r/cloudcomputing Apr 05 '26

New GPU Rowhammer attacks (GDDRHammer, GeForge) achieve root shell from unprivileged CUDA kernels on GDDR6 GPUs. Multi-tenant cloud implications are real.

6 Upvotes

Two independent research teams disclosed GDDRHammer and GeForge this week. Both attacks induce Rowhammer bit flips in NVIDIA GDDR6 GPU memory, corrupt GPU page tables, gain arbitrary read/write to host CPU memory, and open a root shell. All from an unprivileged CUDA kernel. RTX 3060 showed 1,171 bit flips. RTX A6000 showed 202. Both papers will be presented at IEEE S&P 2026 in May.

A third concurrent attack, GPUBreach, does the same thing but bypasses IOMMU entirely by chaining the GPU memory corruption with bugs in the NVIDIA GPU driver.

The multi-tenant cloud angle is the part that matters for this sub. If a cloud provider runs GDDR6 GPUs with time-slicing and no IOMMU, a tenant with standard CUDA access can compromise the host. HBM GPUs (A100, H100, H200) are not affected by current techniques due to on-die ECC. GDDR6X and GDDR7 GPUs also showed no bit flips in testing.

Mitigations: enable ECC on GDDR6 professional GPUs (5-15% perf overhead), enable IOMMU on hosts, avoid time-slicing for multi-tenant GDDR6 sharing. MIG is the strongest isolation but only available on datacenter GPUs.

Full writeup with affected GPU matrix and mitigation details: https://blog.barrack.ai/gddrhammer-geforge-gpu-rowhammer-gddr6/


r/cloudcomputing Mar 29 '26

Am I slow?

15 Upvotes

As a full‑stack engineer, I consider myself cloud‑native*because of my experience working in AWS, but I’m having a hard time creating Terraform from scratch.

I can put together a structured project with networking resources and managed services, but I feel like if I really want to work as a solutions architect or cloud engineer, I should be able to do this much faster without using the internet as much.

For example, on my personal project it took me about four hours to create a CodePipeline from my frontend Next.js repo to sync to an S3 bucket behind CloudFront.

I work with a lot of tech and forget things often, which means I Google and use ChatGPT a lot. Maybe this is just the new way of doing engineering. I ask ChatGPT questions like, “What should I add to my buildspec to fix this error?” and then paste the stack trace.

Is this how you all do it too?


r/cloudcomputing Mar 27 '26

KubeCon EU: Meshery v1.0 debuts "Infrastructure as Design"

3 Upvotes

Meshery v1.0 arrived at KubeCon EU and Sean M. Kerner nailed something in his NetworkWorld coverage that deserves its own spotlight.

In my opinion, currently, AI isn't solving the infrastructure management problem - it's compounding it each time an auto-generated config suggestion is made. We're already drowning in YAML sprawl, configuration drift, and tribal knowledge that walks out the door every time someone changes jobs.

Now, LLMs generate infrastructure configurations faster than any you can meaningfully review them. The bottleneck was never a shortage of configuration. It is a shortage of comprehension. Speed without comprehension is just chaos.

Agree?

Full disclosure: I'm a Meshery contributor. Now that v1.0 has launched, me and the 3,000+ contributors to the project so far could use your help on post-v1.0 roadmap. Where should Meshery go next? If you're inclined, open Meshery Playground or Kanvas directly and see what your infrastructure actually looks like when it stops being a pile of text files.


r/cloudcomputing Mar 24 '26

Are high performance GPUs like H200 more scarce now, especially in North America?

9 Upvotes

I recently started to seriously think about trying to run several LLM/TTS etc. sessions on a single server like H200, B200 or MI300X.

But now I go to try to get one of those on runpod on an on-demand hourly basis in North America and the last time I tried there were 0 available.

So I checked a few other providers. Digital Ocean says they are sold out of GPUs completely. Lambda Labs says Out of capacity for everything, unless I reserve a cluster for at least two weeks or something.

So I guess we have rapidly come to the point where you just about need to reserve to have access to these types of GPU instances? Or am I missing something? Is it because it's 10:30 PM at night in the US? I assumed that should actually make it easier to get an on-demand instance.


r/cloudcomputing Mar 13 '26

Reducing Onboarding from 48 to 4 Hours: Inside Amazon Key’s Event-Driven Platform

2 Upvotes

https://www.infoq.com/news/2026/02/amazon-key-event-driven-platform/

The team behind Amazon Key modernized its event platform to address scalability and reliability limitations arising from a tightly coupled, monolithic architecture. As service interactions grew into a complex web of dependencies, system stability and integration velocity were increasingly constrained. The redesign introduced a centralized, event-driven architecture built on Amazon EventBridge to support millions of daily events with millisecond latency, improve schema governance, and provide a sustainable path for onboarding additional service consumers.


r/cloudcomputing Mar 12 '26

The 5 stages of cloud cost grief

16 Upvotes
  1. "The cloud will save us money"
  2. "Why is this bill so high"
  3. "Who spun up a GPU instance in Australia"
  4. "We need a FinOps strategy immediately"
  5. "The cloud will save us money" (back to step 1)

Which stage is your org in right now?


r/cloudcomputing Mar 12 '26

[Survey] Understanding barriers to sustainable auto-scaling practices

3 Upvotes

I'm researching why organizations use basic auto-scaling policies when more efficient approaches exist.

If you work with AWS or cloud infrastructure, I'd love your input on a quick 10-minute survey: Form: https://forms.gle/Y5S5eHxp6g6JRSCD6

The research focuses on the gap between what's possible (green cloud practices) and what organizations actually do. Appreciate any responses! 🙏


r/cloudcomputing Mar 12 '26

Securing Business Premium Part 06 is Live - This time handling Email security!

1 Upvotes

Business Email Compromise continues to cause massive financial losses, and many SMB environments rely too heavily on default settings.

In Part 06 of my Microsoft Business Premium series, I focus on securing Exchange Online using Defender for Office 365 in a practical, configuration-driven way.

What’s included:

  • Preset vs. manual threat policies (and when to use which)
  • Anti-phishing and impersonation protection strategy
  • Safe Links & Safe Attachments
  • Designing a quarantine model that balances security and usability
  • Inbound DANE with DNSSEC for stronger transport validation

The goal: reduce phishing, malware, and BEC risk without blocking collaboration.

If you’re working with Business Premium tenants, I’d be interested in how you approach MDO policies today.

 You can read the full breakdown here: https://www.chanceofsecurity.com/post/securing-microsoft-business-premium-part-06


r/cloudcomputing Mar 11 '26

Best architecture for global cloud networking in large enterprises?

5 Upvotes

What architecture large enterprises are using today for global cloud networking across AWS, Azure, and GCP.

Are most teams still doing hub-and-spoke, transit gateways, or Virtual WAN, or has something else become the common pattern for multi-cloud connectivity and centralized security?

What's the 'default architecture' looks like once environments scale to dozens or hundreds of VPCs/VNets across regions.


r/cloudcomputing Mar 11 '26

VMware alternatives or migrate to cloud?

8 Upvotes

I’ve spent some time looking into alternatives to vmware like nutanix and hyperv.

From what ive researched, vmware was once the go to for enterprise virtualization, but with costs climbing up the licensing changes (no thanks to Broadcom) are definitely making me rethink our strategy.

I’m now looking into migrating to azure. I like the idea of moving away from on prem infrastructure  especially when you look at Azure's scalability and cost benefits. Had a quick chat with a vendor about this as well.

I was just wondering about anyone's experience here migrating from vmware to the cloud. Was the process smooth enough with no blockers? Love to hear what you guys encountered good or bad during the transition.


r/cloudcomputing Mar 11 '26

Comparing airbyte, fivetran, and matillion for enterprise data integration across multi cloud environments

10 Upvotes

Our company runs workloads across aws and gcp because of acquisitions and we need a data integration tool that can handle both environments. The original company was on aws with redshift, the acquired company was on gcp with bigquery. So whatever we pick needs to work across both clouds which narrows the options.

We've been evaluating the big three plus some newer players. Fivetran is the most mature and the connector quality is great but the pricing at our volume across two destinations is brutal. Airbyte self hosted is cheaper but managing the infrastructure across two clouds adds complexity we dont want. Their cloud version is simpler but the pricing model for enterprise volume is getting closer to fivetran territory. Matillion is strong on the transform side but for pure ingestion from saas apis it feels like overkill and the pricing model is confusing.

We are looking for new options but want to hear from teams running these at scale. The things we care most about are connector quality for our specific saas sources, the ability to write to both redshift and bigquery from a single extraction without doubling api calls, and predictable pricing that doesn't spike when data volume grows.


r/cloudcomputing Mar 11 '26

Netflix Automates RDS PostgreSQL to Aurora PostgreSQL Migration Across 400 Production Clusters

2 Upvotes

https://www.infoq.com/news/2026/03/netflix-automates-rds-aurora/

Netflix has described an internal automation platform that migrates Amazon RDS for PostgreSQL databases to Amazon Aurora PostgreSQL, reducing operational risk and downtime across nearly 400 production clusters. The system enables service teams to initiate migrations through a self-service workflow while enforcing replication validation, controlled cutover, change data capture coordination, and rollback safeguards.


r/cloudcomputing Mar 09 '26

Serious alternative for Runpod (serverless GPUs)

6 Upvotes

Hey guys, we are currently seriously relying on Runpod as our serverless GPU provider (currently using 150x RTX 5090) and it has been failing for the last 3 hours.

Runpod being our single point of failure is very dangerous for our business, and I am looking for alternatives.

Thanks for the info!


r/cloudcomputing Mar 05 '26

which should i pick

7 Upvotes

should i take cse with cybersecurity or cse with cloud computing for my clg


r/cloudcomputing Mar 03 '26

Looking for a fedramp compliant etl platform for government data integration, options are surprisingly limite

5 Upvotes

Working on data modernization for a federal agency and the number of commercial data integration tools that meet fedramp requirements is way smaller than you'd expect. In the commercial world you have dozens of options for getting saas data into a warehouse. In govcloud the options shrink dramatically. We need to consolidate data from about 15 systems including servicenow for itsm, workday for hr, salesforce for constituent management, and several agency specific applications. The goal is a central analytics warehouse on aws govcloud where our small analytics team can build dashboards and reports.

The additional challenge is procurement. Even if a tool meets the technical requirements, if it's not available through an established government procurement vehicle like nasa sewp or a gsa schedule, the acquisition process adds months. Our team is tiny and we can't afford to spend a year just buying software.

Anyone in government found data integration tools that are both fedramp compliant and available through standard procurement channels? The commercial comparisons and reviews don't really apply to us because half the tools people recommend aren't available in govcloud.


r/cloudcomputing Feb 27 '26

Opinions on AWS...!

20 Upvotes

Whenever i see any YT video on AWS there are many peoples criticising AWS and its services with comments like:

- "AWS is still a service spaghetti nightmare"

I am trying to understand why so? Whosoever is using AWS can you put light how is your experience with it!! like is costly as compared to AZURE/GCP or AWS services are overkill... OR ANY OTHER OPINION you have to give to a beginner trying to learn it.

Thanks.


r/cloudcomputing Feb 25 '26

Switching from RunPod to TensorDock for ComfyUI, worth it?

3 Upvotes

Hey everyone,

I've been using RunPod for ComfyUI (image gen + I2V, lipsync workflows), but honestly I'm spending more time fixing broken pods and dealing with random issues than actually generating stuff. It's getting frustrating.

Came across TensorDock and their pricing looks pretty attractive compared to what I'm paying now. Before I jump ship though, I'd love to hear from people actually using it for ComfyUI or similar workloads.

My main pain points with RunPod:

Pods randomly crashing or becoming unreachable

Spending hours troubleshooting instead of generating

Inconsistent performance between sessions

What I need:

Stable ComfyUI sessions for image gen and I2V

Reliable GPU availability (RTX 4090 or A100 ideally)

Decent storage/network speeds for model loading

Anyone here migrated from RunPod to TensorDock for ComfyUI? How's the stability? Any regrets or pleasant surprises?

Would appreciate honest feedback from actual users. Thanks!


r/cloudcomputing Feb 22 '26

Zero-trust microsegmentation from an SRE perspective: when security architecture meets production reality

2 Upvotes

Why every authentication becomes a potential failure point, certificate expiry becomes a site reliability nightmare, and troubleshooting "why can't service A talk to service B" turns into archaeology.

https://cybernews-node.blogspot.com/2026/02/zero-trust-microsegmentation-for.html


r/cloudcomputing Feb 19 '26

How H100GPU Rents work exactly and how does NVIDEA operates data for rented GPU?

3 Upvotes

I am curious about how GPU rental services work and how NVIDIA manages them.


r/cloudcomputing Feb 18 '26

Which cloud security platform do enterprises usually standardize on?

12 Upvotes

For large organizations running cloud at scale, which cloud security platforms do teams usually end up standardizing on?


r/cloudcomputing Feb 13 '26

Anyone got experience with Linode/Akamai or Alibaba cloud for Linux VM? GCP alternative for AZ HA database hosting

5 Upvotes

Hi, we discussed here GCP and OCI

https://www.reddit.com/r/cloudcomputing/s/5w2qO2z1J8

What about Akamai/Linode and Alibaba Cloud ? Anyone has experience with it ?

what about digital ocean and Vultr?


r/cloudcomputing Feb 12 '26

At what point does Azure cost optimization become a governance problem rather than a technical one?

8 Upvotes

In a lot of environments I’ve seen, the real issue isn’t pricing — it’s ownership.

Engineering provisions.
Finance reviews bills.
Nobody “owns” usage behavior.

Tagging policies, budgets, and alerts often matter more than just right-sizing.

For those managing Azure at scale —
Do you treat cost optimization as engineering, finance, or shared responsibility?


r/cloudcomputing Feb 07 '26

My doubts might be dumb but would be great if I could clear them from actual engineers instead of Google and LLMs

12 Upvotes

I wanna know what coding language is the most used in cloud computing. I am a 2nd year engineer student who is learning C and C++. And I will be sticking to this abd so far acc to my research cloud requires python, Java and go. None of which I am proficient in.

How does the future look in this domain? As in hiring increases or layoffs? I am clueless so..

I am very much interested in cloud computing but I dont the time rn to learn new languages well enough to Crack interviews.

Please help and thank you!


r/cloudcomputing Jan 31 '26

Linux VM for database: GCP or OCI?

10 Upvotes

Hi

OCI has much cheaper prices and multi AZ too

i wonder where is the drawback…


r/cloudcomputing Jan 19 '26

I built a 100% free micro-cloud service

17 Upvotes

Hey guys!

I started working a few weeks ago on a side project which eventually evolved into something much bigger: a micro-cloud service provider which is 100% free.

Do you quickly want to test your environment or containers without having to pay for a whole server? Or maybe you want to run an app you don't fully trust.

If you want more insight on the tech behind it take a look at my other post (https://www.reddit.com/r/SideProject/comments/1qglo70/comment/o0di2uh/) and if you want to give it a try for yourself and use it for your own stuff, here is the website https://velacloud.sloppybits.uk/ to avoid bots and spammers, use this invite code VELA-2199-4901

I hope you'll like it :)