If you want valid certs you can generate them with mkcert and add them to your system trust store.
1,514 karma · joined April 15, 2011
If you want valid certs you can generate them with mkcert and add them to your system trust store.
LLM's are surprisingly good at making diagrams in monospaced ascii or MermaidJS.
+----------------------+ +-----------------------+
| User Browser | | WordPress Site |
| (viewing from | CORS Error | (blog.com) |
| example.com) | Browser enforces CORS | |
| +------------+ | Direct request | +------------+ |
| | Frontend |<-----------------------------------X | xmlrpc.php | |
| | App | | example.com → blog.com | | | |
| +------------+ | | +------------+ |
+----------------------+ +-----------------------+
Browser security blocks cross-origin
requests (CORS is browser-only!)
The bottle app presumably uses some python library like Requests. It wouldn't care about CORS. +----------------------+ +------------------------+ +-----------------------+
| User Browser | | App Server | | WordPress Site |
| (viewing from | | (example.com) | | (blog.com) |
| example.com) | | | | |
| +------------+ | | +------------+ | | +------------+ |
| | Frontend |<-------->| | Backend |<---------->| | xmlrpc.php | |
| | App | | | | (Bottle) | | | | | |
| +------------+ | | +------------+ | | +------------+ |
+----------------------+ +------------------------+ +-----------------------+
Same origin Uses requests library Different origin
Browser allows this No CORS checks here! (Server doesn't care
(Not a browser!) about origin)Some of these comments suggest that having satellite internet onboard a cruise ship is a new thing. It's certainly not.
After some quick googling it looks like the current provider is O3b Networks (now part of SES), using modem equipment manufactured by ST Engineering iDirect.
I somehow doubt that when O3b Networks won that contract in 2013 it made the front page of HN. But now, there's "SpaceX's Starlink" in the title and it sits on #7 on the front page with 130+ comments.
"multipass launch" and "multipass shell" do the same as "vagrant up" and "vagrant ssh".
Vagrant has been around since 2010 and is super mature by now. Multipass seems to be limited to LTS Ubuntu releases, for now at least. There are Vagrant boxes for all Ubuntu releases but also Debian, CentOS or whatever else you would want to run.
I'm a sysadmin, so I like tools like this to test out provisioning of servers with configuration management such as Ansible or Puppet.
Running tests at the end where I actually test the endpoints of the deployed services would be really nice to have, but impossible to do through NAT.
I guess that's a niche use case for this because Vagrant had the same issue for a long time, where setting up a bridged network was not possible or required some hacks.
Yes, to address the United Nations.
I think it's a worthwhile study, especially considering such dogs are currently still used in law enforcement. It's important to be aware of the shortcomings and biases of this methodology, and to do so in a sound, scientific manner.
Starting in January, the ECB will stop the distribution of the €500 bill.
We're nearing the death of cash.
Being able to host my own authoritative servers for my domains inside my org is a fantastic feature of DNS.
It lets me do things like split-horizon, which lets me deal with clients coming from different origins that may reach certain servers with or without NAT.
I'm also not keen on putting all my records on public name servers, for everyone to discover.
They use "Deutsche" and "Danske" as a shorthand throughout the article itself, too.
rm -rf "${FOO}/"
ShellCheck helpfully warned me that that could have disastrous consequences when FOO is unset, instead it advised me to use this: rm -rf "${FOO:?}/"
I'd also like to point out that ShellCheck is in the AUR for users of Arch Linux[0], and that there's a handy plugin which I use for the Atom editor[1].[0]. https://play.google.com/store/apps/details?id=keepass2androi...
I agree it's very silly.
[0] www.bbc.co.uk/programmes/p01gns25
Clicking the first result will bypass the paywall.
These were not casual muggers, since they resorted to kidnapping, also keep in mind that this was done to steal a very valuable car.
With phones also now also becoming wallets, it's not outlandish to think a thief would cut off a finger.
You rarely see curl|sh installers for server stuff though. I think the topic at hand mostly concerns workstations.
It's really a shame that you have to wrap the best practices aproach in a bad practice in order to make it convenient.
> Point being that even if you install "the right way" on linux using package managers it's still a multi-step complicated process that benefits from being automated in a bash script.
Right, because distributions want different things than software authors.
If you're a Debian/Ubuntu/RHEL maintainer, you want stable, tested versions of software that you can vouch for and support for several years.
If you're the maintainer of an application, in this case Docker, you want your users to run the latest and greatest version of your software. You can't just demand that each distro just ships the latest and greatest version of your software. So if you're Docker you end up having to do the following for each distro:
* package the software for that distro
* sign that package
* serve your your own repository containing that package
* ask your users to add the repository
* ask your users to trust the signature
And then finally your users can install the package.That's one of the reasons I like running Arch Linux on my workstation. The desires of the software authors, distro maintainers and users align.
Docker Inc: "Hey wouldn't it be cool if your users could install the latest
stable version of Docker?"
Arch Linux maintainers: "Yeah, it would. We'll keep the latest version in the
repo and our users can just `sudo pacman -S docker`"
Docker Inc: "Cool."
Arch Linux users: "Cool."There's a section on their website[0] there are installation instructions for various distributions using repositories and package managers. In other words, the right(tm) way of doing software distribution on Linux.
But then on a different part of their website I found the curl | sh instructions you allude to[1]. Bizarre that they still support that installation method.
To make matters worse, the big orange "Get Started" call to action button actually leads to the curl|sh installation instructions. In light of that I certainly can't blame you for not knowing about the proper distribution packages.