Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jcgl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
121.
▲
by
jcgl
6mo ago
Look up systemd-userdb (the systemd component that added this field). Like the sibling comment said, this is basically equivalent to adding a GECOS field. A totally optional field.
122.
▲
by
jcgl
6mo ago
Because someone came with a pull request for this; this additional field was meant to support a feature in something else they were working on (an xdg portal). It was a simple PR that addressed a need that the programmer had. And it was a
123.
▲
by
jcgl
6mo ago
Is it some sort of well-known fact that Xi has some egotistical need to build some kind of strongman legacy? I’m no expert, but the China that he has built is one of extreme competence and long-term thinking. It’d seem contradictory to comp
124.
▲
by
jcgl
6mo ago
Appreciate the nit. Had no idea that Flask wasn't production-grade. Yeesh. I really don't miss this part of the Python world. When I started on backend stuff ~10 years ago, the morass of runtime stuff for Python webservers felt be
125.
▲
by
jcgl
6mo ago
Yeah, the field of software engineering has come a long way since then. But just because previous implementations of the analysis phase were flawed doesn't mean that the phase itself was flawed.
126.
▲
by
jcgl
6mo ago
To the extend that Python is indeed "batteries included," that seems true. But just how "batteries included" is it? I'd argue that its batteries are pretty limited. Exhibit A: everybody uses the third-party request
127.
▲
by
jcgl
7mo ago
> In Linux, all windows share the same message loop thread. I'm no expert, but aren't you just talking about Xorg here? As far as my limited knowledge goes, there's nothing inherent in the Wayland protocol that would imply
128.
▲
by
jcgl
7mo ago
Yes, of course. But my question was why are you focusing on DNS here? Everything you've said so far is true of setting up literally any public service . Considering how cheap DNS is to serve in the common case, running an authoritativ
129.
▲
by
jcgl
7mo ago
Sure, but if the services are available, you can just purchase as-needed. If the problem never comes up, you're golden.
130.
▲
by
jcgl
7mo ago
I feel no need to. I'm quite certain that the certbot folks are aware of the existence of distro packages and even know how to check https://pkgs.org/download/certbot for availability. One might guess that they on
131.
▲
by
jcgl
7mo ago
Knot (as suggested by others) is good. As are BIND and PowerDNS. These are the big authoritative resolvers I think of at least, and all of them allow for basically hands-free DNSSEC; just flip a switch and you'll have it. I've run
132.
▲
by
jcgl
7mo ago
Not that I disagree with the fact that these risks exist, but how is that different than running any other service for a mission critical platform? The main thing I can think of is DNS amplification attacks, but that's more your DNS se
133.
▲
by
jcgl
7mo ago
Unfortunately, it's more than that: the Linux installation instructions on the certbot website[0] give options for pip or snap. Distro packages are not mentioned. [0] https://certbot.eff.org/
134.
▲
by
jcgl
7mo ago
Great timing! Check this out: https://lore.kernel.org/netdev/20260319151230.655687-1-ralf@...
135.
▲
by
jcgl
7mo ago
You could also provide a dual stack jump host. Then v4-only clients just set the ProxyJump option to get to all the v6-only hosts via the jump host.
136.
▲
by
jcgl
7mo ago
Static hosting is amazing for toooons of use-cases. Especially those where You Just Need A Website (business hours, contact info, general info).
137.
▲
by
jcgl
7mo ago
> Sure, but if once every ~8 years is good enough for the root zone [0], then surely it's good enough for everyone :) Yeah, I don't know how to feel about that exactly :) like, is it actually good enough for them? Probably, I s
138.
▲
by
jcgl
7mo ago
> But in theory, you shouldn't need to update your DS records much more often than you update your NS records Maybe? You'd update DS whenever changing your key-signing keys. You'd update your NS records and/or glue re
139.
▲
by
jcgl
7mo ago
> Isn't that the same as any DNS mistake though? No, only the DNS mistakes that involve zone delegation; if you screw those up, then yes, it's pretty much the same. But most DNS mistakes are scoped to one or a handful of names
140.
▲
by
jcgl
7mo ago
I agree. Someone was working on that, though the work seems quite stale now: https://codeberg.org/IPv6-Monostack/ipxlat-net-next
141.
▲
by
jcgl
7mo ago
> 1) Duh? I'm discussing a failover situation where your router has unexpectedly lost its connection to the outside world. You'd hope that your existing connections would fail quickly. The existence of the deprecated IP shoudn&
142.
▲
by
jcgl
7mo ago
> * Hosts react to the change by reconfiguring via SLAAC and/or DHCPv6, depending on the settings in the RA This is the linchpin of the workflow you've outlined. Anecdotal experience in this area suggests it's not broadly
143.
▲
by
jcgl
7mo ago
In any scenario where you want to do traffic steering at a network level. Managing multiple network upstreams (e.g. for network failover or load balancing) is a common example that is served well by numerous off-the-shelf routers with IPv4.
144.
▲
by
jcgl
7mo ago
NetworkManager just recently got CLAT! https://gitlab.freedesktop.org/NetworkManager/NetworkManager... Issue for CLAT in systemd-networkd: https://github.com/systemd/systemd/issues/23674
145.
▲
by
jcgl
7mo ago
Could be interesting. What do you see as the main problems with NSS? I've never needed to use it directly myself. It seems quite crusty of course, but presumably there's more that your referencing. Moving from linking stuff in-pro
146.
▲
by
jcgl
7mo ago
I had no idea that you could run Lineage on the Jelly Star! That sounds phenomenal. My dream phone is a Star running Graphene. But short of that, Lineage would be great. Any notes on your experience?
147.
▲
by
jcgl
7mo ago
That's a fair point, and shelling out to id is probably a good solution. I guess what bothers me is the software authors who don't think this through, leaving applications non-functional in these situations. At least with Go, if
148.
▲
by
jcgl
7mo ago
> I don't care about glibc or compatibility with /etc/nsswitch.conf. So what do you do when you need to resolve system users? I sure hope you don't parse /etc/passwd, since plenty of users (me included) use
149.
▲
by
jcgl
7mo ago
> 3. use clevis to enable automatic unlocking of the root fs only when secure boot check passes; Can also use systemd-cryptsetup/systemd-cryptenroll for this. I've not used clevis myself, but I'd imagine you have to do som
150.
▲
by
jcgl
7mo ago
> I think agents will have much better luck with TUIs than browsers. I’m very skeptical. Why would you think that? TUIs inherently don’t provide programmatically accessible affordances; if they have any affordances at all, they’re purely
More ›