Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dave_universetf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
dave_universetf
6y ago
Also, we run on platforms like iOS, where we have very severe memory constraints (the NetworkExtension is allowed 15MiB of total RAM). Given that we juggle a lot of IP-related data types, even modest optimizations help. That said, I'd
62.
▲
by
dave_universetf
6y ago
Oh no, that's another shorthand that's different from all the others. A single number should be interpreted as a big-endian uint32, and so "1" should be "0.0.0.1". However, I can confirm that `ip` interprets it
63.
▲
by
dave_universetf
6y ago
It wasn't, but I'm glad to have plausible deniability :) I fixed the typo.
64.
▲
by
dave_universetf
6y ago
I can help here: these definitely aren't cursed, because curses aren't real. I was exagerating for comic effect, because this was just a twitter rant that got out of control :) That said, many of those representations no longer ma
65.
▲
by
dave_universetf
6y ago
My counter to that is that people mostly don't roll their own, so the defaults matter. Adding more implementations just increases the total amount of complexity going on. That probably argues for "Deployment shouldn't have be
66.
▲
by
dave_universetf
6y ago
Sound advice. Sadly, the industry is by and large ignoring it, and the median k8s cluster size is single digits. There are a few elephants who run thousands of nodes, and at that scale the benefits outweigh the complexity tax. But a huge ch
67.
▲
by
dave_universetf
6y ago
Pretty OT, but: I know of many large providers using MetalLB as a core part of their k8s infrastructure, who gave nothing back. If walking away punishes them for that, then I'm very pleased :) MetalLB is in a healthier place now than w
68.
▲
by
dave_universetf
6y ago
I very much didn't think through it, and opened with exactly that disclaimer :). You're right that the lofty ideas probably won't survive contact with reality. In my defense, I wrote this in a couple of hours to get it out of
69.
▲
by
dave_universetf
6y ago
Author here. If I had to run Kubernetes for money-making purposes, I would still seriously consider GKE. I still think they're the best at running k8s. It's just that k8s limits what any operator can hope for.
70.
▲
by
dave_universetf
6y ago
"it depends". There used to be NATs that did linear allocation or some other weird schemes (e.g. linear, but matching the lower bit of the WAN port to the LAN port, for reasons to do with SIP weirdness). These days, due to the mis
71.
▲
by
dave_universetf
6y ago
The article makes the distinction, because it's a useful empirical distinction to draw :). While you're correct that linux is, strictly-speaking, an endpoint-dependent implementation, it goes to sufficient effort to reuse mappings
72.
▲
by
dave_universetf
6y ago
If I were trying this again today, I'd probably poke at what Matrix can do in terms of non-user-visible messages. It seems to be a successor to XMPP in terms of the communication model, so if it can do broadcast+unicast of non-visible
73.
▲
by
dave_universetf
6y ago
Yup, exactly right. In the article, I tried to call those "trivial" NATs, because from a NAT traversal POV they might as well not exist. You do need to do a tiny bit of work to get them up and running, but once that's done, y
74.
▲
by
dave_universetf
6y ago
As I said in the article, many years ago I played with using XMPP as the side channel for NAT traversal software. XMPP was handy for this because you can just define your own extension that chat programs will ignore, but XMPP itself will st
75.
▲
by
dave_universetf
6y ago
author here. NAT traversal definitely still works, but it's very situational. I'd estimate the simple techniques get you successful p2p in 90% of cases, but those 90% are unevenly distributed: for a particular pair of endpoints, t
76.
▲
by
dave_universetf
6y ago
You're on the right lines, yeah. On the wire, out on the internet, there is a packet with all the information we need to get through the easy/hard pair, but we can't access it. According to the author of dublin-traceroute, it
77.
▲
by
dave_universetf
6y ago
Author here. You are correct, the challenge in an easy/hard pair is the stateful firewall built into the easy side. Even thought the _NAT_ is easy (we can discover our public ip:port), the firewall still wants to see transmissions to&#
78.
▲
by
dave_universetf
7y ago
It's planned. Although note that DERP only relays the encrypted wireguard packets. All we see is "please send this ciphertext blob to pubkey X", i.e. exactly what any router on the internet sees. Still, for latency and compli
79.
▲
by
dave_universetf
7y ago
"supporter tier" is an interesting idea! We're still figuring out what kind of pricing makes sense for personal use vs. company use. Hopefully we'll have something soon! In the meantime, it's fine to be on the solo
80.
▲
by
dave_universetf
7y ago
(Tailscale employee here) For personal use, we're planning a "sharing" feature, so that you can share machines (or individual services) with friends, and they just show up on their network (after mutual approval, of course).
81.
▲
by
dave_universetf
7y ago
(Tailscale employee here) Automatic provisioning is definitely on the list. It's an enabler for immutable infra deployment, getting connectivity into containers, and building things like automatic enrollment based on external sources o
82.
▲
by
dave_universetf
7y ago
Github's on the list to support, yeah. We can speak most "identity provider" protocols these days (OAuth, OIDC, SAML, etc.), but it's this weird little universe: the protocols are meant to let you implement once to suppo
83.
▲
by
dave_universetf
7y ago
IPv6 by and large solves the NAT problem per se, but doesn't solve the stateful firewall traversal problem. Fortunately that one is _much_ simpler, especially now that we have QUIC as a robust stream protocol over UDP. IPv6 also introd
84.
▲
by
dave_universetf
7y ago
Oh, that kind of TCP hole punching. No, we don't do that, because we run over UDP only. So far, I don't think we've seen network conditions where UDP is blocked but the NAT is friendly enough to permit TCP traversal (same pro
85.
▲
by
dave_universetf
7y ago
(Tailscale employee here) UDP relays - that's roughly our DERP relay network. It currently operates over HTTPS because that's the last-resort "most likely to work in hard networks" transport, but adding a UDP option for
86.
▲
by
dave_universetf
7y ago
AUR package maintainer here (also tailscale employee). The poor experience was definitely on me. Relaynode's initial setup flow is a bit weird, and I didn't make the package explain anything. I think you were the first user of the