Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
masom
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
masom
3y ago
The issue is UFW ignoring other firewall rules, Docker just adds itself to iptables, but UFW actively ignores other chains. The bug is on UFW being insecure by design.
32.
▲
by
masom
3y ago
It would be nice if the post title would include the article title, I didn't know who was Robbie Robertson, what they did, and why it might be relevant. https://news.ycombinator.com/newsguidelines.html
33.
▲
by
masom
3y ago
It really depends what you design your system to handle. A sudden burst of traffic that can be spread for minutes is fine (ex: Elasticsearch indexing requests can usually be delayed through background jobs). > Basically those things only
34.
▲
by
masom
3y ago
The reason docker is integrating this way is to easily group the rules it introduced. > I feel Docker should have tried to play nicer with the firewall. The problem is on the UFW side not setting up properly when other chains are presen
35.
▲
by
masom
3y ago
It's a bit difficult to cover as it is highly dependent on the queue system you use. You'd usually want your queue system to fail the enqueue if it is full, and you'd want monitoring to ensure the queue isn't growing at
36.
▲
by
masom
3y ago
It does not bypasses them, it uses the firewall to add forwarding rules to the container. If you read https://www.baeldung.com/linux/docker-container-published-po... there's a bunch of ways to prevent this from ha
37.
▲
by
masom
3y ago
> I don't understand how you can make queueing high-performance. Queueing things is literally the opposite of making things fast. You likely need to read about message queues, why they are used, and why they have performance constra
38.
▲
by
masom
3y ago
Leaving your car door open isn't a great analogy. The internet is closer to leaving your own journal open at the library or a magazine store, and people going through it. You made it available for everyone to peek at in a public space.
39.
▲
by
masom
4y ago
Feels like most of those posts, and people using StackOverflow + Google search popularity, somewhat misses a few key aspects that would cause people to search. It seems to ignore technologies not present, or lower ranking, might just have b
40.
▲
by
masom
4y ago
GDPR isn't really related to the infrastructure, and isn't a problem if you built your product knowing you'll need to conform. Shopify is GDPR compliant, for all merchants, and runs on Google Cloud in multiple regions.
41.
▲
by
masom
4y ago
InReach, and any users (other brands offering competing two-way communicators) of the Iridium satellite network, have ongoing fees. They're rather small compared to someone dying in the wilderness.
42.
▲
by
masom
4y ago
No, the article just mentions it started as C#.
43.
▲
by
masom
4y ago
Hydro power has some high drawbacks, including being affected by droughts. They're flooding large swaths of land, destroying ecosystems, are extremely energy intensive while being built, cannot be built anywhere you'd need one, an
44.
▲
by
masom
4y ago
Measuring your fridge is important as it could point to a bad compressor or bad seals. Your fridge compressor shouldn't be running 24/7, and it should mostly be on standby until temperature rises.
45.
▲
by
masom
5y ago
> Android doesn't have anything like it either. Uh, it sure does through the applications section. You can see running services, which ones are taking battery, and stop/disable those as well.
46.
▲
by
masom
6y ago
We use Stripe...
47.
▲
by
masom
6y ago
> This certainly makes Stripe the most valuable private startup in the world. Stripe has not been a startup for a while, they've been in public operations for about 10 years now and probably power a large portion of online purchases
48.
▲
by
masom
6y ago
> Shopify does not have an open API where anyone can access data given an OAuth token We do offer a full GraphQL and REST API that can be accessed through private app keys (apps installed outside of the app store) or through the app stor
49.
▲
by
masom
9y ago
What would be Facebook options to stop Kogan or Cambridge Analytica? They already have the data, other than suing, what's possible here?
50.
▲
by
masom
9y ago
That is mostly what happened. Some French company wouldn't play nice.
51.
▲
NGINX unit Ubuntu signing key provided over unencrypted HTTP
1 points
by
masom
9y ago
|
0 comments
52.
▲
by
masom
9y ago
That's not very useful for your CEO/CTO/CFO/sales/etc when they are offsite or traveling.
53.
▲
by
masom
9y ago
> almost every basic function needs to be imported from some third party, which also feels not so safe, as a sys admin Go (and most languages) also supports importing a lot of packages from third-parties. Just pin your dependencies to sp
54.
▲
by
masom
11y ago
Thumbor let's you store and retrieve your images anywhere. We use AWS S3 with a redis storage cache + another redis cluster to store the result cache.
55.
▲
by
masom
11y ago
> Still hard to figure out which version of openssl is actually running in production You could check the version of openssl in a specific image id and check if that image is used on the cluster. If one of your image has a package with k
56.
▲
by
masom
13y ago
Seeing that PHP 5.6 is just about to be released and PHP 5.4 has been out for years, I would target php 5.4+ PHP 5.2 has reached end of life over 3 years ago. http://php.net/eol.php
57.
▲
by
masom
13y ago
* No logging * No unit tests
58.
▲
by
masom
13y ago
Indeed. I don't quite understand the reasoning behind the license.
59.
▲
by
masom
13y ago
Please don't mix tab and spaces :( https://github.com/goldenice/Kamele-Framework/blob/master/sy... Using proper namespaces would be great, the `System` namespace will probably collide with other pro