HNHacker News
TopNewBestAskShowJobs

magicpointer

63 karma · joined October 13, 2019

submissionscomments
magicpointer··on macOS Sonoma Boot Failures
Also with the M1 Pro MacBook, my LG USB-C monitor broke during the upgrade. Black screen, same on another connected USB-C laptop. Tried different cables, unplugging power from the monitor and factory reset on the monitor, no luck. Other inputs like HDMI and DisplayPort still work. I don't think the breakage during the upgrade is a coincidence.

I would really advise against having anything connected to the Macbook during upgrades, except the charger...

magicpointer··on Ory Kratos v1.0 with passkeys, MFA and multi-region
One approach that can be used is to use the centralized service to answer a broader question like: given this user, what rules can I use to know if a document is accessible for them. And have the service give you a set of rules to apply. Then take the result and embed those restrictions in your query.

An example access service response would be: this user can access data from groups they are part of + documents for which a share exists towards this user + documents for which a share exists to any of the users' groups.

Such an approach using OPA is described in https://blog.openpolicyagent.org/write-policy-in-opa-enforce....

This is not exactly the same as the first option you described, because instead of storing access controls in the index data, you use the available metadata + the rules from the access control service.

magicpointer··on Updates and Deletes on Columnar Postgres
Great product! I think with the updates and deletes it will be applicable to many more scenarios. HTAP is really getting important now that many more apps have user-facing analytics. In our case, we use plain PostgreSQL at the moment but I'm always on the lookout for PostgreSQL extensions. With Citus, Timescale and now Hydra this space is exciting!

I noticed by reading the documentation that the fact this is built on top of a Citus columnar fork is a bit hidden (mentioned only in a blog post). Why did you choose to fork rather than contribute to the Citus columnar project directly? AFAIK they also want to add update and deletes and vectorized execution.

magicpointer··on Podman Desktop: A Free OSS Alternative to Docker Desktop
Unfortunately I'm on MacOS and not Windows. But I'll pass this info to my Windows-using colleagues, thanks!
magicpointer··on Podman Desktop: A Free OSS Alternative to Docker Desktop
There's also Rancher Desktop in the same space, which includes k3s as a local K8s solution.

For personal use I found it great and lighter than Docker Desktop. At work, unfortunately all options but Docker Desktop have issues with either 1) Our Cisco AnyConnect VPN, or 2) Our authenticated http proxy. Couldn't find anything else providing a container runtime + a local k8s on MacOS that works in this environment. So we just got Docker Desktop licenses.

magicpointer··on Removal of Heroku free product plans
Fully managed PostgreSQL service, with point in time recovery like in Heroku + ability to take manual snapshots if needed. Daily snapshots are not flexible enough.
magicpointer··on Graphviz: Open-source graph visualization software
In a similar vein there is Schemaspy[1]. It generates a static documentation website for your DB, which also uses GraphViz to build ER diagrams.

[1] https://github.com/schemaspy/schemaspy

magicpointer··on UUID, serial or identity columns for PostgreSQL auto-generated primary keys?
To alleviate the issue of having a sequential part, they make it wrap around so that you cannot tell the order between two UUIDs. It's already some protection, and the random part is still large.
magicpointer··on UUID, serial or identity columns for PostgreSQL auto-generated primary keys?
About UUID as Primary Key and performance, the following article has some insights and benchmarks as well: https://www.2ndquadrant.com/en/blog/sequential-uuid-generato...

Essentially, they observed sizeable performance improvements by using UUID generators that are tweaked to get more sequentia resultsl. It results in better indexes. The articles compares sequences, random UUIDs and 2 kinds of sequentialish UUID generators.

magicpointer··on Casbin: An authorization library that supports authz models like ACL, RBAC, ABAC
Did you use OPA as a sidecar or a separate service? I have a similar setup but with a separate service the "diff pushing" approach adds quite some complexity, due to OPA and the data source having separate lifecycles.
magicpointer··on Ask HN: What to use instead of Bash / Sh for scripting?
Also go has the advantage of producing a single static binary. Easy to build on your machine and run on another host.
magicpointer··on I don't want to learn your query language (2018)
A JVM library in this space I recently started using seriously and fell in love with: jOOQ. It's not an ORM, rather a query builder but an extremely smart one.

In the codegen mode, it scans your DB schema and generates record classes + a lot of utilities. If the DB is well done (and it should be), it interprets many constructs, including relationships, domain types and various constraints. It can also generate activerecord-like classes if needed.

It allows far better safety and composability than raw strings and a lot of control on the query. Most DSL functions are called the same as in standard SQL, and the docs always shows the DSL next to the SQL version.

Everyone in the Java world seems to reach for JPA directly, but for me working with something closer to the DB is really a breath of fresh air. The DB-firat approach really works wonderfully.

magicpointer··on Threema – Secure and Private Messenger
The Swiss government is using the Threema Work version as its official internal messenger [1]

They also provide a transparency report about metadata shared with government agencies through court orders, requests have been going up in the last years [2]

[1] https://twitter.com/ThreemaApp/status/1095675070922534912?s=...

[2] https://threema.ch/en/transparencyreport

magicpointer··on JDK 15
This situation is still a bit hard to understand for me as a simple Java dev. Until now I thought that there were 3 kinds of "LTS":

1) OpenJDK Updates binary builds: they take the source code of the project, build it, and provide binaries. Examples I know are AdoptOpenJDK and the free Azul OpenJDK distribution.

2) Open source LTS: they take the OpenJDK Updates project, then add bugfixes they did for their PAYING customers. They publish the source code of the result. Here I see RedHat OpenJDK (such as the OpenJDK 8/11 builds distributed with RHEL 7/8). Those are then made available for free in binary form as well, such as part of CentOS. If you want a big fixed in those versions you have to pay, but you can benefit from bug fixes made for others. "LTS" here means as long as the RHEL version lives.

3) Paid LTS with custom support. Those do the same as 2, but don't release the source or binaries to the public, only to paid customers. Maybe there are even custom builds for specific customers. That would be Oracle mainly, and Azul and IBM as well.

What's unclear to me is if fixes from 2 flow into 1. Also, I don't know which kind Coretto is (Probably 1).

Is that a correct assessment of the situation?