Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kodama-lens
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
How to Not Join Kubernetes Nodes – Reporting a Vulnerability
(henrikgerdes.me)
2 points
by
kodama-lens
17d ago
|
0 comments
2.
▲
by
kodama-lens
3mo ago
In a world where code generation is cheap, why use untyped languages? Types add confidence, stricter interfaces, and most likely a better runtime performance.
3.
▲
by
kodama-lens
3mo ago
Firecracker has more tooling, but setting ist up and managing it is also more complicated, at least for k8s workloads. Libkrun is so easy for k8s! Compile crun with Libkrun support, crate a symlink of crun with the name krun, done. Works li
4.
▲
by
kodama-lens
5mo ago
I think there is an Issue/PR right now to change this. See: https://github.com/containerd/containerd/issues/13307
5.
▲
by
kodama-lens
5mo ago
Yeah, kind of. Lidl and Kaufland is owned by the Schwarz Group. They have been busy replicating the AWS orgin story. Their cloud is called StackIT. I've worked with them. Still some room to grow but a solid foundation. I like that comp
6.
▲
by
kodama-lens
6mo ago
I'm happy that there will be more tooling, but the reason for that (and the target audience) should not be ai agents. It should be a good experience for humans! Tools should be tested and quality assured. Something that was utterly mis
7.
▲
by
kodama-lens
7mo ago
I switched our entire container build setup to buildkit. No kaniko, no buildah, no dind. The great part is that you can split buildkitd and the buildctl. Everything runs in its own docker runner. New buildkitd service for every job. Caching
8.
▲
by
kodama-lens
8mo ago
It is a know problem. The strange part for me is that they fixed it in v1.35 with the FeatureGate AuthorizePodWebsocketUpgradeCreatePermission for pods but not for nodes which have a far greater attact vector. The author also references thi
9.
▲
by
kodama-lens
9mo ago
Thanks for the write up. It is indeed a simple and good solution for smaller workloads and as already pointed out it has some limitations. For devs the explicit configuration of that HTTP_PROXY is annoying, so the last time I did an egres
10.
▲
by
kodama-lens
10mo ago
Great way to apply your gathered Kubernetes knowledge! But I find the pricing tough and I don't like to give 3rd party tools that level of access to my clusters. I know its early state but I see several problems: Right now it seems to
11.
▲
by
kodama-lens
10mo ago
Since customers carry out QA, the title is correct.
12.
▲
by
kodama-lens
10mo ago
It has gotten way worse since the Ai rise. Before it was the "how to be a winner" mindset now everything gets posted. Mostly AI garneted slop with glitchy AI images that advertise just plain false information. No one corrects st
13.
▲
by
kodama-lens
11mo ago
Author here. I know the old way still works and I respect that. Given the history I ask myself how long will it work, since ist not the default anymore.
14.
▲
by
kodama-lens
1y ago
I tried podman for multiple times. Normal testing & sandox stuff just works and you really can do alias docker=podman. But ass soon as you add nertworking me broke for me. And for me it is really just a tool and I need my tools working.
15.
▲
by
kodama-lens
1y ago
There are so many bad OAuth explanations and articles, this is NOT one of them! Thanks for writing it. Will recommend when I have to explain OAuth yet another time. My only nit pick is that the separation between OAuth and OIDC could have u
16.
▲
by
kodama-lens
2y ago
I don't think that WASM will replace containers. They will continue to move closer to each other but still have their advantages in different fields. Right now I can run containers and WASM workloads in the same k8s clusters. I dont ev
17.
▲
by
kodama-lens
2y ago
In my last year of university (5 years ago) I took a networking seminar. Each student took a look at a different technology to utilize multiple links for internet data transfers. Initially I was amazed by MPTCP and wondered why it had so li
18.
▲
by
kodama-lens
2y ago
It would fix a lot of the provider specific aspects of OAuth2, if the spec would be more strict on some claim (attribute) names on the jwt ID token. Some provide groups, some don't. Some call it roles or direct_groups. Some include pre
19.
▲
by
kodama-lens
2y ago
At my old company we used to git pull and do make install on the prod server. Now I have to file an exceptions for a found buffer overflow vulnerability in libfdisk1 identified in my miminal container image running in a locked down, read on
20.
▲
by
kodama-lens
2y ago
When I was finishing university I bought into the framework-based web-development hype. I thought that "enterprise" web-development has to be done this way. So I got some experience by migrating my homepage to a static VUE.JS vers
21.
▲
by
kodama-lens
2y ago
I can confirm this. All Google container registries, including the official k8s repos are unaccessible via some hetzner ipv4 domains. There is a GitHub issue that also covers the problem and it states you should report thos IPS to their sup
22.
▲
Taking a look at what drives our Kubernetes Containers
(henrikgerdes.me)
2 points
by
kodama-lens
2y ago
|
0 comments
23.
▲
by
kodama-lens
2y ago
> Ansible, if I'm not mistaken, requires python3 installed on remote hosts. It is not a requirement. There is the raw module that just sends commands over ssh . But if you want to do anything beyond basic most people use raw just to
24.
▲
by
kodama-lens
2y ago
While I don't agree with quite some assumptions and comparisons the author makes I tend to agree that microservices are often not the right answer for your problem. They can be great when: * You need just one function that is not direc
25.
▲
by
kodama-lens
2y ago
> Certainly my utility websites (e.g. electric/gas) are a lot more functional and a lot less user hostile, because...those companies would really like it if you paid your bill on time, so at least that workflow is pretty polished. Y
26.
▲
by
kodama-lens
2y ago
You mean everyone that runs a Crossplane cluster? Already happening
27.
▲
by
kodama-lens
2y ago
Naming things is hard and I don't mind if you cant tell what a software/service does by it's name but I don't like that there so little separation between the names: > I just deployed the Grafana Oparator, oops I ment
28.
▲
by
kodama-lens
2y ago
In advance: I like the Grafana, Prometheus, Mimir Loki stack BUT: I have difficulties understanding their product lineup and roadmap. Everything is named Grafana something. Grafana the company, Grafana the monitoring Frontend, Grafana Agent
29.
▲
by
kodama-lens
3y ago
Is there anything that makes spin stand out? From what I've read, it seems much more complicated then it has to be. I've been running crun with wasmtime enabled since about 1 year in my private test clusters. No shim, no operator
30.
▲
by
kodama-lens
3y ago
Authentik has completely messed up their implementation of the oauth client credentials grant. It is not fixable without breaking changes and does not work with many tools using the cc grant. After seeing this they were completely off the t
More ›