Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
davidstrauss
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
1.
▲
by
davidstrauss
8mo ago
Hi, I'm David, founding product lead. Our entire team will be at FOSDEM, and we'd be thrilled to meet more of the Mullvad team. Protecting systems like yours is core to us. We want to understand how we put the right roots of trust
2.
▲
by
davidstrauss
11y ago
> because upstart could grok the scripts without change I don't believe that's the case. The "service" command (which is part of the sysvinit-utils package, not Upstart) invokes either Upstart or SysV init as necessar
3.
▲
by
davidstrauss
11y ago
The closest I could find in the docs to what digi_owl said is the following: > Internally, these functions send a single datagram with the state string as payload to the AF_UNIX socket referenced in the $NOTIFY_SOCKET environment variabl
4.
▲
by
davidstrauss
11y ago
> it's not exactly a good choice for embedded systems. I don't develop embedded systems, but systemd is actually popular in that space because of its watchdog capabilities and its inclusion in projects like GenIVI and Tizen. Mo
5.
▲
by
davidstrauss
11y ago
Directly talking to the notify socket is not considered using systemd internals. It is documented as a stable, public interface: https://wiki.freedesktop.org/www/Software/systemd/InterfaceS... Socket activati
6.
▲
by
davidstrauss
11y ago
The entire BSD kernel and init system are all in one repository. Are those developers "bringing on" confusion by doing that?
7.
▲
by
davidstrauss
11y ago
> The fact that Lennart was giving out presentations about nspawn specifically makes me believe it's very much intended to be used in production, as a "chroot on steroids". This is a recent development -- and why I put the
8.
▲
by
davidstrauss
11y ago
I don't think Red Hat was the driving force behind systemd's container and VM integration. systemd-nspawn was created to provide rapid testing of systemd, and it was (and, for now, still is) marked as an experimental utility that
9.
▲
by
davidstrauss
11y ago
> Might wish to check your history a bit. No matter how many complaints you may find about SysV boot time -- or even discussion about how to improve it -- it does not make systemd's primary purpose solving that problem. How many dis
10.
▲
by
davidstrauss
11y ago
> Why assume the user is too stupid or lazy to manually invoke vim and then systemctl daemon-reload? This is what it does: (1) Locates the current unit file, regardless of whether it shipped with a package or is already a custom one in &
11.
▲
by
davidstrauss
11y ago
If that were the case, wouldn't the author support the kdbus work? It seems like they're not a fan of that, either, given the (misleading) complaints about systemd's support for kdbus. Edit: phrasing
12.
▲
by
davidstrauss
11y ago
> Honest question: Why does an init system need to know anything about screen brightness in the first place? Shouldn't X11 handle screen brightness? I think that's a reasonable question. I am only a regular desktop user of syst
13.
▲
by
davidstrauss
11y ago
As a systemd committer, I certainly can. I don't have time for all of them, so I'll pull the first couple and a few other egregious ones. > Systemd was introduced to decrease the boot up time. Now that they do not understand al
14.
▲
by
davidstrauss
13y ago
Especially once you start using hardware RAID controllers, the physical overhead of running I/O commands is pretty abstracted away from the kernel.
15.
▲
by
davidstrauss
13y ago
> However, using xen or kvm solves that problem, by giving each guest their own ram that nobody else can fuck with. It gets hard to say whether a shared page cache is a good thing or not, even though it may be unfair. I say this becaus
16.
▲
by
davidstrauss
13y ago
Just a note as the author of the Linux Journal article, I absolutely would have mentioned Docker if I had written the article now. Unfortunately, the article only recently made it to publication (and now post-paywall) despite my having writ
17.
▲
by
davidstrauss
13y ago
I just timed a spin-up of a 16GB Fedora 18 instance on in the current-generation Rackspace Cloud's DFW data center. It took 7 minutes and 10 seconds to complete. Launching a somewhat larger-in-RAM instance on EC2 in Oregon took over 10
18.
▲
by
davidstrauss
13y ago
> I am intimately familiar with eWLM and I think it's quite unfair to call it containers. I feel like you're strawmanning me, here. I specifically avoided calling WLM "containers." I said they're building blocks
19.
▲
by
davidstrauss
13y ago
Yes: "All the buffered writes are still system wide and not per group. Hence we will not see service differentiation between buffered writes between groups." [1] [1] https://www.kernel.org/doc/Documentation&#x
20.
▲
by
davidstrauss
13y ago
RCTL can enforce specific limits, which is good if you either want to divide resources such that there can't be (or is unlikely to be) contention. cgroups offers hard limits for some things, like memory, but it mostly opts for a model
21.
▲
by
davidstrauss
13y ago
> Citation needed. First, I define containers by their capabilities, not a vendor or kernel calling them "containers." The Linux kernel, internally, has no concept of containers; it merely provides the resource-sharing and secu
22.
▲
by
davidstrauss
13y ago
I'm the author of the article. It doesn't mention Windows Azure because I wrote it for the Linux Journal, and a full discussion of containerization outside of Linux wasn't possible in the allotted article space.
23.
▲
by
davidstrauss
13y ago
cgroups are the method of doing fair resource sharing.
24.
▲
by
davidstrauss
13y ago
> That's not true -- Linux has had local root exploits pretty much at ALL times. If you're in a container, you can break out with one of these exploits. You'll be root and have access to all other containers on the machine
25.
▲
by
davidstrauss
13y ago
> Now, if I can figure out how to do the same with disk? Hi, I'm the author of the article. You should check out cgroups. You can isolate disk access between services and containers using block I/O shares with cgroups. The way
26.
▲
by
davidstrauss
13y ago
How would you suggest we efficiently partition and sell computing resources, then? It's not cost-effective or even power-efficient to run separate hardware for each scale of computing. For example, many projects only need a container o
27.
▲
by
davidstrauss
13y ago
Hi, I'm the author of the article. FreeBSD Jails lack the same fine-grained isolation choices versus the base system that the Linux kernel exposes through namespaces and cgroups. That's not to say that Jails don't capture mos
28.
▲
by
davidstrauss
13y ago
Hi, I'm the author of the article. > Containers have been mature for longer than the article implies (freebsd jails, Solaris zones). Mature containers have been around since the the days of mainframes. The recent (say, last decade)