Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kkamperschroer
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
kkamperschroer
4y ago
As I was reading your comment I was thinking "whoa, that sounds like Damien or Robert" and sure enough :) Hope you are doing well!
2.
▲
by
kkamperschroer
4y ago
I saw Plex mentioned, but personally I like Subsonic better for music specifically: http://www.subsonic.org/pages/index.jsp If you're already hosting Plex, what's one more Docker container running Subsonic? :
3.
▲
by
kkamperschroer
10y ago
I did a couple years ago. Attack Pattern ( http://attackpattern.com/ ). They are still alive and well, but I ultimately had to find a different job when I decided I wanted to go remote.
4.
▲
by
kkamperschroer
11y ago
A useful layman's explanation of gravitational waves and the LIGO experiement: https://www.youtube.com/watch?v=1Tstyqz2g7o
5.
▲
by
kkamperschroer
11y ago
Nice! The FUSE mounting method for obtaining secrets is similar to how Keywhiz does this. Very cool and novel solution. Though, if you are unfortunate enough to still have Windows servers in your architecture, I think you're out of luc
6.
▲
by
kkamperschroer
11y ago
Fantastic. Thank you!
7.
▲
by
kkamperschroer
11y ago
So if you potentially need to roll a secret you would just run your deployment playbook limited to the secrets task?
8.
▲
by
kkamperschroer
11y ago
Cool, thanks! Seems like a pretty direct competitor to AWS KMS. The pricing is identical, so I guess the choice between the two is quite obvious if you are hosted in Azure or AWS.
9.
▲
by
kkamperschroer
11y ago
That's very similar to the problem we are encountering. Getting the secrets to the machines at deploy time isn't too bad, but then they are available to a potential attacker. Accessing secrets as needed at runtime instead requires
10.
▲
by
kkamperschroer
11y ago
Do you take advantage of Consul's ACL system them for limiting access to secrets? Also, do you have any form of auditing then when using consul? Thanks for your input!
11.
▲
by
kkamperschroer
11y ago
That's an interesting solution. I guess this would really only work though if you are self hosted, right? Thanks!
12.
▲
by
kkamperschroer
11y ago
Nice, thank you! I haven't heard of that one.
13.
▲
by
kkamperschroer
11y ago
Thanks for the tip. I guess the easiest thing to do is use git-crypt with some encrypted file and have the secrets available at deploy time, but I'm worried about long term disadvantages to this approach. Rolling secrets would then req
14.
▲
Ask HN: In a microservice architecture, how do you handle managing secrets?
134 points
by
kkamperschroer
11y ago
|
57 comments
15.
▲
by
kkamperschroer
11y ago
I found my current position at AttackPattern here on HN a year ago, and I really love it. I would highly recommend others check it out.
16.
▲
by
kkamperschroer
11y ago
Currently no, but that is certainly something I could add as options to customize. Thanks for the suggestion!
17.
▲
by
kkamperschroer
11y ago
Looking for some honest feedback on this idea I had for a new tab page replacement where I can keep some notes. Currently alpha as I have not cleaned up all of my original hacks from a prototype and there is currently no version control. So
18.
▲
Show HN: NewTabNotes – A synchronized markdown notepad for Chrome
(chrome.google.com)
4 points
by
kkamperschroer
11y ago
|
3 comments
19.
▲
by
kkamperschroer
11y ago
Using consul ( https://www.consul.io/ ) in conjunction with HAProxy is another great way for service discovery and routing.
20.
▲
by
kkamperschroer
11y ago
CenturyLink Cloud AppFog is a good alternative. I know, I know, it's CenturyLink and that's concerning to you. Cloud is like a different company entirely. Disclaimer: I helped build AppFog as a contractor.
21.
▲
by
kkamperschroer
12y ago
Thanks. I'll add it to my backlog!
22.
▲
by
kkamperschroer
12y ago
I'm a Chrome extension author and I've been contacted at least a half-dozen times by shady companies that want me to add some "totally unobtrusive" ad-injection javascript into my extension. I've been told I could m
23.
▲
by
kkamperschroer
12y ago
That is essentially the definition of financial independence, and it's certainly possibly with a job in software. It just involves saving as much as you can afford to and taking advantage of compound interest early on.
24.
▲
by
kkamperschroer
12y ago
Linux with Crouton: https://github.com/dnschneid/crouton
25.
▲
by
kkamperschroer
12y ago
Of course you can fake a plastic card today, however it's far easier to mimic and manipulate pixels than it is a plastic cards look, feel, holographic logos, etc.
26.
▲
by
kkamperschroer
12y ago
The article makes no mention of this being used outside of law enforcement, but wouldn't this be incredibly easy to fake at a bar, for example? A nearly identical app except it's one where you can change the information. I don
27.
▲
by
kkamperschroer
12y ago
You can even just set them equal to Infinity. Win!
28.
▲
by
kkamperschroer
12y ago
My mistake! Sorry!
29.
▲
by
kkamperschroer
12y ago
Since it was just released, I doubt many outside of github have an established workflow with this. Maybe someone with the Windows client can provide more insight, given the similarities.
30.
▲
by
kkamperschroer
12y ago
Thanks! I'm glad you like it. :)
More ›