As an anecdote: you can let your tap water be tested for free if you have a newborn to ensure and confirm that you can use it for baby food without doubt.
894 karma · joined July 6, 2011
As an anecdote: you can let your tap water be tested for free if you have a newborn to ensure and confirm that you can use it for baby food without doubt.
> git was invented before continuous delivery
git was invented 2005. So you mean when people used the term Continuous Delivery more frequently? Because using CI and automatically deploy is not "new" and was surely done before git - I remember doing that even with CVS and SVN.
"Wi-Fi Assistant
Auto-connects you to high quality open WiFi and secures your connection with a VPN back to Google."
I really do not want to tunnel my whole traffic through Google's servers.
https://developers.google.com/analytics/devguides/collection...
Or don't use the Oracle proprietary distribution but the OpenJDK of your operating system which normally doesn't exclude proper crypto algorithms.
(be aware that the JDKs downgrade silently if certain libraries are missing in your host)
It is the spot between chroot and VM. Looks like a VM from the inside, provides some degree of resource usage QoS and does not require you to run a full operating system like a VM.
Another concept that is now also often automatically connected to containers is the distribution mechanism that Docker brought. While provisioning is an orthogonal topic to runtime, it is nice that these two operational topics are solved at the same time in a convinient way.
rkt did some nice work to allow you to choose the runtime isolation level while sticking to the same provisioning mechanism:
https://coreos.com/rkt/docs/latest/devel/architecture.html#s...
[0] https://github.com/zalando/spilo [1] https://github.com/zalando/PGObserver
Edit: https://github.com/zalando/patroni is a better link
It is the most important step that you can package containers without having to know the production secrets and to have a "standard" was to retrieve them.
No one, without production access, has a way to obtain them.
You have to argue that Docker uses the Linux isolation mechanisms that make those containers virtual machines in the sense and spirit of PCI.
Treating containers as VMs makes some other requirements even easier like the request to have a minimal system and to only have one function per server - thats how you want containers to work anyway.
(Btw PCI has nothing to do with PII.)
(I am not affiliated with Jetbrains in any way)
This directive will drastically increase fines for data leaks in the EU.
'Article 1 of the Basic Law (in German legal shorthand GG, for Grundgesetz), which establishes this principle that "human dignity is inviolable" and that human rights are directly applicable law, ...'
https://en.m.wikipedia.org/wiki/Basic_Law_for_the_Federal_Re...
https://clojuredocs.org/clojure.core/io℅21
The 'io!' macro marks a code block to have side effects which prevents using it in a STM transaction as 'dosync' might need to execute the functions multiple times in case of conflicts during the optimistic locking.
git config --global user.signingkey $GPGKEY
git config --global commit.gpgsign true
In general, since you definitely do not want to upload your key material to GitHub, you won't be able to use the pull request merge button and the new squash button. This means, your pull requests need to be fast-forwardable, else you cannot merge (as this merge would be unsigned). Also, instead of using the squash button, you would need to squash the commits on your local machine and push the newly signed squashed commit again. It comes as a cost but it also leverages the decentralized nature of git: you can do everything locally and sign locally so you do not need to trust someone else.1) as another commenter already pointed out, I would really like to see an "unverified" badge instead of the "verified" to make GPG signing the default; everyone should really be aware that all commit metadata like author and committer are completely voluntary and you can lie as you want.
2) Please, add another merge restriction that only allows commit pushes/merges-to-master with GPG signatures. This allows me to fully verify future git repositories.
"Applications that use clone()-like system calls to share the complete address space between processes may be able to replace system call arguments after they have been evaluated by systrace and escape policy enforcement."
http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man1/...
OpenBSD apps leverage traditional approaches heavily like chroot and privilege separation through different users - even within applications but there is no network separation or similar as in jails or Linux namespaces.
PierOne is a Docker registry in Clojure with S3 backend and OAuth support. I wrote swagger1st[0] which is used there. Swagger supports authorization definitions via scopes. Besides that, you can only define required basic auth or API key usage for authentication but not for authorisation.
Swagger defines various places, where you can add own x-* attributes to fill in your own logic if swagger is not expressive enough.
"netzpolitik.org" was accused of treason for publishing classified documents about plans by Germany's domestic spy agency to expand the surveillance of online communication. A big outcry to protect freedom of press brought a big political affair in which the federal prosecutor* was fired. The minister's own role will still be discussed.
*) The same prosecutor decided to stop investigating the NSA's role in spying at german politicians/companies/people.