Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
eriksjolund
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
eriksjolund
1y ago
Sometimes it's possible to not use the Podman API at all. Convert the compose file to quadlet files with the command-line tool podlet and start the container with "systemctl --user start myapp.service". Due to the fork/e
2.
▲
by
eriksjolund
1y ago
That workaround is not needed if the web server container supports socket activation. Due to the fork-exec architecture of Podman, the socket-activated socket is inherited by the container process. Network traffic sent over this socket-acti
3.
▲
by
eriksjolund
1y ago
The license would no longer be open source if you limit use to only community. See "6. No Discrimination Against Fields of Endeavor" in The Open Source Definition https://opensource.org/osd
4.
▲
by
eriksjolund
1y ago
I did it out of pure interest, just to explore ways of locking down a web server.
5.
▲
by
eriksjolund
1y ago
You can use the podman option `--network=none` together with the systemd directive `RestrictAddressFamilies=` I wrote a demo: https://www.redhat.com/en/blog/podman-systemd-limit-access Podman will then not have th
6.
▲
by
eriksjolund
1y ago
Podman quadlet supports "Socket activation of containers" https://github.com/containers/podman/blob/main/docs/tutorial... This allows you to run a network server with `Network=none` (--net
7.
▲
by
eriksjolund
2y ago
Socket activation can be used with quadlets but not with docker-compose. That is a big advantage. https://github.com/containers/podman/blob/main/docs/tutorial...
8.
▲
by
eriksjolund
2y ago
If you want to know why bootc is needed check this list of goals: https://containers.github.io/bootable/ I found that URL by following the link in "bootc is the key component in a broader mission of bootable conta
9.
▲
by
eriksjolund
2y ago
Another tool that can be used by an unprivileged user for analysing network traffic is rootless Podman with Pasta. Just add the podman run option --network=pasta:--pcap,myfile.pcap Pasta then records the network traffic into a PCAP file tha
10.
▲
by
eriksjolund
3y ago
How to display circles on top of zoomable images without getting flickering is an interesting problem. (This comment does not refer specifically to displaying a tree map) I noticed that painting the circles on top of an overlay with OpenSea
11.
▲
by
eriksjolund
3y ago
Here are some documentation and demos from me and others if you're interested: https://github.com/eriksjolund/podman-networking-docs https://github.com/eriksjolund/podman-nginx-socket-activati
12.
▲
by
eriksjolund
3y ago
Rootless Podman uses slirp4netns by default. The default will soon change to pasta. Pasta has better performance than slirp4netns. For best performance if your container supports it, use systemd socket activation because the traffic over th
13.
▲
by
eriksjolund
3y ago
Podman can run a socket-activated network server (such as docker.io/library/nginx) with the "--network=none" option. This improves security.
14.
▲
by
eriksjolund
3y ago
It seems Red Hat believes in Loki Red Hat logging product manager says: "We made the decision to move to Loki and Vector" https://www.youtube.com/watch?v=QZ4Hv85lEJ0&t=938s
15.
▲
by
eriksjolund
3y ago
I just tried this out. The new systemd directive OpenFile= opens up the possibility to pass the file descriptor of a file from the host to a container running in a container. (using rootless Podman running rootless Podman) sudo systemd-ru
16.
▲
by
eriksjolund
4y ago
I wrote a mini tutorial (as a Reddit comment) about how to deal with UID/GID mappings when you run rootless podman and you want a specific container user to write to a bind-mounted directory: https://www.reddit.com/r&#x
17.
▲
by
eriksjolund
4y ago
Podman has a feature that Docker does not yet have: Socket activation of containers. I created a proof-of-concept demo of how to run an nginx container with rootless Podman and socket activation. Using socket activation has some security an
18.
▲
Show HN: Run Nginx with Podman and socket activation
(github.com)
4 points
by
eriksjolund
4y ago
|
1 comments
19.
▲
by
eriksjolund
4y ago
Ok, I understand your concern about Slirp. Regarding the other idea: I've now tested it and verified that it works. The remote address is available when running a socket-activated container with rootless Podman.
20.
▲
by
eriksjolund
4y ago
The remote address is available when running a socket-activated container with rootless Podman. I verified it in a test.
21.
▲
by
eriksjolund
4y ago
Not exactly what you are asking for but there is a Systemd feature request to add Connect= setting to service unit files. https://github.com/systemd/systemd/issues/23067#issuecomment... (That could a be coo
22.
▲
by
eriksjolund
4y ago
You could detect the source IP address by using the command-line option: --net=slirp4netns:port_handler=slirp4netns See https://github.com/containers/podman/discussions/10472#discu... Shouldn't it also b
23.
▲
by
eriksjolund
4y ago
I haven't tried it out, but shouldn't you be able to detect the true remote address by using a socket that has been passed in via socket activation?
24.
▲
by
eriksjolund
4y ago
I like this Podman feature: Socket activation of containers Advantages: - Faster network. Rootless Podman will run with native network speed. Normally rootless Podman runs with reduced network speed due to the performance penalty that comes
25.
▲
by
eriksjolund
4y ago
The --uidmap and --gidmap options can map your regular user on the host to any specific user inside the container. These options may look to be a bit complicated to use, but as soon as you understand how rootless Podman maps UIDs and GIDs i
26.
▲
by
eriksjolund
5y ago
To try it out, click the button "open some example data files and layouts". About the software design: All pyramidal photo tiles and gene expression measurement data are combined into one single file. Instead of downloading the wh
27.
▲
Show HN: Web viewer for gene measurements (single data file and OpenSeadragon)
(eriksjolund.github.io)
1 points
by
eriksjolund
5y ago
|
1 comments
28.
▲
by
eriksjolund
5y ago
I like this Podman feature: Support for socket activation Podman will pass on the socket-activated socket to the container. I wrote a small example demo for setting up socket activation with systemd, Podman, and a MariaDB container: https:
29.
▲
by
eriksjolund
5y ago
Nordic countries also get high numbers: Sweden 74 / 10.35 Mil. = 7.15 / Mil. Denmark 40 / 5.83 Mil. = 6.86 / Mil. Finland 33 / 5.53 Mil. = 5.97 / Mil. Norway 31 / 5.38 Mil. = 5.76 / Mil
30.
▲
by
eriksjolund
5y ago
A few years ago I wrote a small program and script that search for executables that crash when they are executed with argc==0 https://github.com/eriksjolund/empty-argv-segfault-check
More ›