Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
paulfurtado
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
paulfurtado
22d ago
Yes, exactly. And even do things like inject virtual USB drives so you can reinstall an OS or something
2.
▲
by
paulfurtado
22d ago
Fwiw, if performance isn't paramount, you can have a lot of fun with LKL (linux kernel library) and UML (user mode Linux). UML is full Linux running as a userspace process. Tools like guestfish use it to modify disk images. UML can onl
3.
▲
by
paulfurtado
22d ago
There are really two types of KVMs... classic ones were used by consumers to plug multiple computers into one screen, keyboard, and mouse and flip back and forth between them. Networked KVMs let you remotely access a computer or server. It&
4.
▲
by
paulfurtado
8mo ago
It is great for isolation. There are so many VM based containerization solutions at this point, like Kata Containers, gvisor, and Firecracker. With kata, your kubernetes pods run in isolated VMs. It also opens the door for live migration of
5.
▲
by
paulfurtado
2y ago
The benefit of docker for home assistant is the packaging of it, rather than isolation. You can always run a container with host network mode and privileged mode so that it can access everything it needs to the same as if it were running di
6.
▲
by
paulfurtado
3y ago
You don't need a fiber splicer for this. You can order a pre-terminated fiber cable online. On fs.com you can order fiber in custom lengths. An armored pre-terminated 350ft OS2 duplex cable costs $128: https://www.fs.com
7.
▲
by
paulfurtado
3y ago
I used the VLAN "trick" for connecting my cable modem to my router for a few years in an old multi-floor apartment with pre-wired ethernet, but it's not ideal because the router is then not able to detect the link state of th
8.
▲
by
paulfurtado
3y ago
This is of course not the purpose of your post, but since you're interested in this topic, I wanted to mention that you can now create memory-backed files on linux using the memfd_create syscall without using any filesystem (nor unlink
9.
▲
by
paulfurtado
3y ago
Do you have any references to specific bugs here? We depend pretty heavily on containers and I'd love to look into these and see if we are impacted and whether we should carry these patches
10.
▲
by
paulfurtado
4y ago
FWIW on AWS, all nitro instance types can boot as UEFI if the AMI has itself set to use UEFI and all arm64 instances only support UEFI. So if you stick to modern instance types, you can happily use UEFI in AWS. GCP looks like it does UEFI t
11.
▲
by
paulfurtado
4y ago
memfd is a tmpfs file descriptor, but does not use any mounted tmpfs filesystem. It works no matter what filesystems are mounted or access you have. It's truly great for situations where APIs refuse to take anything other than files an
12.
▲
by
paulfurtado
4y ago
If the goal of the test is to debug a sad linux server, containers are going to severely limit what ways the server can be sad in, isn't it?
13.
▲
by
paulfurtado
4y ago
User namespaces have resulted in multiple new container breakout CVEs in the last year. Some guides actually recommend disabling user namespaces because they are still somewhat new and perilous.
14.
▲
by
paulfurtado
4y ago
If you use cri-o as the runtime along with an openshift container registry, it will actually verify signatures at the runtime layer. In addition to crio, podman and anything based on containers/image supports this too. Really that just
15.
▲
by
paulfurtado
4y ago
Are you from the US or another country? Heinz uses different ketchup recipes in different countries and I personally think there is a huge difference. In the US, it is by far the best ketchup, but I hate the heinz in Canada. https:/&#
16.
▲
by
paulfurtado
4y ago
Since 2017, all new aws instance types have been "nitro", which is based on kvm https://www.brendangregg.com/blog/2017-11-29/aws-ec2-virtual... AWS does continue to support older instance types, however,
17.
▲
by
paulfurtado
4y ago
When standard filesystems like ext4 and xfs hit enough io errors,they unmount the filesystem. I find that this happens pretty reliably in AWS at least and I can't imagine the filesystem possibly continuing to do very much when 100% of
18.
▲
by
paulfurtado
4y ago
Yes, under a graceful live migration with no hardware failure, the data is seamlessly moved to a new machine. The problem of moving local data is ultimately no different that live migrating the actual RAM in the machine. The performance doe
19.
▲
by
paulfurtado
4y ago
I can actually say that not supporting this really does hinder crossplane adoption. At work we operate large shared kubernetes clusters. A team attempted to use crossplane and we immediately had to remove it from our clusters immediately be
20.
▲
by
paulfurtado
4y ago
It's not exactly normal, but it's probably a common enough experience in the US with 120v circuits and 15A breakers. Especially if in an old building with imperfect wiring causing excess resistance. Many devices also operate less
21.
▲
by
paulfurtado
4y ago
The disks are physically attached to the host. The VM running on that host moves from one host to another. GCP live-migrates every single VM running on GCP roughly once per week, so live migration is definitely seamless. Standard OSS hyperv
22.
▲
by
paulfurtado
4y ago
When a local disk fails in an instance, you end up with an empty disk upon live migration. The disk won't disappear, but you'll get IO errors, and then the IO errors will go away once the migration completes but your disk will be
23.
▲
by
paulfurtado
4y ago
Both GCP and AWS provide super fast and cheap, but fallible local storage. If running an HA database, the solution is to mitigate disk failures by clustering at the database level. I've never operated scylladb before, but it claims to
24.
▲
by
paulfurtado
4y ago
At a huge price, EBS can finally get you near-local-nvme performance. If you use an io2 drive attached to a sufficiently sized r5b instance (and I think a few other instance types), you can achieve 260,000 IOPS and 7,500 MB/s throughpu
25.
▲
by
paulfurtado
4y ago
I'm not sure if it comes out ahead on price, but I find Waka instant coffee to be great. Similar to your experience with Starbucks Via, it's the first brand that convinced me that instant coffee could be good. You can buy it on Am
26.
▲
by
paulfurtado
4y ago
It's definitely sad that there isn't built-in context support, but if you're looking for a solution to this, it is actually very easy to attach context to logs using threadlocal and a logging filter. When running a webserver
27.
▲
by
paulfurtado
5y ago
With 10,000 nodes running kube-proxy it is a bit expensive and, more importantly: error prone. A problem on a single node that wasn't even talking to the app could stop that app from exiting indefinitely if acks were required and clust
28.
▲
by
paulfurtado
5y ago
With kubernetes you can at least add a preStop hook that sleeps for 60-120sec if the app is not designed to handle SIGTERM. The pod enters the terminating state just prior to executing the preStop hook.
29.
▲
by
paulfurtado
5y ago
Are you aware of the kernel keyring and the keyctl API? I've always been curious why more programs don't use it, I guess it's not the most ergonomic API and doesn't have many language bindings. https://man7.o
30.
▲
by
paulfurtado
5y ago
gvisor is awesome and works for particularly untrusted applications, but it's not a performance hit we'd be willing to take across the board and effectively only protects you from security bugs rather than other kernel issues. We
More ›