Tuesday, July 28, 2026

Android app policy violation triggered by old testing tracks - Blank release fix

We have multiple tracks in google play console for one of our Android apps. Currently we don't need all of them, we need only the production track. But unfortunately, google does not provide a way to delete unwanted tracks. Also, even releases in paused tracks can trigger "policy violation" of having app releases targeting older target SDK values - we need to update every year to the latest target SDK.

Asking Gemini via aistudio.google.com about this, it suggested a "Blank Release" method - create a new release, but don't upload any aab/apk file. We can do this for each of the testing tracks which we don't need. That would make the older releases "Inactive" and prevent the "policy violation" for old releases.

I've done this yesterday for one of our apps, and it seems to be working. The changes were approved after review in just an hour or less. The policy violation popup did not go away yesterday even after the changes were approved, but today I see that the policy violation popup is replaced with "Policy status - No policy issues found" in the "Monitor and improve" tab.

While we can upload the latest release to all of the tracks, and use the "Add from library" method for each track instead of uploading, the "Blank release" strategy above avoids that busy-work, hopefully permanently.

Saturday, July 25, 2026

slightly more user-friendly mass mailing script

Prompted Gemini via aistudio.google.com to make the mass-mailer using Google Apps Scripts a bit more user-friendly - displaying a checklist of actions to be performed for sending the emails, and picking up the rich-text html from a draft email instead of needing to write out the html by hand. Creating a custom menu and displaying a sidebar UI are done by these functions, using this html.

The Draft email with subject MassMailTemplate must not be deleted, it must remain available throughout the run of the script. The body of the email is taken from this Draft.

Inline images inside the draft will be sent as attachments, and it is better to avoid attachments to prevent our mails from being marked as spam. Formatted text is fine.

The Checklist in the Mass Mailer menu item is just for display, unchecking all the items can be done manually before the next send.

disk space alert and cleanup of MySQL databases with Moodle logs

We got an alert from our script that one of our servers had 95% utilization of the root disk. Asked Gemini via aistudio.google.com and carried out the following.

Find the Top 20 largest directories on the root partition:

sudo du -ahx / | sort -rh | head -20

Note: The `-x` flag ensures it only searches the root partition and doesn't scan external mounts or network drives.

Found that 29 GB was being used by MySQL databases.

Find individual files larger than 100MB:

sudo find / -xdev -type f -size +100M -exec ls -lh {} \;

Found that there were some .ibd files, with the names of Moodle table  like logstore_standard_log.ibd which were very large. Gemini suggested retaining only 180 or 365 days of logs instead of "Never delete logs" in Site administration > Plugins > Logging > Standard log.

Then, to get back space ...

First, logged on as the administrator of a particular database which we do not need, and dropped that database.
mysql -u thatusername -p
drop database unuseddbname

(sudo mysql does not work on this server, a root password is set, but I did not need the root password.)

That gave us 3-5 GB. Then, there were two options for Moodle logstore_standard_log - either just truncate the table - very quick, get back disk space instantly - or copy over the last 180 days' logs to a new table and then delete the old table.

(Other methods suggested by Gemini were very slow, mentioning only the good options below. Just deleting entries from a table would require an OPTIMIZE TABLE step afterwards, which would need enough disk space to create a full copy of the table.)

CREATE TABLE prefix_logstore_standard_log_new LIKE prefix_logstore_standard_log;

# find starting id to reduce copy time, since id is an indexed field
SELECT id FROM prefix_logstore_standard_log 
WHERE timecreated >= UNIX_TIMESTAMP(DATE_SUB(NOW(), INTERVAL 180 DAY)) 
LIMIT 1;

INSERT INTO prefix_logstore_standard_log_new 
SELECT * FROM prefix_logstore_standard_log 
WHERE id >= YOUR_NUMBER_FROM_ABOVE_STEP;

The copying of log entries into the new table took 51 seconds using this method for our smallest db.

The quick and dirty way, of deleting all the logstore standard log entries (this is only the "what has the user clicked" data - grades etc are not deleted) -
TRUNCATE TABLE prefix_logstore_standard_log; 

This completes in less than a second, and makes disk space available immediately.

Thursday, July 23, 2026

Azure portal - Review Azure Copilot agent access settings before 1 August

There was an email from Microsoft, letting us know that if we don't take action, we will be opted in for enabling Azure Copilot agents. In general, my instinct is to disable every new "feature' which Microsoft introduces, because sooner or later, that will be involved in some security incident. After consulting the other admins, I disabled "Azure Copilot" on both Azure tenants I have admin access to, with the result that these agents

Observability Agent
Deployment Agent
Troubleshooting Agent
Optimization Agent
Resiliency Agent
Migration Agent

will not be available.

When we navigate to Azure Copilot Admin Center (which we can access via the search at the top of portal.azure.com after logging in) to disable Azure Copilot, there is a link to toggle the control for <User> can manage access to all Azure subscriptions and management groups in this tenant. Since they recommend turning this off, I turned it on, disabled Copilot and turned it back on. The link to this control is https://portal.azure.com/#view/Microsoft_AAD_IAM/TenantProperties.ReactView

The documentation referencing this is at

Wednesday, July 22, 2026

Creating service account for accessing Google Drive API

There was a request from the developers to create a shared drive for them in our Google Workspace, and to create a service account to access it programmatically.

Accordingly, created a new shared drive (and have added email1 and email2 as managers)

I have created the service account under an existing google cloud project under my (admin) google account (initially created for rclone), and have added Google Drive Api to the project.

The service account is called 
servaccname@projectname.iam.gserviceaccount.com

I have added this account also as a Content Manager on the Shared drive and shared the json key with the dev team.

Shared Drive storage quota - According to google help, a single shared drive can theoretically hold up to 5 TB per file, but it is strictly capped at 500,000 total items (files, folders, and shortcuts). 


I've currently not put any other cap on the storage quota for this shared drive.

Tuesday, July 14, 2026

Manage your unused OAuth clients - Google cloud

We got emails from Google cloud, "the following projects that you manage have OAuth clients that have been inactive for at least 5 months, and will be deleted in 30 days unless you take action" - checked, and we're planning on allowing them to be deleted, since those seemed to be clients which are not currently in use.

Friday, July 10, 2026

Google apps script issue - script.google.com refused to connect - google glitch

One of our servers which had a google apps script embedded in a php page started showing "script.google.com refused to connect" - the issue was noticed last afternoon. We checked that no changes had been made to the script, we did have
.setXFrameOptionsMode(HtmlService.XFrameOptionsMode.ALLOWALL);
as mentioned in

The only other change was to install and set up fail2ban on the server, that was unlikely to be the cause. 

"If no changes have been made to the script, then perhaps it is a transient google problem, and might be resolved in a few hours.

If not, we would need to check if google apps scripts have any recent policy changes."

It might have been a google glitch, since last night the issue was resolved by itself. Looked like the outage was for around 8-10 hours.

Tuesday, July 07, 2026

reminder to take a break - Mac version

I wanted to recreate the earlier "reminder to take a break" cron job script on MacOS. Asked Claude about it, and it suggested using launchd instead of cron, since cron jobs run without access to the display by default. After several rounds of trial and error, here is the method that worked.

nano ~/Library/LaunchAgents/com.yourname.walkreminder.plist

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>
    <string>com.yourname.walkreminder</string>

    <key>ProgramArguments</key>
    <array>
        <string>/bin/bash</string>
        <string>-c</string>
        <string>osascript -e 'display notification "Time to take a walk" with title "Reminder" sound name "Ping"'; afplay /Users/yourusername/Sounds/Walk.mp3</string>
    </array>

    <key>StartCalendarInterval</key>
    <array>
        <dict>
            <key>Hour</key>
            <integer>14</integer>
            <key>Minute</key>
            <integer>0</integer>
        </dict>
    </array>

    <key>StandardOutPath</key>
    <string>/tmp/walkreminder.log</string>
    <key>StandardErrorPath</key>
    <string>/tmp/walkreminder.err</string>
</dict>
</plist>

In the above, the schedule is to run once a day at 14:00 hours. For running every half an hour from the time the user was logged on, we can use 

<key>StartInterval</key>
  <integer>1800</integer>

instead of <key>StartCalendarInterval</key>

Or, in my case, since I wanted every half an hour aligned to 0:00 and 0:30 exactly, 

 <key>StartCalendarInterval</key>
    <array>
        <dict>
            <key>Minute</key>
            <integer>0</integer>
        </dict> 
        <dict>
            <key>Minute</key>
            <integer>30</integer>
        </dict>
    </array>

We had to use a Sounds directory which we had created, since afplay could not access the Downloads directory when run from launchd.

launchctl bootstrap gui/$(id -u) ~/Library/LaunchAgents/com.yourname.walkreminder.plist

and test with

launchctl kickstart -k gui/$(id -u)/com.yourname.walkreminder

Troubleshooting can be done with
plutil -lint ~/Library/LaunchAgents/com.yourname.walkreminder.plist
launchctl list | grep walkreminder
cat /tmp/walkreminder.err