Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chousuke
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
25 ms
·
241.
▲
by
chousuke
6y ago
VPNs are commonly used to connect applications to databases living "somewhere else". I don't see any particular reason why wireguard would be a bad choice for that. It's certainly easier to configure than IPsec. Do still
242.
▲
by
chousuke
6y ago
AWS instances usually "randomly fail" because the underlying hardware has issues. I still don't think it's truly random, but the problem is that you don't really get access to any direct indicators that the host is
243.
▲
by
chousuke
6y ago
"cattle vs. pets" misses some important nuance though, especially the way it's usually used to emphasize how you need to architect systems in a cloud environment that way because you have no way of fixing some issues. What
244.
▲
by
chousuke
6y ago
Likely they just had no need for it themselves. Might be that they didn't prioritize having a feature over the risk of someone taking over their hypervisors thanks to a buggy serial port emulator. Pretty much all hypervisors support se
245.
▲
by
chousuke
6y ago
basic loops certainly don't go wrong all that often, but once you get to more difficult requirements, the iterator abstraction really helps. Maybe you need to iterate over two differently sized datastructures in lockstep, or over a com
246.
▲
by
chousuke
6y ago
I dunno. One could say that C string handling is "simple" (it's just byte buffers!) or that manual loops are "simpler" than proper iterator abstractions, but those are both constructs that are hideously error-prone
247.
▲
by
chousuke
6y ago
Most times "calling out" someone in a way that's effective takes effort. I think they're just giving the majority of people an excuse not to bother engaging in any activism that might actually work.
248.
▲
by
chousuke
6y ago
My rule of thumb to avoid these issues is that application/server data gets its own dedicated volume that contains nothing else: logs get their own volume, and root its own. It's an especially bad idea for an application to put
249.
▲
by
chousuke
6y ago
What servers usually run as root? Some may start as root, but usually drop privileges for the actual server processes quickly, eg. apache, nginx, sshd. Nothing that actually does the "serving" or accesses data should be running as
250.
▲
by
chousuke
6y ago
I'm wary of making assumptions about "natural" differences between males and females, since it's easy to confuse them with cultural stereotypes, ie. what you've learned to think of as "normal" vs. what act
251.
▲
by
chousuke
6y ago
Intuitively, it makes sense for something like this to be possible, though I wonder what the trigger is. Drastic change in hormonal balance caused by the transitioning process activating / connecting parts of the brain that were "
252.
▲
by
chousuke
6y ago
I chose to use bitwarden_rs because the official server is huge , and deploying it seemed like a massive pain. Before installing the rust version I actually went through the code to check that it wasn't doing anything untoward; it was
253.
▲
by
chousuke
6y ago
The only thing you have to trust on a BitWarden server is the Javascript client that it serves you, and using that is entirely optional as you can just use other clients. The server could be explicitly malicious and still safe to use. bitwa
254.
▲
by
chousuke
6y ago
All of the sr.ht software is packaged for Alpine, so you can just install and configure them in your Docker container, the same way you would install and configure them in a VM. There's no push-button magic for it, presumably because S
255.
▲
by
chousuke
6y ago
Out of curiosity, what sorts of issues are you having? I don't have much experience specifically with Ubuntu on bare metal, but I find kickstart easier to understand and use compared to preseed, for consistent bare-metal installations.
256.
▲
by
chousuke
6y ago
There's no "Wayland" that could implement a generic way of handling input. Wayland is an extensible set of protocols with several implementations. Handling input is an integral part of what a compositor does, and it's
257.
▲
by
chousuke
6y ago
ibus works with Gnome out-of-the-box. On sway/wlroots, you will have more luck with fcitx. I don't know which tool works best with KDE.
258.
▲
by
chousuke
6y ago
It exists for Wayland: it's called wlroots. Unfortunately, wlroots is only used by everyone except Gnome and KDE, who seem to prefer to do their own thing.
259.
▲
by
chousuke
6y ago
It's a theoretical problem. The window-management parts of sway are tiny and having them in the same process means you don't have to do IPC every time your windows do something. That simplicity means it's easier to write code
260.
▲
by
chousuke
6y ago
That's not a very useful definition. What is it, then, that biologists are interested in? If you answer "life", your definition is circular and without informative value.
261.
▲
by
chousuke
6y ago
The problem is not the editor, it's the human typing on the keyboard that sees , and thinks "that'll do". Using an obscure dedicated character is not going to happen.
262.
▲
by
chousuke
6y ago
> I've had people say "I installed postgres - here's the password". Then... I can't log in. Because I can't switch to the postgres user. You don't need to switch to the postgres user if you have another
263.
▲
by
chousuke
6y ago
This "simple" approach will also lead to all kinds of problems quite quickly once you grow past one concurrent user. If you really must use JSON, at least use SQLite in place of open().
264.
▲
by
chousuke
6y ago
I'm just not sure how it's confusing? PostgreSQL users aren't "tied" to system accounts either. You can have any number of PostgreSQL users that have no system equivalent. In fact, the process seems to be exactly th
265.
▲
by
chousuke
6y ago
With MySQL, you'll still have to switch to root to connect by default? I honestly don't remember, since it's been ages since I set up MySQL manually. If MySQL actually allows administrative access out-of-the-box without any k
266.
▲
by
chousuke
6y ago
In streaming (physical) replication, PostgreSQL sends the WAL only, and it's applied on the replica; no "sending of queries" is involved, or even possible; with physical replication, the secondary has to keep itself identical
267.
▲
by
chousuke
6y ago
Being used to PostgreSQL, this one actually bit me once during a production upgrade. A database migration failed due to a Galera transaction size limit that I unfortunately hadn't caught testing the migrations on a single database, and
268.
▲
by
chousuke
6y ago
A daemon that's listening on a socket is not "running permanently". It'll consume approximately no resources until the kernel wakes it up. Having a separate daemon also saves you from having to grant the other daemons cr
269.
▲
by
chousuke
6y ago
But it does help; in most cases, it requires no effort whatsoever, in contrast to using something like SSH certificates which may not even be possible, depending on the environment. There's no such thing as perfect security, but that d
270.
▲
by
chousuke
6y ago
On Linux, you can harden a bit against memory dumping by disabling ptrace. Set the "kernel.yama.ptrace_scope" sysctl to 3 and the easiest attack will no longer work, if you have processes that don't explicitly request disallo
More ›