Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tetha
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
151.
▲
by
tetha
1y ago
This is how I have it with my guitar. It's a simple Ibanez Gio from a starter kit, probably coming in at 150 Euros - 200 Euros or so, with another 40 Euros spent on a guitar tech to set it up properly. I'll replace it once I know
152.
▲
by
tetha
1y ago
I can't help but read those as Bolt Thrower lyrics[1]. Singled out - Vision becoming clear Now in focus - Judgement draws ever near At the point - Within the sight Pull the trigger - One taken life Vindicated
153.
▲
by
tetha
1y ago
You don't even have to go that far. Firefighters have core pulling kits that take care of 90% of all locks in 2 minutes tops. And for most other locks, the thing holding the lock tends to be less of an issue than the lock.
154.
▲
by
tetha
1y ago
I prefer to combine this with FixedRandomDelay=true. FixedRandomDelay ensures that the randomized delay is an arbitrary number up to RandomizedDelaySec, but it is deterministic per server and timer. I find this useful because this means th
155.
▲
by
tetha
1y ago
In general I try to use odd times for cronjobs. Backups starting at XX:13, analysis scripts at XX:23, data exports at XX:42 and so on. This simplifies the question of "Why does my system go whack at 23:23? Oh, wait".
156.
▲
by
tetha
1y ago
Yes. I have mentioned this internally, but my boss has agreed to keep it.
157.
▲
by
tetha
1y ago
Obsidian also has affordable commercial pricing. By now I very much try to pay support contracts or give back to projects in other ways at work. The problem is that quite a few open core companies immediately go from $0 / year to low t
158.
▲
by
tetha
1y ago
I'm not in our consulting parts for infra, but based on their feedback and some talks at a conference a bit back: Vendors have been working on standardizing on Kubernetes components and mechanics and a few other protocols, which is sim
159.
▲
by
tetha
1y ago
Part of the company I work at is doing infrastructure consulting. We're in fact seeing companies moving to bare metal, with the rise of turnkey container systems between Nutanix, Purestorage, Redhat, ... At this point in time, a few re
160.
▲
by
tetha
1y ago
Heh, I was wondering if you could do something like SSRF exploits, just the other way around. You know, redirect the bot to <cloud-provider-metadata-api>/shutdown. Even funnier, include the EICAR test string in the redirect ot th
161.
▲
by
tetha
1y ago
Mh, in my recently slightly growing, but still tiny experience with HW&DC-Ops: You have a lot more things in a DC than just GPUs consuming power and producing heat. GPUs are the big ones, sure, but after a while, switches, firewalls, st
162.
▲
by
tetha
1y ago
Mh, one of our security admins recently said something that's very fitting to the discussion: If you are removing an employee from a company, and you have to rely on their personal integrity instead of technical controls to avoid probl
163.
▲
by
tetha
1y ago
Oh those size limits are pushed plenty by AI images, no worries. I recently had a good laugh when I found a docker image that was 2 - 3 times as big as the OS partition of a lot of our smaller servers. And our OS image build order would reu
164.
▲
by
tetha
1y ago
I think that the practically available type checkers evolved to a point where many of the common idioms can be expressed with little effort. If one thinks back to some of the early statically typed languages, you'd have a huge rift: Yo
165.
▲
by
tetha
1y ago
I enjoy Sandi Metz' point there as well: Code just looking the same is not enough to call it duplication. Once you have to change two places looking the same to add a new feature or to fix a bug, then you have duplication and should ce
166.
▲
by
tetha
1y ago
This is why I'm sad that hungarian notation has gained into such a bad reputation. Sure, you can overdo it, but a `duration_ms` or a `response.size_bytes` or a `max_memory_mb`, or an `overhead_ns` is so much easier to use.
167.
▲
by
tetha
1y ago
This is our documentation workflow as well: Write it, and then have someone less or not experienced with the system execute the runbook. Also, encourage everyone to work on refining and improving the docs, because after 5 years with a syste
168.
▲
by
tetha
1y ago
Hence you need to start thinking about threat models and levels of compromise, even in your build system. If I control the issuing and governance of these short-lived secrets, they very much help against many attacks. Go ahead and extract a
169.
▲
by
tetha
1y ago
> But why would an npm token in angulartics2 have publication rights to tinycolor? Imo, this is one of the most classical ways organizations get pwned: That one sin from your youth years ago comes to bite you in the butt. We also had one
170.
▲
by
tetha
1y ago
But if we think about a release publishing chain like a BSD process separation, why do they have to be? Sure, there will be a step/stage that will require access to NPM publish credentials to publish to NPM. But why does this stage nee
171.
▲
by
tetha
1y ago
> Only bad experience I remember from Java was the int/Integer primitive/object issue and boxing. Heh, I once had to work in a code base that used an `Integer premiumDefenseLevel`. It contained the level of premium defense a pl
172.
▲
by
tetha
1y ago
There are some baking recipes which measure the other ingredients relative to the weight of the eggs you have at hand. Like, "flour equal to twice your eggs weight"
173.
▲
by
tetha
1y ago
This is causing management at the current company to run in circles a bit as well. The company has been fairly adamant about having support contracts for systems, and it has encountered a number of these stunts. Opscode with chef a long tim
174.
▲
by
tetha
1y ago
When we looked at modernizing our image hosting, it came down to Zot vs Harbor, and we preferred Zot as it looked easier to deploy. Just a go binary with a few environment variables connecting to our minio, what could be easier? However, wh
175.
▲
by
tetha
1y ago
I currently have one concept stuck in my mind, which I would call "Complexity distribution". For example, at work, the simplest solution across the whole organization was to adopt the most complex PostgreSQL deployment structure a
176.
▲
by
tetha
1y ago
> 2. (a few moments later) Onoz, engineers cost money and that sweet VC juice dries up > > 3. echo BuSL > LICENSE; git commit -am"License update"; blog about "safeguarding our customers" or whatever In this
177.
▲
by
tetha
1y ago
I agree. We do have mirrors setup, we do have observability into the images we use across the infrastructure. This has concluded we only have a minor issue with this move, wonderfully. But, just butting users with "Just do this good pr
178.
▲
by
tetha
1y ago
It's also entirely fine if they delete these images to me. But not with a week of time frame, as originally intended. And sure, we can go ahead and discuss how this being free incurs no SLAs or guarantees. That's correct, but does
179.
▲
by
tetha
1y ago
Aye. Between Lets Encrypt and compatible vendors, and e.g. Vault for internal CA-chains, /issuing/ certs in a secure, controlled and audited way (at least for the internal ones) is indeed a solved issue. We do have a lot of intern
180.
▲
by
tetha
1y ago
I deal with a few code bases at work and the quality differs a lot between projects and frameworks. We have 1-2 small python services based on Flask and Pydantic, very structured and a well-written development and extension guide. The newer
More ›