5 ms·
That feels so wrong to me: 1st to install node, an arbitrary script is downloaded and executed without having a look into it. Could do anything with the system
by micw 2y ago
That feels so wrong to me:
1st to install node, an arbitrary script is downloaded and executed without having a look into it. Could do anything with the system.
Then `sudo npm install -g pm2` is called. That means the stuff is installed as root "somewhere" in the system - bypassing debians package management.
Then a "process manager" is installed to start/stop/manage a service - on a system that already has systemd doing the same job.
Is that really the way things should be done? Waiting for the day when the tutorial starts with modifying grub.cfg to directly boot into node.
- wavemode 2y agoFrom the very beginning of the article: > This tutorial is made for beginners ― you only need to be somewhat comfortable with the command line. > It is made as short as possible and avoids using e.g. Docker to keep things simple. Once you feel comfortable with this setup, you should consider using Docker for easier management or automatically deploying from Github with a webhook. Even setting that aside and assuming this tutorial was meant for an experienced engineer, your points still feel like nitpicks without substance. Downloading an "arbitrary script" is not substantially different from downloading an arbitrary executable, which people do anyway. Of course npm packages bypass debian's package management. On the off chance debian's repositories even have the package in question, I certainly wouldn't trust it to be up-to-date. pm2 is a popular process manager with features tailored for node apps. That you personally feel it shouldn't be used over systemd, doesn't mean that using it is "wrong".
- elktown 2y agoDo you inspect your neighbors garage workshop for branch safety standards & best practices? Context and proportionality.