Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chousuke
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
chousuke
5y ago
While replication can be a key part of your disaster recovery plan, I think it's more often useful for operational HA, allowing you to perform database server maintenance with low (seconds) downtime. Actual real disasters where you nee
92.
▲
by
chousuke
5y ago
Well, for "local" TCP, it's pretty straightforward to see how the kernel can be smart and just copy the sent data into the receiving process' buffer directly and skip ACKs and other overhead if no-one's looking. Nei
93.
▲
by
chousuke
5y ago
If you have PostgreSQL or MySQL on the same machine as your application, you can use UNIX sockets; they won't have much latency at all (I think Linux also optimizes TCP on localhost to skip all the pointless protocol overhead). In term
94.
▲
by
chousuke
5y ago
You need to pick your battles and choose what you want to protect against to mitigate risk and enable day-to-day operations. For example, too often people will set up clustered databases and whatnot because "they need HA" without
95.
▲
by
chousuke
5y ago
Sometimes, you have a component which fails in such a way that your redundancies can't really help. I once had to prepare for a total blackout scenario in a datacenter because there was a fault in the power supply system that required
96.
▲
by
chousuke
5y ago
Well, that depends on what you need to support; even if RHEL7 is the oldest distribution that you need to support, you can still assume you have at least Python 3.6, or python 3.4 for RHEL6 (which is already EOL). There's no obligation
97.
▲
by
chousuke
5y ago
I'd state it as "don't use external dependencies carelessly". It applies to more than just Python. Writing and deploying Python tools is easy if all your dependencies come in distro packages.
98.
▲
by
chousuke
5y ago
You should still use passwords with SSH keys to ensure that they're encrypted on disk. An SSH agent makes the user experience not annoying, so there's no point in opting out of the extra security.
99.
▲
by
chousuke
5y ago
Using different keys for different services is overkill most of the time. Generally you need to have one key per host that you use (or per any storage location). You can use separate keys for separate services is if you for eg. privacy re
100.
▲
by
chousuke
5y ago
I have the same feeling of limitation when using Windows. As someone who's used to Linux and other UNIXy systems, the idea of having and using GUI software on servers is... distasteful to me, to put it mildly. GUI configuration makes
101.
▲
by
chousuke
5y ago
I would say that vi (at least the more modern ones) is user-friendly, but not beginner-friendly . You really do need to start by running vimtutor.
102.
▲
by
chousuke
5y ago
Bah. If a sysadmin woke up from a coma, systemd would be the least of their worries, since it has a comprehensive manual, working backwards compatibility for most standard interfaces, and is in most cases much, much easier to deal with th
103.
▲
by
chousuke
5y ago
But it doesn't work like that. You might reserve 20% of the time to chores, but you don't have to use all of that 20% every week. Efficiency of maintenance will improve after you get your processes and tooling in order and every
104.
▲
by
chousuke
5y ago
I've noticed that I get worse hunger if I eat more often, especially if I just eat bread to postpone the hunger. For some reason, the hunger I feel when on a lower-carb diet is much less pressing, and can be easily ignored for quite
105.
▲
by
chousuke
5y ago
Leaving aside all the other benefits and even if you never need to rebuild your system, having some sort of IaaC automation in place allows for extremely powerful change management . When your system is defined as code[0], change over time
106.
▲
by
chousuke
5y ago
Both are important. A good CMDB is key in finding your documentation that points you at the configuration management used for the actual system. Let me tell you, just a wiki with a search is not enough beyond a certain size, and you hit t
107.
▲
by
chousuke
5y ago
If you already have something that works, by all means, stick with it. If you want to learn Ansible, you don't even have to throw away your scripts; Ansible is a perfectly good way to run ad-hoc scripts if that solves your problem bett
108.
▲
by
chousuke
5y ago
There's no such thing as an oneshot if you're creating a system that someone will actually use and depend on. All systems have a lifecycle, and even on a "trivial" system you have backups, access, monitoring, logging and
109.
▲
by
chousuke
5y ago
Of course; no tool is perfect. But in the general case, they're good enough, and they do help. For example, I manage nodes with Puppet, and Puppet can and will "clean" things like sudoers.d, yum.repos.d, nginx.conf.d etc. of
110.
▲
by
chousuke
5y ago
I do not think automation is "premature optimization", nor do I that think everything needs to be high-quality; I did not say that. I do think, however, that everything you do should be of acceptable quality. And for me, having
111.
▲
by
chousuke
5y ago
Sure, but then again, typing shell commands into text files is assuming you already know shell commands. You have to spend time to learn your tools at some point. For simple configuration management, Ansible is a straight upgrade to most sh
112.
▲
by
chousuke
5y ago
I think it should be noted that even with with encrypted data you'll generally just encrypt the master key with multiple passphrases; one (or more) master keys for admin use and one for the user themselves. There's really very rar
113.
▲
by
chousuke
5y ago
The difference is in the kind of audit trail it leaves. If a sysadmin impersonates a user, that leaves a different kind of trail than a user logging in with their own key that only they can access. In principle, the sysadmin should explicit
114.
▲
by
chousuke
5y ago
Declarative configuration management systems solve this by unchanging your configuration after someone messes with it manually. :) Hard to forget to change the automation when it persistently undoes all your hard labour. You can help solv
115.
▲
by
chousuke
5y ago
I would argue that all deployments (no matter how small) should have configuration management. In the simplest case, a deployment consists of: 1. Install packages 2. Install configuration files, possibly from templates. 3. Configure servi
116.
▲
by
chousuke
5y ago
I get the feeling that many people do not even know what problems databases solve. It seems to be common to treat them as an extension to the application's memory that somehow isn't lost between restarts, and the properties, opera
117.
▲
by
chousuke
5y ago
I think that you can keep systems simple and HA if you forget about multi-master components and design active/passive solutions instead, whose behaviour in failure scenarios is much easier to understand and much less likely to go wro
118.
▲
by
chousuke
5y ago
Nah, you figure it out, then throw it out and rebuild a better alternative. X11 has had too much piled on it already; it needs to go.
119.
▲
by
chousuke
5y ago
I've run Wayland Firefox over waypipe. It's a bit finicky to set up, but fast enough that you can play videos with no trouble.
120.
▲
by
chousuke
5y ago
X11 forwarding essentially does that anyway nowadays. Modern toolkits don't actually use most of X11 because it's inefficient and unnecessary with the hardware we have.
More ›