HNHacker News
TopNewBestAskShowJobs

sontek

743 karma · joined May 9, 2011

https://sontek.net
submissionscomments
sontek··on Show HN: Zapier's first API
This is going to be an awesome way to optimize Zapier usage. I'm not a huge AI guy but love the idea of sprinkling a little on top of my existing zaps to make them even more useful!

For example I have a zap right now that every time I react in slack with :todoist: it adds it to my TODO backlog. If I can use AI to read that thread and put a summary in there that'll make me more productive.

sontek··on Gail.com FAQ
My only complaint is it goes full wide screen. If he put a limit on the width the text expands to so it was readable on large screens that would be perfect.
sontek··on Dotfiles Management
I see a lot of people mentioning home-manager / nix in the comments. I tried drinking the nix kool-aid and home-manager and all that was a little too much more me and landed on a hybrid approach:

https://github.com/sontek/homies

1. I use a `justfile` that calls `nix profile install ...` to install my packages, rather than using a nix configuration file. This allows me to use a standard package manager workflow rather than going "all in".

https://github.com/sontek/homies/blob/master/justfile#L24-L2...

2. I then use GNU Stow to install my dotfile configuration:

https://github.com/sontek/homies/blob/master/justfile#L93-L9...

I think this is a great middle ground where I can utilize `nix` as my package manager across Linux and Mac and have consistency while not having to learn the whole configuration language or change my workflow.

The other tools I use heavily in my environment:

- https://asdf-vm.com/: I find this better than installing python/node/etc from nix.

- https://github.com/casey/just: I use this as my command runner (similar to make but cleaner in my opinion)

sontek··on Ask HN: Company is going through layoffs, but still interviewing me. Red flag?
Not completely a red flag... I've only been through layoffs twice but both times the cuts the company made were pretty logical in terms of investing more in the existing profitable parts of the company and cutting things that were bets but would have take awhile to even prove if they were the right bets to make.

The one thing I would be concerned about is the ~2 months after layoffs are pretty rough morale wise.

- People lost their friends and are upset about it

- Systems start breaking and the knowledge of them was lost

- Team restructuring means learning how to work with new people

- Adjusting expectations for the new velocity of the remaining engineers takes time

I personally would not join a company that recently did layoffs because socially its going to be awkward for awhile.

sontek··on France bans Office 365 and Google Docs from schools and public administration
I like the genera idea of not using the big companies and forcing them into compliance but if the France government is anything like the USA gov I can't imagine them running a self-hosted solution like NextCloud at the same level of security, compliance, and reliability that are imposed on MS and Google.
sontek··on The End of CI
I wouldn't trust my computer to be the pre-commit judge if my code is good or not. It looks nothing like the target environment and has plenty of modifications. I'll trust CI to do that check for me.
sontek··on Ubuntu Unity desktop back from the dead after several years' hiatus
Who in the server crowd is using snaps?
sontek··on Don't use Kubernetes yet
But if we are comparing apples to apples, you would just use AWS provided stuff for EKS right?

  > K8s can go a lot of different ways depending on the type of LB 
k8s flexibility shouldn't be counted against it here. If you are considering k8s against fargate, you should only be considering ALB / NLB ingress and not the many more ways you could. Just use what AWS provides and be happy with it :)

  > ECS you just configure a log group and get persistent logging and basic aggregated searching with Cloudwatch Insights
You can log to cloud watch with EKS as well. Fluentd can log to cloudwatch with very little configuration.

I agree that if you are already "all AWS" and just want to put one more thing in there, Fargate might match your existing patterns better. But saying "Fargate is easier than managed kubernetes" is very wrong.

In general I've seen people have an easier time understanding kubernetes manifests for declaring their services instead of the equivalent terraform to get fargate up and running to do the job.

sontek··on Don't use Kubernetes yet

  > On AWS, that would be Fargate on ECS, or on Google Cloud, Google Cloud Run.
  > You won't have to manage servers, network overlays, logging, or other necessary middleware.
I disagree with this take. EKS is a managed service just like Fargate and you have to learn how to manage both equally (VPCs, CIDR ranges, IAM rules, etc). You might as well start on kubernetes if you are going to switch to it eventually.

  > I'd suggest that teams adopting Kubernetes (even the managed versions) have an SRE team, or at minimum, a dedicated SRE engineer.
I'd love to hear what parts of running EKS require an SRE team and how Fargate/ECS solve that issue and make it self-serviceable.
sontek··on Dragonflydb – A modern replacement for Redis and Memcached
Haha, I thought the same thing until it wasn't! It turns out there are a lot of humans in the world and if you are unfortunate enough to get a large portion of them to start utilizing the software you write you'll find some bottlenecks in almost every system you thought was fast enough.
sontek··on Architecture Notes: Datasette
Yeah, it'd be crazy if sites like Reddit, SurveyMonkey, Dropbox, Spotify, Instagram, Pinterest, Lyft, and Sentry were built on a silly little prototyping language like Python instead of a real programming language. Right?
sontek··on Y Combinator's Message to Founders
I think I've only worked at companies that under-hired. At small start-ups it that they were worried about runway and so made everyone wear many hats and overwork / crunch on things. At large orgs its just difficult to hire and very competitive, so you always have a hard time hitting your goals even though the roles are very much needed.

I can't think of one org I've ever worked at that hit a sweet spot where you were able to hire exactly as many engineers as you needed while keeping up with growth and attrition.

sontek··on Explain the first 10 lines of Twitter's source code to me
I saw a tweet yesterday where someone with 4 years of experience was looking for a Staff Engineer position. One thing the engineering community doesn't lack is confidence in our abilities, even if we aren't there yet.
sontek··on Nix: An idea whose time has come
Yeah, I think its things like this that make it hard to adopt nix. If you search for a package on search.nixos.org it tells you to install it using `nix-env`.

All I want is a way to say "I want jq, kubectl, and terraform installed" and have it available globally. Not for specific projects or anything like that.

Right now I maintain a makefile that installs everything for me using `nix profile`:

https://github.com/sontek/homies/blob/master/justfile#L14-L2...

Which almost exactly like I want. Only issue is sometimes a new hash is generated (which I don't understand.. maybe a config update in the repos?) and the makefile can't run anymore:

    error: packages '/nix/store/y65pp5hipid0fzxl1z7xjxdk4h9jwfw7-exa-0.10.1/bin/exa' and '/nix/store/gy0bqcs9mcan8af47wakdylhal67dpy4-exa-0.10.1/bin/exa' have the same priority 5; use 'nix-env --set-flag priority NUMBER INSTALLED_PKGNAME' to change the priority of one of the conflicting packages (0 being the highest priority)

I've avoided home-manager because it says:

    Unfortunately, it is quite possible to get difficult to understand errors when working with Home Manager, such as infinite loops with no clear source reference. You should therefore be comfortable using the Nix language and the various tools in the Nix ecosystem. Reading through the Nix Pills document is a good way to familiarize yourself with them.

If its common enough to warn about it, not quite the tool I'm looking to pull into my environment.
sontek··on Nix: An idea whose time has come
But I don't want it temporarily, I want it all the time. So I want to be able to make it available for future me too, that way next time I try to use it I don't have to run `nix-shell -p <package>` again
sontek··on Nix: An idea whose time has come
Yeah, this could be a NixOS vs every other OS problem. Even when files are declared it was my understanding that `nix-env` was the way to install the file?

For example, docs I've referenced in the past are here: https://nixos.org/manual/nixpkgs/stable/#sec-declarative-pac...

It says to run:

    nix-env -iA nixpkgs.myPackages
Is this incorrect?
sontek··on Nix: An idea whose time has come
Yeah, the UX for the new search although faster is more of a problem for me. When it returns `legacyPackages.x86_64-linux.ripgrep` that makes me think "oh no, I don't want the legacy package. I want the good one", but no non-legacy package is returned.

Also the name is confusing, it return `x86_64-linux` on linux and `x86_64-darwin` but why does that information need to be included? Then it brings up the problem if I need to install with the whole long string or if I can just install with `ripgrep`.

The other big grip I have with the new CLI is the installed packages. If you run:

    > nix profile list
You get a gob of mostly unreadable text scrolling through your screen:

    72 flake:nixpkgs#legacyPackages.x86_64-darwin.toilet github:NixOS/nixpkgs/19574af0af3ffaf7c9e359744ed32556f34536bd#legacyPackages.x86_64-darwin.toilet /nix/store/hnvdydra5syylxnxwj2fmn91aqwz26p6-toilet-0.3
    73 flake:nixpkgs#legacyPackages.x86_64-darwin.asdf-vm github:NixOS/nixpkgs/b66b39216b1fef2d8c33cc7a5c72d8da80b79970#legacyPackages.x86_   64-darwin.asdf-vm /nix/store/skk5pfhjnj49gw184jwivd5wakxx5g23-asdf-vm-0.8.1
and for some reason includes a bunch of duplicate packages, so its very confusing:

    > nix profile list|grep lolcat
    22 flake:nixpkgs#legacyPackages.x86_64-darwin.lolcat github:NixOS/nixpkgs/19574af0af3ffaf7c9e359744ed32556f34536bd#legacyPackages.x86_64-darwin.lolcat /nix/store/zxnkjsimmcvv0jnwsy5jxxmjak01k52f-lolcat-100.0.1
    46 flake:nixpkgs#legacyPackages.x86_64-darwin.lolcat github:NixOS/nixpkgs/19574af0af3ffaf7c9e359744ed32556f34536bd#legacyPackages.x86_64-darwin.lolcat /nix/store/zxnkjsimmcvv0jnwsy5jxxmjak01k52f-lolcat-100.0.1
    71 flake:nixpkgs#legacyPackages.x86_64-darwin.lolcat github:NixOS/nixpkgs/19574af0af3ffaf7c9e359744ed32556f34536bd#legacyPackages.x86_64-darwin.lolcat /nix/store/zxnkjsimmcvv0jnwsy5jxxmjak01k52f-lolcat-100.0.1
Same package name, hash, and version listed 3 times for some reason. I ended up writing an alias that would give me a readable list:

    > which npl
    npl: aliased to nix profile list|awk '{print $2}'|sort|uniq|sed s/flake:nixpkgs#legacyPackages.x86_64-//g|sed s/darwin\.//g

    > npl
    argocd
    asdf-vm
    aws-vault
    awscli2
sontek··on Nix: An idea whose time has come
For me it is a context switching issue. If I'm reaching for a package it is because I was in the middle of something that needed it. I'm not sitting there thinking "What packages might I need some day?".

So if nix could allow me to get the tools I need without context switching that would be a great addition. I don't want to have to go edit configuration files just because I haven't installed some tool yet.

sontek··on Nix: An idea whose time has come
Yeah, the hard part is maintaining a file just to have the tools you want is a major hurdle that is not reasonable for most people to jump over. If I'm working I might do something like this:

    curl example.com/data.json | jq ...
and I'll realize I don't have `jq` installed. I do not want to open vim, edit a configuration file, and then re-run a command to rebuild my system. I just want jq. I can't change context like that just to get a package.

I understand this isn't aligned with the purity stance that nix has but if they were able to allow this use case, it would most likely get more people doing it the right way eventually.

I can't drink all the kool-aid at once, I really need to replace bits of my workflow at a time and I can't do that with nix currently.

The approach I've laid out in my original comment (using `nix-env`) provides a bad developer experience and makes me not able(willing?) to move forward with the adopting more of the practices. If the initial experience was better, I'd invest more time learning more.

sontek··on Nix: An idea whose time has come
I love the idea of nix but the inconsistency and developer experience is terrible. I want to suggest people use it but there is too many rough edges currently.

For example, if you want to install a package the old way, you'll install it including the channel:

    nix-env -iA nixpkgs.ripgrep

but then if you want to remove one, you don't reference the channel:

    nix-env -e ripgrep
You have a similar issue if you want to use the new `nix` command. To install a package you'll do:

    nix profile install nixpkgs#ripgrep

but running:

    nix profile remove nixpkgs#ripgrep

will do nothing. It won't say "I didn't remove the package" or "package not found". It just returns silently. The only way to remove it is to point to the number from `nix profile history` or the actual path.

It is unbearably slow:

    > time nix-env -qaP ripgrep
    nixpkgs.ripgrep  ripgrep-13.0.0

    11.17s user 2.70s system 73% cpu 18.970 total

Overall I love the idea but it has a long way to go in developer experience and quality before it is ready for any mainstream adoption.
sontek··on Let's Encrypt DST Root CA X3 has expired
We had hundreds of old lambda functions that have been running for years and so we haven't thought about them for a long time.

Since they were on node v10 they stopped being able to talk to letsencrypt SSL sites today. Since AWS has stopped supporting v10 we couldn't upgrade them to the minor version of v10 that supports the CA

sontek··on CoffeeShopWifi.com – An HTTP website for connecting to guest WiFi
I use http://neverssl.com :)
sontek··on I made a mistake with Terraform and Azure made it worse
Yeah, terraform cloud from hashicorp does this
sontek··on HN was down
Same, I don't understand why the font is so small by default. Just use the default browser font size I've defined as a user!
sontek··on Why we went passwordless on our new product
Maybe he can clarify. I don't want to assume he meant "not equals" but thats what I found on google
sontek··on Why we went passwordless on our new product
A layer of privacy shouldn't be downvoted or considered complexity. If someone chooses to not be tracked that is not something to look down on.

If you care about privacy, you'll pick flows that all your users to maintain their privacy.

sontek··on Why we went passwordless on our new product
I'd expect most 2fa to be through an authenticator app (google authenticator for example), SMS, or a physical device like yubikey.

I don't think I've seen anyone use e-mail for 2fa. All the devices I listed above are in real-time through TOTP timings. E-mail is NOT in real-time.

sontek··on Why we went passwordless on our new product
I had to google "~=" had no idea some languages use that for "not equals" instead of !=.

I've only found lua and MATLAB that use it but its interesting to understand. I was super confused on what you were trying to say.

sontek··on Why we went passwordless on our new product
How are magic links higher security than passwords + two-factor auth? A magic link gives an attacker the ability to compromise any sites using magic links as long as they get access to the e-mail.

2fa + password means they could compromise the e-mail and still not be able to reset a password without the TOTP.

Social Auth is even more secure than magic links because the larger companies like Facebook and Google have already implemented SECURE 2fa and they've also implemented IP / Computer tracking so that if abnormal authentication happens you have to go through better verification.

If a magic link gets opened from Argentina when the user traditionally logs in from North Dakota, are you blocking that until they go through more verification? If not its not more secure.

sontek··on Why we went passwordless on our new product
"Passwords are dying"

NOPE. Magic Links are dieing. This is probably the 20th time I've seen a start-up posting proudly about how they chose magic links over standard auth and I don't think any of them have stuck.

It is a TERRIBLE user experience.

* We have a tab open on your site, it tells us to go to our e-mail to get a link, and then that opens up a different tab.

* Or we only check that address on phone which means we can't easily login on desktop unless we also have that e-mail address logged in on desktop as well.

* It removes our ability to use password managers.

* Doesn't allow us to have multiple e-mail addresses easily. Now I have to remember what e-mail address I used for your service to go find the magic link.

STOP doing it. Give people two-factor authentication. Give people options if you want and see if anyone opts into magic links.

All that being said... It looks like this service does require password for sign-up and login right now unless you use google auth? Not sure how this blog post relates to the actual company. Maybe its something they are thinking about doing?

← PreviousPage 3 of 11Next →