Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chousuke
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
151.
▲
by
chousuke
5y ago
If I could I would instantly replace every L2L IPsec tunnel configured everywhere I have access, but unfortunately until Cisco, Juniper, Fortigate etc. implement Wireguard, IPsec remains the only option. I am already using it for production
152.
▲
by
chousuke
5y ago
Overkill? Git is not overkill for a single file . If it's text and you edit it, use git.
153.
▲
by
chousuke
5y ago
diff and patch feel like tools that have existed forever. I feels weird to think that someone wrote them instead of them just manifesting fully formed with the first version of UNIX.
154.
▲
by
chousuke
5y ago
SQL is great for querying (and steampipe exists just for that reason), but the point of Terraform is to be a desired state configuration system; SQL updates would remove its best feature. You could use the database as the desired state, but
155.
▲
by
chousuke
5y ago
I feel the same way. Default setting should be secure, unsurprising and suitable for at least small-time production, and good software further guides the user to use it such that they aren't likely to shoot themselves in the foot. Unfo
156.
▲
by
chousuke
5y ago
To my understanding, you can use existing Linux kernel facilities like seccomp to build equivalents for pledge and unveil. The latter are less flexible but also easier to use, which is a point in their favour; ease of use matters for secu
157.
▲
by
chousuke
5y ago
I suspect it's the bait-and-switch approach that annoys people. Podman (and RHEL, through community rebuilds) is free to use even for enterprises; you don't pay for the software itself, you pay for support.
158.
▲
by
chousuke
5y ago
I have the UEFI/boot partition followed by an LVM PV. If it's a VM, data disks just get the whole disk, though I still usually set up LVM because it enables stuff like live storage migrations. I've actually had to do those mo
159.
▲
by
chousuke
5y ago
Ansible is sort of bad at everything, and does a few things decently. I use it as an orchestrator / clusterssh replacement, but for configuration management it makes me nervous because I can't trust it to just not break for stupid
160.
▲
by
chousuke
5y ago
The thing about Jira is that it provides much more than just tickets. It's really not even bad at what it does as far as user workflows go, it's just really easy to misconfigure due to lackluster administrative tooling. I work w
161.
▲
by
chousuke
5y ago
Terraform is a massive improvement over Ansible if you do anything non-trivial; even if it sucks, it sucks significantly less than Ansible at managing infrastructure resources. I sometimes fool myself into thinking I can use Ansible in si
162.
▲
by
chousuke
5y ago
I'm not sure what the tradeoff is. You can give a user access to rootless containers or you can give them root access to run containers. User namespaces are at least attempting to improve on the Docker situation where access to the Doc
163.
▲
by
chousuke
5y ago
In my experience it's more likely the entry-level person who will write overly complicated code (or create such systems in general); they haven't yet learned how to identify potential approaches and to choose the most suitable one
164.
▲
by
chousuke
5y ago
I think the best use in studying patterns and approaches is thinking about where they are applicable and where they aren't and reflecting that on what you've done. You can't really use architectural patterns as shortcuts be
165.
▲
by
chousuke
5y ago
Cursive makes sense of you're a writer and still for some reason write your drafts by hand. The final result will get printed anyway. Otherwise, it's rather useless as anything but an art form; modern pens don't benefit from
166.
▲
by
chousuke
5y ago
You need ownership tracking even in languages with GC because you will be dealing with resources that are more than just memory, and with those GC isn't really enough. A GC alone doesn't really help you deal with concurrent access
167.
▲
by
chousuke
5y ago
In my view it's very pragmatic to leave dealing with ownership to the compiler. It's something that you have to deal with in any language (even if you have a GC) if you want to write correct code, but it's not something mos
168.
▲
by
chousuke
5y ago
Ansible and Puppet are tools that do very different things. I mostly agree with you, but Ansible does work decently as an orchestrator . You want to use tools like Puppet and Terraform to define the state of your systems, and Ansible to ru
169.
▲
by
chousuke
5y ago
My first experience with Ruby was writing rspec tests and chef recipes, and I can't say I was very happy when I had to debug that code. It's given me a deep aversion towards any Ruby DSL that still persist. I will work with Ruby i
170.
▲
by
chousuke
5y ago
I feel like there should be a distinction between full-blown ORMs and just query builders. I dislike ORMs that hide database operations from the application code by pretending that in-memory application objects are in concept interchangeabl
171.
▲
by
chousuke
5y ago
I often hear mentions of "no schema" when people talk about NoSQL, but I think that's a lie; it's not possible for data to have no schema because an application that assumes its data has no structure can't do anyt
172.
▲
by
chousuke
5y ago
I don't think you even need to learn how to make truly fast systems right out of the box. Just learn how not to make mind-bogglingly slow ones. There's a lot of low-hanging fruit when it comes to performance and quite often it
173.
▲
by
chousuke
5y ago
That's kind of the problem. The database absolutely should get in your way if you try to put nonsense data in it. For the kinds of uses SQLite sees, the loose approach to data integrity may not have caused much grief, but I can't
174.
▲
by
chousuke
5y ago
SSH certificates are a good solution, though I think you could still use longer-lived SSH identities as part of the authentication process to the system that signs your certificate with MFA on top. I personally really just don't like
175.
▲
by
chousuke
5y ago
As a developer, you should want as little power on as few servers as needed to do your work. With the unlimited access to do whatever you want, you also get lots of responsibility, which means you need to develop your security-consciousne
176.
▲
by
chousuke
5y ago
Living in Europe, I genuinely had no idea cards with magnetic stripes were still in use. I thought everything used chips nowadays. I still prefer my card for contactless payments though; using my phone is not really much more convenient sin
177.
▲
by
chousuke
5y ago
Personally, I like merge commits. I often merge feature branches even if I could do a fast-forward, because the merge commit explicitly documents the set of patches that made up a feature. The question isn't really about merge vs. reba
178.
▲
by
chousuke
5y ago
Realistically, a single commit is not going to contain hundreds of thousands of lines of changes unless they're generated code or something. I'm not advocating that you should merge branches by squashing all commits into one lump;
179.
▲
by
chousuke
5y ago
Rebase is not only useful, but necessary for a distributed VCS to be useful. To be precise, you need to be able to create new commits from old ones using the VCS itself, and if you can do that, you can also rebase. One of the major reas
180.
▲
by
chousuke
5y ago
mosh has very good latency hiding and your connection can actually be interrupted for longer than a TCP session would tolerate. The latency hiding alone makes it worth it; SSH is miserable over links with any lag, mosh feels as responsive a
More ›