Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
m_sahaf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
m_sahaf
3y ago
The pprof format is not tied to Go. From my understanding, it's used within Google across multiple languages. The format is defined in the pprof repository[0], and the visualization tool is source-language agnostic. I've seen libr
32.
▲
by
m_sahaf
3y ago
You could've used the nginx-adapter and skip the faulty LLMs https://github.com/caddyserver/nginx-adapter
33.
▲
by
m_sahaf
3y ago
I had fun building it. It was illuminating seeing where implicit trust is unconsciously assumed, break that down, and identify the threat entry-points (absence of policy definition for the ACME server) as areas of improvement for Caddy. I&#
34.
▲
Zero-Trust Architecture with Caddy
(caffeinatedwonders.com)
5 points
by
m_sahaf
3y ago
|
2 comments
35.
▲
by
m_sahaf
3y ago
> I’m not aware of anyone running Caddy at any sort of scale for customers. Well, to name a few... - Stripe ( https://twitter.com/caddyserver/status/1559591673511813120 ) - Mercedes-Benz ( https://githu
36.
▲
by
m_sahaf
3y ago
I don't know what metric to use of "good", but the throwaway app I've used it for worked flawlessly with both, so good enough for me ¯\_(ツ)_/¯
37.
▲
by
m_sahaf
3y ago
For web, Flutter has 2 renderers and offers 3 options: - html: Uses HTML elements and CSS - canvaskit: which, as you mentioned, uses canvas to own the full drawing process - auto: defaults to canvaskit on web but html on mobile. Source: ht
38.
▲
by
m_sahaf
3y ago
Worthy of note the Calibre-Web[0] project, which builds atop Calibre library to provide powerful web interface. The project and its maintainer deserve some love and support. [0] https://github.com/janeczku/calibre-web
39.
▲
by
m_sahaf
3y ago
Adding to Francis input, the release artifacts (not the .deb packages, which are signed with Matt's key) published on GitHub are authenticated with Sigstore tooling[0]. You can verify the artifacts and the .deb packages were not tamper
40.
▲
by
m_sahaf
3y ago
Bolt has an open source Go package that tries to do that: https://github.com/BoltApp/sleet
41.
▲
by
m_sahaf
4y ago
Well, effort for such undertaking has started by yours truly as a Caddy module/plugin. Here's my announcement blog post: https://www.caffeinatedwonders.com/2022/03/28/new-ssh-server... . It's no
42.
▲
by
m_sahaf
4y ago
You configure Caddy to disable certain challenge types[0], which in this is the HTTP challenge, like so: example.com { tls { issuer acme { disable_http_challenge } } file_server } [0] https:&#
43.
▲
by
m_sahaf
4y ago
You're right that a customer shouldn't care the staff are too busy or too ignorant. You're also right in how complaining online short-circuits all that to actually receive help. I continuously advocate for the presence of pat
44.
▲
by
m_sahaf
4y ago
> Don't blame minimum wage earners If that's directed at me, I am not blaming anyone. Chill. I'm saying it's a human thing.
45.
▲
by
m_sahaf
4y ago
As someone who worked as front-line support and turned into the authority who's asked to resolve complex cases, this is nonsense. They aren't playing Tetris ignoring the queue. It's more likely the front-line staff are overwh
46.
▲
by
m_sahaf
4y ago
C is a huge disadvantage when it comes do security.
47.
▲
by
m_sahaf
4y ago
You can use Caddy to automatically fetch certs and keep them renewed without much hassle[0]. Disclaimer: I'm affiliated with Caddy [0]: https://caddy.community/t/using-caddy-to-keep-certificates-r...
48.
▲
by
m_sahaf
4y ago
Caddy is capable of handling bidirectional gRPC streams! I have just tested it, and it works just fine. Caddy will immediately flush writes when upstream is `h2` or `h2c`[0] instead of having to wait until reading from socket is complete
49.
▲
by
m_sahaf
5y ago
That's right. Moreover, the activity no the repo has been a bit stagnant (no disrespect to the maintainers, they are likely busy with other projects or life). Other projects have opted to fork the repo, rewrite the module repo path, an
50.
▲
by
m_sahaf
5y ago
The plans are there! I focused on implementing the absolute necessary parts of every layer before taking round-2 for the more in-depth implementation. I actually have both the linked thread and the article saved aside to study when I'm
51.
▲
by
m_sahaf
5y ago
To be fair, this bit is borrowed/forked from github.com/gliderlabs/ssh.
52.
▲
by
m_sahaf
5y ago
That's right! Currently such (static) keys are loaded at provision-time, when the server is first booting up, but there's nothing preventing it from being lazy-loaded at authentication-time. Of course loading them at authenticatio
53.
▲
by
m_sahaf
5y ago
> - if your Goal was "secure by default", why did you allow passwords in the first place? Following Caddys recipe would be more like SSH-Keys only, wouldn't it? Is there a reason other than compatibility? Compatibility was
54.
▲
by
m_sahaf
5y ago
Names are hard. I did consider changing the name but couldn't find another one. Feel free to pitch names on GitHub. Caddy provides the module system and the config management backed by powerful REST API for config query and patching. I
55.
▲
by
m_sahaf
5y ago
Not very too level. I had to take that into consideration at some parts. For example, the static username_password provider calls a hasher defined in Caddy which uses `subtle.ConstantTimeCompare` function used. At other places, I don't
56.
▲
by
m_sahaf
5y ago
Thank you! Indeed, you're right. The ultimate goal is to be drop-in replacement. There is a PR hanging waiting to be taken up. I might look at it once I finish furnishing the foundation, but others are welcome to take it up!
57.
▲
by
m_sahaf
5y ago
Hi everyone! Author here This has been my stress-reliever for the past ~2 years. I'm sticking around, so feel free to ask any questions. Github Repo: https://github.com/mohammed90/caddy-ssh
58.
▲
Show HN: Caddy-SSH
(caffeinatedwonders.com)
280 points
by
m_sahaf
5y ago
|
131 comments
59.
▲
0day “In the Wild”
(docs.google.com)
2 points
by
m_sahaf
5y ago
|
0 comments
60.
▲
by
m_sahaf
5y ago
> abstracting information processing Information processing is bookkeeping. > Is math just bookkeeping? (of course not) Why "of course not" though?
More ›