Somehow I was able to get it to work, but I have memories of trying to compile programs and having to dive into the source and make changes with the blind confidence only a teenager could have. I'm surprised the system was as stable as it was
Somehow I was able to get it to work, but I have memories of trying to compile programs and having to dive into the source and make changes with the blind confidence only a teenager could have. I'm surprised the system was as stable as it was
That is an awesome sentence. I sometimes miss this blind confidence I had as a teenager.
Specifically, I want to make some devops tools that I need and don't exist yet:
- A simple HTTP file server that uses mutual-TLS for auth and all configuration comes from a single TOML file. Passwords are poisonous to security. Stateful config APIs are poisonous to maintainability.
- A lightweight Dockerd replacement that uses mutual-TLS for auth, fetches binaries from the file server, actually verifies the SHA-256 digest of binaries (dockerd doesn't), and receives all configuration by HTTP PUT of a single config.toml file. It will store VM stdout logs locally and make them available via mutual-TLS HTTP.
- A metrics server that fetches logs via mutual-TLS HTTP, stores them in the file server, parses them (as JSON), calculates metrics and alarm states, caches derived data on the file server, serves a dashboard, re-exports specific metrics and alarm states, and notifies third-party services (Pagerduty/Opsgenie) on alarm state changes. All config comes from a single config.toml file.
- A simple monitoring daemon that performs repeated website and API requests and emits metrics to logs. These get picked up by the metrics server.
- An infrastructure management tool without the problems of Terraform. Specifically, it must support creating resources which contain other resources. And it shouldn't require the maintenance nightmare of multi-stage Terraform deployments.
I started writing this stuff in Golang. But I quickly became frustrated with Golang's incomplete libraries. There are stupid things missing like min(int,int) and basic synchronization structs (WaitableBool). Golang's http library doesn't support dynamic server-side request timeouts or mutual-TLS. I guess they want you to run Golang servers behind nginx or expensive Google Cloud load balancers, probably on Kubernetes. No thanks.
I learned Rust and started writing the tools above. I fell in love with forbid(unsafe). All of Rust's HTTP server libraries contain copious amounts of unsafe code. And none support mutual-TLS. So I started writing a safe Rust HTTP client & server library. Half-way through, I realized how much unsafe code is in tokio & async-std. So I wrote and released a small safe Rust async runtime, called "safina". Amazingly, it works. I resumed working on the HTTP library, adding TLS support. Then I realized that rustls has a lot of unsafe Rust/C/assembly code. So I started writing a safe Rust TLS 1.3 library. Now I'm deep into that project. It's satisfying.
I wish you will forget your limitations and try new things without reservation.
If you're using shared hosting, or your data has any value, why would you use anything besides a reverse proxy/Wireguard to access your hosted application server?
Wanna double click that risky .exe from a torrent? Linked clone that base Windows install.
I didn’t really get to a command line again until Mac OS X some years later.
I’m so jealous of today’s budding computer nerds. The world is their oyster. Info about how to use new things is very accessible. Damn kids /s.
That's how I got my monthly PC Magazine subscription (this was when they were the best magazine about PC)
Also good technical books were practically non-existent
I got my first Assembly and Norton's book from a bookstore specializing in bootleg copies
Only years later I began to be able to buy good books
Things are so much better now, thankfully
I went through a few Linux distributions for it: MkLinux first, then LinuxPPC, and finally Yellow Dog Linux. The driver for the Ethernet card needed to be patched for big-endian machines and the kernel needed a patch to allow the ADB keyboard CapsLock to be remapped to Control. Fun times.
These PPC Macs are a bit overlooked, in my mind, but of course this is exactly the era that I really started to get into computers. Just seems like everyone else is either attracted to the compacts, or the colourful iMac era ones.