4 ms·
> but I have memories of trying to compile programs and having to dive into the source and make changes with the blind confidence only a teenager could have. T
by seppel 6y ago
> but I have memories of trying to compile programs and having to dive into the source and make changes with the blind confidence only a teenager could have.
That is an awesome sentence. I sometimes miss this blind confidence I had as a teenager.
- mleonhard 6y agoSome months ago, something snapped and I decided to finally let myself start working on the impossible projects that I have dreamed about for a while. I got back that feeling I had as a teenager, of coding without any ideas of the limits of my own abilities. Specifically, I want to make some devops tools that I need and don't exist yet: - A simple HTTP file server that uses mutual-TLS for auth and all configuration comes from a single TOML file. Passwords are poisonous to security. Stateful config APIs are poisonous to maintainability. - A lightweight Dockerd replacement that uses mutual-TLS for auth, fetches binaries from the file server, actually verifies the SHA-256 digest of binaries (dockerd doesn't), and receives all configuration by HTTP PUT of a single config.toml file. It will store VM stdout logs locally and make them available via mutual-TLS HTTP. - A metrics server that fetches logs via mutual-TLS HTTP, stores them in the file server, parses them (as JSON), calculates metrics and alarm states, caches derived data on the file server, serves a dashboard, re-exports specific metrics and alarm states, and notifies third-party services (Pagerduty/Opsgenie) on alarm state changes. All config comes from a single config.toml file. - A simple monitoring daemon that performs repeated website and API requests and emits metrics to logs. These get picked up by the metrics server. - An infrastructure management tool without the problems of Terraform. Specifically, it must support creating resources which contain other resources. And it shouldn't require the maintenance nightmare of multi-stage Terraform deployments. I started writing this stuff in Golang. But I quickly became frustrated with Golang's incomplete libraries. There are stupid things missing like min(int,int) and basic synchronization structs (WaitableBool). Golang's http library doesn't support dynamic server-side request timeouts or mutual-TLS. I guess they want you to run Golang servers behind nginx or expensive Google Cloud load balancers, probably on Kubernetes. No thanks. I learned Rust and started writing the tools above. I fell in love with forbid(unsafe). All of Rust's HTTP server libraries contain copious amounts of unsafe code. And none support mutual-TLS. So I started writing a safe Rust HTTP client & server library. Half-way through, I realized how much unsafe code is in tokio & async-std. So I wrote and released a small safe Rust async runtime, called "safina". Amazingly, it works. I resumed working on the HTTP library, adding TLS support. Then I realized that rustls has a lot of unsafe Rust/C/assembly code. So I started writing a safe Rust TLS 1.3 library. Now I'm deep into that project. It's satisfying. I wish you will forget your limitations and try new things without reservation.
- waltwalther 6y agoI love this comment. I love how one project can/often does lead to other sub projects that can all have their own sub projects. In the end it all comes together...and in my case I usually look back on days/weeks/months of work and am impressed with what I learned along the way. I also love the feeling that comes along with it.
- acct776 6y ago> I guess they want you to run Golang servers behind nginx or expensive Google Cloud load balancers, probably on Kubernetes. If you're using shared hosting, or your data has any value, why would you use anything besides a reverse proxy/Wireguard to access your hosted application server?
- sneak 6y agoIt can be yours again if you dedicate an additional SSD to holding a bunch of variously-snapshotted VM images. Wanna double click that risky .exe from a torrent? Linked clone that base Windows install.