going forward. I I like my sense is once this GA is that the old way of table level access and the reason I say it's probably gonna go away is 'cause they started calling it the legacy method of setting table levelread. That's usually a good hint. That's my hint that at some point like when this capability GA's they'll get away from the old way of doing it. 'cause the old way of doing it was still Azure identity driven but you were doing a ton with custom roles at the end in in that one and you really had to get like super granular in your definitions of those roles to get them to where they needed to be and really get 'em like dialed in. So this is potentially a little bit easier there. There might be trade-offs in granularity or things like that. Like we'll see if they even introduce like additional additional levels in there. Do you get to the point where there is say like a query versus a read versus an update kind of RAC thing that you can push in at a table level? You know, who knows? We'll see if it gets there. Got it. So that table level, I'm reading this article more, the access control mode is that differentiation has been around for a couple years now. Since 2019. It's just the table level RAC stuff that's in preview that's brand new. I. Think it's confusing though 'cause technically like when I go look at the old stuff, the old table level of access was also RAC. Like it was all based on on it. Was still got it Azure. Roles and application of those roles to an identity, those kinds of things. So I think this is bringing more clarity to what are the permissions within those roles and potentially like rationalizing, make that management a little bit easier. Yeah, I found it. This is the one disadvantaged to shared tab. Scott, I can't see where you are. The set table level read access versus the legacy set table read access in this article. Huh? It's a confusing one but kicking out there in preview. It's been in preview for I think like a month or two now, like a little hot minute. So hopefully not too much longer. And then that one GA's sounds. Good. I need to go look at this one some more too. This one's on my list, Scott, my never ending list. This one makes it there. There we go. Added to the list. All right, success. Sounds good. Well I have a meeting now in three minutes. So with that we will wrap it up on this Monday morning and get to our work week a meeting and then we have to go renew some Azure certs because they're expiring. Yep, sounds like a plan. Alright. . Well thanks Scott.Enjoy the rest of your day week and I'm sure we will talk to you a little later this week. All. Right, thanks Ben. Yep. bye-Bye. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn about Office 365 and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 357 – Community galleries for Azure Compute Gallery
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 36:56 — 25.4MB)
In Episode 357, Ben and Scott run through the recently announced Community gallery capability that has been added to the Azure Compute Gallery service. They also take a few minutes to discuss the public preview of table-level RBAC read-access controls for your Log Analytics workspaces.
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 319 – Taking a peek at the Microsoft 365 roadmap
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Feb 2, 2023 | Podcast
Blubrry Player
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 319 – Taking a peek at the Microsoft 365 roadmap
|
Back 15 secondsForward 15 secondsPlay Speed
Podcast: Play in new window | Download (Duration: 29:27 — 20.3MB)
In Episode 319, Ben and Scott talk through a fun new way to keep up with updates to the Microsoft 365 roadmap using Office 365 Roadmap watch and them discuss a new item on the roadmap – explicit recording consent for Teams Meetings. Next up they get into IPv6 support coming to conditional access in March 2023 and some changes coming to Azure reservations now that Savings plans for compute are here.
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 129 – The Latest and Greatest in Azure and Office 365
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Jun 13, 2019 | Podcast
Blubrry Player
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 129 – The Latest and Greatest in Azure and Office 365
|
Back 15 secondsForward 15 secondsPlay Speed
Podcast: Play in new window | Download (Duration: 36:43 — 25.2MB)
In Episode 129, Ben and Scott talk about the ability to login to your Linux virtual machines in Azure with Azure AD, adoption resources for Microsoft Teams, updates to Outlook on the desktop and mobile, and Yammer controls for data residency.
Sponsors
- Mover.io – Scan, Plan, Migrate, Report. Migrations that don’t suck – with Mover!
- Opsgility – Your Cloud enablement partner to help guide your organization through all phases of Cloud migration and adoption
- ShareGate – ShareGate helps you uncomplicate your cloud. Our industry-leading products help IT professionals worldwide migrate their business to the Office 365 or SharePoint, automate their Office 365 governance, and understand their Azure usage & costs
- Office365AdminPortal.com – Providing admins the knowledge and tools to run Office 365 successfully
- Intelligink – We focus on the Microsoft Cloud so you can focus on your business
Show Notes
- It was just a three-hour tour…
- Adding Azure Active Directory to Linux Virtual Machines
- Save your Office deployment configurations to the cloud
- How to get started with Microsoft Teams, 10 questions to ask yourself to help you get started!
- NEW: Microsoft Adoption Resource Hub
- Outlook for Windows rolls out its simplified user experience
- Outlook Mobile Updates
- New Yammer files in Office 365-connected groups will be stored in SharePoint
- Yammer Supports EU Data Residency with No External Collaboration
- We’re increasing the SharePoint hubs limit to 2,000
Previous Episodes
- Episode 89 – Azure Migrate with Jeremy Winter
- Episode 116 – Azure Sentinel
- Episode 117 – Azure Enterprise Scaffold
- Episode 126 – Privileged Accounts In Azure AD The Right Way
About the sponsors
| Mover is a cloud migration company that specializes in moving your company’s files from file servers or cloud storage like Box, Dropbox, and Google, into Office 365. Their patented technology makes Mover the fastest OneDrive file migrator in the world. Moving dozens of terabytes of data a day is a breeze. Scan, Plan, Migrate, Report. Migrations that don’t suck – with Mover! Visit mover.io for more info. |
|
| As the leading global brand for enabling the Microsoft Cloud, Opsgility’s global Microsoft MVP and multi-certified Cloud Solutions Architect team has authored over twenty MOC Courses, the Microsoft Press Book Implementing Azure Solutions 70-533 and numerous Microsoft Cloud Practice Playbooks for Microsoft Partners. And for a limited time, you can get your team certified in the most exciting cloud business today with a 25% discount off instructor-led training prep courses for Azure and Microsoft 365! Visit https://opsgility.com/MicrosoftCloud to learn more. | |
| Every business will eventually have to move to the cloud and adapt to it. That’s a fact. ShareGate helps with that. Our industry-leading products help IT professionals worldwide migrate their business to the Office 365 or SharePoint, automate their Office 365 governance, and understand their Azure usage & costs. Visit https://sharegate.com/ to learn more info. | |
| Intelligink utilizes their skill and passion for the Microsoft cloud to empower their customers with the freedom to focus on their core business. They partner with them to implement and administer their cloud technology deployments and solutions. Visit Intelligink.com for more info. |
Episode 122 – Saving Money on Compute in Azure
by [Ben](/content/author/benmsclouditpro/ "Posts by Ben"/index.html) | Apr 25, 2019 | Podcast
Blubrry Player
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 122 – Saving Money on Compute in Azure
|
Back 15 secondsForward 15 secondsPlay Speed
Podcast: Play in new window | Download (Duration: 35:05 — 24.1MB)
In Episode 122, Ben and Scott talk about strategies for saving money on virtual machines in Azure by stopping them when they’re not needed, right-sizing your workloads, and techniques for horizontal scaling with Azure autoscale.
Sponsors
- Mover.io – Scan, Plan, Migrate, Report. Migrations that don’t suck – with Mover!
- Sperry Software – Powerful Outlook Add-ins developed to make your email life easy even if you’re too busy to manage your inbox
- Opsgility – Your Cloud enablement partner to help guide your organization through all phases of Cloud migration and adoption
- Office365AdminPortal.com – Providing admins the knowledge and tools to run Office 365 successfully
- Intelligink – We focus on the Microsoft Cloud so you can focus on your business
Show Notes
- Start/Stop VMs during off-hours solution in Azure Automation
- Virtual machines lifecycle and states
- Properly Shutdown Azure VM to Save Money
- Overview of autoscale in Microsoft Azure Virtual Machines, Cloud Services, and Web Apps
- Webhooks: Integrating Microsoft Azure Automation with Slack
- Azure Autoscale
- Sizes for Windows virtual machines in Azure
- Sizes for Linux virtual machines in Azure
- Azure products available by region
- Azure Global Bootcamp Locations
Related Episodes
About the sponsors
Buy us a Coffee
Name
FirstLast
Product Name
Small - $2.00Medium - $3.50Large - $5.00
Total
Payment Method
PayPal CheckoutCredit Card
MasterCard
Visa
Supported Credit Cards: MasterCard, Visa
Credit Card Number
expiration-monthexpiration-yearcvv
Card Number Expiration Date
Expiration Date CVV
Security CodeCardholder Name
×
Contact Us
Contact Us
Contact Form
This field is for validation purposes and should be left unchanged.
First Name
Question or Comment
Add me to the mailing list
Signup to be notified when new podcasts are published, participate in listener surveys and give input into future episodes!
Sign me up!!
This field is hidden when viewing the form
Tags
Checking your Browser…
Verify you are human
Verifying...
Stuck? Troubleshoot
Success!
Verification failed
Verification expired
Verification expired
×
Microsoft Cloud IT Pro Podcast
Episode 429: Getting started with LLM Wikis
Microsoft Cloud IT Pro PodcastMicrosoft Cloud IT Pro Podcast
Episode 429: Getting started with LLM WikisEpisode 429: Getting started with LLM Wikis
More
Speed: 50%Speed: 75%Speed: NormalSpeed: 125%Speed: 150%Speed: 175%Speed: DoubleSpeed: Triple
Back 15 seconds
Forward 60 seconds
More
more
Speed: 50%Speed: 75%Speed: NormalSpeed: 125%Speed: 150%Speed: 175%Speed: DoubleSpeed: Triple
Back 15 seconds
Forward 60 seconds
Currently Playing
More
Notifications
PayPal