Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mpasternacki
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
Backups Suck – a rant
(3ofcoins.net)
4 points
by
mpasternacki
13y ago
|
0 comments
32.
▲
Distributing confidential Docker images
(3ofcoins.net)
5 points
by
mpasternacki
13y ago
|
1 comments
33.
▲
by
mpasternacki
13y ago
The issue here is not only the depth limit, but also: * performance overhead of each layer, however small * disk space for files removed in intermediate steps (scenario: ADD huge-ass source tarball, commit, RUN compile+install+remove, commi
34.
▲
by
mpasternacki
13y ago
The main cost is less clarity: the build steps aren't isolated anymore, so it's harder to pinpoint issues. There's also obvious risk of my script not interpreting all options correctly. Actually, I've just disabled VOLUM
35.
▲
by
mpasternacki
13y ago
I want to inherit from the base image, to keep the shared files actually shared. This is a feature. It's just the dozen layers of that inheritance that bothers me.
36.
▲
by
mpasternacki
13y ago
I have even linked to it in the article. I am going to comment and suggest this kind of approach - I wanted first to flesh out the idea and validate the proof of concept in this script.
37.
▲
by
mpasternacki
13y ago
Yes, this is convenient and speeds up Dockerfile development. At the same time, this is an issue when you consider using Docker as a part of your production deployment toolchain. I think both ways should be supported: incremental multi-laye
38.
▲
by
mpasternacki
13y ago
Doesn't it just remove the containers, but still keep the generated images layered? I'll take a look (running 0.6.1 here), but it seems to solve a different issue.
39.
▲
by
mpasternacki
13y ago
I've seen both; Docker's main registry provides some base images (the most used is named `ubuntu` and has base system for Precise and Raring), and I've seen many imaged descending from author's own base - it's quite
40.
▲
Flat Docker Images
(3ofcoins.net)
96 points
by
mpasternacki
13y ago
|
28 comments
41.
▲
Help MiniGit: need opinion on syntax
(3ofcoins.net)
3 points
by
mpasternacki
13y ago
|
0 comments
42.
▲
MiniGit: a simple Ruby interface to the Git command
(3ofcoins.net)
2 points
by
mpasternacki
14y ago
|
0 comments
43.
▲
by
mpasternacki
14y ago
Thanks! I don't use Windows, so I can't promise anything, but there's nothing there that may prevent it from working on Windows. It's pure Perl, so the code itself is portable. If you have any particular problem, feel free to email me (addr
44.
▲
by
mpasternacki
14y ago
Yup, enterprise-y is what I've been trying to avoid here. A lot of overhead for users that I can count on my fingers without using binary. Also, much of the big SSO systems seem to require the application to be aware of it, which is a shows
45.
▲
by
mpasternacki
14y ago
I don't like this idea as a main authentication system for a couple reasons, besides the logout problem. First, it requires team members to register every single browser they'll be using to access the panels – which may also mean being lock
46.
▲
by
mpasternacki
14y ago
Thank you! This will be closed up by end of this week. As I wrote in the article and in the presentation, one of main points of open sourcing it is to have people smarter than myself look at the crypto and protocols to find any issues like
47.
▲
by
mpasternacki
14y ago
Thank you for your remarks, this is really helpful. It doesn't seem to me that timing attack is feasible here: timing of comparison of a relatively short string vs network latency and everything else that happens during Apache's request han
48.
▲
Ginzametrics Open Sources Odin, A Cookie-Based Single Sign On for Apache
(ginzametrics.com)
41 points
by
mpasternacki
14y ago
|
20 comments