Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
weavenetwork
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
weavenetwork
11y ago
Thanks @takeda. Are you aware that we did not roll our own crypto? Instead we used the NaCl crypto libs[1]. Weave adds about 300 LOC to integrate NaCl. You can read about it here - http://docs.weave.works/weave/late
2.
▲
by
weavenetwork
11y ago
What about them? Would you recommend one of them over the others?
3.
▲
by
weavenetwork
11y ago
I'll have to stop saying please when in the US then ;-) But seriously, thanks for taking the time to explain your point of view. alexis.
4.
▲
by
weavenetwork
11y ago
cripes. on each host? what kind of physical network are you using, and how many containers per host? how many hosts? let me know if I should email about this instead.
5.
▲
by
weavenetwork
11y ago
What throughput do you need, on a per-host basis?
6.
▲
by
weavenetwork
11y ago
We are open to recommendations, help and overall insight from expert contributors in security. As many people on this thread have pointed out, it is a big and complex world..
7.
▲
by
weavenetwork
11y ago
We did not roll our own crypto. We used NaCl. The rationale is explained here - http://weaveworks.github.io/weave/how-it-works.html#crypto We agree that other approaches are possible, but this is the one we picked f
8.
▲
by
weavenetwork
11y ago
No, for example it is 100% uncharitable and unreasonble to assert that "please" is sarcastic. The truth is quite the opposite.
9.
▲
by
weavenetwork
11y ago
Paul, I think our work is good. We thought about our approach very carefully.. And we have built systems like this before. The main difficulty is to combine moving fast with limited resources, with delivering something supportable and im
10.
▲
by
weavenetwork
11y ago
Complaining on twitter is not the same as finding an issue! Criticism has value, but not all commentary deserves equal weight or time before it is reasonable to request reciprocal effort.
11.
▲
by
weavenetwork
11y ago
indeed. at the risk of entering tinfoil hat land, note the following http://blog.cryptographyengineering.com/2014/12/on-new-snowd... ..although also the not 100% reassuring https://nohats.ca/wordp
12.
▲
by
weavenetwork
11y ago
although, sometimes not obviously so: https://github.com/GoogleCloudPlatform/kubernetes/pull/4483#...
13.
▲
by
weavenetwork
11y ago
Tony, the team recently updated the crypto docs to clarify the rationale etc etc - http://weaveworks.github.io/weave/how-it-works.html#crypto ... Moreover the entire crypto code for weave is about 300 lines. Please pl
14.
▲
by
weavenetwork
11y ago
Using an account that I share with other people in the same team is not the same as 'marketing'. I am sorry if this somehow offends, but think of the handle as just one poster.
15.
▲
by
weavenetwork
11y ago
edit: here is a kubernetes link: https://github.com/GoogleCloudPlatform/kubernetes/pull/4483#... the author, who was part of the MS Azure team at the time, said: "as of today, this Weave/CoreOS tool
16.
▲
by
weavenetwork
11y ago
True. We did try ipsec, and couldn't find an implementation that was oss, demonstrably safe, and easy enough to pull into a first release. As weave matures, we'd love to work with experts to implement standard solutions, even if
17.
▲
by
weavenetwork
11y ago
I'm sorry but I find your interpretations of 1-4 completely uncharitable and unreasonable.
18.
▲
by
weavenetwork
11y ago
I don't think anyone meant, or said, "fuck you". Why are you even implying such a thing? Ultimately we can't work on even a fraction of the features that every person wants, and Laurie said his idea was simple to implem
19.
▲
by
weavenetwork
11y ago
as laurie mentions in his article, you can easily use off the shelf security solutions with weave... the point of the current crypto is to provide something basic that works. we chose nacl for ease of implementation primarily. happy to ad
20.
▲
by
weavenetwork
11y ago
You can of course use etcd with weave... indeed weave can be run with no dependencies, so it may make sense as a way to bootstrap etcd ;-)
21.
▲
by
weavenetwork
11y ago
I haven't seen those used in the wild yet, but fwiw, weave is working on a 'fast data path' that uses the same kernel path as ovs
22.
▲
by
weavenetwork
11y ago
I should add that one way to get more throughput is to use more than one CPU.
23.
▲
by
weavenetwork
11y ago
yes, microseconds surely - we estimate that the cost of switching from kernel to user space, and back again, several times, adds up to 2-300 microseconds. in return for this, you gain a lot of flexibility and ease of use. for apps that ne
24.
▲
by
weavenetwork
11y ago
I'm not sure why you think so, but fwiw, irl, I am alexis at weave dot works
25.
▲
by
weavenetwork
11y ago
Correct! Once upon a time people said Amazon cloud was too slow. Then they said it wasn't suitable for large workloads. Then they said it did not make money ... etc etc. I'm not saying we are like Amazon, I'm just saying
26.
▲
by
weavenetwork
11y ago
That's an entirely subjective statement. What do you mean by 'large'?
27.
▲
by
weavenetwork
11y ago
hello, weave here. a few very quick comments! weave has lots of very happy users who find that weave is plenty fast enough for their purposes, see eg http://blog.weave.works/2015/02/24/get-your-kicks-on-cloud
28.
▲
by
weavenetwork
11y ago
Hoping to see something soon! We at Weaveworks are involved and mentioned progress on our blog this week.
29.
▲
by
weavenetwork
12y ago
this began as a chat between me and solomon, and I then invited everyone at dockercon who was implementing network/extension related stuff. this all happened over a few hours... so wasn't possible to invite folks to hop on a plan
30.
▲
Using Fig and Flocker to build, test, deploy and migrate multiserver Docker apps
(clusterhq.com)
14 points
by
weavenetwork
12y ago
|
1 comments
More ›