HNHacker News
TopNewBestAskShowJobs

amouat

1,656 karma · joined December 9, 2008

Currently Technical Community Advocate at Chainguard. Wrote "Using Docker" for O'Reilly.

http://www.adrianmouat.com

submissionscomments
amouat··on Dario, Please
Right, you mean it didn't go through a gateway? But would that actually have helped? The requests all went through jfrog didn't they? I guess it depends on the level of filtering at the gateway?

Whilst it might not be JFrog's threat model, I wouldn't assume it can be used as a full internet proxy.

I don't really mean to defend OpenAI here, but they did make some attempts at sandboxing. Although it does seem that they didn't really know what they were doing.

amouat··on Dario, Please
Isn't that exactly what they did? The bots could only access the jfrog instance, so they hacked jfrog?
amouat··on Being ambitious and being a dad
I don't disagree, except that you've taken ambitious to mean climbing the corporate ladder, which is a relatively narrow reading.

It can also mean wanting a achieve a large dream or goal e.g. writing a book.

amouat··on Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)
Yeah. But it's 10 paragraphs of AI nonsense that barely mentions the actual story.

Who could have thought this was a good idea? It literally reads like "ai security is important, btw we're the reason hugging face got hacked, we're awesome at securing things"

amouat··on Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)
So they are the proxy in the hugging face hacking incident?

Way to bury that lede.

amouat··on We all depend on open source. We will defend it together
No, not really, and I don't think you need to be snarky.

It may be an industry body, but it runs multiple community conferences and projects which support Open Source. A notable example in this case being the OpenSSF https://openssf.org/

The LF is not perfect, but I would expect them to come from an OSS and community angle on this.

amouat··on We all depend on open source. We will defend it together
My best understanding from reading this is a) where possible and b) where necessary. This is the Linux Foundation, so it must put OSS and community first, surely.

People talk about contributing financially, but how and to what end? Most projects aren't set up to accept or utilise donations. That said, I would say we should be providing all OSS projects with significant access to AI in order to review their codebases and PRs and hopefully relieve some of the maintenance burden. I know there are some initiatives in this area already.

amouat··on The most unlikely school bag
I stopped reading in anger at "That’s not an accident; it was the point."

It's pretty disrespectful imo -- it feels like the reader's time is worth less than the author's.

amouat··on Gonon: Building a Clock with No Numerals
That's what I thought, but in the 2nd para:

> No Roman numerals. No Arabic numerals. No left-to-right reading direction. No assumed orientation. Something that works in a mirror, in zero gravity, in any language spoken on Earth or beyond it.

As other comments have pointed out, base 10 is a pretty big assumption though.

amouat··on Statement from Dario Amodei on our discussions with the Department of War
I noted "warfighter" as well. Never heard that before.
amouat··on Vim-pencil: Rethinking Vim as a tool for writing
I played with some of these tools 12 years ago and created "dim", but it was really just Vim with limelight and goyo in a Docker container.

https://github.com/amouat/dim

There is something nice about having the editor as a separate command especially for writing.

amouat··on A novelist who took on the Italian mafia and lived
I assume they just pretend to be the Googlebot so the site just gives the text.
amouat··on Ask HN: Share your personal website
Personal blog: adrianmouat.com
amouat··on Find a pub that needs you
Seems to be England only. No results for Edinburgh.
amouat··on I Want You to Understand Chicago
It's all the same people. If you really don't know, a few of the incidents are here: https://www.bbc.co.uk/news/videos/c6299nrj76yo
amouat··on MinIO stops distributing free Docker images
The ladder is still there! See that pile of wood there? That's where we put the rungs. And if dig in that hole over there you might even find the extension we removed last week...
amouat··on Docker Model Runner
I'm pretty sure that's in development, it's just more difficult.
amouat··on SimSig: Railway Signalling Simulations
Also traksy e.g: https://traksy.uk/live/T+EDB+KGX+d+@2024-07-10T13:00/M+1+EDI...
amouat··on Tmux is worse-is-better
Just wanted to say that I appreciate how well written this is. It does make a difference when an author can clearly and succinctly state their case.
amouat··on I found one of my first programs (Java, 2011) on the Wayback Machine and it runs
I wrote a similar program once. To get it to be efficient I had to use a bunch of heuristics including scrabble scoring words, so it would prefer words with low scrabble scores which were more likely to fit in with other words.
amouat··on Jeff Geerling: Corporate Open Source Is Dead
The declining share price and profits is exactly what made it possible for IBM to buy Hashicorp. The license change didn't juice things -- it watered down the price. $6 billion is a snip compared to the $14 billion IPO valuation.

Fintan Ryan has a nice write-up here: https://medium.com/@fintanr/on-ibm-acquiring-hashicorp-c9c73...

amouat··on Psychedelia syndrome: the pixels and code of Jeff Minter's 'Psychedelia'
From @stefantalpalaru (comment dead)

> The software being used to illustrate an unrelated song: https://www.youtube.com/watch?v=L7UsnI_HQYM

amouat··on Ask HN: My Cofounder was diagnosed with cancer, what should I do?
Support him? Start by talking to him and seeing what he thinks is fair.
amouat··on Nix is a better Docker image builder than Docker's image builder
I'm using this quote:

"I love it but sometimes it feels like being a Morty on Rick’s adventure to the compilerland."

amouat··on Chainguard Images now available on Docker Hub
Sort of.

A few things though:

- we don't use scratch. Our base image is chainguard/static which includes certs and a few other things typically needed by apps.

- we have our own Linux distribution called Wolfi

- we don't "defeat scanners". We work with scanners and publish security advisories. They recognise Wolfi. You can definitely find some images of ours that have CVEs (especially if you have an old image lying around).

amouat··on Chainguard Images now available on Docker Hub
I did a short YouTube version of the announcement: https://www.youtube.com/watch?v=QuyBWDx21d0
amouat··on Chainguard Images now available on Docker Hub
I work at Chainguard.

In a nutshell we produce minimal container images with a low CVE count. In many cases they should be drop in replacements for the containers you are currently using.

This is particularly useful if your team uses a scanner like trivy/snyk/grype/Docker Scout and spends time investigating CVEs. Less CVES == less time investigating. It can also be critical in regulated environments.

amouat··on Musl 1.2.4 adds TCP DNS fallback
Wolfi packages are served from https://packages.wolfi.dev/os which can be used with apk tools or apko.

The built Chainguard images are all on the cgr.dev registry.

Wolfi is completely OSS.

The policies regarding Chainguard Images have changed over time, so if there are docs that don't properly reflect this, please let me know and I'll get them updated.

amouat··on Musl 1.2.4 adds TCP DNS fallback
I'm very sorry that we broke things for you.

To be clear, nothing has changed with Wolfi. Wolfi is an open source community project and everything is still available there: https://github.com/wolfi-dev/.

We have made changes to Chainguard Images - our commercial product built on top of Wolfi - which mean you can no longer pull images by tag (other than latest). Chainguard images are rebuilt everyday and have a not inconsiderable maintenance cost (and the money we make here directly helps us support Wolfi).

The easiest way to avoid this is to build the images yourself. You can rebuild identical images to ours using apko and the source files in the images repo e.g: https://github.com/chainguard-images/images/blob/main/images... (note you can replace package names with versioned versions). You can also just use a Dockerfile with the wolfi-base image to "apk add" packages. Full details are here: https://www.chainguard.dev/unchained/a-guide-on-how-to-use-c...

I agree that pinning is a best practice. The above blog explains that you can still do it using a digest, but I accept this isn't the simplest solution.

If I can help any more, please feel free to get in touch - you can find me most places including twitter https://twitter.com/adrianmouat

amouat··on Musl 1.2.4 adds TCP DNS fallback
You might want to check out Wolfi and Chainguard Images. Wolfi is a Linux distro that we use to build minimal images that are roughly comparable to Alpine in size but, everything is compiled from source against glibc.

Our images come without a shell or pacakge manager by default, but there are -dev variants that include these.

https://github.com/wolfi-dev/ https://github.com/chainguard-images/images

Page 1 of 13Next →