HNHacker News
TopNewBestAskShowJobs

sarnowski

894 karma · joined July 6, 2011

submissionscomments
sarnowski··on Kubernetes V1 Released
Kubernetes Cluster Federation (proposal) "Ubernetes"

"Today, each Kubernetes cluster is a relatively self-contained unit, which typically runs in a single "on-premise" data centre or single availability zone of a cloud provider (Google's GCE, Amazon's AWS, etc)."

https://github.com/GoogleCloudPlatform/kubernetes/blob/relea...

sarnowski··on Der Spiegel Targeted by US Intelligence
Almost all discussions are focused inwards. That a foreign agency is trying to spy is no surprise. The big shock* comes from the details how german agencies were not only incapable of protecting anything but even helped foreign agencies to spy on our government and industry (obviously, spying on all citizens was not even a real topic for the governemt).

*) Unfotunatly, its mostly some media who even care about this stories. Most citizens are too lazy to even admit that this is a big scandal and Merkel uses her strategy of just doing nothing until media cannot earn enough money with the stories so that everyone just forgets. The only bigger outcry came from the industrial spionage allegations (media were like 2-3 weeks on it) because $$$.

sarnowski··on Boiling frog, or when did we lose it with /etc?
Not all modern OS have that directory mess:

http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man7/...

https://www.freebsd.org/cgi/man.cgi?query=hier&sektion=7

sarnowski··on A persistent key-value server in 40 lines and a sad fact (2014)
But its neither a Java nor JVM problem.
sarnowski··on A persistent key-value server in 40 lines and a sad fact (2014)
Don't know your "real" world. In my real world, the AWS instance takes several minutes to come up - I can spare some milliseconds on thr JVM startup.
sarnowski··on A persistent key-value server in 40 lines and a sad fact (2014)
http://blog.ndk.io/2014/02/11/jvm-slow-startup.html

40ms sounds okay for me, even for most command line tools. Oh and I most probably don't get a segmentation fault ;-)

sarnowski··on The ultimate OpenBSD router
Actually, soekris were pretty good but they are kinda outdated. I just got an apu1d4 from pcengines[0] and OpenBSD works like a charm on it. Half the price, much more power.

[0] http://www.pcengines.ch/apu1d4.htm

sarnowski··on Bazel – Correct, reproducible, fast builds for everyone
This is true for Maven. The Maven repository project is very impressive and outstanding in its kind anyways. But leaving this great repository you are often on your own. Look at what happens to Google Code. How much stuff will be lost when its shut down? Hopefully nothing that you depend on. Its nice to have the binaries in a backup maybe but without access to the code, maintenance will be a nightmare.
sarnowski··on Bazel – Correct, reproducible, fast builds for everyone
Tbh, if your company relies on this software, I would also make sure that it cannot just vanish - and thats the most efftive solution. Artifacts can disappear from the internet and you don't know if the downloaded stuff is still the same as before. Especially, if you look outside of the maven ecosystem, but even there you have to rely on apache and their partners. An outage can mean that you cannot deploy critical bugfixes to your platform.
sarnowski··on Introducing OpenBSD's new httpd [pdf]
That's correct. They are still available in the ports. If were operating a complex setup, you probably already used nginx from ports before.

Not being in the base means that it doesn't get the same security attention as its not officially part of OpenBSD anymore.

sarnowski··on Stack Overflow: How we upgrade a live data center
Most leasing contracts are on a 3 year basis.
sarnowski··on Adopting Microservices at Netflix: Lessons for Architectural Design
Thats what circuit breakers are for to not have cascading errors.
sarnowski··on Go concurrency isn't parallelism: Real world lessons with Monte Carlo sims
Actually that is exactly the case in a library of mine[0]. Its not a bug of my code directly but due to non-POSIX compliance of Linux that triggers only with multiple threads (setuid does set the uid only for the executed thread and not for the others of the same process - unlike the manual page and POSIX states). Its a cornercase but I also explicitly raise the GOMAXPROCS in the test case to trigger it[1].

[0] https://github.com/sarnowski/mitigation

[1] https://github.com/sarnowski/mitigation/blob/master/mitigati...

sarnowski··on An experimental, automatically generated set of AWS clients in Go
I guess they also have a lot of software running that they rely on and is written in C or C++. And still, there is no SDK - there is also no (Node)JS SDK. Using Docker does not force you to support golang in any way.
sarnowski··on Uber Confirms It Is Assisting Police in India Following an Alleged Rape
https://news.ycombinator.com/item?id=8711284

600+ upvotes, top #1, vanishes from one second to another - whats up HN?

sarnowski··on GopherJS – A compiler from Go to JavaScript
> its like clojure core.async only more powerful.

Can you explain why its more powerful than core.async?

sarnowski··on On building portable Linux binaries
http://harmful.cat-v.org/software/dynamic-linking/

..comes to my mind. Shared libraries and their advantages are at least.. controversal.

sarnowski··on OPM – Open PostgreSQL Monitoring
Since we (Zalando) are heavy PostgreSQL users, we also had the need for monitoring and part of the result we came up with is http://zalando.github.io/PGObserver/ and https://github.com/zalando/pg_view
sarnowski··on Rhine – A Lisp on LLVM
>> ... `setq` though (a feature not present in Clojure...

I am not familiar with elisp but from first google result it reads that the equivalent is alter! / swap!.

sarnowski··on Rhine – A Lisp on LLVM
At some point most applications have to have some state. Most clojure projects are nice functional libraries that work without state but somewhere are one or to refs (or atoms). A good example is Datomic where Rich Hickey said, it only has 6 refs. Its 99% persistent but somewhere you need at least a pointer to your current state. Of course you can push the problem to your database or some libraries but I really like refs with their optimistic locking and am using them to have in-memory consistency.
sarnowski··on Rhine – A Lisp on LLVM
Someone mentioned the JVM interop of Clojure is it's main selling point. While its definitly awesome to have that great integration (I'm a heavy interop user), for me, the main strength is having persistent data structures at its base for everything. I myself played with the thoughts of creating a native runtime based on Clojure's syntax and data structures. I cant see that this project uses persistent data structures. Am I wrong? please enlighten me.
sarnowski··on Goless: Go-like semantics built on top of Stackless Python
IIRC stackless python implemented microthreads and channels before go existed - thats the whole point of stackless python - so whats the benefit here on top of that?

http://www.stackless.com/wiki/Tasklets http://www.stackless.com/wiki/Channels

sarnowski··on Use after free bug in OpenSSL
Because now your command isn't /path/ independant. The original assumed you downloaded the patch to your current directory and you can just copy&paste this command. Your example requires me to modify your line making this "process" more error prone.
sarnowski··on Quake III bounty: we have a winner
I suggest looking at LinuxFromScratch[0], especially II.5. It's hard to do a "real" cross-platform compiler because your target system might not only be a different architecture but also has different libraries on the system with which the compiler has to work. All in all, doing it right and being able to ship binaries is a lot of work and constant maintenance as your target system, in this case Raspbian, also changes their libraries.

[0] http://www.linuxfromscratch.org/lfs/view/stable/

sarnowski··on Docker and Security
Agree. I keep telling that container may provide some benefits but its really not security (especially docker which uses LXC which is still not complete und as you said uses a shared kernel - one plus point is Ubuntu's combination with AppArmor which mitigates certain attacks but configuring AppArmor is itself often overseen. Other distros are worse).

If you want to secure one app from another, just use separate hardware.

sarnowski··on FreeBSD 10.0-RC1 now available
For the end user this means: different command line parameters for commands; more consistent userland; consistent documentation; less drivers; slightly less applications
sarnowski··on OpenBSD 5.4 Released
This is true for me too as long as I don't use OpenBSD. The cause is that GNU/Linux manpages are horrible. They are mostly outdated and not in sync with the versions that are actually installed.

As soon as you log in to your newly installed OpenBSD system, your root account has a mail in her mailbox stating to read the "afterboot" manpage. When I first time entered "man afterboot" in my shell, I was blown away.

http://www.openbsd.org/cgi-bin/man.cgi?query=afterboot

  The idea is to create a list of items that can be checked
  off so that you have a warm fuzzy feeling that something
  obvious has not been missed.
It gives you a fast introduction with all informations you need and then references all locations where you find every other topic. At that point, you don't need google anymore where you again find outdated and incorrect informations.

The documentation is so high quality that this is the biggest advantage I appreciate the most.

sarnowski··on Why Putting SSH On Another Port is a Good Idea
The "change-port" discussion for SSH is so boring :-/ OpenSSH is I guess the most secure daemon on all your servers. People should more think about to change the HTTP(S) ports of their non-public facing sites and other daemons and frameworks they use.
sarnowski··on How is Docker.io different from a normal virtual machine?
Do you have a link for this statistic? Since I don't know of a local root privilege escalation since several years in OpenBSD, this is a quite high mark.

Edit: this is not a os-or-vm problem. You will have local problems and now, in addition, rooting a server may give you access to even more servers that run on your hyp.

sarnowski··on How is Docker.io different from a normal virtual machine?
> Docker (and LXC) seems like a huge step backwards for security.

Sry but link says it all. No further comment from me: http://marc.info/?l=openbsd-misc&m=119318909016582&w=2

← PreviousPage 3 of 5Next →