HNHacker News
TopNewBestAskShowJobs

pqdbr

1,453 karma · joined March 3, 2012

submissionscomments
pqdbr··on Tin: full-text search for Postgres
Sorry, i should have been clearer: bare metal here meaning any other provider like, for instance, Hetzner. We use a local provider. 10x savings when compared to AWS.
pqdbr··on Tin: full-text search for Postgres
The problem is that they don’t support bare metal. I’d love to use PlanetScale in our bare metal servers.
pqdbr··on I don't like passkeys
Related: the UX is currently terrible. Every time I go to a website that has passkey flow, I'm presented with: - MacOS native UI; which I cancel; then I see - Bitwarden UI; which I cancel; then I see - Chrome UI; which I cancel;

Like, seriously?

pqdbr··on Muse Spark 1.3
Thats 3 months in AI years.
pqdbr··on Fastpotify
Carmine is cooking. His work on RubyLLM has been incredible, even going as far as upstreaming important work about fiber usage into Rails Solid Queue so that we reap the Async benefits, which are essential in this LLM age.
pqdbr··on There's no such thing as a small software team anymore
Totally agree. And having a Rails monolith that the LLM can see the entire context - even our marketing landing pages - is a blessing in AI era.
pqdbr··on Solid Queue 1.6.0 now supports fiber workers
You can, and Carmine (who coded this update) wrote exactly about this on this blog post: https://paolino.me/solid-queue-doesnt-need-a-thread-per-job/

From his article:

One backend, two modes

Fiber mode isn’t universally better. CPU-bound jobs get nothing from it, and blocking libraries or C extensions that do not cooperate with Ruby’s fiber scheduler stall the reactor. And that’s fine – you don’t have to pick one.

As Trevor Turk pointed out in the PR discussion, that’s the whole point: separately configured worker pools. Here’s what Chat with Work actually runs in production:

workers: - queues: [ chat ] fibers: 10 processes: 2 polling_interval: 0.1 - queues: [ turbo ] fibers: 10 processes: 1 polling_interval: 0.05 - queues: [ notifications, default, maintenance ] fibers: 5 processes: 1 polling_interval: 0.2 - queues: [ cpu ] threads: 1 processes: 1

pqdbr··on Solid Queue 1.6.0 now supports fiber workers
Carmine (which coded this Fibers update) wrote about this in his blog. See the section 'The database connection math'. And no, you won't have one connection per fiber.

The difference is staggering when you compare to threaded mode: it requires 1,320 database connections to run the same benchmark that the fiber mode runs with 60.

https://paolino.me/solid-queue-doesnt-need-a-thread-per-job/

pqdbr··on The new rules of context engineering for Claude 5 generation models
Fair hit
pqdbr··on You only need the frontier model for one single edit
It's literally all there is to it. Write your prompt normally. then, at the last paragraph, you write:

Use a workflow to implement this. You (Fable) are the orchestrator, planner and reviewer. Opus agents are implementers.

That's all there's to it. it will create the dynamic workflow - has a nice interface native to Claude Code - and do all the coordination to deliver what you asked.

pqdbr··on Hacker wipes Romania's land registry database
My friend, our users would flood our support within 30 seconds of the first blip of this happening.

I'm curious: what's _your_ defense against this?

pqdbr··on Hacker wipes Romania's land registry database
This is how we implemented this at our company:

- We have 2 sources of data that we must backup to continue existing as a business; our postgres and binary files in S3. Everything else is derivable (elasticsearch, so on).

- For postgres, we use barman. With the help of opus/fable, you can get a streaming replication backup working in no time. We have one into another server in the same datacenter (we use baremetal) and another one in another server in a different datacenter.

- We then have a last resort barman backup with bi-weekly base backups + WAL streaming to S3 (both the base backup and WALs). It sends these backups + wal segments into an specific S3 bucket that has object lock in compliance mode. This is a feature from AWS S3 that even the most privileged account credentials (super admin) can't turn off nor delete the files before the object lock, which is 10 days in our case. Object lock compliance mode can only be extended, never shortened.

- For S3, we store them into another versioned bucket, with lifecycle rules to also expire non current versions (== deleted objects) after 10 days. No point in object lock compliance here because it would only protect objects for the most recent 10 days, and you gain nothing. What we do instead: the app servers only have access to these bucket tru an IAM credential that can't delete old versions (so deleted objects have to expire manually via the lifecycle rule) AND this IAM credentials also can't change the object policy.

IMHO, this protects us enough so that even in the worst case scenario (ransomware) we have 10 days to sort everything out and recover our AWS access.

And yes, we test the S3 barman restoration and it works fine. Data loss is at max 5 minutes due to the archive_timeout=300s on the primary.

For the streaming replications in the two servers I mentioned, it's less <1ms, but those wouldn't protect us much in the case of the ransomware - even tough we use tailscale and one compromised server can't ssh into the other.

pqdbr··on You only need the frontier model for one single edit
I’m using Claude code dynamic workflow like this. I tell Fable to use a workflow. He is the planner, orchestrator and reviewer. Opus agents are implementers. Works unbelievably well.
pqdbr··on A full body MRI earns you a year of smoking
Is the commentator not even opening the article before commenting?
pqdbr··on GPT-5.6
Glad I’m not the only one noticing this. It’s maddening.
pqdbr··on GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos
Agreed, hard enforced by code. Surprised to see many comments here finding it reasonable that the agent could reply with private repo information on a question posted on a public repo, which IMHO is obviously a bug.
pqdbr··on PostgreSQL Benchmark: AWS RDS vs. Self-Hosted on Hetzner (2026)
Claude Code has been a blessing for all our devops work. We use baremetal servers and now have reliable, tested, fault tolerant postgres with streaming replication and barman for backups configured and running, with less than a second of replication lag, including a S3 redundant backup with < 1 minute of data loss (archive_timeout=60s) with S3 object-lock set up in compliance mode (so even the ransonware scenario is protected).

Yes, it takes some time to set up and test (~3 days in our case, 360GB database). But it's not that complex and the models (Opus 4.8+) know a lot about these days.

pqdbr··on Do We Have Fable? Claude Fable 5 Subscription Status
Has anyone actually enabled /usage-credits to use Fable at API pricing?

It's ridiculously expensive. At my _previous_ usage in the subscription, I estimated (with Claude) that I would spend more than 20k USD in a month.

It's insane.

pqdbr··on Fable 5 to return soon according to this "scoop" from axios
The difference is so big I can't even put it into words.
pqdbr··on Anthropic employees accuse Trump administration of targeting them
So all non-fictional movies ever made were unnecessary?
pqdbr··on Codex just found a "workaround" of not having sudo on my PC
Like the known Docker "feature" that it completely bypasses UFW and unless your ports look like "- 127.0.0.1:PORT:PORT" (and many of the examples use "-PORT:PORT") you expose everything to the internet?
pqdbr··on Claude Opus 4.8
This. So much jargon, so much made-up-words-with-hyphens, so much abbreviations. The mental tax to understand it is enormous.
pqdbr··on Claude Opus 4.8
At lest for me, it's a disaster. It's like we're back to GPT-2 era.

It can't read files anymore. Uses 'sed' out of the blue with non existent paths. In this session alone it has excused itself more then 10 times for making 'false claims'.

I hope this is a bug - it's a bad one - that will get sorted out soon. It's a complete mess.

pqdbr··on Gemini 3.5 Flash
In my tests, in real production use cases, it's a hard pass.

It's actually 10-15% slower and also more expensive than Gemini 3.1 Pro, because it thinks more than 2.5x Gemini 3.1 Pro.

So that thinking verbosity nullifies the speed and cost gains.

AND the quality is worse than 3.1 Pro for our use cases, making mistakes Pro doesn't make.

pqdbr··on Ask HN: What Are You Working On? (April 2026)
that looks really cool. do you plan on building a docker image like pgvector does?
pqdbr··on Subscription bombing and how to mitigate it
Recently we suffered a different kind of subscription bombing: a hacker using our 'change credit card' form to 'clean' a list of thousands credit cards to see which ones would go through and approve transactions.

He ran the attack from midnight to 7AM, so there were no humans watching.

IPs were rotated on every single request, so no rate limiter caught it.

We had Cloudflare Turnstile installed in both the sign up form and in all credit card forms. All requests were validated by Turnstile.

We were running with the 'invisble' setting, and switched back to the 'recommended' setting after the incident, so I don't know if this less strict setting was to blame.

Just like OP, our website - to avoid the extra hassle on users - did not require e-mail validation, specially because we send very few e-mails.

We never thought this could bite us this way.

Every CC he tried was charged $1 as confirmation that the CC was valid, and then immediately refunded, erroring out if the CC did not approve this $1 transaction, and that's what he used. 10% of the ~2k requests went through.

Simply adding confirmation e-mail won't cut it: the hacker used - even tough he did not need it - disposable e-mail addresses services.

This is a big deal. Payment processors can ban you for allowing this to happen.

pqdbr··on 1M context is now generally available for Opus 4.6 and Sonnet 4.6
I have no experience building this two-pass approach, but I arrived at it intuitively while planning for a new project. Any references to actual implementations?
pqdbr··on Returning to Rails in 2026
We've also been running Rails in production for 15+ years (since 2011) in two companies and it has been serving us greatly. Hiring is tough, but I definitely believe the stack makes up for it due to the productivity gains.

In late 2025 we decided to migrate one of them to Inertia. Public facing pages is already done, and we're 80% through migrating the logged in area (it's a huge app). We choose Vue.js.

It's amazing how powerful this stack is and how little you have to change in the backend.

pqdbr··on Cloudflare crawl endpoint
No. I do think that Cloudflare is a great company and got where it's at today because they care for this type of issue, and has a much better chance of contacting their peering traffic partner than me because they take care of ~20% of all internet traffic, while I take care of none.
pqdbr··on Cloudflare crawl endpoint
Off-topic, but I'm having a terrible experience with Cloudflare and would love to know if someone could offer some help.

All of a sudden, about 1/3 of all traffic to our website is being routed via EWR (New York) - me included -, even tough all our users and our origin servers are in Brazil.

We pay for the Pro plan but support has been of no help: after 20 days of 'debugging' and asking for MTRs and traceroutes, they told us to contact Claro (which is the same as telling me to contact Verizon) because 'it's their fault'.

Page 1 of 11Next →