HNHacker News
TopNewBestAskShowJobs

dkoston

413 karma · joined March 16, 2013

Early employee at some fun places (cPanel, Cloudflare). Builder of other less exciting things. Engineering Leader. Father.
submissionscomments
dkoston··on The Bullshit Web
True. Hopefully anti-competitive stuff like this will be challenged in court so we don’t have to play the game.
dkoston··on The Bullshit Web
I disagree that the AMP cache is the main benefit of AMP. There are plenty of CDNs that give performance similar to, or better than the AMP cache.

The only benefit of AMP is that the pages are promoted higher in results.

Back to the main topic of the article, the same could be said for the desktop and the mobile phone. Developers and framework builders are constantly adding bloat as cpu/memory increase. Since most people aren't writing their own frameworks and many are importing large parts of their apps from npm/gems/etc, everyone gets hit with the bloat. It's a vicious cycle for sure.

It's a shame that so many open source authors add bloat into their packages in exchange for popularity. They want all the users so you get tons of code that's never used in 90% of projects.

The big example of the above is express. It's a terrible cycle as the vast majority of people learning JavaScript have hopped on the express bandwagon and are now creating APIs with mediocre performance by importing a massive webserver they often do not need.

Overall though, it seems to show that most people prefer convenience over accuracy and performance (passive aggressive stab at mongo?)

dkoston··on 24% of Tesla Model 3 orders have been canceled, analyst says
There is no distinction in the reservation. When your reservation becomes available, you can configure any “trim” that is currently available. That was the long range first, and now long range and performance.
dkoston··on Improving our account management policies to better support customers
Exactly, it was a major process overhaul. They thought an automated system could handle this and then realized that was overzealous.
dkoston··on Improving our account management policies to better support customers
Kudos to Google for taking feedback and working internally to make things better. Too often do people expect every process at a company to work perfectly so it's great to see that the community has done a good job of providing feedback here and Google using it to improve.

I tend to stick with vendors who are open to improvement rather than expecting perfection up front. There's always something that can be improved.

dkoston··on ASK: Is Google cloud “private”, can it store PII, does it mine data like gmail?
Not true if you bring your own disk encryption keys. AWS also allows you to bring your own keys.
dkoston··on Show HN: Find your competitor's Websites
Be wary of shared SSL. For example, sites on Cloudflare often share SSL carts but are not owned by the same person. You may have to blacklist certs with Cloudflare CNs to avoid false positives.
dkoston··on Avoiding the Distributed Monolith
Totally agree this is content marketing. However, this topic is the wrong content for a contract firm. It would be great coming from a large tech organization who actually had metrics on monoliths vs microservices at different stages of growth. From someone who appears to never have worked on a project of massive scale, it comes off as sub par content clickbait.
dkoston··on Avoiding the Distributed Monolith
It’s good that you want to update it and make it better. However, it it works fine for the clients and they are happy, you should be too.

We all look back on our previous work and see room for improvement, that’s a good thing. However, spending too many cycles trying to achieve perfection where it’s not desired will prevent you from moving on with your life to bigger and better pursuits.

Be really happy that you have a software project which survived for 7 years. Many fail in far shorter time and provide no value.

dkoston··on Ask HN: Do worthwhile things have to be hard?
What’s your motivation for starting the endeavors in the first place? If you’re willing to give something up because it’s too easy, you are probably thinking about it incorrectly. Becoming the world’s number one pianist is not an easy task, it would takes years, or a lifetime.

Regardless, if you were on track to become the world’s best pianist and then gave it up because guitar is “harder”, why did you even want to be the world’s best pianist in the first place?

It sounds like you are dabbling in a bunch of things trying to see if somehow the learning of a new skill will give you a sense of enrichment. It will, however, that will fade quickly.

After learning a new skill and becoming “good” at it, there’s a lull phase where you think things are easy. That’s because you don’t know what you don’t know. Mastery of almost anything is hard and takes a long time.

All of this returns to motivation though. If you are looking for a short term sense of accomplishment, then dabble in a bunch of stuff and get “good” at it. If you are looking for a pursuit, find some motivation that will drive you to try and master something.

dkoston··on Avoiding the Distributed Monolith
Yes, others also include:

- Proxies that upload/retrieve assets to multiple cloud providers (i.e. upload files to / retrieve from GCS and S3 in case one is down)

- A service that screens/transforms attachments/uploads for security before allowing them to reach other services

- An API for sending mail/SMS/other contacts via multiple providers to deal with outages to one or more providers.

Often, these are before built as libraries and imported into multiple projects which is the wrong approach. Offering up an API for these instead can help decouple.

However, the author probably doesn't understand versioning and deprecates or makes breaking changes to APIs and then has to update a bunch of consumers. If you want a decoupled system, you have to not break the system. This is why legacy stuff exists at older companies. Once API v1 of the mail sending service is done and working, there's no reason you need to break it, or add new features, or take it down. Keep it running and also run v2 so that people can use the new features. The author is probably running v1 and v2 out of the same codebase and overwriting the v1 history so they can't maintain it, that's just bad software project management.

Maybe the title should switch to: "coordinating a complex architecture is hard, I only build easy stuff"

dkoston··on Avoiding the Distributed Monolith
Not sure why a contract development shop is putting stuff like this on their blog. Perhaps they have small clients asking for microservices when unnecessary?

Agree that this headline is presumptive and so is the article. Not every piece of engineering is a "slap it together in 3 weeks" build and many systems are designed with independent parts that use different technologies and scale at different rates.

I think what the author was trying to say is: "If you don't have enough experience to derive an architecture that isn't just some battle of buzz words or copying off blogs posts, you're in for a crude awakening when you have to maintain, scale, and refactor your work. Also, creating and maintaining a continuous delivery architecture with tons of moving parts is a lot of work".

At large companies (and small) devops, engineers, architects, CTOs, and many other players collaborate to develop an architecture which evolves over time and includes legacy systems, greenfield projects, duct tape, off-the-shelf bits, vendor-specific bits, open source bits, and other concerns that all have to work together. These organizations already have massive teams (or small and really good teams) taking care of making sure everything works together.

If you have a small team, little funding, and/or little experience you are probably getting in over your head trying to architect and orchestrate tons of moving pieces. It really depends on what you are building, your budget, and your team as to how you should build. Some industries and products require complexity, scale, and proper function from the beginning while others are accepting of bugs, scaling issues, and long delays.

TLDR: There's not a simple playbook that defines how everything should be engineered. Also, don't read some poorly written blog post which provides zero insight on the complexities of approaching an engineering challenge and decide to choose X or Y approach.

dkoston··on Former Walmart US CEO says Congress should consider splitting up Amazon
He has a massive conflict of interest because he was compensated heavily in Walmart shares, a direct competitor to Amazon.
dkoston··on Tesla Looked Like the Future, Now Some Ask If It Has One
Do you have 2018.10.4 or above? It drove me through 220 miles of rain including torrential downpours yesterday with ease. Up until that update, I’d agree that AP2 was sub par but the new update has dramatically improved EAP.
dkoston··on Large Scale NoSQL Database Migration Under Fire
No N1QL was involved that needed to be ported/re-architected?

N1QL was our primary use case for using Couchbase at my last position and it worked wonderfully (though at less than half your scale).

For straight key operations, the overhead of all the JVM stuff on couchbase seems like a lot, especially when considering the alternative amount of K/V stores these days.

Glad to hear Aerospike turned out well. Been keeping an eye on them over the past few years.

dkoston··on Ask HN: GitHub vs. GitLab paid plans (2017)
As a solo developer, wouldn't all these git repos be on your local machine as well?

What risk are you trying to avoid?

If gitlab or github is down and you have the repo locally, you don't have an issue.

If you've already handed off the repo to someone else, that's on them to store it and it'll likely be under their account.

I guess it's not clear from your intro what features you use 3rd party git hosting for other than backing up your repos.

Are you submitting pull requests to clients? Tracking issues? Other?

dkoston··on Ask HN: Who is hiring? (August 2017)
Help.com | Multiple Positions | Austin, TX | ONSITE | FULL TIME

It's 2017 and customer service still sucks. Companies have tons of data about you (what you've purchased, every page view to your site, every interaction you've ever had with them). However, that data is stuck in a bunch of fragmented systems and even the customer service systems they currently use don't connect their own data between different channels (tickets, chats, phones, etc).

Help us eliminate terrible customer service experiences by building out the world's best customer service and support platform. With workflows shaped from our time at HostGator (10M+ customers) and GoDaddy (10M+ customers), and technology skills developed from building cPanel, Cloudflare, CBS Sports apps, Node itself, and more.

We are predominantly in the JavaScript/Node.JS ecosystem, specifically a React/Redux stack on the front-end with Jest and Enzyme driving testing. On the backend, we launch Node.JS services of sizes ranging from micro to large. Everything is built and deployed in containers on Kubernetes and we're building for scale.

Our product is real time, distributed, and relies on a great user experience. Since we're a communications platform, we strive for 100% uptime (multi-zone, multi-region, horizontally scalable, cross datacenter replication). As such, simple things on a single application/server become fun challenges in a distributed system :)

Open Roles:

  - Quality Assurance Engineer (JavaScript)
  - Software Engineer (Front-end - React.js)
  - Senior Software Engineer (Backend - Node.js)
  - Software Engineer (Backend - Node.js)
Perks:

  - Working with 2 Node Core Contributors and tons of other smart folks
  - Founders have helped build many successful companies before (cPanel, Cloudflare, HostGator, etc)
  - On-site lunch
  - Well tested code and agile practices
  - Your code is used 8+ hours a day by our customers so you'll gain massive amounts of experience and feedback
Currently Predominant Technologies:

  - Node.JS
  - React/Redux (Jest, Flow, Enzyme)
  - Docker / Kubernetes
  - Google Cloud Platform, AWS
  - Message Queues (NATS, Google Pub/Sub)
Apply today at https://jobs.lever.co/help.com/
dkoston··on Ask HN: Who is hiring? (May 2017)
Help.com | Austin | Software Engineer (Front-end - React.js)| ONSITE

It's 2017 and customer service still sucks. Companies have tons of data about you (what you've purchased, every page view to your site, every interaction you've ever had with them). However, that data is stuck in a bunch of fragmented systems and even the customer service systems they currently use don't connect their own data between different channels (tickets, chats, phones, etc).

Help us eliminate terrible customer service experiences by building out the world's best customer service and support platform. With workflows shaped from our time at HostGator (10M+ customers) and GoDaddy (10M+ customers), and technology skills developed from building cPanel, Cloudflare, CBS Sports apps, Node itself, and more.

We are predominantly in the JavaScript/Node.js ecosystem, specifically a React/Redux stack on the front-end with Jest and Enzyme driving testing. Everything is built and deployed in containers on Kubernetes and we're building for scale. We are looking for a front-end engineer to assist with development for our customer service platform.

As our product is real time, distributed, and relies on a great user experience, we’re looking for an engineer that has extensive experience in building single page applications.

Qualifications - Extensive experience with React and it's ecosystem (Webpack, Redux, ES6, Flow), ideally on a single page app with 100,000+ users. - 3+ years experience with front end JavaScript development. Experience with Javascript testing frameworks such as Jest and enzyme. - Experience with REST-ful web services. - Experience working with Git. - Passionate about UX. - Experience with Agile methodologies and JIRA.

Perks - Working with 2 Node Core Contributors and tons of other smart folks - Founders have helped build many successful companies before (cPanel, Cloudflare, HostGator, etc) - On-site lunch - Well tested code and agile practices - Your code is used 8+ hours a day by our customers so you'll gain massive amounts of experience and feedback

Apply today at https://jobs.lever.co/help.com/

dkoston··on Let’s Encrypt, OAuth 2, and Kubernetes Ingress
Make sure to use an HPA and set up resource constraints on that ingress controller pod. Unbounded resource utilization may bite you in the a$$.

https://kubernetes.io/docs/user-guide/horizontal-pod-autosca...

Also, you may have redacted it but you don't appear to be adding a service with a static IP:

spec: loadBalancerIP: 1.2.3.4

Not having a global static IP for publicly accessible resources seems risky for uptime.

We've gone away from using ingress controllers and using services with static IPs + HPAs on nginx pods for this reason. Having to add a service + ingress controller adds complexity and doesn't really add value (IMO) since you can easily add nginx.conf as a ConfgMap and get the same ease of configuration as an ingress controller. Your mileage may vary with let's encrypt integrations.

dkoston··on Helm 2.0 stable release
Immutable containers still may need specific names when they are launched, netowrking settings, etc. Helm holds your deployment configs.

Think about having a redis cluster. You need 6 redis containers (at minimum), known names to add to your connection settings in your apps, a job container to run redis-trib, etc.

Using helm has let us define a redis cluster configuration that we know works well and anyone at the company can now launch one just by flipping out the pod (container) names, setting a namespace, and configuring memory and CPU limits.

For monolithic applications this stuff won't be super useful (or for simple software applications) but in a modern SOA, it saves us tons of time. Need a HA Postgres setup for your new microservice? Great, just change the name of the database pods to match your service name and run "helm install -f my-service-db.yaml postgres"

For us at Help.com, it's the new Ansible. We run everything in kubernetes and Helm ensures we have consistent deployments of containers for database clusters, redis clusters, message queue clusters, etc.

In addition, the delete feature is amazing when developing your configs. Previously we had to run a ton of kubectl commands to clean up after testing runs or put stuff in a specific namespace which we deleted and recreated. With Helm, we can simply delete a Helm release and it takes care of removing the pods, services, deployments, secrets, etc.

dkoston··on Ask HN: Who is hiring? (November 2016)
Help.com | Austin, TX | on-site or remote | Sr Node Developer

Love node? Hate terrible customer service experiences? Come work with two Node CTC members and a bunch of other smart and experienced engineers at Help.com.

Present day customer service experiences show that customer service software isn't providing companies with the tools they need to deliver great experiences. With all the data a company knows about its customers, contacting customer service should be smooth sailing rather than "what's your account number?" and "hang on for 3 minutes while I look that up".

Help us elevate customer service and get thousands of people off the chat, ticket, or call minutes faster.

Tech highlights: Node, Kubernetes, Docker, golang, microservices, React, Redux, and a CTO who helped build cPanel and many projects at CloudFlare.

https://jobs.lever.co/help.com/ea972c24-982c-4724-bb4a-11cdf...

dkoston··on Node v6.9.0 (LTS)
Sorry to hear about your experience. Been using it for years as part of our build processes with no false positives.

You're always welcome to write a replacement if you find it unsuitable.

dkoston··on Node v6.9.0 (LTS)
Seriously? It takes 5 seconds to add an eslint rule to avoid this issue.

http://eslint.org/docs/rules/handle-callback-err

dkoston··on Cloudflare app for thedaywefightback.js
https://github.com/dkoston/thedaywefightback

The banner code is pulled in from the awesome work that thedaywefightback.org folks did. The repo basically shows how to package an app for CloudFlare.

dkoston··on Don't Ignore the Trolls. Feed Them Until They Explode.
Corporatism was developed by the Greeks and viewed in a positive light when pondered by the likes of Plato. In such a light, the concept is often viewed positively.

Later, the concept was also used by some fascist states, especially Mussolini's Italy. In this sense, it was used in a more negative light.

As such, corporatism is not necessarily a fascist concept but I can see how you could make that connection.

There wasn't any indication from my side that I wish to maintain a coalition of powerful subgroups. However, I'd be naive to argue that any large scale society has existed without a number of subgroups who either share power within the accepted system, or take power from outside its constraints. This is because society is made up of people who have all sorts of positives and negatives but have also adapted to form groups (families, tribes, states, nations).

The thought was initially posed due to the limited time and effort that any human being has. If you want to go through the list of groups that experience the most harm and reduce that harm and move onto the next group, you need some way to choose which group to start with. Devotion to that group or perceived ability to change their fate are simple ways to select which cause (not necessarily group) to align yourself with.

In no way does that require you to align yourself with only one cause or group or exclude yourself from the same. For example: being devoted to your family doesn't make you not devoted to your country, it simply adds additional complexity to the rules and scope of your devotion to both groups.

dkoston··on Don't Ignore the Trolls. Feed Them Until They Explode.
You can't use only the statistical properties of a subset to determine it's moral weight. For nearly any statistic you can think of, there are massive (i.e., 2^bignum >> population of earth) numbers of statistically identical subsets.

A core part of this disagreement/discussion is that there is no accepted formula for determining moral weight.

It's certainly fine to have a discussion at more of a core philosophical level but I think that your arguments would more accepted by the HN audience if you would provide more context about what level of depth you are choosing to discuss instead of calling the article "ridiculous" and providing a single data point about one of the many thoughts posed by the article.

Most people responding are considering the current state of the world and what incremental actions they would take to improve it, not philosophical questions like "what is a harm?", "which harms are worst?", "should we eliminate harms?", "is it right to eliminate harms from one group over another?"

There are many tough questions that need to be answered before you can even discuss selecting or not selecting groups of people and considering their moral weight. Without posing or answering questions like "what is a harm?", "what harms are not permissible?", and "should we eliminate harms?", it's impossible to know whether or not we will be at a philosophical impasse when asking "should one group get additional weight for societal protection from harms over others?".

dkoston··on Don't Ignore the Trolls. Feed Them Until They Explode.
You can only determine which deserves more weight by your ability to change an outcome or your level of devotion to that outcome being changed. Women clearly have a vested interest in reducing negative outcomes for their group, just as furries, latinos, gays, asexuals, etc do for their own groups.

If you're arguing that it's silly to place all our emphasis on a single group rather than trying to make society better by not giving preference to any group, that would be a potentially valid argument however, it's one that likely wouldn't survive outside a classroom setting.

History has shown us that the banding together of some groups (civil rights movement for blacks, women's suffrage for women) has worked to enact change.

I'd assume that a psychological influence towards change may be that it's easy to feel sympathetic to a group when you have a personal connection with one of its members. Having no clear members to connect with (in a world where no groups are given preference) would prevent people who are close minded from feeling sympathetic towards change. That is simply an assumption though. I tend to lean that way because it has been shown that facts don't win arguments(1). As such, I am doubtful that providing evidence to harassers about the ill effects of their harassment or evidence about the potential benefits of them stopping would have any effect on their behavior.

In addition, the problem of harassment, bigotry, and prejudice is one that is both complex and large in scale. It seems logical to break this larger problem into smaller batches (i.e. working on the most populous groups that are affected) in order to promote immediate change instead of waiting for a solution to completely solve the problem (which is unlikely to exist).

(1) http://bigthink.com/think-tank/the-backfire-effect-why-facts...

dkoston··on Don't Ignore the Trolls. Feed Them Until They Explode.
It's been clearly documented that women are subject to lower wages(1) then men and while I don't have statistics about online harassment, women accounted for 84% of potential workplace harassment victims in 2007(2) which may or may not be similar to the online harassment gap. USC also did a study noting that men are less empathetic to discrimination(3) which can cause even more harm.

You argue that choosing any subset is arbitrary but it is clearly not if we choose that subset based on a set of data that shows behavior which society disapproves of (attaching criteria to our subset inherently makes it non-arbitrary).

Now, you could argue that choosing women as a subset is arbitrary because you don't think that the representation of people on money should be correlated to population statistics. However, why are you arguing against correlation for pictures on money but not also arguing that nothing should be correlated to population statistics at all (or perhaps your comment wasn't perfectly written? same as the article?).

In general, it seems that you are also choosing to be arbitrary as well. In addition, you seem to lack compassion for other people who are expressing their concerns about their right to live a happy life, free from harassment. Whether or not you agree with the small details in the article or whether or not they are 100% accurate is not important. If you can't read the article for the overall concept it purveys, and feel some sympathy for the author, I feel sorry for you.

(1) http://www.bbc.co.uk/news/education-21698522 (2) http://www.workharassment.net/index.php/sexual-harassment-in... (3) http://www.livescience.com/2428-men-discrimination-women.htm...

dkoston··on Ask HN: How do you drive web traffic to your successful side projects?
"traffic" is a really ambiguous word. If I take it at face value, it's really easy to drive traffic to a site: - recruit a bunch of affiliates to post pages with links back to your site (be discriminating on quality and frequency) - use paid ads - connect with a reputable backlink service that doesn't trip Google's radar. - distribute a javascript widget that is hosted on your servers - run a big promo with the promise of free gadets

However, I'm assuming what you really want is users/conversions. In that case, you need to think about your project/site/business as a relationship between 2 parties with the internet simply being a more scalable medium for communication between you.

To get people interested in a product/service, it has to fix a pain point, be really interesting, or you have to be the best. You can "be the best" by showcasing your knowledge of the problem with blog posts, interviews, helping people out on forums, and becoming involved in communities that would be in your target demographic (forums, meet ups, irc groups, etc).

Fixing a pain point or being really interesting is a product /market fit problem so if you've shown your site/product/service to a lot of people and it's not sticking, you need to do in-person interviews to figure out what's not good enough.

In general, if you're trying to build up traffic, that's really building up a community of people (who are the source of good traffic) so you need to approach that in the same way you'd build up a community offline: be interesting, be a good community citizen, and give without asking much in return.

dkoston··on Poll: Will you be changing how you manage your data after the NSA scandal?
Cloud services provide great help but blindly relying on their security doesn't make sense. If you built the system ground up, you'd take time on security so you should do so with your data no matter where its located. Tools like BoxCryptor (or encfs for us diy folks) make quick work of securing remote files. If you store trade secrets or pass sensitive information through cloud services, you should consider the risk/reward of choosing those over a solution you can have more control over (and consider if there's an option to secure your data). While remotely hosted applications can make life easier, you need to always consider that security and convenience are at odds.
← PreviousPage 5 of 6Next →