Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aliguori
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
aliguori
8y ago
Hi, I work at AWS and before that on KVM since it was a thing. Restricting /dev/kvm these days doesn't make much sense. The interface is designed to be safe for any user. The fact that we started as a character device and n
2.
▲
by
aliguori
8y ago
Kata Containers is a lot of infrastructure for running containers and it uses QEMU to run the actual VMs. Firecracker just replaces the QEMU part and we're eager to work with folks like the Kata community. I love QEMU, it's an am
3.
▲
by
aliguori
8y ago
Yes, the root volume on i3.metal is exposed as NVMe and is EBS-backed.
4.
▲
by
aliguori
8y ago
Sorry for that. The timeout behavior on earlier kernels is a bit of a pain. There's a lot to love about NVMe and timeouts are not actually part of the NVMe specification itself but rather a Linux driver construct. Unfortunately, earl
5.
▲
by
aliguori
9y ago
Yes, all customer PV instances in EC2 are running in an HVM container and are protected against the guest-to-guest Meltdown vulnerability. As with all virtual and physical machines, patches are necessary to protect against process-to-proces
6.
▲
by
aliguori
9y ago
We're still working the details out upstream but the TL;DR is that the way to address Meltdown with Xen PV is to use nested virtualization so that the outer guest is an HVM or PVH guest.
7.
▲
by
aliguori
9y ago
C5 does not support nested virtualization but i3.metal allows using virtualization technology without nested virtualization. Both i3.metal and c5 use the same underlying Nitro technology.
8.
▲
by
aliguori
9y ago
I tried to cover this in my re:Invent session and walked through how we have been evolving the Nitro System over the last 5 years. Videos and slides will be posted eventually.
9.
▲
by
aliguori
9y ago
Thanks! Would love to hear more about the counters that your interested in. We've exposed more in C5 than in previous instance types and we are trying to make more available over time in a safe way.
10.
▲
by
aliguori
9y ago
It's exactly the same as with the i3.16xlarge instance type. There are eight 1900 GB drives. In an i3.16xlarge, those eight drives are passed through to the instance with PCIe passthrough but for the i3.metal instance, you avoid goin
11.
▲
by
aliguori
9y ago
There is more coming at re:Invent. We have more talks queued up tomorrow on this too.
12.
▲
by
aliguori
9y ago
You can provision these servers just like any other instance. They work just like any other Amazon EC2 instance (same Nitro System platform as C5). Disclaimer: I work at AWS on the team responsible for the Nitro System including EC2 Bare M
13.
▲
by
aliguori
9y ago
> Hopefully Amazon will disclose more details. We will have some more details on how this all works at re:Invent in a couple weeks.
14.
▲
by
aliguori
13y ago
You claim it's objectively bad then only cite subjective things like function, structure, and variable names. That word doesn't mean what you think it means :-)
15.
▲
by
aliguori
13y ago
Technically that was breaking out of QEMU. It was not KVM specific. If you break into QEMU, you should be a non-privileged user. If you are using libvirt, you are in a cgroup based jail (basically a container) with SELinux being enforced
16.
▲
by
aliguori
13y ago
IBM uses a test called IPAT for hiring. It's more of an IQ test than personality.
17.
▲
by
aliguori
13y ago
Maybe if you work down town but a lot of tech companies are in north Austin where housing is very cheap.
18.
▲
by
aliguori
13y ago
These are all good points and I agree for the most part. However, I have found that a lot of the benefits of virtualization are often lost because of the flexibility of having a full blown Linux OS. People stick too many services on the ho
19.
▲
by
aliguori
13y ago
Michael Hines has done a fantastic job getting this series merged. It's a rather invasive change and I am amazed at how quickly it was merged.
20.
▲
by
aliguori
13y ago
I don't think you understand the problem. The problem is that the PRNG has a weak default entropy source. The same problem existed in the kernel for ages. See http://www.factorable.net The real advice here ought to be tha
21.
▲
by
aliguori
13y ago
This analysis of steal time is not entirely correct. Steal time exists to fix a problem. When a hypervisor needs to pre-empt a running guest, without steal time, when the hypervisor eventually resumes that guest, as far as the guest can
22.
▲
by
aliguori
13y ago
> Workload Manager (WLM) [1] has been a part of IBM z/OS since before it was even called z/OS. WLM implemented something like cgroups scheduling, in that existing utilization samples feed into future scheduling to ensure respon
23.
▲
by
aliguori
13y ago
Hi David, > Mature containers have been around since the the days of mainframes. Citation needed. I'd go as far as to say that there is no such thing as a mature container technology. The fundamental problem of containers is that m
24.
▲
by
aliguori
13y ago
This is not about privacy, it's about self incrimination which is far, far more important. You can be compelled to testify under oath for many reasons none of which involve doing anything wrong. When you testify under oath, you must answer
25.
▲
by
aliguori
14y ago
http://www.slideshare.net/openstackindia/openstack-at-paypal... Has more details. Looks like it's KVM.
26.
▲
by
aliguori
14y ago
There's a feminist belief that all forms of "pornography" are inherently discriminatory toward women with pornography being a very broad concept--basically any form of sexuality not associated with love. See http://en.wikipedia.org/wiki/G
27.
▲
by
aliguori
14y ago
This is ultimately about scalability. To achieve this kind of IOP rate, you need to be able to scale very large guests very well. KVM has always been exceptionally good at this and QEMU was really the bottle neck. We've now overcome this
28.
▲
by
aliguori
14y ago
"Again, I hadn't lived there or worked there since 2003, but I did own part of a business that was headquartered in MA, and the state was using this fact to harass me for income tax money." If you own a business headquarted in MA, aren't yo
29.
▲
by
aliguori
14y ago
Yes, you can over-subscribe RAM either through ballooning or just by over-subscribing the host. Both KVM and Xen use QEMU for their device models so the machine they emulate is very similar (at least in HVM mode). Xen and KVM use different
30.
▲
by
aliguori
14y ago
There seems to be a pretty fatal flaw in MessagePack that doesn't exist in [BCD]ER. MessagePack doesn't explicitly represent strings and only provides a binary data type. Besides not being able to distinguish between a true binary blob and
More ›