HNHacker News
TopNewBestAskShowJobs

robinhoodexe

1,338 karma · joined January 2, 2014

submissionscomments
robinhoodexe··on AyaFlow: A high-performance, eBPF-based network traffic analyzer written in Rust
Would love to see a screenshot of the dashboard.
robinhoodexe··on Shai-Hulud compromised a dev machine and raided GitHub org access: a post-mortem
Wouldn’t the IP allowlist feature on the GitHub organisation work wonders for this kind of attack?
robinhoodexe··on Google denies 'misleading' reports of Gmail using your emails to train AI
I've been using mailbox.org for 5 years and like it very much. Cost some 3 EUR per month (actually there's a 50% discount this week).

Dead simple email that just works. Their webUI is fine, but I almost exclusively use it on iOS or macOS with the default mail app. They also have some other features (calendar, office suite, video calls) that I don't use. I really like the option to create up to 25 email aliases.

robinhoodexe··on Run Nix Based Environments in Kubernetes
First, congrats on the release. I’ve looked at flox and devenv for nixifying our container builds. Our distribution of languages is about 40/30/20/10 of Python, F#, R and nodejs.

A dilemma I’m facing is that the win from nix in terms of faster builds and smaller images would be largely from python and R images (where the average size is often 1Gi or larger). However, the developers that use Python or R are less likely to “get” the point of Nix and might have a steeper learning curve than F# developers (where the builds are quite efficient).

That was the context, my question is, how’s the integration with Flox and R/RStudio? I know there’s Rix[1] for managing R packages with Nix.

[1] https://github.com/ropensci/rix

robinhoodexe··on Cache Benchmarks
Agreed, it'd be nice to see the graphs with a linear scale.
robinhoodexe··on Understanding the Go Scheduler
Looks like it was just merged btw.
robinhoodexe··on Tini: A tiny but valid `init` for containers
We use this for internal base images at $DAYJOB in order to get SIGTERM properly passed in Kubernetes, mostly a problem with Python, R and Elixir. Works wonders with only a default ENTRYPOINT in the base image, so it’s completely “hidden” from the developers (most of them don’t care, and rightly so).
robinhoodexe··on An intro to DeepSeek's distributed file system
I’m interested in how it is compared to seaweedfs[1], which we use for storing weather data (about 3 PB) for ML training.

[1] https://github.com/seaweedfs/seaweedfs

robinhoodexe··on A filmmaker and a crooked lawyer shattered Denmark's self-image
The director also made Kim Jong Il’s Comedy Club[1], an absolutely insane documentary on North Korea.

[1] https://www.imdb.com/title/tt1546653/

robinhoodexe··on Show HN: Subtrace – Wireshark for Docker Containers
It’d be neat to use subtrace in an ephemeral pod for debugging purposes, that just runs alongside the regular pod.

For monitoring the network traffic for the whole cluster, the CNI and/or whatever ebpf-based runtime security stuff you’re using (falco, tetragon, tracee) is usually enough, but I can definitely see the usefulness of subtract for more specific debugging purposes. If run as a DaemonSet make sure to add some pod filtering such as namespace and label selectors (but I’m sure you’ve already thought about that).

robinhoodexe··on Linux kernel could cut energy use in data centres by up to 30 per cent
So how do we enable the feature?
robinhoodexe··on Dwarf Fortress Adventure Mode – Out Now – Official Release Trailer [video]
I tried an Ubuntu x86 VM with UTM on a M1 MacBook Pro, but the results was extremely slow.

I think Intel Macs will give a better result.

robinhoodexe··on Dwarf Fortress Adventure Mode – Out Now – Official Release Trailer [video]
I asked for a status on the forums[1] but the it doesn’t look too positive. From a September 2024 steam post:

> After investigating the programming requirements, we have decided it’s best to cancel the Mac build for the time being. Porting the game over to Mac would take significant time and resources away from improvements to Fortress and Adventure Mode that simply don’t make sense for us to dedicate right now, given the low number of Mac-only users. There is a significant amount of work that would be required for maintaining a Mac build that would delay all patches in the future, and as we know, you all want patches faster. We aren’t saying it will -never- happen but do not count on it any time soon. We are very sorry to all the Mac users who have been waiting patiently for an update on this.

[1] http://www.bay12forums.com/smf/index.php?topic=169696.6135

robinhoodexe··on The Problem of HFT
Is the book available somewhere online free of charge?
robinhoodexe··on Proxmox Announces Proxmox Datacenter Manager
This link seems to work:

https://www.proxmox.com/en/about/press-releases/proxmox-data...

robinhoodexe··on Show HN: Kubernetes Spec Explorer
Very nice!

Adding support for CRDs would be very nice. Maybe look up popular CNCF projects and find their official helm charts, that contain the CRDs?

robinhoodexe··on Prometheus 3.0
We’re extremely pleased with Talos. Much more secure than Azure (our cloud of choice, unfortunately) which run a full-blown Ubuntu underneath. We haven’t run into any issues with Talos and upgrading is super easy with the talosctl tool, both Kubernetes and Talos version.

We currently have a thanos instance in each cluster. We could move it to a separate cluster to reduce some overhead, but the current approach works. We’re ingesting about 60Gi per day of metrics into the S3 bucket, so we might have to optimise that.

robinhoodexe··on Prometheus 3.0
I can’t recall the reason for using thanos over mimir to be honest. I think thanos seemed like a good choice given it’s part of the kube-prometheus-stack community helm charts.
robinhoodexe··on Prometheus 3.0
We’re running standard Prometheus on Kubernetes (14 onprem Talos clusters, total of 191 nodes, 1.1k cpu cores, 4.75TiB memory and 4k pods). We use Thanos to store metrics in self-hosted S3 (seaweedfs) with 30 days retention, aggressively downsample after 3 days.

It works pretty good tbh. I’m excited about upgrading to version 3, as is does take a lot of resources to keep going, especially on clusters with a lot of pods being spawned all the time.

robinhoodexe··on Bpftune uses BPF to auto-tune Linux systems
Is tuning the TCP buffer size for instance worth it?
robinhoodexe··on Show HN: I built a tool that helps people scan and clean any repo for secrets
A similar tool is detect-secrets[1].

[1] https://github.com/Yelp/detect-secrets

robinhoodexe··on Ask HN: What distributed file system would you use in 2024?
We have been using seaweedfs for about 3 months and so far it’s pretty solid, the integration with kubernetes is nice and the maintainer is very active on slack and when opening GitHub issues.
robinhoodexe··on Install Asdf: One Runtime Manager to Rule All Dev Environments
What exactly are the problems with using it on macOS? So far (on my, admittedly, short nix journey), I’ve not encountered any issues that wasn’t fixable with 5 mins of google (even as a beginner).
robinhoodexe··on Install Asdf: One Runtime Manager to Rule All Dev Environments
I'm considering doing a pilot (~5 devs out of 120) with using nix to manage dependencies and build containers at $DAYJOB, and here I think devenv is nice as a "one package" plus an active community for support.
robinhoodexe··on Install Asdf: One Runtime Manager to Rule All Dev Environments
Sounds like nix using devenv[1] also would solve this problem.

[1] https://devenv.sh/

robinhoodexe··on Ask HN: What Are You Learning?
Nix for developer environment and building containers.

I’m wondering if it’s worth it to introduce to the rest of the company. We’re pretty comfortable building/“maintaining” ~400 container images, and it’s relatively fast (~3-5 min build time if no packages are changed), but there a lot of shared dependencies between all these container images, and using nix to get actual reproducible AND minimal container images with a shared cache of Linux and language-specific packages (dotnet, node, python and R) would bring in a ton of efficiency, as well as a very consistent development environment, but I won’t force all the developers to learn nix, so the complexity should optimally be absorbed into some higher level of abstraction, like an internal CLI tool.

I’m aware that the caching of dependencies can be improved, as well as creating more minimal container images, but it’s tricky with R and Python in particular, and then I figured why not just to balls-deep on nix that actually solved these issues, albeit at a cost of complexity.

robinhoodexe··on Pure Bash Web Server
Out of curiosity, how would you run Python or R workloads in kubernetes without a distro or shell?
robinhoodexe··on GitHub having issues today
And just as we're about to migrate 4 kubernetes clusters with a total of ~4k pods. Terraform in github actions on selfhosted runners and argoCD is failing.
robinhoodexe··on Gvisor: Application Kernel for Containers
Looks somewhat similar to the talos Linux project[1]

[1] https://www.talos.dev/

robinhoodexe··on Show HN: Anchor – developer-friendly private CAs for internal TLS
Can you elaborate on this? We have some 300 internal APIs on a valid domain. We used to use let’s encrypt, but got rate limited for obvious and fair reasons when we were migrating between clusters. It’s a bit better with zerossl, but we still get 429s when cert-manager is issuing a ton of certs at the same time.
Page 1 of 8Next →