Does Google not offer an ability to set monthly budget caps?
I’ve never used Google’s service but I use Azure and one of the first things I do is set a budget on every resource group I create.
I sympathize with the developers and Google can certainly afford to cut them a break, but you should definitely never give any usage-based service a blank check to bill you.
blacknwhitecookie on
”The developers said they did not believe they made any „obvious“ operational mistake.” Yet they didn’t have two factor authentication activated. Might not be the reson this happened but c’mon. It’s standard practice for at least a decade.
SimRacingSensations on
This is exactly why I always set budget caps on cloud services even for development keys. I once had an AWS key leak from a public repo and woke up to 00 in charges before I noticed. Now I have alerts set for any spending over 0/day and budgets on every service. Its extra work but these stories prove its worth it. Also, 2FA should be mandatory for API access by now.
snesericreturns on
Always tie it to a privacy card with a hard spend limit. Then this won’t happen.
toolrules on
gcp ui/ux sucks. no one could find it if it exists
Difficult-Way-9563 on
So basically the future is people selling and buying stolen AI API keys?
Leave A Reply
Du musst angemeldet sein, um einen Kommentar abzugeben.
8 Kommentare
I actually didn’t know if tag it as Artificial Intelligence or Security, so I had to choose the lesser of weevils.
https://www.reddit.com/r/googlecloud/s/QxBSG4VoaL
Does Google not offer an ability to set monthly budget caps?
I’ve never used Google’s service but I use Azure and one of the first things I do is set a budget on every resource group I create.
I sympathize with the developers and Google can certainly afford to cut them a break, but you should definitely never give any usage-based service a blank check to bill you.
”The developers said they did not believe they made any „obvious“ operational mistake.” Yet they didn’t have two factor authentication activated. Might not be the reson this happened but c’mon. It’s standard practice for at least a decade.
This is exactly why I always set budget caps on cloud services even for development keys. I once had an AWS key leak from a public repo and woke up to 00 in charges before I noticed. Now I have alerts set for any spending over 0/day and budgets on every service. Its extra work but these stories prove its worth it. Also, 2FA should be mandatory for API access by now.
Always tie it to a privacy card with a hard spend limit. Then this won’t happen.
gcp ui/ux sucks. no one could find it if it exists
So basically the future is people selling and buying stolen AI API keys?