Shared posts

30 Sep 10:09

Un pueblo de Salamanca, con menos de 100 habitantes, ofrece gestionar el único bar que queda por un euro al año

by Quinqui

Coca de Alba, en Salamanca, cuenta con apenas 95 habitantes empadronados y se enfrenta al mismo difícil futuro que tantos otros pueblos de la España

etiquetas: salamanca, bar, gestión

» noticia original (www.directoalpaladar.com)

30 Sep 10:05

A qué se llama Estado palestino mientras Israel comete más genocidio

by TooBased

Se llama Estado palestino, en el mejor de los casos, al 22% de la Palestina histórica. La mayor parte de ese 22% también está ocupada por Israel: son islotes sin conexión territorial y controlados por la potencia ocupante. En los últimos días otros diez países han reconocido el Estado palestino, entre ellos, Francia y Reino Unido, miembros permanentes del Consejo de Seguridad de la ONU. El paso británico es especialmente simbólico, ya que Londres fue potencia ocupante de Palestina tras la Primera Guerra Mundial y firmó en 1917 la Declaración Ba

etiquetas: estado palestino, israel, genocidio

» noticia original (www.eldiario.es)

30 Sep 07:41

TRUMP y NETAHYAHU ANUNCIAN un PLAN de PAZ para GAZA

by Rubén Gisbert

El primer ministro israelí, Benjamin Netanyahu, ha aceptado este lunes el plan del presidente de EEUU, Donald Trump, para la paz en Gaza y también en Oriente Medio. Así lo han anunciado ambos líderes en una rueda de prensa tras mantener una reunión de unas tres horas en la Casa Blanca. La propuesta, compuesta por 20 puntos, contempla un Gobierno de transición sin Hamás supervisado por un Consejo de Paz que presidiría el propio Trump o la futura creación de un Estado palestino. "Hoy es una jornada histórica, uno de los mejores días en la historia de la civilización", ha asegurado el mandatario estadounidense.

¡ATENCIÓN! (Hasta el 30 de Septiembre) SI ERES AUTONOMO o EMPRESA APROVECHA y OBTÉN LA HERRAMIENTA de Inteligencia Artificial “AIKIT” y un curso de adaptación a tu negocio 100% SUBVENCIONADO con una partida ya entregada al gobierno de España a fondo perdido (LO QUE NO SE ENTREGUE A LOS SOLICITANTES SE LO QUEDA EL GOBIERNO), inscribirte son 2 min.

No tendrás que pagar nada ya que AiKit es un agente digitalizador y puede pedir por ti la subvención QUE ACABA el 30 de Septiembre. No tendrás que pagar nada. Solo inscribirse en el enlace y solicitarán la ayuda en tecnología de IA adaptada a tu negocio y con formación y si lo necesitas, un cheque tecnológico (ordenador, smartphone, tablet…)

ESTA EMPRESA ES CONSULTORA DE 14.000 EMPRESAS A NIVEL NACIONAL con una dilatada trayectoria y experiencia en el sector privado.

Enlace de INSCRIPCIÓN: https://www.ia-empresarial.es/?ref=rg
30 Sep 07:39

TODA la VERDAD DETRÁS de la FOTO del REY FELIPE con JOLANI en la ONU

by Rubén Gisbert
30 Sep 07:37

Qué significa cuando una persona se ríe sola en voz alta, explicado por la psicología

by Luz Marina Carpio

No hay nada más común que reír a carcajadas con otros, pues es una señal clara de que estás disfrutando. Y cuando una persona se ríe sola y en voz alta, la sensación es muy similar, además este gesto significa que liberas tensiones, revives recuerdos o, simplemente, que te desahogas.

En relación con este tema, una investigación en Discover Mental Health indica que el 10 % de la risa ocurre en soledad. De acuerdo con el modelo de la risa solitaria (MRS), reírse solo, estando acompañados o no, es producto del humor y las emociones, o es algo que se cultiva por placer o autocuidado. Estamos ante una acción con varias interpretaciones que aquí te explicamos.

Regreso de un recuerdo

Hay experiencias inolvidables, llenas de humor y que te hicieron reír sin parar; son esos momentos que quisieras repetir. Por lo general, se trata de eventos que involucran a más de una persona o anécdotas divertidas que viviste sin nadie más. Gracias a la memoria emocional, cada vez que estas escenas vuelven a tus pensamientos es posible que rías en voz alta, aunque estés solo, como resultado de una emoción positiva.

Libertad

Cuando alguien se ríe solo es consciente de que otros no pueden oírle y es precisamente esa soledad lo que aprovecha para soltar las carcajadas que quizás en público no lanzaría. De acuerdo con un artículo de European Journal of Humour Research, en varios foros web los participantes afirman reírse con más libertad en soledad.

Coraje

Como se comentó al principio, puedes reírte en voz alta sin compañía o en público. En este último escenario, la risa llega a considerarse un acto de coraje, señala la Revista Clínica Española. No toda persona se anima a carcajearse frente a otros, por pena, por cumplir normas sociales o culturales y por respeto a ciertas situaciones o contextos.

Desahogo y felicidad

La Asociación Mexicana de Alternativas en Psicología preguntó a estudiantes universitarios sobre las emociones y su relación con la risa. La mayoría de los participantes contestó que, al reírse en solitario, se experimenta principalmente desahogo, tranquilidad, relajación, paz y felicidad. Esto significa que cuando una persona se ríe sola en voz alta, estaría cultivando emociones positivas, según el análisis.

Autosuficiencia

Discover Mental Health explica que al reírnos en voz alta a solas “transformamos positivamente la experiencia de la soledad, mejorando potencialmente la autosuficiencia y la resiliencia”. De este modo, se aprovechan las ventajas de estar sin compañía, se aprecia el valerse por sí mismo y la capacidad de adaptación a situaciones complejas.

No te vayas sin leer: Curiosidades de la risa

¿Cuándo es un problema si una persona se ríe sola en voz alta?

En general, reírse es un gesto de felicidad, pero si la risa en solitario viene acompañada de otras señales, es posible que sea el síntoma de un problema de salud. Esto se conoce como risa patológica, suele ser incontrolable y se asocia con ciertas enfermedades del sistema nervioso central (refiere la revista Pediatría Integral), por ejemplo: demencia, ictus, tumores. También con enfermedades mentales como la esquizofrenia o manías.

Es esencial acudir a un profesional de la salud mental cuando la risa solitaria es frecuente y fuera de lugar, y hay comportamientos extravagantes o conductas erráticas que alteran la vida cotidiana. Pero por sí sola, no tiene por qué considerarse como algo preocupante.

En conclusión, reír en silencio o en voz alta, ayuda a canalizar las emociones, a cultivar los sentimientos positivos, a alegrar los días y a regalarse una dosis de bienestar. Por ello, no son de extrañar los estudios que avalan el papel crucial de la risa como reductora del estrés, la ansiedad, la enfermedad y el dolor. Sírvete de ella: reír es gratis y hace bien.

La entrada Qué significa cuando una persona se ríe sola en voz alta, explicado por la psicología se publicó primero en La Mente es Maravillosa.

30 Sep 07:28

El Mundo de Camus en 50 Frases Esenciales

by Bloghemia

En un mundo que a menudo parece desprovisto de sentido absoluto, la voz de Albert Camus emerge no con respuestas dogmáticas, sino con una valiente y lúcida afirmación de la vida misma. Su pensamiento, forjado en el crisol de la guerra, la injusticia y la belleza mediterránea, constituye un faro de dignidad humana frente al absurdo de la condición humana. Más que un sistema filosófico cerrado, Camus nos legó una actitud: una rebelión serena que rechaza tanto la desesperación nihilista como las consolaciones ilusorias, invitándonos a encontrar valor en el corazón mismo de la lucha.

Este “Breviario de la dignidad humana”, compilado con motivo del centenario de su nacimiento, funciona como un mapa esencial para navegar su obra. A través de sus propias palabras, extraídas de novelas, ensayos y diarios, somos testigos de la coherencia de un hombre que puso la fidelidad a lo humano por encima de cualquier ideología. Sus frases no son solo ideas, sino experiencias vividas; son destellos de lucidez que iluminan los grandes temas que lo obsesionaron: la felicidad como acto de rebelión, la solidaridad frente al sufrimiento, la búsqueda de la justicia sin traicionar a la libertad y la belleza como antídoto contra la muerte.

Recorrer estas cincuenta frases es, por lo tanto, adentrarse en un diálogo íntimo con una de las conciencias más necesarias del siglo XX. Nos confrontan con preguntas esenciales sobre cómo vivir con autenticidad en un universo indiferente, cómo amar este mundo efímero y, sobre todo, cómo ser un hombre, en el sentido más noble y sencillo de la palabra. Camus no ofrece una paz barata, sino la noble tarea de crear sentido desde la finitud, abrazando la luz y la sombra con igual coraje.

  1. “La lucidez es la herida más próxima al sol.”
  2. “En medio de la plenitud del aire y la fertilidad del cielo, parecía que la única tarea de los hombres era vivir y ser felices.”
  3. “El interés por la libertad y la independencia solo son concebibles en un ser que aún conserva la esperanza.”
  4. “Lo único que importa es la voluntad de ser feliz.”
  5. “No se vive más o menos tiempo feliz. Uno es feliz y punto, no hay más.”
  6. “La felicidad está próxima a las lágrimas.”
  7. “Quisiera poder amar a mi país amando a un tiempo la justicia. No quiero para él ninguna forma de grandeza, ni la de la sangre ni la de la mentira.”
  8. “¿Qué es un hombre? […] Es esa fuerza que siempre termina derrocando a los tiranos y a los dioses.”
  9. “El hombre debe afirmar la justicia para luchar contra la eterna injusticia, crear la felicidad para protestar contra el universo de la desdicha.”
  10. “Sigo creyendo que este mundo no posee un sentido superior. Pero sé que algo en él posee sentido y es el hombre, porque él es el único ser que exige que lo tenga.”
  11. “Solo la servidumbre es solitaria, incluso cuando se escuda en mil bocas para ovacionar al poder.”
  12. “La libertad no es un regalo que nos dé un Estado o un jefe, sino un bien que se conquista todos los días, con el esfuerzo de cada individuo y la unión de todos ellos.”
  13. “Sin la cultura, y la relativa libertad que ella supone, la sociedad, por perfecta que sea, no es más que una jungla.”
  14. “Las tiranías de hoy se han perfeccionado: ya no admiten el silencio, ni la neutralidad. Hay que pronunciarse, estar a favor o en contra. Pues bien, en ese caso, yo estoy en contra.”
  15. “Como artistas tal vez no tengamos necesidad de intervenir en los acontecimientos de nuestro siglo. Pero como hombres sí.”
  16. “No puedo evitar inclinarme hacia el lado de lo cotidiano, hacia el lado de aquellos, tanto da quiénes sean, a los que se humilla y se degrada.”
  17. “Existe una solidaridad de todos los hombres en el error y en el extravío.”
  18. “Ni en el corazón de los individuos ni en las costumbres de las sociedades habrá una paz duradera mientras la muerte no quede fuera de la ley.”
  19. “La nobleza de nuestro oficio siempre tendrá sus raíces en dos compromisos difíciles de mantener: el rechazo a mentir sobre lo que sabemos y la resistencia a la opresión.”
  20. “Jamás he podido renunciar a la luz, a la alegría de existir, a la vida libre del lugar donde crecí.”
  21. “Estamos en alta mar. El artista, como cualquiera, también debe remar, a ser posible sin desfallecer, es decir, viviendo y creando.”
  22. “Los sueños varían con cada hombre, pero la realidad del mundo es nuestra patria común.”
  23. “El arte, en cierto sentido, es una rebelión contra aquello que de fugaz e incompleto tiene el mundo.”
  24. “Tal vez alcancemos la grandeza del arte en esa perpetua tensión entre la belleza y el dolor, entre el amor a los hombres y la locura de la creación.”
  25. “El hombre que se rebela no reclama la vida sino las razones de la vida.”
  26. “La afirmación de una limitación, de una dignidad y de una belleza comunes a los hombres tan solo implica la necesidad de extender estos valores a todos y a todo.”
  27. “Es posible rechazar toda la historia y tomar no obstante el mundo de las estrellas y del mar.”
  28. “Sin duda, la belleza no hace las revoluciones. Pero siempre llega el día en que las revoluciones la necesitan.”
  29. “Una revolución solo merece que muramos por ella si nos asegura la supresión inmediata de la pena de muerte.”
  30. “La verdadera generosidad con el porvenir consiste en darlo todo en el presente.”
  31. “En este tierra hay plagas y víctimas y, en la medida de lo posible, hay que negarse a estar con la plaga.”
  32. “Me siento más solidario con los vencidos que con los santos, me parece que no tengo debilidad por el heroísmo ni por la santidad. Lo que me interesa es ser un hombre.”
  33. “Siempre llega la hora en la que nos cansamos de las cárceles, del trabajo y del coraje y reclamamos el rostro de un ser querido y el corazón maravillado de la ternura.”
  34. “Si existe algo que es posible desear siempre, y obtener a veces, es la ternura humana.”
  35. “En el hombre hay más cosas admirables que despreciables.”
  36. “Sí, existe la belleza y existen los humillados. Por difícil que sea la empresa, querría no ser jamás infiel ni a la una ni a los otros.”
  37. “Pues en no ser amado solo hay mala suerte, pero en no amar hay desgracia.”
  38. “En medio del invierno, aprendí al fin que había en mí un ser invencible.”
  39. “Hoy, Dios mío, tan solo tengo una ambición: ser un hombre, del modo más sencillo posible. En efecto, también es un orgullo.”
  40. “No existe amor a la vida sin desesperación de vivir.”
  41. “Juzgar si merece o no la pena vivir es responder a la cuestión fundamental de la filosofía.”
  42. “En el apego de un hombre a la vida hay algo más fuerte que todas las miserias del mundo.”
  43. “Hay que imaginar a Sísifo feliz.”
  44. “La guerra no es buena, porque vencer a un hombre es tan amargo como ser vencido.”
  45. “Ser feliz es un deber.”
  46. “Pero ¿qué es la felicidad sino el simple acuerdo entre un ser y la existencia que lleva?”
  47. “No estoy hecho para la política porque soy incapaz de desear o de aceptar la muerte del adversario.”
  48. “Ni siquiera deseo ser un genio, pues bastante me cuesta ya ser un hombre.”
  49. “Es necesario amar la vida antes de amar su sentido. […] Y cuando el amor a la vida desaparece ningún sentido nos consuela.”
  50. “Envejecer es pasar de la pasión a la compasión.”

El cargo El Mundo de Camus en 50 Frases Esenciales apareció primero en Bloghemia.

30 Sep 07:26

GCP IAM & Co. - Practical Scenarios for Engineers and Cloud Certification Mastery

by Antonella Blasetti

Stop guessing about permissions

Let’s be honest: Identity and Access Management (IAM) can feel like a dry, boring topic. Any environment.

But it’s also the source of many common technical problems and a critical area of knowledge for any Google Cloud certification.

So, let’s take a different approach: Practical, real-world scenarios. You grasp these examples, and you are OK. I am betting that, if you are an expert, you are going to find out something new (as I did).

Core Concept: What is an Identity?

Before we look at what someone can do (permissions), we must first understand who or what is asking for access. In GCP, this “who” or “what” is called an Identity. An identity is just a principal that can be authenticated and authorized to use Google Cloud resources.

Identities are for people and for Infrastructure/Software (Service Account): It’s like a keycard. The VM running a nightly script doesn’t use a developer’s personal password; it uses its own dedicated “Service Account” ID badge

Types of Recognized Identities

To be used in an IAM policy, an identity must be “known” to Google’s authentication system. It doesn’t have to belong to your organization, but Google needs a way to verify who it is. Here are the main types:

  • Google Accounts: This is the most direct way. It includes any personal @gmail.com account or any corporate account managed through Google Workspace (e.g., user@your-company.com).
  • Google Groups: A collection of the Google Accounts. Importantly, a group can contain users from your own organization as well as external Google Accounts (e.g., from partner companies or personal @gmail.com accounts).
    This means that you can give easily permissions to external users in this way.
  • Service Accounts: These are native GCP identities for applications.
  • Federated Identities: This is the “external” part. Through services like Cloud Identity or Workload Identity Federation, you tell Google to trust an external Identity Provider (like Azure AD, Okta, or AWS). When a user from that external system tries to access GCP, Google effectively asks the external provider, “Do you vouch for this person?” If the provider says yes, Google accepts their identity.
    It is the standard way to obtain SSO (single sign on).

So, every IAM policy is about connecting one of these identities with a role (a set of permissions) on a specific resource.
Only resource permissions! (for AWS users)

The GCP IAM Golden Rule: Resources Hold the Permissions

This is the single most important concept to understand.

In GCP, permissions (roles) are never attached directly to an identity when it is created.

Instead, the process is always:

  1. You create an identity (e.g., my-service-account@…). At this point, it is just a name with no permissions.
  2. You go to a resource (e.g., a Storage Bucket).
  3. You modify that resource’s IAM policy to grant a role to the identity.
This is not immediately evident. In the Console you have the feeding that you can just set roles for the current project, in a bit clumsy way. But if you select folders or organizations in the project textbox, you can assign privileges at any level. More in the following scenarios.

Scenario 1: The “Hands-Off” Stakeholder

Need/Requirement: A project manager needs to monitor spending for a new app project. They must be able to view all billing reports and cost breakdowns, but for compliance and security reasons, they must have absolutely no ability to change, stop, or delete any technical resources (like VMs, databases, or storage buckets).

GCP Solution: Grant the project manager the IAM role of Billing Account Viewer (roles/billing.viewer) on the specific Billing Account. This gives them read-only access to billing information without any permissions to view or alter the technical resources themselves.

Example CLI Command:

gcloud billing accounts add-iam-policy-binding 012345–67890A-BCDEF0 \
- member="user:pm@example.com" \
- role="roles/billing.viewer"

Scenario 2: The Departmental Sandbox

Need/Requirement: The Data Science team needs a “sandbox” environment where they can do anything to any resources for their experiments.
However, they should not be able to see or touch the resources of the main “Production” environment. A central IT team must retain ultimate control over all environments.

GCP Solution: Use the Resource Manager to create two separate Folders, one named “Production” and one named “Data Science Sandbox,” under the Organization node.

The Data Science team (via a Google Group) is granted the Editor role (roles/editor) on the “Data Science Sandbox” folder.

The Production team gets relevant permissions only on the “Production” folder.

The central IT team is granted the Organization Admin (roles/resourcemanager.organizationAdmin) role at the Organization level.

Key Concepts:

Resource Hierarchy: The Organization > Folders > Projects structure is the key to enterprise-level control.

Permission Inheritance: Permissions granted at a higher level (like a Folder) automatically flow down to all the projects within it, simplifying management.

Isolation and Containment: Using the hierarchy to build strong security boundaries between teams and environments.

Example CLI Command:

# Create the folder under your organization
gcloud resource-manager folders create \
--display-name="Data Science Sandbox" \
--organization=123456789012

# Grant the Editor role to a group on the new folder (ID from previous command)
gcloud resource-manager folders add-iam-policy-binding 987654321098 \
--member="group:data-scientists@example.com" \
--role="roles/editor"

Scenario 3: The Automated Nightly Job

Need/Requirement: A developer has created a script that runs every night on a Compute Engine VM. This script needs to read data from a specific Cloud Storage bucket and write a summary into a specific BigQuery table. The script must run automatically without human interaction, and its credentials must be secure and limited only to the exact resources it needs.

GCP Solution (Following the Golden Rule):

Create the Identity: First, create a dedicated Service Account for the script. At this point, it has no permissions.

Grant Permissions on Resource #1: Go to the specific source bucket and edit its IAM policy. Add the new service account as a principal and grant it the Storage Object Viewer role (roles/storage.objectViewer).

Grant Permissions on Resource #2: Go to the specific destination dataset in BigQuery and edit its IAM policy. Add the same service account as a principal and grant it the BigQuery Data Editor role (roles/bigquery.dataEditor).

Attach the Identity: Finally, attach this service account to the Compute Engine VM. The VM now uses this identity to run the script.

Key Concepts:

Service Accounts: A non-human identity for applications, scripts, and VMs, allowing for secure, automated authentication.

Resource-level Permissions: The power of GCP IAM is applying permissions not just at the project level, but to individual resources (one bucket, one dataset, etc.).

Secure Automation: Eliminating the need to embed user credentials or keys in scripts, which is a major security risk.

Example CLI Command:

# 1. Create the identity (the service account)
gcloud iam service-accounts create nightly-job-sa --display-name="Nightly Job SA"

# 2. Grant permission on Resource #1 (the bucket)
gcloud storage buckets add-iam-policy-binding gs://my-source-bucket \
--member="serviceAccount:nightly-job-sa@<project-id>.iam.gserviceaccount.com" \
--role="roles/storage.objectViewer"

# 3. Grant permission on Resource #2 (the BigQuery dataset)
# Note: bq command is used for dataset-level permissions
bq add-iam-policy-binding --member-type serviceAccount --identity nightly-job-sa@<project-id>.iam.gserviceaccount.com --role roles/bigquery.dataEditor my_project:my_dataset

# 4. Attach the identity to a new VM
gcloud compute instances create my-vm --service-account=nightly-job-sa@<project-id>.iam.gserviceaccount.com

Scenario 4: The Secure Developer Workflow

Need/Requirement: A developer needs to test an application on her local laptop. The application is designed to run in a Cloud Function with very specific, limited permissions. To avoid bugs, she needs to ensure her local test environment has the exact same permissions as the production Cloud Function, not the broader permissions of her own user account (e.g., Project Editor). Typical.

GCP Solution:

A dedicated Service Account is created for the application, e.g., my-app-sa@….

This service account is granted the minimal required role, e.g., Pub/Sub Publisher on a specific topic. It has no other permissions.

The developer’s user account (developer@company.com) is granted the Service Account Token Creator role (roles/iam.serviceAccountTokenCreator) only on that specific service account.

The developer configures her local gcloud SDK to impersonate my-app-sa. When she runs her code locally, it authenticates to GCP as the service account, inheriting its tightly restricted permissions.

Key Concepts:

Service Account Impersonation: A user temporarily “borrowing” the identity of a service account. The user needs the iam.serviceAccounts.actAs permission to do this.

High-Fidelity Local Testing: Ensures that the development environment perfectly mirrors the production IAM environment, catching permission-related bugs before deployment.

Privilege Reduction: Even if the developer is a Project Editor, the script she is running is not. This drastically reduces the “blast radius” of a potential bug in the code.

Example CLI Command:

# Allow a user to impersonate a service account
gcloud iam service-accounts add-iam-policy-binding my-app-sa@<project-id>.iam.gserviceaccount.com \
--member="user:developer@example.com" \
--role="roles/iam.serviceAccountTokenCreator"

# Developer runs this on their local machine to assume the identity
gcloud auth application-default login --impersonate-service-account="my-app-sa@<project-id>.iam.gserviceaccount.com"

Scenario 5: The Centralized CI/CD Pipeline

Need/Requirement: Central GCP project (project-cicd-tools) for its CI/CD pipeline (e.g., Jenkins, GitLab Runner, or Cloud Build).
This pipeline needs to automatically deploy applications to multiple, separate production projects (project-webapp, project-backend-api, etc.). The pipeline must have permission to manage resources in those projects without having overly broad permissions.

GCP Solution:

  • A dedicated Service Account is created in the central tools project, e.g., deployer-sa@project-cicd-tools.iam.gserviceaccount.com.
  • In the target project-webapp, the administrator grants the Cloud Run Admin role to the full email address of that service account.
  • In the target project-backend-api, the administrator grants the Kubernetes Engine Developer role to the same service account.
  • The CI/CD pipeline is configured to use this service account to authenticate its deployment jobs.

Key Concepts:

  • Cross-Project Permissions: An identity (like a Service Account) is global and can be granted roles on resources in any project. The IAM policy on the resource simply needs to reference the identity’s unique email.
  • Centralized Tooling Architecture: A highly common and recommended pattern for managing shared services like CI/CD, monitoring, or security scanning, which avoids duplication and simplifies management.
  • Scalable Permissions: Prevents the need to create and manage separate credentials for each project, making the entire system more secure and easier to maintain.

Example CLI Command:

# In the TARGET project, grant deploy permissions to the SA from the CICD project
gcloud projects add-iam-policy-binding target-project-id \
--member="serviceAccount:deployer-sa@cicd-project-id.iam.gserviceaccount.com" \
--role="roles/run.admin"

Key Concept: Using Google Groups with External Users

A common and powerful question is: “Can I add users from outside my company to a Google Group?”

The answer is yes, absolutely. This feature is a cornerstone of secure collaboration in GCP.

Who can you add? You can add any valid Google Account to a group you manage, regardless of their email domain. This includes personal @gmail.com accounts and users from other Google Workspace organizations (e.g., consultant@external-firm.com).

The Prerequisite: The administrator of the Google Group must have the setting “Allow members outside your organization” enabled. This is usually on by default but is a critical check.

Why is this important for GCP? This allows you to grant permissions to a group that you control, but populate it with external members. You manage the permissions in GCP; the external partner manages their own people. This is the foundation for the delegated administration model shown in the next scenario.

Scenario 6: The External Partner

Need/Requirement: Your company (company-a.com) hires an external consulting firm (consulting-b.com) to manage your production Kubernetes clusters. You need to grant the engineering team of the external firm administrative access to your GKE resources without creating and managing user accounts for them in your own organization.

GCP Solution:
The consulting firm creates and manages a Google Group within their own domain, e.g., gke-admins@consulting-b.com.In your company’s production GCP project, you add gke-admins@consulting-b.com as a new principal.

You grant this group the Kubernetes Engine Admin role (roles/container.admin).

Key Concepts Demonstrated:

Federated Identity Management: Granting permissions to identities that exist entirely outside of your own GCP Organization. The IAM system trusts Google’s global identity system to authenticate the user.

Delegated Administration: The consulting firm is now responsible for managing who is in that group. If an employee leaves their firm, they are removed from the group, and their access to your projects is instantly and automatically revoked. This is a massive security and operational benefit.

Business-to-Business Collaboration: This is the standard, secure pattern for enabling collaboration between different companies on GCP.

Example CLI Command:

gcloud projects add-iam-policy-binding your-project-id \
--member="group:gke-admins@consulting-firm.com" \
--role="roles/container.admin"

Scenario 7: The Default Service Account Trap

Need/Requirement: A developer deploys a new VM or a 1st Gen Cloud Function. For convenience, they don’t specify a service account, accepting the default. The application works, but the security team is concerned. What is the risk and what should be done?

  • What is a Default Service Account? To reduce initial friction, GCP automatically creates a service account when certain services (most notably Compute Engine and App Engine) are enabled for the first time in a project. This allows a new user to immediately launch a VM or deploy a function that “just works” without needing to manually create an identity first.
  • The Hidden Problem: The convenience comes at a high security cost. This default service account ([PROJECT_NUMBER]-compute@… or [PROJECT_ID]@appspot.com) is granted the highly privileged Editor role on the project. This means any code running on that VM or Function can read, modify, and delete nearly any other resource in the same project.

GCP Solution and Guidelines:

  • Guideline: Avoid Defaults in Production. The number one rule is to never use default service accounts for production workloads. The Editor role presents too large a security risk if the service is compromised.
  • Best Practice: Create Dedicated Service Accounts. For any real application, create a new, dedicated service account with a clear name (e.g., invoice-processing-func-sa).
  • Apply Least Privilege. Grant this new account the absolute minimum permissions it needs to function. If a Cloud Run service only needs to read from one Pub/Sub topic, grant it the Pub/Sub Subscriber role on that specific topic, not on the whole project.
  • Explicitly Attach. Attach this new, limited-privilege service account to your VM, Cloud Function, or Cloud Run service during deployment.
  • Audit and Remediate. Security-conscious organizations should regularly audit projects to find resources using default service accounts and replace them. You can also safely remove the Editor role from the default service accounts if they are not being used, effectively disabling them.

Example CLI Command:

# Create a dedicated, minimal-privilege SA first
gcloud iam service-accounts create my-webapp-sa

# Grant it ONLY the permissions it needs (not shown here)

# Create the VM explicitly using the new SA
gcloud compute instances create my-secure-vm \
--service-account=my-webapp-sa@<project-id>.iam.gserviceaccount.com

Scenario 8: The Time-Bound Contractor Access

Need/Requirement: A contractor needs emergency access to debug a production issue. They need the powerful Project Editor role, but for strict security compliance, their access must automatically expire at 5 PM today and must only be usable from the corporate office’s IP address.

GCP Solution: Grant the contractor’s user account the Project Editor role, but attach an IAM Condition to this specific role binding. The condition is written in Common Expression Language (CEL) and contains two clauses:

  • A time-based clause to set an expiration: request.time < timestamp(“2025–09–28T17:00:00+00:00”)
  • An IP-based clause for location: origin.ip == “203.0.113.50”

Key Concepts Demonstrated:

  • IAM Conditions: The ability to add dynamic, attribute-based logic to an IAM policy. The permission is only granted if the condition evaluates to true at the moment of access.
  • Temporary Access (Just-in-Time): This is a core principle of modern security. Permissions are granted for a limited duration, eliminating the risk of forgotten, lingering accounts. Access automatically revokes without any manual cleanup
  • Context-Aware Access: Restricting access based on contextual attributes like IP address, time of day, or the type of resource being accessed. This is a foundational element of a Zero Trust security model.

Example CLI Command:

gcloud projects add-iam-policy-binding your-project-id \
--member="user:contractor@external.com" \
--role="roles/editor" \
--condition='expression=request.time < timestamp("2025-09-29T17:00:00Z") && origin.ip == "203.0.113.50",title=temp_access,description="Expires at 5PM UTC on Sep 29 2025"'

Scenario 9: Protecting Sensitive Data in a Pipeline

Need/Requirement: A company has an automated data pipeline. Raw data containing PII (Personally Identifiable Information) is uploaded to a “landing zone” Cloud Storage bucket. A Dataflow job processes this data, anonymizes it, and writes the clean, safe results to a BigQuery dataset for business analysts. The security requirements are strict:

  • Only the ingestion service can write new data to the raw PII bucket.
  • The Dataflow processing job can read from the PII bucket but cannot modify or delete the raw data.
  • Business analysts must be able to query the final BigQuery data but must be explicitly blocked from ever accessing the raw PII bucket, even accidentally.

GCP Solution: This requires a multi-layered approach using resource-level permissions and a Deny Policy.

  • Create Service Accounts: Create two dedicated service accounts: ingestion-sa and dataflow-sa.
  • Lock Down the PII Bucket: On the raw-pii-data bucket’s IAM policy:
  • Grant ingestion-sa the Storage Object Creator role (roles/storage.objectCreator).
  • Grant dataflow-sa the Storage Object Viewer role (roles/storage.objectViewer).
  • Do not grant any other permissions to this bucket.
  • Secure the BigQuery Dataset: On the clean_analytics_data dataset’s IAM policy:
  • Grant dataflow-sa the BigQuery Data Editor role (roles/bigquery.dataEditor).
  • Grant the Google Group analysts@company.com the BigQuery Data Viewer role (roles/bigquery.dataViewer).
  • Create a Deny Policy: At the Project level, create an IAM Deny Policy. This is a separate policy that overrides any allow permissions.
  • Denied Principal: group:analysts@company.com
  • Denied Permissions: storage.objects.get, storage.objects.list
  • Target Resource (via Tag): The policy applies to any resource with the tag data-sensitivity=pii. Apply this tag to the raw-pii-data bucket.

Key Concepts:

  • Data Pipeline Security: A practical example of securing an end-to-end data flow by giving each component the minimum necessary permissions on the data resources.
  • Defense in Depth: Using multiple security controls (least privilege on the bucket, least privilege on the dataset, and a deny policy) to protect sensitive data.
  • IAM Deny Policies: An advanced feature where deny always overrides allow. This is the ultimate safety net to prevent a group of users from ever accessing certain resources, regardless of any other roles they might have (like Project Viewer).
  • Policy Enforcement with Tags: Using resource tags to apply security policies (like a Deny Policy) at scale. You can ensure that any future storage bucket tagged with pii automatically gets this protection.

Example CLI Command:

# (Deny policies are complex to create via CLI; this is a conceptual example using a YAML file)
# 1. Define the deny rule in a file, e.g., deny-rule.yaml
# 2. Apply the policy to the project
gcloud iam policies create deny-analyst-access \
--attachment-point=[cloudresourcemanager.googleapis.com/projects/your-project-id](https://cloudresourcemanager.googleapis.com/projects/your-project-id) \
--kind=denypolicies \
--policy-file=deny-rule.yaml

Scenario 10: ABAC for Data Residency

Need/Requirement: A multinational company must enforce strict data residency rules due to regulations like GDPR. The finance team is split between the EU and the US. The policy must be:

  • Members of the EU finance team can only access data in storage buckets physically located in the EU.
  • Members of the US finance team can only access data in storage buckets physically located in the US.
  • The policy must scale automatically to new buckets and new team members without needing manual IAM changes on every bucket.

GCP Solution: This is a perfect use case for Attribute-Based Access Control (ABAC), implemented with Tags and IAM Conditions.

  • Define a Resource Attribute (Tag): At the Organization level, create a Tag Key called data-location with two possible Tag Values: eu and us.
  • Apply Tags to Resources: Tag the relevant Cloud Storage buckets. The europe-financial-reports bucket gets the tag data-location: eu. The usa-quarterly-earnings bucket gets the tag data-location: us.
  • Define User Attributes (Groups): Use Google Groups to represent the user attributes. Create two groups: gcp-finance-eu@company.com and gcp-finance-us@company.com.
  • Create a Single, Conditional IAM Policy: At the Project level, create a single IAM binding that grants the Storage Object Admin role (roles/storage.objectAdmin) to both groups, but with a condition for each.
  • For the gcp-finance-eu group, the condition is: resource.matchTag(‘YOUR_ORG_ID/data-location’, ‘eu’)
  • For the gcp-finance-us group, the condition is: resource.matchTag(‘YOUR_ORG_ID/data-location’, ‘us’)

Key Concepts:

  • Attribute-Based Access Control (ABAC): The access decision is not based on a static role alone, but on a dynamic evaluation of attributes: the user’s group membership (their attribute) and the resource’s tag (its attribute).
  • Scalable Governance: This is the key benefit. When a new EU finance team member joins, you add them to the Google Group, and the policy automatically applies. When a new EU bucket is created, you simply tag it data-location: eu, and it is instantly protected by the same project-level policy. You don’t need to update IAM policies on hundreds of buckets.

Enforcing Data Residency: This pattern provides a robust and auditable way to enforce data sovereignty and compliance rules across an entire organization.

Example CLI Command:

gcloud projects add-iam-policy-binding your-project-id \
--member="group:gcp-finance-eu@example.com" \
--role="roles/storage.objectAdmin" \
--condition='expression=resource.matchTag("123456789012/data-location", "eu"),title=eu_data_only'

Scenario 11: The Zero Trust Application

Need/Requirement: A company needs to host an internal web application (e.g., an HR portal) on Compute Engine. The security requirements are stringent:

  • The application must not be exposed to the public internet.
  • Only authenticated employees of the company can access it.
  • The web server VMs must be able to connect to a backend Cloud SQL database, but the database must be completely isolated from all other network traffic.
  • Data from the database must not be exportable to an unauthorized location.

GCP Solution: This multi-layered solution combines identity and network security.

  • User Access (Identity-Aware Proxy): Place the application’s load balancer behind Identity-Aware Proxy (IAP). On the IAP settings, grant the IAP-secured Web App User role to the Google Group employees@company.com. This ensures only authenticated employees can even reach the application’s login page.
  • Network Segmentation (Firewall Rules with Service Accounts): Create two dedicated service accounts: webapp-sa and database-sa. Attach webapp-sa to the web server VMs. In the VPC firewall rules, create a rule that allows TCP traffic on port 3306 with a source of serviceAccount:webapp-sa and a target of serviceAccount:database-sa. This locks down database access to only the web application VMs, regardless of their IP addresses.
  • Data Exfiltration Prevention (VPC Service Controls): Place the project containing the application and database inside a VPC Service Controls perimeter. This perimeter blocks GCP APIs by default. It prevents a user or compromised service from, for example, running a gcloud sql export command and saving the data to a public Cloud Storage bucket in another project.

Key Concepts:

  • Zero Trust Architecture: The principle of “never trust, always verify.” Access is granted based on verified identity (IAP), strict network segmentation (firewall rules), and API-level controls (VPC SC), not just network location.
  • Identity-Aware Proxy (IAP): A powerful tool for securing web applications by wrapping them with Google’s identity and access management layer.
  • Micro-segmentation: Using service accounts in firewall rules to create fine-grained network controls based on workload identity, not just IP addresses.

VPC Service Controls: A critical defense against data exfiltration, creating a secure “walled garden” for your most sensitive projects.

Example CLI Command:

# Allow a group to access an IAP-secured application
# (Requires getting the existing policy, adding the member, and writing it back)
gcloud iap web set-iam-policy policy.json

# Create a firewall rule based on service account identity
gcloud compute firewall-rules create allow-app-to-db \
--allow=tcp:5432 \
--source-service-accounts=webapp-sa@<project-id>.iam.gserviceaccount.com \
--target-service-accounts=database-sa@<project-id>.iam.gserviceaccount.com

Create a dry RUN policy

Create a file: policy-dry-run.yaml.

constraint: constraints/compute.vmExternalIpAccess
dryRun:
allValues: DENY
  • constraint: This specifies which Organization Policy you want to configure. In this case, it’s the one that controls external IP addresses on VMs.
  • dryRun: This is the key part. By putting the rule under dryRun:, you are telling GCP, “Do not enforce this policy yet. Just log what would happen if you did.”
  • allValues: DENY: This defines the rule you are testing. You are testing a rule that would DENY all values, effectively blocking any VM from having a public IP.
This command reads the configuration from your YAML file and applies it to your organization in dry-run mode. Nothing will be blocked, but from this point forward, any action that violates the policy will generate a specific log entry for you to review.

Need/Requirement: A company’s central security team needs to ensure that all GCP projects continuously adhere to corporate security policies. They need to prevent certain risky configurations, detect any misconfigurations that slip through, and get proactive advice on improving their IAM posture over time.

GCP Solution: This is a layered governance strategy using several integrated services.

  • Prevention (Organization Policies): The team sets up Organization Policies at the root Organization node to enforce non-negotiable rules. For example, they enforce the iam.allowedPolicyMemberDomains constraint to ensure only identities from their own corporate domain can be added to IAM policies.
  • Testing with Dry-Run Mode: Before enforcing a restrictive policy, they first apply it in dry-run mode. This doesn’t block any actions but creates detailed audit log entries for any action that would have been denied. The team analyzes these logs for a period to understand the impact, remediate non-compliant resources, and then confidently switch the policy to “enforce” mode.
  • Detection (Security Command Center): The team activates the Premium tier of Security Command Center (SCC) at the organization level. This provides a central dashboard for all security findings. SCC’s built-in Security Health Analytics automatically scans for hundreds of potential misconfigurations. When a developer accidentally leaves a sensitive port open in a firewall rule, SCC generates a high-priority finding.
  • Investigation (Cloud Audit Logs): Upon seeing the SCC finding, the security team needs to know “how did this happen?” They use the Logs Explorer to query Cloud Audit Logs for the project in question, filtering for the specific firewall-related API calls around the time of the incident to identify the exact user and action.
  • Optimization (Active Assist — IAM Recommender): To reduce risk proactively, the team regularly reviews the recommendations from the IAM Recommender. They discover several service accounts with the over-privileged Editor role. The recommender, having analyzed 90 days of usage data, suggests specific, more restrictive roles. The team applies these recommendations, hardening their IAM posture without breaking applications.

Key Concepts:

  • Continuous Compliance: Security is not a one-time setup. This demonstrates the lifecycle of preventing, detecting, and remediating issues.
  • Organization Policies: The primary tool for establishing preventative “guardrails” that enforce corporate policy across the entire cloud environment.
  • Security Command Center (SCC): The single pane of glass for security monitoring, threat detection, and compliance reporting.
  • IAM Recommender (Active Assist): A powerful tool for rightsizing permissions and continuously applying the principle of least privilege based on actual usage data.

Expert-Level Scenarios

Scenario 13: The Ultra-Specific Auditor (Custom Roles)

  • Need/Requirement: A company hires a third-party auditing firm to run a compliance tool. The tool only needs to perform two very specific actions: list the Compute Engine instances in a project and get the details of the firewall rules. Granting a broad role like Compute Viewer is a security risk, as it includes many unnecessary permissions (e.g., viewing disk data). A new, minimal role is needed.

GCP Solution: Create a Custom IAM Role at the project or organization level.

  • Define a new role, for example, firewallAndVmAuditor.
  • Instead of choosing from predefined roles, you add individual permissions to this new role. In this case, you would add only two permissions:
  • compute.instances.list
  • compute.firewalls.get
  • Grant this new, custom role to the auditor’s service account. The tool now has exactly the permissions it needs and nothing more.

Key Concepts:

  • Custom Roles: The ability to create your own roles when none of GCP’s hundreds of predefined roles meet your specific, minimal requirements. This is the ultimate application of the Principle of Least Privilege.
  • Granular Permissions: Understanding that roles are simply collections of individual permissions (e.g., service.resource.verb). Custom roles give you direct control over these permissions.
  • Secure Third-Party Integration: A critical pattern for safely integrating external tools and vendors into your environment by ensuring they cannot access anything beyond their specific mandate.

Example CLI Command:

# 1. Create a role definition file, e.g., role-definition.yaml
# ---
# title: "Firewall And VM Auditor"
# description: "Minimal permissions for the compliance tool"
# stage: "GA"
# includedPermissions:
# - compute.instances.list
# - compute.firewalls.get
# ---

# 2. Create the custom role in your project from the file
gcloud iam roles create firewallAndVmAuditor --project=your-project-id \
--file=role-definition.yaml

Scenario 14: The Multi-Cloud Pipeline (Workload Identity Federation)

Need/Requirement: An organization’s primary CI/CD pipeline runs in AWS CodePipeline. This pipeline needs to deploy a container image to Google Cloud Run and Artifact Registry. The CISO has forbidden the use of long-lived service account keys, as downloading and managing a JSON key file is a major security risk. A secure, keyless authentication method is required.

Key Concept: What is a Service Account Key?
A service account key is a permanent, downloadable password for an application. It’s a JSON file containing a private key. Any application that possesses this file can authenticate to GCP as that service account, inheriting all its permissions. The risk is that this key is long-lived (valid forever until revoked) and, being a file, can be easily leaked (e.g., committed to Git, stolen from a laptop).

GCP Solution: Use Workload Identity Federation. This provides a general solution for any external workload.

  • Establish Trust in GCP: In GCP IAM, create a Workload Identity Pool and a Provider. Configure the provider to trust the AWS account where the pipeline runs. You can add attribute conditions, for example, to only trust actions originating from a specific AWS role.
  • Grant Permissions in GCP: Grant a GCP service account (e.g., aws-deployer-sa) the necessary roles (Cloud Run Admin, Artifact Registry Writer). Then, allow the trusted identities from the AWS provider to impersonate this GCP service account.
  • Exchange Credentials in AWS: In the AWS CodePipeline script, use the native AWS identity to get temporary AWS credentials. The script then calls the GCP Security Token Service, presenting its AWS credentials.
  • Receive GCP Token: GCP STS verifies the AWS credentials against the trusted provider. If valid, it returns a short-lived GCP access token for the aws-deployer-sa service account. The pipeline now uses this token to deploy to Cloud Run, all without ever seeing a GCP key.

Key Concepts:

  • Workload Identity Federation: The modern, secure standard for allowing workloads outside GCP (in AWS, Azure, on-prem) to access GCP resources.
  • Keyless Authentication: This is the primary benefit. It completely eliminates the need for service account keys, which are a common source of security breaches if leaked.
  • Identity Federation: The core principle is establishing a trust relationship between GCP and an external Identity Provider (IdP). The external workload authenticates with its native credentials, which are then exchanged for temporary, short-lived GCP credentials.

Universal Applicability: This pattern works for virtually any external system that can provide a verifiable identity token (OIDC, SAML, AWS), making it a true 360-degree solution for multi-cloud and hybrid environments.

Example CLI Command:

# 1. Create the identity pool
POOL_ID="my-aws-pool"
PROVIDER_ID="aws-provider"
AWS_ACCOUNT_ID="YOUR_AWS_ACCOUNT_ID" # Replace with your actual AWS Account ID
GCP_PROJECT_ID=myproject" # Your GCP project ID

gcloud iam workload-identity-pools create ${POOL_ID} \
--location="global" \
--display-name="AWS Workload Identity Pool for Deployment" \
--description="Pool for federating AWS identities to GCP." \
--project=${GCP_PROJECT_ID}

# 2. Create the AWS provider within the pool
gcloud iam workload-identity-pools providers create-aws ${PROVIDER_ID} \
--workload-identity-pool=${POOL_ID} \
--account-id=${AWS_ACCOUNT_ID} \
--location="global" \
--display-name="AWS Provider" \
--description="Trusts identities from specified AWS account." \
--attribute-condition="attribute.aws_role='arn:aws:iam::${AWS_ACCOUNT_ID}:role/YourSpecificAWSRoleName'" \
--project=${GCP_PROJECT_ID}

The Crucial Difference (Workforce vs. Workload)

Think of a Workforce Identity Pool as a way to grant your company’s employees (your “workforce”) access to GCP using their existing corporate login credentials, without needing to create a Google Account for each person.

The Problem: Imagine your company has 10,000 employees who use Okta or Azure Active Directory to log in to all their corporate apps. You want to give a team of 500 of them access to some GCP projects.

The Solution (Workforce Identity Federation): You create a “Workforce Pool” in GCP and configure it to trust your company’s Identity Provider (IdP), like Okta.

  • When an employee wants to access GCP, they just log in through their familiar corporate portal.
  • Your IdP (AD) gives their browser a secure token.
  • They are then seamlessly redirected to GCP, which exchanges that trusted token for a temporary GCP access token.
  • They can now use the GCP console or CLI as themselves, using their corporate identity (e.g., sara.rossi@my-company.com).
  • Workforce Federation is for HUMANS: It’s for employees, contractors, and partners who need to interact with GCP. It lets them “bring their own identity” from a corporate IdP.
  • Workload Federation (Scenario 14 ) is for MACHINES: It’s for applications, CI/CD pipelines, and scripts running outside of GCP that need to authenticate to GCP APIs without using a service account key.

Scenario 15: Granular Access Control in Practice

Need/Requirement: An administrator needs to perform two specific, unrelated tasks:

  • Grant a junior analyst read-only access to a single table within a large BigQuery dataset, without letting them see any other tables.
  • Grant a team of auditors read-only access to all projects within the “Finance” folder.

GCP Solution: This requires applying permissions at two very different levels of the resource hierarchy.
Part 1: Granting Access to a Single BigQuery Table

Console Steps:

  1. In the Google Cloud Console, navigate to the BigQuery UI.
  2. In the Explorer panel, find and expand the dataset that contains your target table.
  3. Click the three-dot menu next to the specific table name and select Share.
  4. Click Add Principal.
  5. Enter the junior analyst’s email address in the “New principals” field.
  6. In the “Select a role” dropdown, choose the role BigQuery Data Viewer.

Click Save. The analyst can now query this table but cannot see or access others in the dataset.

Example CLI Command:

bq add-iam-policy-binding --member-type=user --identity=analyst@example.com --role=roles/bigquery.dataViewer your-project-id:your_dataset.your_table

Part 2: Granting Access to Multiple Projects via a Folder

  1. In the Google Cloud Console, navigate to IAM & Admin.
  2. Using the resource selector at the top of the page, navigate to and select the “Finance” folder.
  3. On the IAM page for the folder, click Grant Access.
  4. In the “New principals” field, enter the auditors’ Google Group email (e.g., auditors@example.com).
  5. In the “Select a role” dropdown, choose the role Browser. This role provides read-only access to browse the projects and their resources.
  6. Click Save. The auditors now have read-only access to every project currently in that folder, and any new ones added in the future.

CLI Command (using gcloud)

gcloud resource-manager folders add-iam-policy-binding FOLDER_ID \
--member="group:auditors@example.com" \
--role="roles/browser"

A Note on Costs: Free vs. Paid Guardrails

Need/Requirement: An organization needs to understand the costs associated with the governance and security tools discussed in the previous scenarios.

Solution Breakdown: GCP’s security tools are priced in tiers, allowing you to establish a strong baseline for free and add advanced capabilities as needed.

Free Guardrails:

  • Organization Policies: This fundamental service for setting preventative guardrails (e.g., restricting resource locations) is free.
  • IAM Recommender (Active Assist): Receiving and applying recommendations to right-size permissions is also free.
  • Security Command Center (Standard Tier): The standard tier provides a baseline of security health analytics and is free.

Paid Guardrails:

  • Security Command Center (Premium Tier): This is a paid service that unlocks advanced features like real-time threat detection, container vulnerability scanning, and compliance reporting.
  • Cloud Audit Logs: While Admin Activity logs are free, Data Access logs (tracking who reads/writes data) are paid based on the volume of logs ingested and stored beyond a monthly free tier.

Key Concepts:

  • Tiered Pricing Model: GCP allows users to start with a strong, free security foundation and scale into paid services for more advanced, enterprise-grade capabilities.
  • Cost Management: Understanding which services generate costs (like high-volume logging) is critical for managing a cloud budget effectively.

Capstone Scenario: Designing for a Global Enterprise

Need/Requirement: Imagine you are designing the cloud foundation for a massive, publicly-traded company. This enterprise has multiple distinct business units (e.g., soft drinks, bottling, food products), dozens of iconic global brands, and operates in every major geographic region. They work with hundreds of external marketing and technology partners and have existing workloads in on-premise data centers and other public clouds. They need a GCP setup that provides strong central security and governance while still allowing individual brands and regions the autonomy to innovate.

GCP Solution: The solution is a holistic design that combines all the previous scenarios into a federated governance model.

Resource Hierarchy (The Blueprint): The foundation is a meticulously planned resource hierarchy.

  • Organization: A single Organization node tied to the corporate domain.
  • Folders for Divisions: Top-level folders are created for each major business unit (“Global Brands,” “Bottling Investments,” “Corporate IT”) and geographic region (“EMEA,” “APAC”).
  • Nested Folders for Environments: Within each folder, nested folders isolate environments (Prod, Staging, Dev).
  • Projects: Applications and workloads live in projects at the bottom of this hierarchy (e.g., prj-brand-x-website-prod).

Identity Management (The People & Partners): User management is entirely federated and automated.

  • Central IdP: The company’s central Identity Provider (e.g., Azure AD, Okta) is the single source of truth, federated with Google Cloud Identity.
  • Delegated Administration: The central cloud team manages permissions at the Organization level and delegates Folder Admin roles to the business units, allowing for autonomous but contained management.
  • Federation for Partners: External partners are managed using the model in Scenario 6, granting roles to Google Groups owned by the partner companies.
  • Workload Identity Federation: All on-premise and multi-cloud workloads authenticate using keyless federation as shown in Scenario 14.

Governance and Security (The Rules): A central security team enforces a non-negotiable baseline.

  • Organization Policies: Strict guardrails are set at the Organization root to enforce data residency, control IAM policies, and manage network configurations.
  • Centralized Networking: A Shared VPC model is used to ensure all projects adhere to a central set of firewall rules and network security policies.
  • Unified Monitoring: The security team uses the Security Command Center dashboard at the Organization level to get a single pane of glass for all security findings and threats across the entire global enterprise.

Key Concepts: This capstone exercise integrates nearly every concept in this guide: Hierarchical Governance, Federated Identity, Delegated Administration, Least Privilege, Centralized Security, Keyless Authentication, and Continuous Compliance Monitoring at a global scale.

Conclusions

A lot of stuff!!! I just hope that grasping practical scenarios will make things easier…..


GCP IAM & Co. - Practical Scenarios for Engineers and Cloud Certification Mastery was originally published in Google Cloud - Community on Medium, where people are continuing the conversation by highlighting and responding to this story.

30 Sep 07:26

Building a GKE Cluster with Terraform for Varonis

by Jeffrey S. Levine
This is not an official publication of any business. The opinions expressed are solely those of the author. The author makes no warranty for the contents of the article.

Introduction

Google Cloud customers of Varonis can use Google Kubernetes Engine (“GKE”) to host private collectors to provide data security posture management (“DSPM”) capabilities. The containers in these collectors analyze a customer’s cloud assets within in the customers’ Google Cloud environments and send asset metadata to Varonis where it is correlated with user activities to provide customers with insights about their data security. When collectors are used, no actual data is sent out of the customer’s Google Cloud environment, only metadata.

In this article we revisit GKE basics and show how to create a collector environment for Varonis using a private GKE cluster and an optionalbastion host in Google Cloud using Terraform code from a GitHub repository.

Using a private cluster means that the GKE nodes and control plane will not have publicly addressible IP addresses. You can access the cluster using the DNS endpoint whose access is brokered by IAM. This is similar to what the Identity-aware Proxy does for Compute Engine instances and provides an additional layer of security.

A high level diagram of the infrastructure created by the Terraform code appears below.

Why a bastion host?

The creation of a bastion host is optional. The Terraform code generates a DNS endpoint for the GKE cluster so you can securely access the private cluster. A bastion host is useful if you do not have access to utilities such as kubectl. The bastion host also contains common tools for working with databases.

Prerequisites, assumptions, caveats, etc.

  1. You will need a Google Cloud project in which the GKE cluster (and optional bastion host) will be created.
  2. You will use the Google Cloud CLI](`gcloud`).
  3. You must have the roles listed below.
    - Compute Admin (roles/compute.admin)
    - Compute Network Admin (roles/compute.networkAdmin)
    - Kubernetes Engine Admin (roles/container.admin)
    - Service Usage Admin
  4. These instructions assume you are familiar with the skills listed below.
    - Terraform
    - Google Cloud core concepts (e.g. APIs, projects)
    - The Google Cloud CLI (gcloud)
  5. The instructions only cover the installation of Google Cloud infrastructure, not Varonis components.

Instructions

These instructions are written assuming that your workstation is set up with the Google Cloud CLI. You can use these instructions in the Cloud Shell as well. If you are using Windows, you will need to adapt these instructions.

Set up

  1. Clone this repository and change your working directory to the directory into which the repository was cloned.
  2. If you have not already done so, authenticate to Google Cloud and set your application default credentials.
    gcloud auth login — update-adc
  3. Set the environment variable REPODIR to the repository base directory using the command below.
    export REPODIR=`pwd`
  4. Set the environment variable PROJECT_ID to the repository base directory using the command below.
    export PROJECT_ID=INSERT_YOUR_PROJECT_ID_HERE
  5. Set your current Google Cloud project ID
    gcloud config set project $PROJECT_ID
  6. Set your Google Cloud billing/quota project.
    gcloud auth application-default set-quota-project $PROJECT_ID

Enable APIs

Before the GKE cluster and optional bastion host are built, you will use
Terraform code to enable the APIs below.

  • Cloud Resource Manager
  • Compute Engine
  • Kubernetes Engine
  • Identity & Access Management (IAM)
  • Identity-aware Proxy (IAP)
  • Cloud Logging
  • OS Login
  • Service Usage
  1. Move to the enableAPIs subdirectory.
    cd $REPODIR/enableAPIs
  2. Create the terraform.tfvars file from the template.
    cp terraform.tfvars.example terraform.tfvars
  3. Open the file `terraform.tfvars` with a text editor.
  4. Replace your-project-id-goes-here with your Google Cloud project id. Do not delete the quotation marks.
  5. Save the file.
  6. Initialize Terraform.
    terraform init
  7. Create the Terraform plan.
    terraform plan --out=plan.out
  8. Apply the Terraform plan to enable the APIs.
    terraform apply plan.out
    Terraform should complete in 1–2 minutes. The required APIs are now built.

Build the GKE cluster and optional bastion host

  1. Move to the subdirectory with the appropriate Terraform code.
    cd $REPODIR
  2. Create the terraform.tfvars file from the template.
    cp terraform.tfvars.example terraform.tfvars
  3. Open the file `terraform.tfvars` with a text editor. The file contains several variables you can set, tthe most important of which are described below. Retain all quotation marks in the variable definitions.

    - project_id (Required, string) Replace your-project-id-goes-here with your Google Cloud project id. This is the only required change.
    - region (optional, string, default = “us-central1") The region for the GKE cluster and optional bastion host.
    - create_bastion_host (optional, boolean, default = “false”) Set this value to “true” if you want to create a bastion host
    - bastion_zone (optional, boolean, default = “false”) Set this to the zone for the optional bastion host. This zone must be part of the region defined by the region variable.
    - gke_location (optional, string, default = “us-central1-a”) Set this to the location of the GKE cluster. You can specify a region or zone. If a region is specified, it must be the same as the region as the region variable. If a zone is specified, it must belong to the region specified by the region variable.
    - gke_node_count (optional, numeric, default =2 ) The number of nodes to have per zone of the GKE cluster. If the cluster is regional, this variable will be multiplied by the number of zones in the region to get the total number of nodes.
  4. Save the file with your changes.
  5. Initialize Terraform.
    terraform init
  6. Create the Terraform plan.
    terraform plan — out=plan.out
  7. Apply the Terraform plan to enable the APIs.
    terraform apply plan.out
    Terraform should complete in 10–15 minutes. If you are running this command in the Cloud Shell, remember tha the Cloud Shell will terminate if the keyboard is idle for more than five minutes. Press the Enter/Return key every few minutes to keep the Cloud Shell from terminating.

Terraform outputs

Terraform will display output after the completion of the build.
You can redisplay these outputs with the command below.

terraform output

An example of the output appears below. You may need to scroll horizontally to see the entire command and its output.


Bastion_host_instance_id = “varonis-bastion-3tcj”
Bastion_ssh = “gcloud compute ssh — zone us-central1-a varonis-bastion-3tcj — tunnel-through-iap — project YOUR_PROJECT_ID”
GKE_cluster_DNS_endpoint = “gke-LONG_STRING.us-central1-a.gke.goog”
GKE_cluster_get_creds = “gcloud container clusters get-credentials varonis-gke-cluster-3tcj — dns-endpoint — location us-central1-a”
GKE_cluster_name = “varonis-gke-cluster-3tcj”
NAT_ip = “#.#.#.#”
Random_suffix = “3tcj”
ZZZ_SSH_Msg = <<EOT
*
* Please grant the IAM role below to users at the orgination or
* project level of the resource hierarchy to enable users to SSH
* into the GKE nodes and optional bastion host.
*
* IAP-secured Tunnel User (roles/iap.tunnelResourceAccessor)
*
*
EOT
  • Bastion_host_instance_id is the id of the instance associated with the bastion host. The value is defined only if the Terraform variable create_bastion_host is set to true.
  • Bastion_ssh is the command used to access the bastion host. The value is defined only if the Terraform variable `create_bastion_host` is set to true.
  • GKE_cluster_DNS_endpoint is the DNS endpoint of the GKE cluster.
  • GKE_cluster_get_creds is the command to fetch the GKE cluster credentials and store them in your Kubernetes configuration director, by default $HOME/.kube/config. You must do this before running commands such as kubectl.
  • GKE_cluster_name is the name of the GKE cluster.
  • NAT_ip is the IP address of the NAT gateway that is created to allow the GKE cluster and optional bastion hast to have internet access.
  • Random_suffix is a set of characters generated when Terraforms runs that is appended tonGoogle Cloud resources. Using a random suffix allows more multiple builds to happen within the same Google Cloud
    project.
  • ZZZ_SSH_Msg is a reminder to users of this Terraform build to ensure that the appropriate permissions are granted to enable ssh logins to the GKE nodes and optional bastion host.

Using the GKE cluster

In the Terraform outputs from the installation, copy the value of the GKE_cluster_get_creds. Do not include the quotation marks. Paste this value into your command interpreter and execute it. An example of this command and its output appear below. You may need to scroll horizontally to see the entire command and its output


gcloud container clusters get-credentials varonis-gke-cluster-3tcj — dns-endpoint — location us-central1-a
Fetching cluster endpoint and auth data.
kubeconfig entry generated for varonis-gke-cluster-gsoq.

You can now execute commands against the cluster such as `kubectl`.

Using the bastion host

  1. If you created a bastion host, In the Terraform outputs from the installation, copy the value of the `Bastion_ssh`. Do not include the quotation marks.
  2. Paste this value into your command interpreter and execute it.
    An example of this command appears below. Note that the command wraps onto multiple lines.

    gcloud compute ssh — zone us-central1-a varonis-bastion-3tcj — tunnel-through-iap — project YOUR_PROJECT_ID
  3. If you would like to connect to the cluster, you can use the command contaained in the GKE_cluster_get_creds output variable. You can also run the file /tmp/get_gke_creds which contains the command.

Cleaning up

  1. Change to the directory in which the Terraform code has been installed.
    cd $REPODIR
  2. Enter the command below to destroy the resources.
    terraform destroy
  3. Confirm the action by entering `yes` when prompted.

Common errors

  1. A message saying something like `Error: Error when reading or editing` usually means that your login credentials have expired. Reauthenticating as described in the set up instructions often fixes this.

Building a GKE Cluster with Terraform for Varonis was originally published in Google Cloud - Community on Medium, where people are continuing the conversation by highlighting and responding to this story.

30 Sep 07:24

100X Faster: How We Supercharged Netflix Maestro’s Workflow Engine

by Netflix Technology Blog

By Jun He, Yingyi Zhang, Ely Spears

TL;DR

We recently upgraded the Maestro engine to go beyond scalability and improved its performance by 100X! The overall overhead is reduced from seconds to milliseconds. We have updated the Maestro open source project with this improvement! Please visit the Maestro GitHub repository to get started. If you find it useful, please give us a star.

Introduction

In our previous blog post, we introduced Maestro as a horizontally scalable workflow orchestrator designed to manage large-scale Data/ML workflows at Netflix. Over the past two and a half years, Maestro has achieved its design goal and successfully supported massive workflows with hundreds of thousands of jobs, managing millions of executions daily. As the adoption of Maestro increases at Netflix, new use cases have emerged, driven by Netflix’s evolving business needs, such as Live, Ads, and Games. To meet these needs, some of the workflows are now scheduled on a sub-hourly basis. Additionally, Maestro is increasingly being used for low-latency use cases, such as ad hoc queries, beyond traditional daily or hourly scheduled ETL data pipeline use cases.

While Maestro excels in orchestrating various heterogeneous workflows and managing user end-to-end development experiences, users have experienced noticeable speedbumps (i.e. ten seconds overhead) from the Maestro engine during workflow executions and development, affecting overall efficiency and productivity. Although being fully scalable to support Netflix-scale use cases, the processing overhead from Maestro internal engine state transitions and lifecycle activities have become a bottleneck, particularly during development cycles. Users have expressed the need for a high performance workflow engine to support iterative development use cases.

To visualize our end users’ needs for the workflow orchestrator, we create a 5-layer structure graph shown below. Before the change, Maestro reached level 4 but faced challenges to satisfy the user’s needs in level 5. With the new engine design, Maestro is able to power the users to work with their highest capacity and spark joy for end users during their development over the Maestro.

Figure 1. A 5-layer structure showing needs for the workflow orchestrator
Figure 1. A 5-layer structure showing needs for the workflow orchestrator.

In this blog post, we will share our new engine details, explain our design trade-off decisions, and share learnings from this redesign work.

Architectural Evolution of Maestro

Before the change

To understand the improvements, we will first revisit the original architecture of Maestro to understand why the overhead is high. The system was divided into three main layers, as illustrated in the diagram below. In the sections that follow we will explain each layer and the role it played in our performance optimization.

Figure 2. The architecture diagram before the evolution.
Figure 2. The architecture diagram before the evolution.

Maestro API and Step Runtime Layer

This layer offers seamless integrations with other Netflix services (e.g., compute engines like Spark and Trino). Using Maestro, thousands of practitioners build production workflows using a paved path to access platform services . They can focus primarily on their business logic while relying on Maestro to manage the lifecycle of jobs and workflows plus the integration with data platform services and required integrations such as for authentication, monitoring and alerting. This layer functioned efficiently without introducing significant overhead.

Maestro Engine Layer

The Maestro engine serves several crucial functions:

  • Managing the lifecycle of workflows, their steps and maintaining their state machines
  • Supporting all user actions (e.g., start, restart, stop, pause) on workflow and step entities
  • Translating complex Maestro workflow graphs into parallel flows, where each flow is an array of sequentially chained flow tasks, translating every step into a flow task, and then executing transformed flows using the internal flow engine
  • Acting as a middle layer to maintain isolation between the Maestro step runtime layer and the underlying flow engine layer
  • Implementing required data access patterns and writing Maestro data into the database

In terms of speed, this layer had acceptable overhead but faced edge cases (e.g. a step might be concurrently executed by two workers at the same time, causing race conditions) due to lacking a strong guarantee from the internal flow engine and the external distributed job queue.

Maestro Internal Flow Engine Layer

The Maestro internal flow engine performed 2 primary functions:

  • Calling task’s execution functions at a given interval.
  • Starting the next tasks in an array of sequential task flows (not a graph), if applicable.

This foundational layer was based on Netflix OSS Conductor 2.x (deprecated since Apr 2021), which requires a dedicated set of separate database tables and distributed job queues.

The existing implementation of this layer introduces an impactful overhead (e.g. a few seconds to tens of seconds overall delays). The lack of strong guarantees (e.g. exactly once publishing) from this layer leads to race conditions which cause stuck jobs or lost executions.

Options to consider

We have evaluated three options to address those existing issues:

  • Option 1: Implement an internal flow engine optimized for Maestro specific use cases
  • Option 2: Upgrade Conductor library to 4.0, which addresses the overheads and offers other improvements and enhancements compared with Conductor 2.X.
  • Option 3: Use Temporal as the internal flow engine

One aspect that influenced our assessment of option two is that Conductor 2 provided a final callback capability in the state machine that was contributed specifically for Maestro’s use case to ensure database synchronization between the Conductor and Maestro engine states. It would require porting this functionality to Conductor 4 though it had been dropped given no other Conductor use cases besides Maestro relied on this. By rewriting the flow engine it would allow removal of several complex internal databases and database synchronization requirements which was attractive for simplifying operational reliability. Given Maestro did not need the full set of state engine features offered by Conductor, this motivated us to consider a flow engine rewrite as a higher priority.

The decision for Temporal was more straightforward. Temporal is optimized towards facilitating inter-process orchestration and would involve calling an external service to interact with the Temporal flow engine. Given Maestro is operating greater than a million tasks per day, many of which are long running, we felt it was an unnecessary source of risk to couple the DAG engine execution with an external service call. If our requirements went beyond lightweight state transition management we might reconsider because Temporal is a very robust control plane orchestration system, but for our needs it introduced complexity and potential reliability weak spots when there was no direct need for the advanced feature set that it offered.

After considering Option 2 and Option 3, we developed more conviction that Maestro’s architecture could be greatly simplified by not using a full DAG evaluation engine and having to maintain the state machine for two systems (Maestro and Conductor/Temporal). Therefore, we have decided to go with Option 1.

After the change

To address these issues, we completely rewrote the Maestro internal flow engine layer to satisfy Maestro’s specific needs and optimize its performance. This new flow engine is lightweight with minimal dependencies, focusing on excelling in the two primary functions mentioned above. We also replaced existing distributed job queues with internal ones to provide a strong guarantee.

The new engine is highly performant, efficient, scalable, and fault-tolerant. It is the foundation for all upper components of Maestro and provides the following guarantees to avoid race conditions:

  • A single step should only be executed by a single worker at any given time
  • Step state should never be rolled back
  • Steps should always eventually run to a terminal state
  • The internal flow state should be eventually consistent with the Maestro workflow state
  • External API and user actions should not cause race conditions on the workflow execution

Here is the new architecture diagram after the change, which is much simpler with less dependencies:

Figure 3. The architecture diagram after the evolution.

New Flow Engine Optimization

The new flow engine significantly boosts speed by maintaining state in memory. It ensures consistency by using Maestro engine’s database as the source of truth for workflow and step states. During bootstrapping, the flow engine rebuilds its in-memory state from the database, improving performance and simplifying the overall architecture. This is in contrast to the previous design in which multiple databases had to be reconciled against one another (Conductor’s tables and Maestro’s tables) or else suffer race conditions and rare orphaned job status.

The flow engine operates on in-memory flow states, resembling a write through caching pattern. Updates to workflow or step state in the database also update the in-memory flow state. If in-memory state is lost, the flow engine rebuilds it from the database, ensuring eventual consistency and resolving race conditions.

This design delivers lower latency and higher throughput, avoids inconsistencies from dual persistence, simplifies the architecture, and keeps the in‑memory view eventually consistent with the database.

Maintaining Scalability While Gaining Speed

With the new engine, we significantly boost performance by collocating flows and their tasks on the same node throughout their lifecycle. Therefore, states of a flow and its tasks will stay in a single node’s memory without persisting to the database. This stickiness and locality bring great performance benefits but inevitably impact scalability since tasks are no longer reassigned to a new worker of the whole cluster in each polling cycle.

To maintain horizontal scalability, we introduced a flow group concept to partition running flows into groups. In this way, each Maestro flow engine instance only needs to maintain ownership of groups rather than individual flows, reducing maintenance costs (e.g., heartbeat) and simplifying reconciliation by allowing each Maestro node to load flows for a group in batches. Each Maestro node claims ownership of a group of flows through a flow group actor and manages their entire lifecycle via child flow actors. If ownership is lost due to node failure or long JVM GC, another node can claim the group to resume flow executions by reconciling internal state from Maestro database. The following diagram illustrates the ownership maintenance.

Figure 4. Ownership maintenance sequence diagram.

Flow Partitioning

To efficiently distribute traffic, Maestro assigns a consistent group ID to flows/workflows by a simple stable ID assignment method, as shown in the diagram’s Partitioning Function box. We chose this simpler partitioning strategy over advanced ones, e.g. consistent hashing, primarily due to execution and reconciliation costs and consistency challenges in a distributed system.

Since Maestro decomposes workflows into hierarchical internal flows (e.g., foreach), parent flows need to interact with child flows across different groups. To enable this, the maximal group number from the parent, denoted as N’ in the diagram, is passed down to all child flows. This allows child flows, such as subworkflows or foreach iterations, to recompute their own group IDs and also ensures that a parent flow can always determine the group ID of its child flows using only their workflow identifiers.

Figure 5. Flow group partitioning mechanism diagram.

After a flow’s group ID is determined, the flow operator routes the flow request to the appropriate node. Each node owns a specific range of group IDs. For example, in the diagram, Node 1 owns groups 0, 1, and 2, while Node 3 owns groups 6, 7, and 8. The groups then contain the individual flows (e.g., Flow A, Flow B).

In this design, the group size is configurable and nodes can also have different group size configurations. The following diagram shows a flow group partitioning example while the maximal group number is changed during the engine execution without impacting any existing workflows.

Figure 6. A flow group partitioning example.

In short, Maestro flow engine shares the group info across the parent and child workflows to provide a flexible and stable partitioning mechanism to distribute work across the cluster.

Queue Optimization

We replaced both external distributed job queues in the existing system with internal ones, preserving the same fault‑tolerance and recovery guarantees while reducing latency and boosting throughput.

For the internal flow engine, the queue is a simple in‑memory Java blocking queue. It requires no persistence and can be rebuilt from Maestro state during reconciliation.

For the Maestro engine, we implemented a database‑backed in‑memory queue that provides exactly‑once publishing and at‑least‑once delivery guarantees, addressing multiple edge cases that previously required manual state correction.

This design is similar to the transactional outbox pattern. In the same transaction that updates Maestro tables, a row is inserted into the `maestro_queue` table. Upon transaction commit, the job is immediately pushed to a queue worker on the same node, eliminating polling latency. After successful processing, the worker deletes the row from the database. A periodic sweeper re-enqueues any rows whose timeout has expired, ensuring another worker picks them up if a worker stalls or a node fails.

This design handles failures cleanly. If the transaction fails, both data and message roll back atomically, no partial publishing. If a worker or node fails after commit, the timeout mechanism ensures the job is retried elsewhere. On restart, a node rebuilds its in‑memory queue from the queue table, providing at-least-once delivery guarantee.

To enhance scalability and avoid contention across event types, each event type is assigned a `queue_id`. Job messages are then partitioned by `queue_id`, optimizing performance and maintaining system efficiency under high load.

From Stateless Worker Model to Stateful Actor Model

Maestro previously used a shared-nothing stateless worker model with a polling mechanism. When a task started, its identifier was enqueued to a distributed task queue. A worker from the flow engine would pick the task identifier from the queue, load the complete states of the whole workflow (including the flow itself and every task), execute the task interface method once, write the updated task data back to the database, and put the task back in the queue with a polling delay. The worker would then forget this task and start polling the next one.

That architecture was simple and horizontally scalable (excluding database scalability considerations), but it had drawbacks. The process introduced considerable overhead due to polling intervals and state loading. The time spent in one polling cycle on distributed queues, loading complete states, and other DB queries was significant.

As Maestro engine decomposes complex workflow graphs into multiple flows, actions might involve multiple flows spanning multiple polling cycles, adding up to significant overhead (around ten seconds in the worst cases). Also, this design didn’t offer strong execution guarantees mainly because the distributed job queue could only provide at-least-once guarantees. Tasks might be dequeued and dispatched to multiple workers, workers might reset states in certain race conditions, or load stale states of other tasks and make incorrect decisions. For example, after a long garbage-collection pause or network hiccup, two workers can pick up the same task: one sets the task status as completed and then unblocks the downstream steps to move forward. However, the other worker, working off stale state, resets the task status back to running, leaving the whole workflow in a conflicting state.

In the new design, we developed a stateful actor model, keeping internal states in memory. All tasks of a workflow are collocated in the same Maestro node, providing the best performance as states are in the same JVM.

Actor-Based Model

The new flow engine fits well into an actor model. We also deliberately designed it to allow sharing certain local states (read-only) between parent, child, and sibling actors. This optimization gains performance benefits without losing thread safety due to Maestro’s use cases. We used Java 21’s virtual thread support to implement it with minimal dependencies.

The new actor-based flow engine is fully message/event-driven and can take actions immediately when events are received, eliminating polling interval delays. To maintain compatibility with the existing polling-based logic, we developed a wakeup mechanism. This model requires flow actors and their child task actors to be collocated in the same JVM for communication over the in-memory queue. Since the Maestro engine already decomposes large-scale workflow instances into many small flows, each flow has a limited number of tasks that fit well into memory.

Below is a high-level overview of the Maestro execution flow based on the actor model.

Figure 7. The high level overview of the Maestro execution.
  • When a workflow starts or during reconciliation, the flow engine inserts (if not existing) or loads the Maestro workflow and step instance from the database, transforming it into the internal flow and task state. This state remains in JVM memory until evicted (e.g., when the workflow instance reaches a terminal state).
  • A virtual thread is created for each entity (workflow instance or step attempt) as an actor to handle all updates or actions for this entity, ensuring thread safety and eliminating distributed locks and potential race conditions.
  • Each virtual thread actor contains an in-memory state, a thread-safe blocking queue, and a state machine to update states, ensuring thread safety and high efficiency.
  • Actors are organized hierarchically, with flow actors managing all their task actors. Flow actors and their task actors are kept in the same JVM for locality benefits, with the ability to relocate flow instances to other nodes if needed.
  • An event can wake up a virtual thread by pushing a message to the actor’s job queue, enabling Maestro to move toward an event-driven approach alongside the current polling-based approach.
  • A reconciliation process transforms the Maestro data model into the internal flow data.

Virtual Thread Based Implementation

We chose Java virtual threads to implement various actors (e.g. group actors and flow actors), which simplified the actor model implementation. With a smaller amount of code, we developed a fully functional and highly performant event-driven distributed flow engine. Virtual threads fit very well in use cases like state machine transitions within actors. They are lightweight enough to be created in a large number without Out-Of-Memory risks.

However, virtual threads can potentially deadlock. They’re not suitable for executing user-provided logic or complex step runtime logic that might depend on external libraries or services outside our control. To address this, we separate flow engine execution from task execution logic by adding a separate worker thread pool (not virtual threads) to run actual step runtime business logic like launching containers or making external API calls. Flow/task actors can wait indefinitely for the future of the thread poll executor to complete but don’t perform actual execution, allowing us to benefit from virtual threads while avoiding deadlock issues.

Figure 8. Virtual thread and worker thread separation.

Providing Strong Execution Guarantees

To provide strong execution guarantees, we implemented a generation ID-based solution to ensure that a single flow or task is executed by only one actor at any time, with states that never roll back and eventually reach a terminal state.

When a node claims a new group or a group with an expired heartbeat, it updates the database table row and increments the group generation ID. During node bootstrap, the group actor updates all its owned flows’ generation IDs while rebuilding internal flow states. When creating a new flow, the group actor verifies that the database generation ID matches its in-memory generation ID, otherwise rejecting the creation and reporting a retryable error to the caller. Please check the source code for the implementation details.

Figure 9. An example sequence diagram showing how generation id provides a strong guarantee.

Additionally, the new flow engine supports both event-driven execution and polling-based periodic reconciliation. Event-driven support allows us to extend polling intervals for state reconciliation at a very low cost, while polling-based reconciliation relaxes event delivery requirements to at-most-once.

Testing, Validation and Rollout

Migrating hundreds of thousands of Netflix data processing jobs to a new workflow engine required meticulous planning and execution to avoid data corruption, unexpected traffic patterns, and edge cases that could hinder performance gains. We adopted a principled approach to ensure a smooth transition:

  1. Realistic Testing: Our testing mirrored real-world use cases as closely as possible.
  2. Balanced Approach: We balanced the need for rapid delivery with comprehensive testing.
  3. Minimal User Disruption: The goal was for users to be unaware of the underlying changes.
  4. Clear Communication: For cases requiring user involvement, clear communication was provided.

Maestro Test Framework

To achieve our testing goals, we developed an adaptable testing framework for Maestro. This framework addresses the limitations of static unit and integration tests by providing a more dynamic and comprehensive approach, mimicking organic production traffic. It complements existing tests to instill confidence when rolling out major changes, such as new DAG engines.

The framework is designed to sample real user workflows, disconnecting business logic from external side effects like data reads or writes. This allows us to run workflow graphs of various shapes and sizes, reflecting the diverse use cases across Netflix. While system integrations are handled through deployment pipeline integration tests, the ability to exercise a wide variety of workflow topologies (e.g., parallel executions, for-each jobs, conditional branching and parameter passing between jobs) was crucial for ensuring the new flow engine’s correctness and performance.

The prototype workflow for the test framework focuses on auto-testing parameters, involving two main steps:

1. Caching Production Workflows:

  • Successful production instances are queried from a historical Maestro feed table over a specified period.
  • Run parameters, initiator, and instance IDs are extracted and organized into an instance data map.
  • YAML definitions and subworkflow IDs are pulled from S3 storage.
  • Both workflow definitions and instance data are cached on S3 for subsequent steps.

2. Pushing, Running, and Monitoring Workflows:

  • Cached workflow definitions and instance data are loaded.
  • Notebook-based jobs are replaced with custom notebooks, and certain job types (e.g., vanilla container runtime jobs, templated data movement jobs) and signal triggers are converted to a special no-op job type or skipped.
  • Abstract job types like Write-Audit-Publish are expressed as a single step template but are translated to multiple reified nodes of the DAG when executed. These are auto-translated into several custom notebook job types to replace the generated nodes.
  • Workflows and subworkflows are pushed, with only non-subworkflows being run using original production instance information.
  • 1. In the parent workflow, each sub-workflow is replaced with a special no-op placeholder so that the overall topology is preserved but without executing any side-effects of child workflows and avoid cases using dynamic runtime parameter logic.
  • 2. Each sub-workflow is then separately treated like a top-level parent workflow not initiated from its parent, to exercise the actual workflow steps of the sub-workflow.
  • The custom notebook internally compares all passed parameters for each job.
  • Workflow instances are monitored until termination (success or failure).
  • An email detailing failed workflow instances is generated.

Future phases of the test framework aim to expand support for native steps, more templates, Titus and Metaflow workflows, and include more robust signal testing. Further integration with the ecosystem, including dedicated Genie clusters for no-op jobs and DGS for our internal workflow UI feature verification, is also being explored.

Rollout Plan

Our rollout strategy prioritized minimal user disruption. We determined that an entire workflow, from its root instance, must reside in either the old or new flow engine, preventing mixed operations that could lead to complex failure modes and manual data reconciliation.

To facilitate this, we established a parallel infrastructure for the new workflow engine and leveraged our orchestrator gateway API to hide any routing or redirection logic from users. This approach provided excellent isolation for managing the migration. Initially, specific workflows could explicitly opt in via a system flag, allowing us to observe their execution and gain confidence. By scaling up traffic to the parallel infrastructure in direct proportion to what was scaled down from the original infrastructure, the dual infrastructure cost increase was negligible.

Once confident, we transitioned to a percentage-based cutover. In the event of a sustained failure in the new engine, our team could roll back a workflow by removing it from the new engine’s database and restarting it in the original stack. However, one consequence of rollback was that failed workflows had to restart from the beginning, recomputing previously successful steps, to ensure all artifacts were generated from a consistent flow engine.

Leveraging Maestro’s 10-day workflow timeout, we migrated users without disruption. Existing executions would either complete or time out. Upon restarting (due to failure/timeout) or triggering a new instance (due to success), the workflow would be picked up by the new engine. This effectively allowed us to gradually “drain” traffic from the old engine to the new one with no user involvement.

While the plan generally proceeded as expected with limited edge cases, we did encounter a few challenges:

  • Stuck Workflows: Around 50 workflows with defunct or incorrect ownership information entered a stuck state. In some cases, a backlog of queued instances behind a stuck instance created a race condition in which a new instance would be started immediately when an old instance was terminated, perpetually keeping the workflow on the old engine. For these, we proactively contacted users to negotiate manual stop-and-restart times, forcing them onto the new engine.
  • Configuration Discrepancies: A significant lesson learned was the importance of meticulous record-keeping and management of parallel infrastructure components. We discovered alerts, system flags, and feature flags configured for one stack but not the other. This led to a failure in a partner team’s system that dynamically rolled out a Python migration by analyzing workflow configurations. The absence of a required feature flag in the new engine stack caused the process to be silently skipped, resulting in incorrect Python version configurations for about 40 workflows. Although quickly remediated, this caused user inconvenience as affected workflows needed to be restarted and verified for no lingering data corruption issues. This issue also highlighted limitations in the testing framework since runtime configuration based on external API calls to the configuration service were not exercised in simulated workflow executions.

Despite these challenges, the migration was a success. We migrated over 60,000 active workflows generating over a million data processing tasks daily with almost no user involvement. By observing the flow engine’s lifecycle management latency, we validated a reduction in step launch overhead from around 5 seconds to 50 milliseconds. Workflow start overhead (incurred once per each workflow execution) also improved from 200 milliseconds to 50 milliseconds. Aggregating this over a million daily step executions translates to saving approximately 57 days of flow engine overhead per day, leading to a snappier user experience, more timely workflow status for data practitioners and greater overall task throughput for the same infrastructure scale.

We additionally realized significant benefits internally with reduced maintenance effort due to the new flow engine’s simplified set of database components. We were able to delete nearly 40TB of obsolete tables related to the previous stateless flow engine and saw a 90% reduction in internal database query traffic which had previously been a significant source of system alerts for the team.

Conclusion

The architectural evolution of Maestro represents a significant leap in performance, reducing overhead from seconds to milliseconds. This redesign with a stateful actor model not only enhances speed by 100X but also maintains scalability and reliability, ensuring Maestro continues to meet the diverse needs of Netflix’s data and ML workflows.

Key takeaways from this evolution include:

  • Performance matters: Even in a system designed for scale, the speed of individual operations significantly impacts user experience and productivity.
  • Simplicity wins: Reducing dependencies and simplifying architecture not only improved performance but also enhanced reliability and maintainability.
  • Strong guarantees are essential: Providing strong execution guarantees eliminates race conditions and edge cases that previously required manual intervention.
  • Locality optimizations pay off: Collocating related flows and tasks in the same JVM dramatically reduces overhead from the Maestro engine.
  • Modern language features help: Java 21’s virtual threads enabled an elegant actor-based implementation with minimal code complexity and dependencies.

We’re excited to share these improvements with the open-source community and look forward to seeing how Maestro continues to evolve. The performance gains we’ve achieved open new possibilities for low-latency workflow orchestration use cases while continuing to support the massive scale that Netflix and other organizations require.

Visit the Maestro GitHub repository to explore these improvements. If you have any questions, thoughts, or comments about Maestro, please feel free to create a GitHub issue in the Maestro repository. We are eager to hear from you. If you are passionate about solving large scale orchestration problems, please join us.

Acknowledgements

Special thanks to Big Data Orchestration team members for general contributions to Maestro and diligent review, discussion and incident response required to make this project successful: Davis Shepherd, Natallia Dzenisenka, Praneeth Yenugutala, Brittany Truong, Jonathan Indig, Deepak Ramalingam, Binbing Hou, Zhuoran Dong, Victor Dusa, and Gabriel Ikpaetuk — and and internal partners Yun Li and Romain Cledat.

Thank you to Anoop Panicker and Aravindan Ramkumar from our partner organization that leads Conductor development in Netflix. They helped us understand issues in Conductor 2.X that initially motivated the rearchitecture and helped provide context on later versions of Conductor that defined some of the core trade-offs for the decision to implement a custom DAG engine in Maestro.

We’d also like to thank our partners on the Data Security & Infrastructure and Engineering Support teams who helped identify and rapidly fix the configuration discrepancy error encountered during production rollout: Amer Hesson, Ye Ji, Sungmin Lee, Brandon Quan, Anmol Khurana, and Manav Garekar.

A special thanks also goes out to partners from the Data Experience team including Jeff Bothe, Justin Wei, and Andrew Seier. The flow engine speed improvement was actually so dramatic that it broke some integrations with our internal workflow UI that reported state transition durations. Our partners helped us catch and fix UI regressions before they shipped to avoid impact to users.

We also thank Prashanth Ramdas, Anjali Norwood, Eva Tse, Charles Zhao, Sumukh Shivaprakash, Joey Lynch, Harikrishna Menon, Marcelo Mayworm, Charles Smith and other leaders for their constructive feedback and guidance on the Maestro project.


100X Faster: How We Supercharged Netflix Maestro’s Workflow Engine was originally published in Netflix TechBlog on Medium, where people are continuing the conversation by highlighting and responding to this story.

29 Sep 21:38

Los Adolescentes Que Hackearon la CIA

by Lord Draugr

Consigue todos los servicios de Proton: su VPN, gestor de contraseñas, almacenamiento en la nube, calendario... Todo cifrado y respetando tu privacidad:
https://proton.me/ceodeproton
29 Sep 20:03

No, no es un reto de “desintoxicación digital”. Es el hermano de Sánchez esquivando a Hacienda mientras fingía vivir en Portugal para pagar menos impuestos.

by Fino

No, no es un reto de “desintoxicación digital”. Es el hermano de Sánchez esquivando a Hacienda mientras fingía vivir en Portugal para pagar menos impuestos.

Este periódico ha tenido acceso a un informe de la Unidad Central Operativa (UCO) de la Guardia Civil, remitido a la magistrada Beatriz Biedma, titular del Juzgado de Instrucción número 3 de Badajoz, que investiga al músico. En ese documento se detalla cómo el hermano del presidente dio de baja el número que había utilizado durante más de una década el 5 de noviembre de 2021, apenas unas semanas después de regresar de una excedencia de un año en Tailandia. Desde entonces, y hasta el 22 de marzo de 2022, Sánchez se mantuvo un apagón de sus comunicaciones. No tuvo ningún número activo a su nombre en territorio nacional y, de esta manera, no podía ser geolocalizado por las antenas de telefonía. Una maniobra que, según los investigadores, no es casual, ya que coincide con su instalación en el complejo presidencial, donde residió junto a su esposa, la japonesa Kaori Matsumoto. eldebate

No, no es un reto de “desintoxicación digital”. Es el hermano de Sánchez esquivando a Hacienda mientras fingía vivir en Portugal para pagar menos impuestos.

@adais_casares

Ver post completo: No, no es un reto de “desintoxicación digital”. Es el hermano de Sánchez esquivando a Hacienda mientras fingía vivir en Portugal para pagar menos impuestos.

29 Sep 20:03

Este es el plan presentado por Trump para lograr la paz entre Israel y Palestina según los diplomáticos que han recibido el acuerdo.

by Fino

Este es el plan presentado por Trump para lograr la paz entre Israel y Palestina según los diplomáticos que han recibido el acuerdo.

Concesiones israelíes:

– No habrá cesiones territoriales entre Israel y Gaza.

– No se llevarán a cabo asesinatos de miembros de Hamás en territorio Qatarí.

– Los civiles palestinos de Gaza podrán salir y entrar de la franja de forma segura.

– Un equipo internacional supervisará la retirada israelí.

Concesiones de Hamás:

– Liberación inmediata de todos los rehenes.

– Desmantelamiento de todas las «armas ofensivas».

– Gaza se transformará en una zona de comercio internacional, con exenciones de aranceles aduaneros.

– La Autoridad Palestina (no Hamás) participará en el consejo de gobierno tras la eliminación de los elementos extremistas de la misma.

Es un resumen de los 21 puntos que ha propuesto Trump para el proceso de paz, que podéis ver en este artículo de 20Minutos.

Ver post completo: Este es el plan presentado por Trump para lograr la paz entre Israel y Palestina según los diplomáticos que han recibido el acuerdo.

29 Sep 20:01

DELITO DE ODIO | El nuevo totalitarismo emocional #terrorismosemántico #delitodeodio

by Liberalístico

En este episodio me enfrento directamente a las acusaciones recibidas tras el primer capítulo de esta serie documental. *¿Estoy cometiendo yo misma “terrorismo semántico”?* *¿Estoy exagerando al utilizar esa expresión?*
Lo analizamos punto por punto.

📚 Utilizo, de forma rigurosa, la definición vigente del término “terrorismo” según la RAE:

👉 “Empleo de violencia y terror para infundir miedo en una colectividad.”
👉 “Dominación por el terror.”
👉 “Sucesión de actos violentos para causar terror.”
👉 “Actuación criminal de grupos organizados que buscan crear alarma social con fines políticos.”

Y sostengo que el fenómeno que denuncio —el terrorismo semántico— encaja plenamente en esta definición, porque no se trata de un simple uso simbólico del término, sino de una forma de dominación política que recurre a violencia real: multas, sanciones, despidos, juicios y cárcel por no someterse a los marcos lingüísticos impuestos desde el poder.

📌 *¿Qué demuestro en este vídeo?*
✔️ Que la violencia no es simbólica ni metafórica: se ejerce con amenazas físicas, económicas o legales sobre quienes no usan el lenguaje aprobado.
✔️ Que no se trata de casos aislados, sino de una sucesión sistemática de actos: normativas, represalias institucionales y campañas de difamación.
✔️ Que existen grupos organizados —desde el ámbito político, mediático y educativo— que operan con fines ideológicos y coercitivos.
✔️ Que esta presión sobre el lenguaje no busca inclusión, sino control social a través del miedo y la arbitrariedad legal.

💬 Hoy, *hablar se ha convertido en un riesgo, en algo que da MIEDO* Y eso no es casualidad. Es la estrategia. El nuevo poder se disfraza de árbitro moral y actúa en nombre de las emociones ajenas. No protege a las víctimas, fabrica colectividades vulnerables a medida para justificar su propia intervención.

🧠 *¿Y qué pasa con los niños y adolescentes?*
Este modelo de censura emocional se infiltra en el sistema educativo, inhibiendo el pensamiento crítico y asociando la lógica con la crueldad, mientras eleva la emoción como única medida del bien.

🎥 Este vídeo forma parte de la serie documental “Terrorismo Semántico”
📣 *¿QUÉ OPINAS TÚ?*
🗨️ ¿Es una exageración?
🗨️ ¿O estamos ya viviendo bajo un totalitarismo emocional?
🗨️ ¿Puede una emoción justificar el uso de la fuerza institucional?

👇 Déjalo en comentarios.
29 Sep 20:01

Estado-Nación soberano: ¿la última forma de esclavitud? Historia de la esclavitud en Europa.

by Liberalístico

Nos enseñaron que la esclavitud fue abolida. Que somos ciudadanos. Que vivimos en democracia. Pero… ¿alguna vez te preguntaste cuándo y cómo se abolió la esclavitud en Europa? ¿Quién definió lo que significa ser libre?

Este documental te lleva a través de una historia silenciada:
- Cómo la esclavitud no desapareció, sino que se transformó.
- Cómo los siervos se convirtieron en súbditos.
- Y cómo hoy todos obedecemos… no a un rey, sino a una idea: el Estado Soberano.

📜 Desde el Imperio Romano hasta la Paz de Westfalia.
🏰 Del siervo medieval al ciudadano moderno.
🧠 De las cadenas visibles a las cadenas mentales.

👉 ¿Y si te dijera que hoy tenemos más obligaciones que un siervo medieval… pero estamos convencidos de que somos más libres?
👉 Descubre cómo se redefinió la servidumbre, cómo se diluyó el lenguaje de la libertad, y por qué el poder más absoluto… es el que ya no necesita vigilarte.

📌 *Temas clave:*
👉 El origen político de la esclavitud y su evolución jurídica.
👉 La servidumbre heredada como forma de control sin propiedad.
👉 La transformación simbólica del siervo en ciudadano.
👉 El nacimiento del Estado moderno como sustituto del señor feudal.
👉 La trampa semántica de la libertad representada.

🎙️ Un documental narrado como nunca te lo contaron en clase.
🎬 Con imágenes, arte visual y reflexión crítica.

📢 *Comparte este vídeo si alguna vez sentiste que algo no encajaba del todo.*

--------------------- *BIBLIOGRAFÍA* ------------------------------------------------
*1. De la esclavitud a la servidumbre en Europa*
👉 Finley, M. I. (1980). La esclavitud en la antigüedad clásica
→ Analiza el papel de la esclavitud en Grecia y Roma, su racionalización legal y filosófica.
👉 Patterson, Orlando (1982). Slavery and Social Death: A Comparative Study
→ Concepto clave: la “muerte social” del esclavo. Examina cómo se construyen las condiciones de servidumbre más allá de la propiedad física.
👉 Duby, Georges (1988). Guerreros y campesinos: Desarrollo inicial de la economía europea (500–1200)
→ Clave para entender cómo la servidumbre reemplazó gradualmente la esclavitud en la Alta Edad Media.
👉 Bonnassie, Pierre (1991). De la esclavitud al feudalismo en Europa Occidental
→ Texto esencial sobre la transformación institucional tras la caída de Roma.

*2. Nacimiento del Estado moderno y la soberanía*
👉 Hobbes, Thomas (1651). Leviatán
→ El texto fundacional sobre el Estado moderno como entidad soberana, con un enfoque en el control absoluto.
👉 Strayer, Joseph R. (1970). On the Origins of the Modern State
→ Explica cómo se forjaron los Estados modernos sobre las ruinas del sistema feudal.
👉 Tilly, Charles (1992). Coercion, Capital, and European States, AD 990–1992
→ Fundamental para entender cómo la guerra y la extracción de impuestos dieron forma al Estado moderno.
👉 Elias, Norbert (1939). El proceso de la civilización
→ Describe cómo la centralización del poder fue acompañada por el autocontrol psicológico, que puede interpretarse como una forma de “servidumbre internalizada”.

*3. Control simbólico, obediencia y lenguaje*
👉 Foucault, Michel (1975). Vigilar y castigar
→ El pasaje de la violencia física al control mental. El Estado como vigilante interiorizado.
👉 Scott, James C. (1998). Seeing Like a State
→ Sobre cómo los Estados modernos intentan “simplificar” y “leer” a la sociedad para administrarla y controlarla.
👉 Hayek, F. A. (1944). Camino de servidumbre
→ Aunque centrado en el siglo XX, explora cómo el crecimiento del poder estatal lleva a una forma moderna de servidumbre colectiva.
👉 Huerta de Soto, Jesús (2020). El virus más letal
→ Enfoque liberal radical sobre cómo el Estado usa el miedo y el lenguaje para justificar su expansión.

*4. Westfalia y el orden internacional*
👉 Osiander, Andreas (2001). "Sovereignty, International Relations, and the Westphalian Myth", International Organization.
→ Desmonta el mito de que Westfalia inventó el Estado moderno, pero reconoce su impacto simbólico.
👉 Wilson, Peter H. (2010). Europe's Tragedy: A New History of the Thirty Years War
→ Detalla el contexto político y el impacto estructural de la Paz de Westfalia en el surgimiento del sistema estatal.
👉 Schmitt, Carl (1932). El concepto de lo político
→ Sobre cómo el Estado necesita construir enemigos para legitimar su existencia.
👉 Benedict Anderson (1983). Comunidades imaginadas
→ Cómo las naciones se construyen como ficciones simbólicas sostenidas por lenguaje y medios.

#terrorismosemántico #manipulacióndellenguaje #filosofía #liberalismo #política #historia #economía #Hayek #documental #libertad #esclavitudmoderna #esclavitud
---
00:00 - Introducción
04:27 - La Esclavitud Imperial
07:33 - El Siervo Feudal
13:58 - La Burguesía: La nueva nobleza
19:25 - ¿Súbdito yo?
24:42 - El Estado Nación: Enemigo de la libertad
29 Sep 20:00

¿Cómo MANIPULARON el lenguaje político en la Era de la Razón? #documental #ilustracion

by Liberalístico

Te explico el Terrorismo semántico aquí: https://youtu.be/Bv0fp6nibyI

Este documental es el segundo episodio de nuestra serie *Terrorismo Semántico* y nos adentra en el siglo de la razón, la Ilustración y las revoluciones modernas, para desvelar cómo el poder aprendió a dominar no ya con la fuerza... sino con las palabras.

Tras recorrer el Imperio Romano y la Edad Media en el capítulo anterior, hoy exploramos cómo la *Revolución Científica* y la *Ilustración* sembraron las bases del lenguaje político moderno. Un lenguaje que, bajo la promesa de libertad, razón y progreso, redefinió la legitimidad, la ley y la libertad misma… hasta convertir la obediencia en virtud y el miedo en sistema.

Este episodio no es solo historia: es una advertencia sobre cómo los grandes conceptos que hoy usamos — *libertad,* *razón,* *contrato social,* *ciudadanía* — fueron modelados por el poder para hacer pasar la sumisión por acuerdo, y la imposición por consenso.

🎙️ Viajamos desde *Copérnico, Galileo y Newton hasta Descartes, Hobbes, Locke, Ferguson y Mandeville,* para comprender cómo la razón se convirtió en el nuevo lenguaje del dominio. Veremos cómo la Ilustración no solo desmanteló los mitos medievales… sino que creó otros nuevos, más sofisticados, más invisibles.

🔍 *¿Qué analizamos en este capítulo?*
📌 La revolución semántica de la razón y su papel en la construcción del Estado moderno.
📌 El nacimiento del *contrato social* como mito legitimador.
📌 Cómo el lenguaje del progreso sirvió para justificar nuevos dogmas y nuevas cadenas.
📌 El paso del miedo al poder absoluto (Hobbes) a la fe en la razón colectiva (Rousseau)... y cómo ambos caminos abrieron la puerta al *terrorismo institucional*.
📌 El papel de la ciencia y la técnica en la creación del nuevo lenguaje político: del censo al contrato, del dato al dogma.

🧠 Basado en un análisis histórico, filosófico y político, este documental nos invita a reflexionar: *¿hasta qué punto el lenguaje que creemos emancipador no es, en realidad, la herramienta más eficaz de nuestro sometimiento?*

⚠️ Porque cuando el poder decide el significado de las palabras… ya no necesita reprimirte: basta con que creas que piensas libremente.

📺 Este es solo el segundo paso. En los próximos capítulos desvelaremos como la Revolución Francesa terminó de allanar el camino para que los totalitarismos del siglo XX perfeccionaran este arte del control semántico… hasta convertirlo en política de Estado.

🔔 Suscríbete y activa la campana para seguir descubriendo cómo las palabras moldearon el poder… y el poder, las palabras.
📝 Déjame tu comentario: *¿cuál crees que es hoy la palabra más manipulada?*

#TerrorismoSemántico #Ilustración #contratosocial #libertad #razón #documental #historia #filosofía #neuropsicología #política #Hobbes #Locke #Rousseau #Kant #RevoluciónFrancesa #RevoluciónAmericana #RevoluciónHaitiana #manipulación #lenguaje

------------------------------------------------------------------------------------------------------------
00:00 - 📌 Introducción | El poder cambia de máscara: de Dios a la Razón
05:28 - 🔭 Copérnico, Galileo y Newton | Cuando la ciencia reescribió el orden del mundo
10:40 - 🧪 Bacon, Descartes y la gramática del dominio | La razón como herramienta de control
17:51 - 👹 Hobbes y el Leviatán | El miedo convertido en sistema
33:15 - 🏛️ De súbditos a ciudadanos | El Estado-Nación y la libertad administrada
40:07 - ✊Locke contra el Leviatán | La lucha contra el Terrorismo Semántico
42:01 - 🔥La Revolución Gloriosa | El nacimiento de la Ingeniería Social
50:00 - ⛓️ Ferguson, Spinoza y Mandeville | Los herejes del nuevo dogma
29 Sep 19:59

La TRAMPA de "El Pueblo" y el silencio del rebaño | #documental

by Liberalístico

*¿Qué es el Pueblo?* Todos los discursos políticos lo invocan, todos los poderes lo utilizan… pero nadie lo define. El término carece de una definición jurídica clara: no sabemos si los políticos forman parte o no del pueblo, ni de dónde surge la legitimidad para que, en nombre de esa abstracción, se le arrebate a cada individuo su propia soberanía.
*En este vídeo exploramos el origen histórico de este término:*
- En Roma, “pueblo” era una minoría con voz política.
- Tras la caída del Imperio, la Iglesia transformó al pueblo en un rebaño guiado por un único pastor, una metáfora que unificó Europa durante siglos y que sirvió como contrapeso frente a los monarcas.
- Con la Reforma Protestante, ese relato se fragmentó: aparecieron nuevos “pastores” y, con la consolidación de los Estados modernos, surgió la noción de soberanía absoluta dentro de las fronteras. Cada rey pasaba a decidir incluso la religión de su territorio.
- De Bodin a Althusius, de Grocio a Locke, y finalmente Rousseau, los filósofos redefinieron una y otra vez el concepto de soberanía y del “pueblo”.

🎥 Un viaje histórico y filosófico para entender la trampa semántica detrás de una de las palabras más poderosas de la política moderna: el Pueblo.

📌 *Bibliografía principal:*
*→ Falta de definición jurídica y la indeterminación de “pueblo” como sujeto constituyente:*
Schmitt, C. (1927). Teoría de la Constitución.
Kelsen, H. (1920). Teoría pura del derecho.
Bobbio, N. (1989). Estado, gobierno y sociedad: por una teoría general de la política.
De Vega, P. (1996). La soberanía en la Constitución de 1978.
Rubio Llorente, F. (1991). La forma del poder: estudios sobre la Constitución.
Elster, J. (1995). Forces and mechanisms in the constitution-making process. Duke Law Journal, 45(2), 364–396. https://doi.org/10.2307/1372906
Luhmann, N. (1990). Legitimación por procedimiento.
Sartori, G. (1992). Elementos de teoría política.

*→ Principio de soberanía parlamentaria en el Reino Unido:*
Dicey, A. V. (1885). Introduction to the study of the law of the constitution (p. 38).
Loughlin, M. (2016). The British constitution: A very short introduction.

*→ Concepto de "demos" en Atenas y "populus romanus" en Roma:*
Ober, J. (1989). Mass and elite in democratic Athens: Rhetoric, ideology, and the power of the people.
Mommsen, T. (1854–1856). The history of Rome.
Manin, B. (1997). The principles of representative government.

*→ Cómo la Iglesia recurrió a la autoridad bíblica y a la metáfora del “pueblo de Israel”:*
Markus, R. A. (1997). Gregory the Great and his world.
Tierney, B. (1988). The crisis of church and state, 1050–1300.

*→ Concepto de soberanía y su evolución histórica:*
Bodin, J. (1576). Six Books of the Republic.
Tierney, B. (1982). Religion, law, and the growth of constitutional thought, 1150–1650.
Althusius, J. (1603/1995). Politica methodice digesta.
Locke, J. (1689/1988). Two treatises of government.
Dunn, J. (1969). The political thought of John Locke.
Hunt, L. (2007). Inventing human rights: A history.
Grocio, H. (1625). Sobre el derecho de la guerra y la paz.
Hobbes, T. (1651). Leviatán.
Skinner, Q. (1996). Reason and rhetoric in the philosophy of Hobbes.
Rousseau, J.J. (1762). El contrato social.
Bertram, C. (2012). Routledge philosophy guidebook to Rousseau and the Social Contract.
Hinsley, F. H. (1986). Sovereignty.

*→ Cómo se construyeron las narrativas del monarca como ser sobrenatural (divino y humano):*
Kantorowicz, E. H. (1957). The king’s two bodies: A study in mediaeval political theology.
Strayer, J. R. (1970). On the medieval origins of the modern state.
Bloch, M. (1961). The royal touch: Sacred monarchy and scrofula in England and France.

*→ Paz Augsburgo, Westfalia, guerra Esmalcalda, nacimiento del Estado Moderno..:*
Croxton, D. (1999). The Peace of Westphalia of 1648 and the origins of sovereignty. History Review, 21(3), 569–591.
Osiander, A. (2001). Sovereignty, international relations, and the Westphalian myth. Internat.Organization, 55(2), 251–287.
Parker, G. (1997). The Thirty Years’ War.
Lutz, H. (1997). The Reformation in Germany.
MacCulloch, D. (2003). Reformation: Europe’s house divided 1490–1700.
Wilson, P. H. (2009). Europe’s tragedy: A history of the Thirty Years War.
Strayer, J. R. (1970). On the medieval origins of the modern state.

*→ Sobre Maquiavelo y el concepto de stato:*
Machiavelo, N. (1532). El Príncipe.
Pocock, J. G. A. (1975).
Skinner, Q. (1981). Machiavelo.

📌 *Capítulos:*
0:00 - Introducción
2:27 - Definición de "El Pueblo"
12:05 - Concepto Clásico: "demos" y "populus romanus".
15:00 - La metáfora del Pueblo de Israel
20:30 - "El Pueblo" medieval: colectivismo y legitimidad divina.
30:30 - La lucha por la legitimidad y el poder político.
40:18 - La creación de los Estados Nación Soberanos
50:18 - Volviendo al origen
56:22 - Reflexiones finales.

#documental #historia #historiasoberanía #soberanía #pueblosoberano #bodin #locke #liberalismo #althusius
29 Sep 19:56

MUJER: ¿Qué es?

by Pilar Almagro

Mujer: hembra adulta de la especie humana.
Durante siglos significó eso, hasta que un día… decidieron vaciarla de contenido y rellenarla de todo y de nada. Han acabado con las mujeres porque todo el que tenga el antojo, puede definirse como mujer. Ya no hay mujeres porque cualquiera puede ser mujer, incluso por un rato. La ley apoya y fomenta el absurdo, y castiga al que defienda el sentido común.

Ya no hablamos de evolución natural del lenguaje, sino de manipulación deliberada, como nos dice Cristina Soto.
Cambian las palabras para cambiar las percepciones y eliminar la posibilidad misma de verdad.
Y cuando te cambian el significado de las palabras básicas y esenciales, te cortocircuitan; ya no sabés qué defender… ni a quien.
Quien domina el lenguaje, domina la realidad.

Mañana hablaremos del paso del término JUSTICIA a JUSTICIA SOCIAL, una perversión del concepto justicia.

¿Tú qué piensas?

Si te gustó dale like y suscríbete para más contenido
Sígueme en mis otras redes sociales: https://linktr.ee/pilaralmagromarcos

#neolenguaje #empresa #ahorro #mercado #mercadolibre #consultoríaempresarial #empresarialidad #empresarios #estado #empresa #emprendimiento #capitalismo #capital #liberalismo #liberalismoeselfuturo #empresarial #empresarias #empresaria #innovaciónempresarial #consultoria #libertadeconomica #empresarias #empresario #empresariado #empresariado #liberalesalpoder #empleo #libertarismo #crecimientoempresarial #escuelaaustriaca #trabajo #inversor #inversiones #ceo #produccion #precios #mercado #libremercado #wokeagenda #wokeism #liberalistico #cistinasoto #casaverde #mujer #mujeres #mujerempoderada
29 Sep 19:51

Si tienes entre 50k y 150k euros, eres nivel 3

by Javi Linares

#inversion #javilinares #invertir #finanzaspersonales #finanzas #economia

══════════════

*MIS PLATAFORMAS PARA INVERTIR*

✅ Mi plataforma favorita para invertir en fondos indexados:
Enlace a MyInvestor: https://bit.ly/MyInvestorIndexados

✅ Mi Plataforma favorita para invertir en ETFs con cuenta remunerada para saldo en efectivo:
Enlace a Trade Republic: https://trade.re/linares-interes

✅ Plataforma que uso para invertir en BTC y Cryptos:
Enlace a Kraken: https://bit.ly/krakenYT

══════════════

¿QUIERES APRENDER A INVERTIR y MEJORAR TUS FINANZAS PERSONALES?

📚 Conoce el Método LINVEST, mi programa con soporte 1 a 1 para crear tu cartera de inversión y plan financiero personalizado: https://javilinares.com/metodo-linvest/?utm_source=youtube&utm_medium=organic&utm_campaign=video-short

══════════════

¿QUIERES COMPRARTE UN PISO, CASA O INMUEBLE?

🏠 Broker Hipotecario AQUEOS: Te ayudamos a encontrar la mejor hipoteca para tu propiedad: https://javilinares.com/broker-hipotecario/?utm_source=youtube&utm_medium=organic&utm_campaign=video-short

══════════════

*SECCIONES DEL CANAL*

https://www.youtube.com/playlist?list=PLa--ADK-E7IuKhNjd4uwu3EUMmxOSFQfQ

https://www.youtube.com/playlist?list=PLa--ADK-E7Iu-r16mxAkXNoeoLwd16rmh

https://www.youtube.com/playlist?list=PLa--ADK-E7IutcqRJCjql5IRYMjuc5T5v

https://www.youtube.com/playlist?list=PLa--ADK-E7IsV4CoFE4bezEwgxyOC18-5

https://www.youtube.com/playlist?list=PLa--ADK-E7It2VIDNSKDjM512ypXx1_vf

══════════════

*SÍGUEME EN REDES SOCIALES*

👉🏻 Notificamos de nuevos vídeos en mi Canal en Telegram: https://t.me/LasInversionesDeJavi

👉🏻 Mi Instagram: https://www.instagram.com/soyjavilinares/

👉🏻 Mi Twitter: https://twitter.com/soyJaviLinares

══════════════

Javier Linares Fernández

- Asesor financiero certificado EIP (nº 37391)

══════════════

DISCLAIMER: el contenido de este Canal de YouTube tiene fines únicamente educativos y en ningún caso suponen recomendaciones de inversión o asesoramiento financiero. Por favor consulta con detalle los documentos oficiales de los fondos de inversión y ETFs antes de realizar cualquier inversión y asegúrate que dichos productos cumplen con tus objetivos de inversión.

Recuerda que la inversión siempre debe ser entendida a largo plazo e invertir un dinero que puedas permitirte perder. Antes de invertir es imprescindible entender los datos de los fondos y sobre todo tener un fondo de emergencia de al menos 3 meses de tus costes de vida.

Invierte solo en bancos y brokers regulados y huye de rentabilidades astronómicas, dinero rápido o demás eslóganes de inversión

Javi Linares mantiene relaciones comerciales con MyInvestor y Trade Republic y la referencia a sus productos y servicios se considera publicidad conforme a la normativa vigente.

══════════════
29 Sep 19:51

Experimentos de Microsoft y AMD en hardware que puede que veamos o no en el mundo real

by tendero-digital

En el mundo del hardware digital los fabricantes siempre están realizando experimentos para mejorar el rendimiento. Muchas veces esto genera patentes, prototipos… pero en la mayoría de las ocasiones no vemos luego en el mundo real nada de eso: puede ser que sea caro, que al final no se nota tanto el avance, que algún competidor se adelante, que a los de marketing no les guste, que la empresa cambie y ya no esté interesada en ese mercado…

 

microsoft graba canales en los procesadores para mejorar la refrigeración

 

 

Esta semana pasada he visto dos ejemplos de posibles avances en hardware que tal vez no veamos nunca en el mundo real:

  • Microsoft graba canales microfluídicos en los procesadores para mejorar su refrigeración:
    Microsoft que no es una compañía donde la fabricación de chips sea un apartado importante ha estado investigando sobre sistemas para mejorar la refrigeración de los procesadores. Curiosamente no está pensando en los PCs sino en los procesadores de servidores. Parece que como ahora mismo están desplegando muchos centros de datos para sus servicios ven que es un campo donde pueden caber nuevos enfoques.
    bloque de refrigeración líquida de dell para servidor epyc

    En la imagen superior se puede ver un bloque de refrigeración líquida de un servidor Dell. Realment no hay mucho diferencia con los bloques que podemos usar en un PC normal. Es una superficie plana con varias capas (para que no se escape el agua o el líquido refrigerante). Eso hace que la refrigeración no sea todo lo óptima que podría ser.
    Por ello en Microsoft pensaron que si podían grabar canales finos para que fluya el líquido directamente sobre el silicio la refrigeración sería mejor y además podrían reducir el tamaño de los bloques. Empezaron con modelos de líneas. Entonces solicitaron la ayuda de Corintis una empresa suiza con experiencia en este campo. Corintis usa canales con formas que imitan a la naturaleza. Si os fijáis en la imagen de arriba parece que estemos viendo las alas de un insecto en el diseño de los canales.
    Luego tuvieron que crear un bloque para que el líquido estuviese en contacto con el chip, pero sin que se escapase hacia otros componentes:

    disipador experimental de microsoft con microfluidos

    bloque de refrigeración líquida de dell para servidor epycEn la imagen superior se puede ver el servidor que usaron para hacer pruebas. El experimento parece que tuvo éxito y que Microsoft aprendió cosas sobre este sistema. Las ventajas pasas por un menor tamaño, por las posibilidades de aumentar la velocidad de los chips en los picos de demanda de los servidores. También parece una buena solución para sistemas futuros que apilen los chips. En resumen un experimento para comprobar un concepto que luego veremos o no en el mundo real.

    VIDEO.

 

  • AMDAMD patenta una forma de conectar la memoria DDR5 para aumentar su rendimiento:
    La patente describe el desarrollo de módulos de memoria dual en línea de alto ancho de banda (HB-DIMM) que utilizan pseudocanales y enrutamiento de datos especializado para optimizar el rendimiento. En lugar de rediseñar los chips DRAM, AMD propone acoplar múltiples dispositivos DRAM a chips de búfer de datos avanzados. Estos búferes gestionan el flujo de señal de forma que duplican la salida, aumentando la velocidad de transferencia de los 6,4 gigabits por segundo actuales a 12,8 gigabits por segundo en el bus de memoria.
    La idea de AMD es interesante. Duplican la velocidad de transferencia de la memoria DDR5 actual sin romper mucho los estándares actuales. Es decir que no habría que realizar muchos cambios en chipsets, placas base o microprocesadores para tenerlo en el mundo real.
    Pero en este caso tal vez el problema radique en el origen de la innovación, uno de los grandes fabricantes de procesadores. Lo cual lo hará complicado de adoptar por otros fabricantes.

 

Podemos ver como los fabricantes siguen pensando maneras y formas de mejorar el rendimiento del hardware… ahora toca esperar a ver si lo vemos en nuestros PCs pronto.

La entrada Experimentos de Microsoft y AMD en hardware que puede que veamos o no en el mundo real se publicó primero en Al otro lado del mostrador.

29 Sep 19:49

El Secreto de la OTAN: La Mentira al Descubierto por Jeffrey Sachs

by El Canal del Coronel

En este programa analizamos las causas profundas de la Guerra de Ucrania, basándonos en las declaraciones del economista Jeffrey Sachs, profesor de Harvard y dos veces incluido por Time entre las personas más influyentes del mundo.
En su análisis advierte que la guerra no solo afecta a Ucrania, sino que arrastra a Europa hacia un posible choque directo entre la UE, la OTAN y Rusia.
29 Sep 18:12

El nuevo post delictivo de Trump en Truth Social

by themarquesito

Como ya es costumbre, Donald Trump comete delitos de manera pública y notoria en su red social Truth Social, pero no existe remedio alguno para ello, ya que el único remedio legal contra un presidente que delinque es el impeachment, procedimiento que necesita de una mayoría de 2/3 en el Senado. Éste es su nuevo post con actividad delictiva:

truthsocial.com/@realDonaldTrump/posts/115287641147640374

Traduzco: El autoproclamado comunista de Nueva York, Zohran Mamdani, que se presenta a alcalde, demostrará ser una de las mejores cosas que le hayan ocurrido a nuestro gran Partido Republicano. Va a tener problemas con Washington como ningún alcalde en el la historia de nuestra otrora gran Ciudad. Recordad, necesita el dinero de mí, como Presidente, para llevar a cabo todas sus FALSAS promesas Comunistas. No va a recibir nada, así que ¿por qué votar por él? Esta ideología ha fracasado siempre, durante miles de años. Francasará de nuevo, ¡garantizdo! Presidente DJT

¿Por qué digo que es delictivo? Por la elemental razón de que está amenazando con represalias en caso de que un candidato salga elegido, amenazando con retener fondos federales, cosa que además es ilegal ya que el poder presupuestario lo tiene de manera explícita el Congreso de los EE.UU. Como mínimo, Donald Trump está cometiendo delitos de interferencia electoral y extorsión, además de violar la "cláusula de las apropiaciones" de la Constitución.

¿Tiene relevancia? Por desgracia, no, ya que no hay remedio legal viable contra las actividades delictivas del actual presidente (o más apropiadamente dictador con la actual situación en EE.UU), así que no va a pasar absolutamente nada. Los agradecimientos, a los Siniestros Seis.

etiquetas: artículo

» noticia original ()

29 Sep 18:11

Trabajar de nueve a nueve seis días por semana: qué hay detrás del modelo "996" que es tendencia en Silicon Valley

by jromero1974

"Ahora mismo, para ganar hay que trabajar a toda velocidad los siete días de la semana". El inversor de riesgo Harry Stebbings se pronunciaba así hace meses en una publicación en LinkedIn dirigida a las startups europeas que quieran competir contra "las mejores empresas del mundo". El británico, de solo 29 años, apretaba un poco más las tuercas de un discurso para abrazar el modelo llamado "996"

etiquetas: trabajo, modelo 996

» noticia original (www.rtve.es)

29 Sep 18:10

VÍDEO | Rufián carga contra la derecha "de misa diaria" por negar el genocidio: "Asesinar a niños no es una guerra"

by YeahYa

Gabriel Rufián denuncia la hipocresía de líderes del PP y otros sectores de derechas en España que evitan calificar como genocidio los ataques contra Gaza ...

etiquetas: rufián, ayuso, aznar, pp, gaza, palestina, israel

» noticia original (www.catalunyapress.es)

29 Sep 18:10

Ilia Topuria no se deja utilizar por Ángel Gaitán

by LágrimasdeFacha

A raíz del vacío que le hizo el equipo de Ilia Topuria a Ángel Gaitán, investigamos un poco y descubrimos la verdadera cara del "mecánico de TikTok", utilizando el nombre y la influencia de personalidades famosos para conseguir sus propósitos, ya sea dinero, información o seguidores. Su personalidad egocéntrica se ve reflejada en cada una de sus "campañas de ayuda" o en sus denuncias públicas.

etiquetas: ilia topuria, ángel gaitán

» noticia original (www.youtube.com)

29 Sep 18:06

Doctor en Economía #1: “Estamos al Borde del Colapso Financiero” Cómo Actuar en Crisis: Soluciones.‌

by Tengo un Plan

🎓Apúntate ahora al Directo de Presentación de la Formación Universitaria en Inversión y Finanzas para todo el mundo desde aquí (gratis y online) → https://www.visualfaktory.com/suscripcion-directo-af?utm_source=afiliado&ref=19

🧭📄 Consigue nuestra hoja brújula de 10 preguntas profundas para conocerte y mejorar tu vida. Regístrate aquí: https://bit.ly/4mn7N85

🎧 Escucha nuestro libro totalmente gratis con la prueba de Audible: https://amzn.to/435yTLc

📘 Más de 150 podcast resumidos en un libro, “Lo que Ellos saben y Tú no” disponible aquí: https://amzn.eu/d/8ZcVldi

¡Bienvenidos a Tengo un Plan! 🎙️

Juan Ramón Rallo es economista, doctor en Economía, profesor universitario y escritor. Director del Instituto Juan de Mariana y colaborador habitual en medios, se ha consolidado como una de las principales voces liberales en el mundo hispanohablante. Autor de libros como Una alternativa liberal y Contra la renta básica, Rallo combina rigor académico con un estilo divulgativo que lo ha convertido en referente en debates económicos y políticos en España y Latinoamérica.

TE COMPARTIMOS RECURSOS ÚTILES:

Web: https://juanramonrallo.com/
Instagram: https://www.instagram.com/juanramonrallo/?hl=es
Canal de Youtube: https://www.youtube.com/JuanRallo
X: https://x.com/juanrallo?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor
Libros: https://www.casadellibro.com/libros-ebooks/juan-ramon-rallo/141309?srsltid=AfmBOop537D1dQp9bevDUl17g96nqUz1NjMi3BYX569huD92-l4lW050


📢 ¿Quieres colaborar o ser patrocinador de Tengo un Plan? Puedes contactar aquí:
https://tengounplanpodcast.com/colabora-nueva/


MINUTAJE DEL EPISODIO:

0:00 Intro
2:16 ¿Cómo explicaría Rallo la economía a alguien que acabase de nacer?
4:02 El problema de la vivienda en España ¿Qué sucede?
11:23 Realmente el salario mínimo no ha subido
13:40 La recalificación
17:17 Este porcentaje del precio de la vivienda son impuestos
22:57 El elevado número de inmigrantes que demandan vivienda
27:51 Medida falsa de Pedro Sánchez
33:31 El objetivo de cualquier político (Nos gobiernan los ancianos)
36:43 Así funcionan realmente las pensiones
49:23 La manipulación de los medios
51:02 Nuestro sistema educativo no forma, deforma
52:52 ¿Realmente sirve de algo votar en España?
56:17 Esto es verdaderamente la política
1:01:09 ¿Por qué todos se vuelven corruptos? ¿Qué hay mal en la sociedad?
1:06:54 Pedro Sánchez si sabía la corrupción que había en su partido
1:08:08 ¿Todos los partidos son corruptos?
1:12:37 Que podemos hacer para mejorar realmente nuestra vida
1:14:31 Tiempo y Conocimiento lo más valioso
1:18:23 Tanto ahorro no tiene sentido
1:23:15 Así es el proceso de montar una universidad
1:30:48 ¿Hay futuro para los emprendedores en España?
1:41:36 Las causas que han llevado a Europa al estancamiento
1:47:30 Cuidas la riqueza o la persigues
1:49:33 En que país mi patrimonio estaría seguro
1:53:15 Los paraísos fiscales
2:03:16 Foto con Milei (Curiosidades sobre el)
2:15:14 ¿Milei está cumpliendo con el liberalismo?
2:19:42 El liberalismo para principiantes desde 0
2:21:19 El estado es esto
2:24:27 Los pros y contras de la democracia
2:29:27 El comunismo explicado
2:38:50 El Marxismo y la IA
2:44:56 Si el estado es dueño de todo el papel
2:45:55 ¿Puede la IA manejar el poder de un estado?
2:50:19 Doctor en economía analiza las criptomonedas
2:52:16 Si te expropian no podrán quitarte Bitcoin
2:57:15 El caso de Charlie Kirk
3:02:09 5 libros que influenciaron a Juan Ramón Rallo
3:06:39 Al estado le permitimos hacer cosas que no dejamos a los demás

Recuerda compartir el episodio si te ha gustado, ¡y no olvides suscribirte a nuestro canal de YouTube y valorarnos con 5 estrellas si nos escuchas en plataformas de audio!

¡Nos vemos en el próximo episodio! 👋
29 Sep 18:02

AWS Weekly Roundup: Amazon S3, Amazon Bedrock AgentCore, AWS X-Ray and more (September 29, 2025)

by Matheus Guimaraes

Wow, can you all believe it? We’re nearing the end of the year already. Next thing you know, AWS re:Invent will be here! This is our biggest event that takes place every year in Las Vegas from December 1st to December 5th where we reveal and release many of the things that we’ve been working on. If you haven’t already, buy your tickets to AWS re:Invent 2025 to experience it in person. If you can’t make it to Vegas, don’t worry, make sure to stay tuned here on the AWS News Blog where will be covering many of the announcements as they happen.

However, there are plenty of new exciting new releases between now and then, so, as usual, let’s take a quick look at some of the highlights from last week so you can catch up on what’s been recently launched, starting with one of the most popular services: Amazon S3!

S3 updates
The S3 team has been working really hard to make working with S3 even better. This month alone has seen releases such as bulk target selection for S3 Batch Operations, support for conditional deletes in S3 general purpose buckets, increased file size and archive scanning limits for malware protection, and more.

Last week was another S3 milestone with the addition of a preview in the AWS Console for Amazon S3 Tables. You can now take a quick peek at your S3 Tables right from the console, making it easier to understand their data structure and content without writing any SQL. This viewer-friendly feature is ready to use across all regions where S3 Tables are supported, with costs limited to just the S3 requests needed to display your table preview.

Other releases
Here are some highlights from other services which also released some great stuff this week.

Amazon Bedrock AgentCore expands enterprise integration and automation options — Bedrock AgentCore services are leveling up their enterprise readiness with new support for Amazon VPC connectivity, AWS PrivateLink, AWS CloudFormation, and resource tagging, giving developers more control over security and infrastructure automation. These enhancements let you deploy AI agents that can securely access private resources, automate infrastructure deployment, and maintain organized resource management whether you’re using AgentCore Runtime for scalable agent deployment, Browser for web interactions, or Code Interpreter for secure code execution.

AWS X-Ray brings smart sampling for better error detection — AWS X-Ray now offers adaptive sampling that automatically adjusts trace capture rates within your defined limits, helping DevOps teams and SREs catch critical issues without oversampling during normal operations. The new capability includes Sampling Boost for increased sampling during anomalies and Anomaly Span Capture for targeted error tracing, giving teams better observability exactly when they need it while keeping costs in check.

AWS Clean Rooms enhances real-time collaboration wilth incremental ID mapping — AWS Clean Rooms now lets you update ID mapping tables with only new, modified, or deleted records through AWS Entity Resolution, making data synchronization across collaborators more efficient and timely. This improvement helps measurement providers maintain fresh datasets with advertisers and publishers while preserving privacy controls, enabling always-on campaign measurement without the need to reprocess entire datasets.

Short and sweet
Here are some bite-sized updates that could prove really handy for your teams or workloads.

Keeping up with the latest EC2 instance types can be challenging. AWS Compute Optimizer now supports 99 additional instance types including the latest C8, M8, R8, and I8 families.

In competitive gaming, every millisecond counts! Amazon GameLift has launched a new Local Zone in Dallas bringing ultra-low latency game servers closer to players in Texas.

When managing large-scale Amazon EC2 deployments, control is everything! Amazon EC2 Allowed AMIs setting now supports filtering by marketplace codes, deprecation time, creation date, and naming patterns to help prevent the use of non-compliant images. Additionally, EC2 Auto Scaling now lets you force cancel instance refreshes immediately, giving you faster control during critical deployments.

Making customer service more intelligent and secure across languages! Amazon Connect introduces enhanced analytics in its flow designer for better customer journey insights, adds custom attributes for precise interaction tracking, and expands Contact Lens sensitive data redaction to support seven additional European and American languages.

That’s it for this week!

Don’t forget to check out all the upcoming AWS events happening across the globe. There are many exciting opportunities for you to attend free events where you can meet lots of people and learn a lot while enjoying a great day amongst other like-minded people in the tech industry.

And if you feel like competing for some cash, time is running out to be part of something extraordinary! The AWS AI Agent Global Hackathon continues until October 20, offering developers a unique opportunity to build innovative AI agents using AWS’s comprehensive gen AI stack. With over $45,000 in prizes and exclusive go-to-market opportunities up for grabs, don’t miss the chance to showcase your creativity and technical prowess in this global competition.

I hope you have found something useful or exciting within this last week’s launches. We post a weekly review every Monday to help you keep up with the latest from AWS so make sure to bookmark this and hopefully see you for the next one!

Matheus Guimaraes | @codingmatheus
29 Sep 18:02

Los "China Hawks", orgullo de ir contra China

by Adrián Díaz 李安
29 Sep 17:44

¿Lo contrataríais?

by Fino

¿Lo contrataríais?

¿Lo contrataríais?

Enviado por RS.

Ver post completo: ¿Lo contrataríais?

29 Sep 17:43

¿Y si ambos tienen parte de razón?

by Fino

Quiero decir… está claro que Rodri tiene un complejo de inferioridad que intenta maquillar con “férreos principios” en forma de limitaciones impropias de nuestro tiempo a sus parejas, ahí Irene acierta, pero parte de su discurso esconde una verdad: muchas personas (no solo chicas) “siguen en el mercado” aunque tengan pareja, y eso implica que cuando salgan de fiesta admitirán de buen grado la interacción “en modo tonteo” con algunos sujetos del sexo contrario. Que la sangre llegue al río dependerá de más factores.

Vestirse de forma sexy tiene como objetivo recibir validación y atraer a posibles candidatos, se haga más o menos conscientemente el fin es ese. Si una sale para “pasárselo bien con las amigas” no tiene mucho sentido enseñar más pechuga que una pollería.

Creo que no hay necesidad de negar una realidad tan palmaria. Es algo que todos sabemos y que muchos niegan de forma absolutamente hipócrita. Darle la espalda a la realidad no cambia la realidad.

El “me maquillo para mí”, “me visto como un putón para mí” se lo cree solo la gente que intenta engañar a los demás con mentiras equivalentes.

Ver post completo: ¿Y si ambos tienen parte de razón?

29 Sep 17:42

"El TRABAJADOR tiene que estar PROTEGIDO"

by ConPdePodcast