Release Review
(29.07 - 18.08)
Infrastructure Team
ChainDrop attack
- Problem: On August 4th, Microsoft published information about a new supply chain attack targeting NPM.
- Solution: We scanned all repositories for infected libraries, conducted a security review, and, with Frontend Infrastructure, added extra checks.
- Effect: Within 24 hours, we were back to normal operations without long, expensive follow-ups.

Bot attack
- Problem: LLM bots from China crawled our site, creating unnecessary load and problematic requests.
- Solution: We identified the traffic source and took countermeasures using Cloudflare.
- Effect: In the last 12 hours, we blocked ~350k requests. We will introduce more rules to stop future crawling before it happens.
Bot attack
- Problem: LLM bots from China crawled our site, creating unnecessary load and problematic requests.
- Solution: We identified the traffic source and took countermeasures using Cloudflare.
- Effect: In the last 12 hours, we blocked ~350k requests. We will introduce more rules to stop future crawling before it happens.

Sentinels desync
- Problem: Our Sentinels mixed stage and production configurations. Some mastersets were not resilient to downtime.
- Solution: We moved some masterset configurations between Sentinels and filled configuration gaps.
- Effect: No Redis Cluster problem since fix.
Sentinels desync

Sentinels desync

QA environment manager
- Problem: QA deployment has become more complicated as the number of services has grown. We use a Slack channel to reserve machines. People tend to forget to shut machines down, which leads to unnecessary costs.
- Solution: We introduced a centralized place for everyone to manage QA machines. No K8S knowledge required; SSO; web GUI.
- I hope, you will love it.
QA environment manager

QA environment manager

AI based code review
- Problem: Claude Code had problems connecting to Jira for wider context. Automatic code review is a great place to cover more topics.
- Solution:
Jira connectivity fixed
Claude Code uses the Opus model instead of Sonet
Migrations are evaluated for potential database locking to avoid deployment issues
OWASP 10 check
- Effect: The code review covers critical areas that were often overlooked.
Load Test: July Edition
- Problem: We must know the boundaries of our infrastructure. We wanted to measure Monolith performance after migration.
- Solution: We ran five test scenarios with 3x and 5x organic traffic. Including full registration and activation process.
- Effect: We collected metrics and planned next steps to improve load time and scalability.

Support for new services
Problem: New services require new infrastructure.
- Solution: We created or extended infrastructure for:
User Profile Service (CRAIM)
User Content Service (CRAIM)
Smart Modal (CRAIM)
Job Export (User Acquisition)
incident.io
- Problem: Opsgenie, our incident management tool, will reach EOL soon.
- Solution: We integrated incident.io, which offers much more functionality.
- Effect: The first "shifts" are done with incident.io. We can colaborate easier with non-DevOps to solve problems.
Other
- Fixing and hardening the Monolith in K8s
- Fixing and hardening new monitoring and logging tools
- PHP dependency updates for security reasons
- Last executed searches in the base QA database snapshot
- QA environment Cloudflare cache cleanup job in GitLab pipeline
- OpenSearch fixes
- Recruitment (11 technicals + BBQs)
- Team support
Jobleads Releases Review (29.07 - 18.08)
By Piotr Woszczyk
Jobleads Releases Review (29.07 - 18.08)
- 12