Fck-nat: The (f)easible (C)ost (k)onfigurable NAT
fck-nat.dev
fck-nat.dev
It only gets more expensive when you actually serve large amounts of traffic, need multi-AZ setups, and run multiple AWS accounts for different envs for beta/prod and each engineer's sandbox account. The worst part of cloud billing is how each base cost has several dimensions of multipliers.
I just use public IP addresses.
It's fine, it works. Worked for EC2-Classic, works today.
The website is pretty explicit about that it's testing if a domain/website is available over IPv6 vs IPv4. Clicking on a website also sends you to https://ipv6.fail/domain/cloudflare.net/ where it's even more explicit what they're testing against. Wouldn't call it misleading exactly.
I'll be sticking with ipv4.
Source: I have used NAT64 myself before.
Far too many people forget about that and send their AWS traffic through their NAT GWs.
And AWS is like 10x more expensive than dedicated hosting, minimum. Not 10%, 1000%. To the point that for the price of
I mean if cost matters to you you need to move out of the cloud. Plenty of Kubernetes hosting these days, and very easy to set it up yourself.
As someone who is new to setting up VPCs and networking, how does this work? I was so curious I even tried to query ChatGPT about it a couple of days ago but I got a less than satisfactory answer.
Is the secret to making it work disabling the "source destination check"? Say a host in the private subnet wants to connect to a host on the internet, it tries to connect to <PublicIP>, and sends some IP packets over the subnet via the ENI, does the VPC subnet act like an old-school ethernet connection where fck-nat gets the IP packets for <PublicIP> (source/dest is disabled so it receives the packets) and then it forwards it to the internet gateway and does the network address translations when it receives a response packet?
You've got the gist of it, but you probably want to read about NAT and iptables.
The source destination check is important - but implementation specific here. Google Cloud does it like this - https://cloud.google.com/vpc/docs/using-routes#canipforward
From the VPC perspective, the key here is understanding that subnets within VPCs have route tables that determine where traffic from your subnet goes next. In this case traffic to the internet is sent to an interface on the NAT instance.
The longer term vision for fck-nat is a two node approach using conntrackd and keepalived to actively failover existing connections to the secondary with no loss of availability. This has the added benefit of not requiring all of the auxiliary infrastructure that Alternat sets up.
IPv6 internally doesn't stop you running public IPv4-accessible services.
https://docs.aws.amazon.com/vpc/latest/userguide/aws-ipv6-su...
The other thing is the port allocation algorithm. Many home routers try to preserve the source port (assuming its available.) But there's other algorithms that could be used here like independent delta +1 (increment each new mapping by +1) and others. IDK if there's a target market for something this specific or niche. But thought I'd put it out there.
I'll try and deploy this. Our NAT costs aren't that high, but reducing spend is worth an hour or two. I might leave this as something for the new guy, just so we can see if he can do it without taking down the environment.
maybe something like: ufck?
Even when poking fun at myself, I choose names of projects carefully. It's pretty easy to not be a jerk, at least in this way.
How could you possibly know this, where do you draw the line?
For something people, "Hacker News" is surely offensive because "hacker" is generally thought of as a negative term (Yes, I know our meaning, others generally don't).
GitHub could also be offensive to some, "git" after all is as much of a swear-word as "fck".
Good luck explaining a less-techy client at your job that fck-nat, fsck (which was originally just "fuck", afaik) and so on are fine puns and no one's holding a gun to their head either. I feel similar about recursive acronyms. These are funny-ish when you're in your mom jokes phase, but then someone asks you what that means and sometimes you can see their "what a bunch of creeps" reaction when you try to explain. Not surprising that people try to avoid that "we can use FCK for our SHT instances in CRP network" nonsense.
You learn something new every day. To be fair, this rename is 10 years old!
(Linus was supposedly well aware of the meaning when he chose it.)
In many countries c*nt is one of the more terrible swearwords could imagine. In Ireland it's friendly banter. d*ckhead can be either a term of endearment amongst (close) friends, or an insult in Australia, and worse in other countries.
In many, if not most, non American countries, f*ck just doesn't cut the mustard when swearing.
Heck, in the UK, they have a major high street brand called FCUK.
EDIT: Here: https://cme.h-its.org/exelixis/pubs/JanThesis.pdf
= filesystem check
please stop being this thin skinned
> First, let's review what fsck, or the File System ChecK program, actually does.
Again, stop being this amount of thin skinned, it is rather ridiculous.
Also, I find your reaction thin skinned-ish as well. Why throw stop commands if you ought to not care? Cause it’s ridiculous? Well, we have more in common than you think then.
Oh really. You're the one who can't shut up about some app that used to be named f*ck but was renamed some 30+ years ago still grinds your gears.
It's an (ancient) light hearted joke, please just drop it.
I care about the state of the world, and I find it deeply depressing people run around being prude like we're some kind of Christian middle ages society.
Here's the thing: there is no reason not to keep pointing out that these are just bad names. And by pointing that out every time, someone might just pay attention and give their tool a better name in the future, because they took heed and decided against calling their tool "cwnt" in favour of calling it "check-wnat". And you will never know it could have been called the "oh stop being so thin skinned" cwnt.
And as a bonus, folks don't have to guess at what it does, the name tells you. Imagine if fsck had just been called checkfs... it would have been both a better name and would have saved a lot of askubuntu/superuser/etc posts.