HNHacker News
TopNewBestAskShowJobs

awoimbee

165 karma · joined January 5, 2021

[ my public key: https://keybase.io/awoimbee; my proof: https://keybase.io/awoimbee/sigs/zXvGiUE1SCnJE6BECDg-dtfoUlxXqcpD1VEk1Z9nIYw ]
submissionscomments
awoimbee··on OpenAI: Migrating to HTTPX2
I opened an issue some time ago about them monkey patching urllib3, it was fixed than but I now see the issue has been outright deleted. Oh and now I see there is a URLLIB3_NO_OVERRIDE thing... I would not recommend this project.
awoimbee··on [dead]
I personally use fzf and I'm pretty happy with it, this seems to do a lot more but it's not clear what exactly ?
awoimbee··on IceCream – Never use print() to debug again
Debugging in python is already so easy with `print(f"{myvar=}")` and `breakpoint()`...
awoimbee··on Sem: New primitive for code understanding – not LSPs, but entities on top of Git
The benchmarks aren't great, they're super specific to sem's output: why would I ask Claude how many "entities" were modified by a commit and do I need a tool specifically for this request ? Note that an "entity" is a sem-specific concept...
awoimbee··on Codex just found a "workaround" of not having sudo on my PC
Use podman then, or rootless docker if you can make it work
awoimbee··on DeepSeek reasonix, DeepSeek native coding agent with high caching and low cost
You didn't quote the interesting part:

> our implementation is it only prunes calls from > 3 user messages ago, if context is > 40K, and only if there's at least 20K tokens to be removed

Seems reasonable to me and explains why I can have long sessions (way longer than with zed agents) while still hitting cache. Opencode is just missing per-provider TTL.

awoimbee··on Dirtyfrag: Universal Linux LPE
And your containers need to have specific capabilities enabled, which aren't by default on kubernetes and podman.
awoimbee··on Moving a large-scale metrics pipeline from StatsD to OpenTelemetry / Prometheus
Directly emitting metrics using OTLP instead of having the OTel receiver scrape the metrics endpoint is interesting. I never made that move because the Prometheus metrics endpoint works and is so simple, and it's what most projects (eg kubernetes) use.
awoimbee··on OpenSUSE Kalpa
Tubleweed has snapshots and rollbacks too by default. But yeah immutable distros are good for beginners so they don't destroy their system!
awoimbee··on Infrastructure decisions I endorse or regret after 4 years at a startup (2024)
I was the sole DevOps at my company for a long time, the team is now bigger. I used terraform for AWS and pulumi for K8S (terraform was too restrictive).

IMO pulumi is a huge gain of productivity when you know what you're doing. Cons: * It's plagued by bugs and the pulumi-kubernetes provider is not getting enough attention from the pulumi team (they're always working on compatibility with yet another language instead of focusing on one thing) * You end up with your very specific/personal codebase instead of having a generic/standard thing

Still, no regrets, I saved so much time thanks to pulumi!

With a bigger team: * Oboarding people takes more time * You end up with code quality issues. Most "DevOps" people aren't devs, sadly.

awoimbee··on Garage – An S3 object store so reliable you can run it outside datacenters
How is garage for a simple local dev env ? I recently used seaweedfs since they have a super simple minimal setup compared to garage which seemed to require a config file just to get started.
awoimbee··on Core Devices keeps stealing our work
That's why the GPL license was created.
awoimbee··on Helm 4.0
The feature that makes me love pulumi is crd2pulumi, it generates simple, type checked and documented libraries from CRDs.

E.g. these are the libs I use, generated from CRDs: https://github.com/Extrality/pulumi-crds

awoimbee··on Hyperflask – Full stack Flask and Htmx framework
I ran into: - too high memory usage - no warning when a task doesn't yield - monkey patching: * general confusion like threading.local behaving differently * pain to integrate sentry in gunicorn with gevent since you need to import sentry after monkey patching. The OTel libs work better but you need to be careful * all compiled libs need to be replaced (eg psycogreen) ...
awoimbee··on Hyperflask – Full stack Flask and Htmx framework
Building a framework on a non-async foundation (flask) in 2025 is bizarre. The only way to scale a flask API is to use gevent, which is just problems waiting to happen. Asyncio is just better, safer and has been adopted by the industry.
awoimbee··on iPhone Air
THANK YOU FOR YOUR ATTENTION ON THIS MATTER

This announcement contains so many fake marketing words I can't help but read it in DJT's voice... Add Tim Apple's present and yeah, cool tech, not interested.

awoimbee··on I ditched Docker for Podman
The main issue is podman support on Ubuntu. Ubuntu ships outdated podman versions that don't work out of the box. So I use podman v5, GitHub actions uses podman v3, and my coworkers on Ubuntu use docker. So now my script must work with old podman, recent podman and docker
awoimbee··on Unfortunately, the ICEBlock app is activism theater
This can't be reduced to a boolean (as always). The issue is that ICE is doing #2 via #1.
awoimbee··on XZ Utils Backdoor Still Lurking in Docker Images
Containers != Docker Vulnerable software is an issue outside containers too. Containers allow better isolation.
awoimbee··on Google restricts Android sideloading
I can't find sources to this one sided article nor can I find anything recent when searching for it
awoimbee··on CVE-2024-47081: Netrc credential leak in PSF requests library
That's some horrible url parsing code...

But honestly urllib sucks:

url.hostname doesn't return the port url.netloc also returns the basic auth part So you have to f"{u.hostname}:{u.port}"

awoimbee··on Ask HN: What projects do you donate to?
I donate to immich even though I still use Google photos since I don't want to host critical infra in my spare time

https://github.com/immich-app

awoimbee··on Writing "/etc/hosts" breaks the Substack editor
I'm in the position where I have to run a WAF to pass security certifications. The only open source WAFs are modsecurity and it's beta successor, coraza. These things are dumb, they just use OWASP's coreruleset which is a big pile of unreadable garbage.
awoimbee··on Observability 2.0 and the Database for It
It looks like what the grafana stack does but it's linking specialized tools instead of building one big tool (eg linking traces [0]).

The only thing then is that there is no link between logs and metrics, but I guess since they created alloy [1] they could make it so logs and metrics labels match, so we could select/see both at once ?

Oh ok here's a blog post from 2020 saying exactly this: https://grafana.com/blog/2020/03/31/how-to-successfully-corr...

[0]: https://grafana.com/docs/grafana/latest/datasources/tempo/tr... [1]: https://grafana.com/docs/alloy/latest/

awoimbee··on Ask HN: Who is hiring? (February 2025)
Ansys SimAI | DevOps (more developer than SRE) | REMOTE (France, office is in Paris) | Full time

We're building products to predict the results of numerical simulation and act on them. Since joining the Ansys portfolio we are experiencing more demand than ever and we need help to transform a good product and infra into something truly great.

At SimAI we lightly use AWS and heavily depend on Kubernetes, both being 100% configured through Infrastructure as Code (a bit of terraform and a lot of pulumi). You will mostly work with Typescript (pulumi), Python (scripts and application code), Bash (scripts).

As a DevOps at SimAI you will work with me on exciting subjects like moving the compute closer to the customer, you will also work on improving our security posture and help secure more certifications for our platform. As part of my job at SimAI I personally maintain <https://github.com/Trow-Registry/trow>.

Don't hesitate to apply, motivation matters as much as experience to me ! Apply here: https://careers.ansys.com/job/Montigny-le-Bretonneux-Senior-...

awoimbee··on Wordpress.org Login: "I am not affiliated with WP Engine in any way"
The offer was quite good honestly: people who left got a $30k buyout.
awoimbee··on NumPy QuadDType: Quadruple Precision for Everyone
> The long double type varies dramatically across platforms: > [...] > What sets numpy_quaddtype apart is its dual-backend approach: > Long Double: This backend uses the native long double type, which can offer up to 80-bit precision on some systems allowing backwads compatibility with np.longdouble.

Why introduce a new alias that might be 128 bits but also 80 ? IMO the world should focus on well defined types (f8, f16, f32, f64, f80, f128), then maybe add aliases.

awoimbee··on A single server can go a long way these days
In the current ecosystem even for a single server I would use K8S via something like minikube. You get for free: operators, observability, a standard API (so you can use helm and such), ...
awoimbee··on How I won $2,750 using JavaScript, AI, and a can of WD-40
That 8th entry pouring loads on WD40 on trees is just crazy, that thing is petroleum distillate !
awoimbee··on We cut costs by 70% by moving from GCP and CockroachDB to Hetzner and PostgreSQL
For a single node cluster, just use minikube (or RKE2 if you have masochistic tendencies). And if everything runs on a single small vps, why even use postgres and not SQLite.
Page 1 of 3Next →