HNHacker News
TopNewBestAskShowJobs

CoolCold

581 karma · joined February 26, 2022

submissionscomments
CoolCold··on Deno Under TinyKVM in Varnish
Afair Varnish can store cache in files too? I may be messing things here, as I use Nginx like 500 times more often.

If yes, you can store that data with fixed size tmpfs - while on servers with modern NVMe handling 5 Gbyte/sec I would not bother.

CoolCold··on Deno Under TinyKVM in Varnish
Indeed, that's one of the most popular cases and I even used it myself couple of times.

Though when frontend devs cannot explain which CORS headers and for which origins they do need (again, I'm sysasmin, not even daily reader of Mozilla Developer Network), chances for server/infra level like Varnish to be mentioned is close to 0. With higher chances k8s cluster introduction to be mentioned.

CoolCold··on Deno Under TinyKVM in Varnish
Nowadays I almost have zero intersection with Varnish - my own impression it was much more popular like 10 years ago or even more.

I know couple of frameworks/systems support it, especially in php world.

Looks like that it's lost in layers - dev guys don't care much, sysadmins are sort of extincted, noone to bother to add Varnish into request processing queue. Needless to say, people ok HN even complain on Nginx configs,while for base caching it's much simpler, from my perspective.

CoolCold··on Coolify: Open-source and self-hostable Heroku / Netlify / Vercel alternative
I have much more peace of mind when it's not in chroot but even better inside systemd unit and all that ReadonlyPath and capabilities applied. In the ideal case network access beyond localhost and may be db is denied for greater safety
CoolCold··on How I accepted myself into Canada's largest AI hackathon
I'm curios - my naive understanding that instead of using backend which will allow limited subset of actions/validate input, there is some 3rd party DB ( Firebase ?) which works via some sort of per-user API keys to allow fetch directly by frontend devs?
CoolCold··on Migrating from AWS to a European Cloud – How We Cut Costs by 62%
Long time Hetzner user, but I would not trust new system (S3 storage) in this case for things beyond playground and tests until it has at least couple of years in production - Hetzner just made it public in ~ Nov 2024.
CoolCold··on Kubernetes Home – what do you do if your ISP changes your IP addresses?
> because every time I set up a free v6 tunnel I get banned about 2 days layer for pushing a few terrabytes over it, when all I wanted was to be able to SSH into every one of my containers

can you describe a bit more? I cannot connect the dots here on how terabytes are tied to free v6 tunnel - likely I'm missing some details. Thank you in advance.

CoolCold··on Yoke: Infrastructure as code, but actually
it's not fair to ask such questions
CoolCold··on Linux’s Sole Wireless/WiFi Driver Maintainer Is Stepping Down
unrelated here, but I'm yet to get used to meet "I was a teenager" and "Windows 7" in a single sentence.
CoolCold··on Gixy: Nginx Configuration Static Analyzer
I've tried to try - yet still on Nginx as my primary web server and Apache somewhat secondary (with may be 5% for Apache and 95% for Nginx) web server of choice.

No doubts I'm not an expert in Caddy and there are some chances it has unique selling proposition, but I'm yet to find it.

My take on Caddy was - something to let your quickly-crafted-something-newshiny-loneley-dev-docker-container-to-be-available-to-the-world - sort of the same case if I do some tests (we call it MVP here) on my great-idea Flask app and I need plain reverse proxy in front of it with SSL termination, as noone except me and may be couple of Shodan bots won't see.

Yet not mentioned unclear stable releases policy for Caddy.

CoolCold··on Asdf Version Manager Has Been Re-Written in Golang
indeed, no discussions here (which I'm amused a bit of) - have everyone switched already to wise or uv or something else and asdf is not relevant for fellow sysadmins/devs anymore?
CoolCold··on I'm Done with Ubuntu
If someone was comparing - them should not. Podman + Systemd + Redhats system integration vs freeride Docker.

Hope it clarifies for you.

CoolCold··on I'm Done with Ubuntu
> Podman, Systemd, Wayland and tons of other software was created by or sponsored by Red Hat because everything has to be done their way

Not saying that you are not right, but for clarity, on Podman, and in lesser terms Systemd, there are valid points from RedHat - at least from my perspective as system administrator. I suggest you to make your own mind from this article[1].

> According to Walsh's presentation, the root cause of the conflict is that the Docker daemon is designed to take over a lot of the functions that systemd also performs for Linux. These include initialization, service activation, security, and logging. "In a lot of ways Docker wants to be systemd," he claimed. "It dreams of being systemd."

My key take - Docker's developers cared about moving forward fast and making dev's life easier, not about integrating into existing systems well (which probably alone is the reason why Docker was born - see how FreeBSD guys keep believing they have Jails and it's superior over Docker).

[1] https://lwn.net/Articles/676831/

CoolCold··on Managing Secrets in Docker Compose – A Developer's Guide
Hey, I smell sysadmins stuff in that lines

> RUN set -eux; \

> groupadd -r postgres --gid=999; \

> useradd -r -g postgres --uid=999 --home-dir=/var/lib/postgresql --shell=/bin/bash postgres; \

> install --verbose --directory --owner postgres --group postgres --mode 1777 /var/lib/postgresql

If we start managing [our] systems, won't we become those weirdo sysadmins we successfully (like 80%) escaped by moving things to Docker? Those guys in sweaters were annoying and moaning on "do this, don't do that, chmod 777 is not good for security"

CoolCold··on Ask HN: What is interviewing like now with everyone using AI?
not a problem yet - we still start asking hard question first - on differences on TCP and UDP and which one is better and why - very deep rabbit whole I must say. Then simple questions - how do you manage k8s clusters and what you suggest for multi DC setups
CoolCold··on Sixos: A nix OS without systemd [video]
I remember that on one of the $dayjobs around 2014 we have used runit, but I honestly don't remember why and what it gave us. Very likely just as auxiliary tool, not main init system.

Really curious now what it was so.

CoolCold··on Sixos: A nix OS without systemd [video]
> Yes, but not using those seems to defeat the point of using systemd.

I don't see how it defeats the point - it still nice init / services manager, it still provide features say sysvinit couldn't do at all for my _services_ and management/lifecycle of services.

How often I tackle with resolved or networkd or timesyncd - not even sure, may be once a 2-3 months, while systemd-as-service-manager I do almost every day.

Mind providing some example on your setup/cases?

CoolCold··on Official Arch Linux Image for WSL
Will it be legit enough to tell my classmates "I use Arch, BTW" if it's running as WSL distro on my Windows? :)
CoolCold··on Using uv as your shebang line
I have not checked how that works under the hood, but

> Both methods install the CLI tool, python3.12

Won't that require some compiler (GCC?), kernel headers, openssl-dev/gzip/ffi/other_lib headers to be present on end user system and then compiling Python?

At least that's my experience with ASDF-VM, which uses someother Python-setup toolkit under the hood.

CoolCold··on The Mythical IO-Bound Rails App
Everything is better with Nginx!

As sysadmin I've seen many cases when not letting backend to serve static files drops latency and load significantly. In the worst case, X-accel-redirect is still better than serving through most of the frameworks.

CoolCold··on The Mythical IO-Bound Rails App
Isn't pgbouncer putting extra limitations like prepared statemens use ? Genuine question
CoolCold··on Lenovo has removed the TrackPoint nub from new ThinkPad laptops
typing back from T16 Gen2 - here I don't disable trackpad (due to larger size I guess?) but, on my last T480 - it was surely disabled!
CoolCold··on FreeBSD Suspend/Resume
unluckily, FreeBSD project uses misleading info here - your apps are OUT of equation here, they do split "base" system (if traffic router is your appliance of choice, you may be fine with that), but all useful stuff is in "ports"/"packages" and is rolling updates.
CoolCold··on ZFS 2.3 released with ZFS raidz expansion
NTFS had compression since mot even sure when.

For other stuff, let that nerdy CorpIT handle your system.

CoolCold··on FreeBSD Suspend/Resume
> Why not FreeBSD 14.2 as its already available? Because pkg(8) packages are built against ‘oldest’ FreeBSD version in the current tree – which means FreeBSD 14.1 – and that often breaks kernel related packages such as really important drm-kmod or virtualbox-ose-kmod packages.

FreeBSD still lacks basic LTS functionality and keeping distribution coherent.

May be one day some vendor will create LTS distribution based on FreeBSD with at least 5 years support cycle?

CoolCold··on Developer wrote 25k lines of Neovim plugin code using phone and touchscreen
Airplane tickets by paypal- any other service except Agoda does this?
CoolCold··on Framework 13 AMD Review on Linux: Almost Perfect
For the website/server administrator, I'd recommend to hide MySQL (MariaDB) from public internet.
CoolCold··on GNU Shepherd 1.0 Service Manager Released as "Solid Tool" Alternative to Systemd
> make things overly complicated

Some people say that Systemd units are complicated or even Nginx configs are complicated or ... . Probably for those who do "Guile Scheme" everyday, it's easy peasy.

From my own experience, AFAIR, Django (python based web framework) tend to have settings defined in Python code, not in some sort of INI files/Config DSL or OpenProject heavily relies on Ruby code for configs - from my perspective [as operations guy] this requires extra work on unparsing those "beatiful" things like lambdas or whatever is cool new stuff people can put in such "configs". But for developers of Django/OpenProject - it's their daily stuff and not a problem at all.

So I'd say - depends on product's target audience.

CoolCold··on From where I left
> I think the thing that hurts a lot of folks is the one thing they wanted to do with Redis is use a managed version of it in AWS. And now they can't.

Hum, I have not considered this aspect before - I mean I've realized that AWS probably cannot use Redis [until they pay back], but that users (customers) would be affected...likely I'm biased here cuz not using managed services of that sort, sat having Redis + Sentinel setup of our own.

CoolCold··on Microsoft Discontinues iMac Rival Surface Studio 2
> resetting all the settings that changed in an overnight update

how to track those? I'm on the way of applying 24H2 update right now and laptop's uptime is 28 days, I may have many such settings changed, if I follow your idea correctly

← PreviousPage 4 of 20Next →