Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
adtac
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
adtac
2y ago
Not in the very short term, but we've talked about it internally and we might do it in the future! If you'd like to use Subtrace on Windows, it would be super helpful to understand your use-case deeply so that we build the right t
32.
▲
by
adtac
2y ago
Flat pricing with unlimited requests hosted in the cloud ( https://subtrace.dev/pricing ). We also have an on-prem version of Subtrace for enterprises. It runs in their own AWS account without ever talking to subtrace.dev so
33.
▲
by
adtac
2y ago
What would you like to see? One of things we're thinking about is automatic method/function call tracing. Something like attaching the entire stack trace of calls done to handle the API request. Ideally using the same UI so that y
34.
▲
by
adtac
2y ago
One of my litmus tests for software is "can I use it on a flight?", so you'll be pleased to know Subtrace works great locally without ever talking to subtrace.dev! subtrace run -devtools=/subtrace -- python3 -m htt
35.
▲
by
adtac
2y ago
re self-hosting: yep! Use the -devtools flag to get a stripped down version of Subtrace running entirely locally: subtrace run -devtools=/subtrace -- python3 -m http.server This starts a Python server on localhost:8000 but wit
36.
▲
by
adtac
2y ago
in a different context, maybe: https://news.ycombinator.com/item?id=38044786 :)
37.
▲
by
adtac
2y ago
You can use Subtrace entirely locally without talking to subtrace.dev using the -devtools flag. For example: subtrace run -devtools=/subtrace -- python3 -m http.server Then go to http://localhost:8000/subtrace
38.
▲
by
adtac
2y ago
Thanks! re the Wireshark analogy: the reason I used that was because: (1) Subtrace operates at roughly the same level in the operating system stack, (2) has similar capabilities, (3) has an overlap in use-cases, and (4) has been the most ef
39.
▲
by
adtac
2y ago
You can tag each request with arbitrary key-value maps and search over these later. For example, if you add a `x-subtrace-tags: user=foo, project=bar` header on the response, you can apply a `tags.user == "foo"` filter in the dash
40.
▲
by
adtac
2y ago
> use subtrace in an ephemeral pod for debugging purposes That's a great suggestion. It'd be like kubectl exec-ing into a shell inside the pod, but for network activity. I think I'm going to prototype this tonight :) >
41.
▲
by
adtac
2y ago
httptap is really cool! Their technique is different (they do a filesystem mount instead of intercepting syscalls like Subtrace does) but both tools effectively reach the same goal using different routes.
42.
▲
by
adtac
2y ago
That's totally fair, I can see why Wireshark wouldn't be the most accurate description to someone working on those kinds of problems. And fwiw, I wish my problems (before Subtrace) were cool enough to need to whip out Wireshark fo
43.
▲
by
adtac
2y ago
Subtrace already works great on Kubernetes ( https://docs.subtrace.dev/kubernetes )! Add a single line to your image's Dockerfile and that's it. I'm working on an even simpler way where you can just `kubectl ap
44.
▲
by
adtac
2y ago
Yep, certificate pinning is the one scenario Subtrace can't handle in my experience, but thankfully, it's fairly rare like you said. And IMO there is no general solution to the problem [1], but it's one of those very interest
45.
▲
by
adtac
2y ago
For now, yes :) Since we operate at the TCP level, we can actually handle pretty much any protocol. I have an implementation of a postgres handler in my git stash that intercepts and shows the SQL queries executed + the resulting rows along
46.
▲
by
adtac
2y ago
Subtrace proxies the program's connection using a regular TLS connection to the upstream server. For example, if you do `subtrace run -- curl https://example.com `, curl thinks it's talking to example.com over TLS, but
47.
▲
by
adtac
2y ago
standards ftw!
48.
▲
by
adtac
2y ago
More than 0.01 ms, less than 0.10 ms. Noticeable when you're a high frequency trading firm, probably not otherwise :) In the hot path, Subtrace is just a dumb proxy that copies bytes. All of the processing + indexing happens offline in
49.
▲
by
adtac
2y ago
Yes, but we've managed to do it automatically without any library/language specific hooks! It's probably one of my favourite things in Subtrace :) We generate an ephemeral TLS root CA certificate and inject it into the system
50.
▲
Show HN: Subtrace – Wireshark for Docker Containers
(github.com)
369 points
by
adtac
2y ago
|
73 comments
51.
▲
by
adtac
2y ago
If I do, whether or not I remember my comment, I'll certainly remember yours :(
52.
▲
by
adtac
2y ago
I know that the US government is more complex than twitter lol. I just think it's stupid to automatically invalidate an idea because it was tried in a less complex system.
53.
▲
by
adtac
2y ago
All key personnel were immigrants? Why did the others come back? Also, since the H1B were key to operations and therefore smart, couldn't at least some of them have found a new employer? 61% of the H1B population switched jobs that y
54.
▲
by
adtac
2y ago
Yes, so it's a good thing the first step is: > [Step 1] Question every requirement. Each should come with the name of the person who made it. You should never accept that a requirement came from a department, such as from "the
55.
▲
by
adtac
2y ago
> Had they decided to move on Why didn't they?
56.
▲
by
adtac
2y ago
People should read Elon Musk by Walter Issacson. Here's an excerpt from the chapter on his "algorithm": > [Step 2] Delete any part or process you can. You may have to add them back later. In fact, if you do not end up ad
57.
▲
by
adtac
2y ago
>from untrusted sources if you can't trust your own backend, step one is reevaluating your life choices
58.
▲
by
adtac
2y ago
IMO there's no general solution to the HTTPS part that will work for all kinds of programs and the long tail of certificate pinning implementations. As a proof by counterexample, imagine malware that uses TLS for communication and goes
59.
▲
by
adtac
2y ago
How would hooking on write(2) solve TLS? You'll be able to read and modify the ciphertext, but the process will never call write(2) with the plaintext bytes, so you can't actually read the HTTP request. You'll just see the en
60.
▲
by
adtac
2y ago
Thanks! Subtrace uses BPF, not eBPF :) I think eBPF could be made to work with the same approach, but there's a few differences: - eBPF requires root privileges or at least CAP_BPF. Subtrace uses seccomp_unotify [1], so it works even i
More ›