HNHacker News
TopNewBestAskShowJobs

JustinGarrison

879 karma · joined March 5, 2011

justingarrison.com

justin@linux.com

submissionscomments
JustinGarrison··on AWS App Runner
We optimized the service to work with any container instead of eliminating cost. If you're not getting requests you have a reduced cost for consumed memory and instances but by keeping one warm it makes it so you don't have to engineer around cold starts.

We may add scale to zero in the future. Would love to hear about your use cases on the public roadmap https://github.com/aws/apprunner-roadmap/projects/1

JustinGarrison··on GKE Autopilot: an nodeless and elastic Kubernetes cluster mode
I put together a comparison thread between GKE autopilot and EKS with managed node groups and EKS with fargate.

Autopilot has some benefits depending on how you use Kubernetes.

https://twitter.com/rothgar/status/1364680396315631617

JustinGarrison··on Pixar in a Box: the art of storytelling
Creativity Inc came out in 2014 and John left in 2019. I'm not sure how that would have been covered or relevant to the book.
JustinGarrison··on Getting Started with Signal
I have a link in the post on how to use a twilio number instead of your real phone number. Signal PINS is the first step to making non-phone number identification work.

https://support.signal.org/hc/en-us/articles/360007059792-Si...

JustinGarrison··on Getting Started with Signal
iMessage does store a secure key locally on your device which never leaves. The main difference with iMessage is Apple is able to add more signing keys to decrypt the data if they wanted. This is what happens when you add a new device.

In a no-trust model once you sign in on a new device you wouldn't see all of your old messages. Because all of your old messages are decrypted and sent to the new device this is evidence that a new signing key was added to the communication chain.

Apple could also do this to decrypt your messages to give to a government agency or for whatever purposes they want without notifying you.

https://techcrunch.com/2014/02/27/apple-explains-exactly-how...

JustinGarrison··on Infrastructure for rendering and streaming movies (Kubecon 2019)
This talk was from kubecon na 2020, not 2019.

2020 was a looooooong year y'all

JustinGarrison··on Infrastructure for rendering and streaming movies (Kubecon 2019)
A lot of you seemed interested in Pixar's renderfarm [1] so I wanted to share my high level overview of what it takes to create a movie from my experience at Disney Animation and stream a movie from experience at Disney+

[1]: https://news.ycombinator.com/item?id=25615888

JustinGarrison··on Pixar's Render Farm
I worked at Disney Animation on the Linux engineering team for a few years. The flexibility of Linux was a key enabler for us being able to produce movies the way we did. Artists overall seemed to love the power of the Linux desktop setup we provided.
JustinGarrison··on Pixar's Render Farm
Same here. I had some passing information from Pixar, WDAS, and ILM and they were pretty much all NFS. Lots of NFS caching (avere) and high performance NFS appliances in use.
JustinGarrison··on Pixar's Render Farm
I worked at WDAS and remember talking to the ILM team testing out the mesos VDI stuff. AFAIK it never left the POC stage but it was a really neat demo.

My team at WDAS mirrored pretty closely what Pixar did with VDI although we didn't fully switch to it for different reasons (power and heat constraints in the datacenter and price). IIRC the VDI hosts had static VMs and the teradici connection manager did all the smarts of routing user requests to a VM. There was no dynamic orchestration for us because we only had 60ish users using full VDI VMs, but even our plans of hundreds of users was still to use teradici and standard VMs on each host.

We rendered different than Pixar which also made our system a bit more static. We didn't have a separate render VM and instead rendered directly on the workstation VM when users were idle or disconnected.

JustinGarrison··on Ask HN: Best Talks of 2020?
There are some HPC environments that use Kubernetes but they likely use custom schedulers optimized for batch workloads (e.g. https://github.com/volcano-sh/volcano).

"containers" are often used but not always docker containers. HPC environments I've seen will often use container primitives (e.g. cgroups, namespaces).

There's a lot you can learn with managed Kubernetes and it's a great place to start. You can learn a lot of the parts of Kubernetes with running through https://github.com/kelseyhightower/kubernetes-the-hard-way or reading https://www.amazon.com/Kubernetes-Running-Dive-Future-Infras...

I'll email you to follow-up since tracking HN comments isn't a great way to have a conversation.

JustinGarrison··on Ask HN: Best Talks of 2020?
Rendering is different because the assets are very interdependent and the tooling is very POSIX specific. Rendering a scene (especially with ray tracing) can use thousands of assets from the movie even if they aren't directly on screen. Artists draw and save files in tools like Autodesk Maya and renderers read files from disk and work on them while in memory.

For some assets and tooling FUSE mounted s3 can work but generally FUSE and other userspace mounters I've seen slow down artists and rendering measurably.

Think of rendering assets more like code files and git with trunk based development. You want all of your artists to use the latest assets which are daily being updated. All of the assets should be co-located and you don't want geo-replication because of latency. Even if your artists are located all over the world you'll want them to store the saved assets in one place. Where the rendering happens.

There will be different assets that are hot as the movie progresses. But you're more likely to try to keep the latest version of all assets hot rather than all versions of specific assets hot.

Most studios use HPC style environments. NFS + big compute servers connected with high bandwidth.

JustinGarrison··on Ask HN: Best Talks of 2020?
The storage animation goes through some of it but for the basics using something like an 80/20 rule for content popularity you can also apply that to data cost. Your most popular 20% of content needs to be as close to the client as possible and will probably be the most expensive for you to store (typically in 1 or many CDNs).

The next most popular 20% will probably be semi expensive but doesn't need to be as close. This can be a subset of CDNs (where it financially makes sense) or georeplicated s3 buckets.

The lower ~60% of your content probably doesn't get accessed very often (relative to "hot" content) and depending on your content and user demands can probably live in your own data centers or POP locations.

You'll want to make it as easy as possible to promote/demote content into these tiers. Content popularity happens seasonally and in different regions so keeping the APIs similar between tiers will help you a lot. S3 is a pretty good standard to build toward so you'll probably want something like that on-prem or in your k8s clusters (minio, swift, etc.). We're also talking about each movie having potentially thousands of assets to track (different encodings for video and audio and different DRM wrappers etc) and hundreds or thousands of terabytes for big catalogs. So using immutable object storage is going to save you a TON of time instead of sticking with POSIX based block or file storage.

During the file ingest (when your encoding it) you're probably going to be dealing with POSIX based files so the encoders can work on the file but you'll want as many systems after that dealing with object storage as soon as possible.

JustinGarrison··on Ask HN: Best Talks of 2020?
Thanks! I was constrained by the talk length but intended it to be a starting point for future conversations if people are curious about details. Zach Bintliff has a reinvent talk in January going over some details of how we did deployments at Disney+ if you'd like some specific details about that part of the stack.

The QR code was intended to be functional and worked in editing but I never got it to work after uploading to youtube. It was just a link to justinplus.com

JustinGarrison··on Ask HN: Best Talks of 2020?
I'm going to humbly put my kubecon talk here because it's unlike any conference talk you've ever seen and I'm really happy with how it turned out. https://youtu.be/VtedIghTPzI
JustinGarrison··on Palm – The best small phone for minimalists, athletes, and kids
I wrote a review of the phone after using it as my primary device for a while

https://www.justingarrison.com/blog/palm-companion-review/

JustinGarrison··on Ask HN: Who is hiring? (January 2019)
Disney Streaming Services (formerly BAMTECH Media) | SRE/Infrastructure Engineer | REMOTE (US) or New York, NY | Full time

Looking to add 1 person to the infrastructure team supporting and building Disney's streaming service (Disney+) in AWS.

Currently support many different streaming platforms including ESPN+, NHL, MLB, MLS, PlayStation Vue, HULU live, Twitter live streaming, and more.

Lots of exciting changes coming this year and plenty to learn.

Apply here: https://jobs.disneycareers.com/job/new-york/infrastructure-e... Email or DM me questions: justin.garrison@disneystreaming.com or @rothgar on Twitter

JustinGarrison··on The Economics of Writing a Technical Book
author I'm not sure on this, but I don't think we can. I'm sure if I asked to quote parts of the book they would give me a free license to use the quotes but the contract says O'Reilly gets exclusive usage. FWIW O'Reilly also filed the copyright on our behalf. I never had to do anything to get the book content copyrighted.
JustinGarrison··on The Economics of Writing a Technical Book
I'm glad you liked it. I wanted to write down all the information I wish I had a year ago before I started writing the book.
JustinGarrison··on The Economics of Writing a Technical Book
Yes, there were a few diagrams. We gave rough sketches and descriptions of what we wanted an they had someone create the diagrams for us.
JustinGarrison··on The Economics of Writing a Technical Book
Did you change jobs? Were you able to negotiate a higher salary because of the book? Seeing as this book was just published in November I'm curious to learn how to leverage it into a more long term success.
JustinGarrison··on The Economics of Writing a Technical Book
I completely agree! I learned a lot through the experience of writing the book. I probably put more thought into the topic than most people during the same time which helped me refine my definitions and become more of an expert as I was figuring things out.

The only difference I think is I'm very happy with how our book turned out. It was a ton of work but I'm grateful that other people have been able to learn from our experience.

JustinGarrison··on The Economics of Writing a Technical Book
That's phenomenal! I agree that building an audience is the hardest part and it's what traditional publishers bring to the table for most people. Just last week I saw someone self-publish some artwork in an area they have an audience and they made $4000 in a day. The only marketing they did was a single tweet. I don't think most individuals would be able to gain this level of authority without years of work and spending lots of money traveling to and speaking at conferences and writing blog posts or publishing videos.
JustinGarrison··on The Economics of Writing a Technical Book
author here From what I hear from other O'Reilly authors my experience was more negative than most. We got very little support from our editors because of various situations (job change, maternity leave, etc.)

If I tried to self-publish my first book it would have never happened. I feel like there's too much to figure out I'd spend a year yak shaving and never produce a book. O'Reilly helped me focus on writing and making the content good and they took care of the rest. Coordination with editors, reviewers, and actual printing I'm sure would have taken me months to figure out and with O'Reilly it was just weeks.

Marketing had some push just because it was an O'Reilly book. Podcasts picked it up and that is where the sponsors started to get interested. If it were a self-published book I doubt it would have carried the same authority and not had as much interest. WRT sponsors, I did no work to bring in the sponsors or organize contracts. I only had to review the foreword and then was sent an "congratulations" email from O'Reilly that the book was sponsored. I did a webinar for one of the sponsors for free but haven't done any other work. We also were lucky enough to have CNCF marketing sponsorship who sponsored some of the book signings at events.

I still think O'Reilly added a lot to the process. Most of the extra work I did (website, affiliate programs, ad campaigns etc.) were minor work and didn't drive any meaningful sales.

Let me know if you have other questions.

JustinGarrison··on The Economics of Writing a Technical Book
I wasn't given an option when starting the project. They just set us up with Atlas and AsciiDoc.
JustinGarrison··on The Economics of Writing a Technical Book
author here Do you have examples on how you would correctly capitalize on this expertise? I put some things that have happened since writing the book in the outcomes section but so far they have all been free speaking engagements.
JustinGarrison··on Ask HN: How is your standing desk working for you?
I've been using a standing desk in various forms[1] since 2009. I've also been using dual vertically stacked monitors for a long time and love it when using a standing desk. I wrote my thoughts about how to be successful 4 years ago[2] which break down to.

1. Get a padded mat or soft shoe inserts 2. Don’t force yourself to stand 100% of the time 3. Always start your day standing

I also wrote about how to modify your existing desk[3] or build/buy[4] a standing desk. I haven't taken pictures of my standing desks since ~2014 but my setup hasn't changed much.

[1] https://goo.gl/photos/cUuQvoguMoz7Czj7A

[2] https://medium.com/@rothgar/how-to-be-successful-with-a-stan...

[3] https://www.howtogeek.com/99961/how-to-modify-your-existing-...

[4] https://www.howtogeek.com/100748/15-ideas-to-buy-or-build-yo...

JustinGarrison··on Casync – A tool for distributing file system images
I'd be really interested in creating full disk images and then cloning to another disk. If that is a use case (I think I skimmed the post correctly) it could be very useful and performant over dd and similar disk cloning tools.
JustinGarrison··on Intel's Remote AMT Vulnerability
If I have AMT enabled on systems that never leave my network and no ports are forwarded through my firewall this should not be a problem. It could be a problem if someone found a bug in my router and got through the router but I'd be more concerned about iot devices than AMT on a couple desktops.
JustinGarrison··on Ask HN: How has volunteering helped you grow?
I volunteered to start/run a podcast for the Linux Mint community[1]. I helped host, edit, and hosted the site from 2009-2011. I stopped at episode 50 because I had a kid and went back to school. Near the end of 2010 there was a call for writers for a website I was reading at the time[2] and it even paid money ($20/article). I had no writing experience except for random posts I put on my personal blog at the time. I was told later that a main reason they hired me was because of my podcasting experience.

Because of the podcast I got plugged into more of the Linux community and started attending and occasionally speaking and volunteering at my local Linux conference[3]. A couple years later I was looking to make a jump from low level manager to sysadmin. I had no professional sysadmin experience but I had these two "hobbies" I put on my resume which ended up landing me the job.

My first year at the conference (2008?) I met some people who I got along with and saw them almost every year at the conference for ~5 years. In 2014 they asked if I was looking for work (I was) but I had only been a sysadmin for ~10 months and had no other professional experience outside of helpdesk roles and manager. They hired me because of my pitiful 10 months of experience and all the additional areas where I showed expertise (podcast, writing, speaking).

I've been at the new job for 3 years now and my name is in movie credits for Oscar winning films which is something I would have never expected. I've grown a lot in every new opportunity I've been lucky enough to have.

[1]: http://mintcast.org [2]: https://www.howtogeek.com/author/rothgar/ [3]: http://socallinuxexpo.org/

← PreviousPage 5 of 6Next →