305 karma · joined November 1, 2014
Thank you for sharing! Yes, macOS has such logic and it works just fine. The main issue from clatd that it's pretty tricky to setup and it emulates presence of IPv4 on machine which is not very desirable as it tends to hide issues with other tools.
My plan was to explicitly disable IPv4 connectivity for machine and hide it from other app but keep it active for subset of well known broken tools and then fix them one by one and switch to IPv6 only setup.
More complicated load balancing protocols may need more complicated balancing microcode and eBPF will be helpful in this case.
One of the main differences between BPF and eBPF is number of allowed instructions and it's very big for eBPF.
I think you can do XDP based DHCP server in theory and keep state in eBPF map. Not sure that it does make any sense but clearly doable.
I used to develop and maintain one of the World largest DNS services and summarised my experience with DNS protocol in this blog post: https://pavel.network/please-stop-using-dns-protocol-for-you...
In multiple countries import tax may reach 50% on top of equipment cost. When multiplied by exceptionally weak local currency even medium level server will cost like racing car.
Old equipment without AVX is perfectly capable running modern workloads and artificial requirement to have AVX hurts people and increases digital divide.
To address such cases we found nice trick by using FerretDB to replace MongoDB in such environments: https://fastnetmon.com/docs-fnm-advanced/using-fastnetmon-ad...
dig -t aaaa news.ycombinator.com @8.8.8.8 +short
Returns empty result.
As another angle to make it even more interesting but on network scale I've implemented option for Unbound to suppress A records even if they do exist: https://github.com/NLnetLabs/unbound/pull/819 and push dual stack apps to be IPv6 only.
So I intentionally decided not to have IPv4 connectivity system wide to catch apps with issues in IPv6 only environment and then carefully evaluate issues and report them to authors: https://github.com/mozilla-mobile/mozilla-vpn-client/issues/... https://github.com/signalapp/Signal-Desktop/issues/4121
Dual stack setups tend to hide IPv6 implementation issues and may create illusion that app is IPv6 compatible but in reality it's not.
Clearly my setup is too hostile for home users but as developer I enjoy it a lot.
Most of the services I need for work do support IPv6 and the only exceptions is GitHub.
But I'll be happy to replace it by something else, my load is extremely small and only single requirement is to have DB as network daemon, not as embedded storage as it will be used by 2 applications (main daemon an API).
RethinkDB was really nice candidate for it but it's not alive anymore: https://rethinkdb.com/blog/rethinkdb-shutdown/
Typically, we recommend enabling InfluxDB metrics export for ~1 week (to cover peak times in your region), you can do it this way: https://fastnetmon.com/docs/influxdb_integration/
After that, you can make query to detect peak traffic for packets per second, bytes per second and flow per second metrics. Then you can multiply these value to 2-3 (depends on your capacity) and use as baseline.
Also, it's very good to known limits of your network. For example, if you know that router cannot handle more than 1M packets per second then you need to set threshold way before it. And most important thing is mount of spare capacity from your upstream. If you have only 10G of external capacity utilised up to 90% then your baseline should not exceed amount of your spare capacity.
It require kernel 4.18+ and you can use my guide to build test application very fast: https://github.com/pavel-odintsov/fastnetmon/wiki/af_xdp-tes...
I immediately backed up all my data and created ticket. I wait for I day. I wait for 2 days. After three days (all this time my server was offline) I got answer "we can't replace your drives and can't replace your server because we do not have stock. And you can wait for end of the month for new server".
Isn't it brilliant? :(
We will update proto file to this version in FastNetMon soon! :)
It's in russian but Google trsnalate crashes language baarriers! :)