For example I have a zap right now that every time I react in slack with :todoist: it adds it to my TODO backlog. If I can use AI to read that thread and put a summary in there that'll make me more productive.
743 karma · joined May 9, 2011
For example I have a zap right now that every time I react in slack with :todoist: it adds it to my TODO backlog. If I can use AI to read that thread and put a summary in there that'll make me more productive.
https://github.com/sontek/homies
1. I use a `justfile` that calls `nix profile install ...` to install my packages, rather than using a nix configuration file. This allows me to use a standard package manager workflow rather than going "all in".
https://github.com/sontek/homies/blob/master/justfile#L24-L2...
2. I then use GNU Stow to install my dotfile configuration:
https://github.com/sontek/homies/blob/master/justfile#L93-L9...
I think this is a great middle ground where I can utilize `nix` as my package manager across Linux and Mac and have consistency while not having to learn the whole configuration language or change my workflow.
The other tools I use heavily in my environment:
- https://asdf-vm.com/: I find this better than installing python/node/etc from nix.
- https://github.com/casey/just: I use this as my command runner (similar to make but cleaner in my opinion)
The one thing I would be concerned about is the ~2 months after layoffs are pretty rough morale wise.
- People lost their friends and are upset about it
- Systems start breaking and the knowledge of them was lost
- Team restructuring means learning how to work with new people
- Adjusting expectations for the new velocity of the remaining engineers takes time
I personally would not join a company that recently did layoffs because socially its going to be awkward for awhile.
> K8s can go a lot of different ways depending on the type of LB
k8s flexibility shouldn't be counted against it here. If you are considering k8s against fargate, you should only be considering ALB / NLB ingress and not the many more ways you could. Just use what AWS provides and be happy with it :) > ECS you just configure a log group and get persistent logging and basic aggregated searching with Cloudwatch Insights
You can log to cloud watch with EKS as well. Fluentd can log to cloudwatch with very little configuration.I agree that if you are already "all AWS" and just want to put one more thing in there, Fargate might match your existing patterns better. But saying "Fargate is easier than managed kubernetes" is very wrong.
In general I've seen people have an easier time understanding kubernetes manifests for declaring their services instead of the equivalent terraform to get fargate up and running to do the job.
> On AWS, that would be Fargate on ECS, or on Google Cloud, Google Cloud Run.
> You won't have to manage servers, network overlays, logging, or other necessary middleware.
I disagree with this take. EKS is a managed service just like Fargate and you have to learn how to manage both equally (VPCs, CIDR ranges, IAM rules, etc). You might as well start on kubernetes if you are going to switch to it eventually. > I'd suggest that teams adopting Kubernetes (even the managed versions) have an SRE team, or at minimum, a dedicated SRE engineer.
I'd love to hear what parts of running EKS require an SRE team and how Fargate/ECS solve that issue and make it self-serviceable.I can't think of one org I've ever worked at that hit a sweet spot where you were able to hire exactly as many engineers as you needed while keeping up with growth and attrition.
All I want is a way to say "I want jq, kubectl, and terraform installed" and have it available globally. Not for specific projects or anything like that.
Right now I maintain a makefile that installs everything for me using `nix profile`:
https://github.com/sontek/homies/blob/master/justfile#L14-L2...
Which almost exactly like I want. Only issue is sometimes a new hash is generated (which I don't understand.. maybe a config update in the repos?) and the makefile can't run anymore:
error: packages '/nix/store/y65pp5hipid0fzxl1z7xjxdk4h9jwfw7-exa-0.10.1/bin/exa' and '/nix/store/gy0bqcs9mcan8af47wakdylhal67dpy4-exa-0.10.1/bin/exa' have the same priority 5; use 'nix-env --set-flag priority NUMBER INSTALLED_PKGNAME' to change the priority of one of the conflicting packages (0 being the highest priority)
I've avoided home-manager because it says: Unfortunately, it is quite possible to get difficult to understand errors when working with Home Manager, such as infinite loops with no clear source reference. You should therefore be comfortable using the Nix language and the various tools in the Nix ecosystem. Reading through the Nix Pills document is a good way to familiarize yourself with them.
If its common enough to warn about it, not quite the tool I'm looking to pull into my environment.For example, docs I've referenced in the past are here: https://nixos.org/manual/nixpkgs/stable/#sec-declarative-pac...
It says to run:
nix-env -iA nixpkgs.myPackages
Is this incorrect?Also the name is confusing, it return `x86_64-linux` on linux and `x86_64-darwin` but why does that information need to be included? Then it brings up the problem if I need to install with the whole long string or if I can just install with `ripgrep`.
The other big grip I have with the new CLI is the installed packages. If you run:
> nix profile list
You get a gob of mostly unreadable text scrolling through your screen: 72 flake:nixpkgs#legacyPackages.x86_64-darwin.toilet github:NixOS/nixpkgs/19574af0af3ffaf7c9e359744ed32556f34536bd#legacyPackages.x86_64-darwin.toilet /nix/store/hnvdydra5syylxnxwj2fmn91aqwz26p6-toilet-0.3
73 flake:nixpkgs#legacyPackages.x86_64-darwin.asdf-vm github:NixOS/nixpkgs/b66b39216b1fef2d8c33cc7a5c72d8da80b79970#legacyPackages.x86_ 64-darwin.asdf-vm /nix/store/skk5pfhjnj49gw184jwivd5wakxx5g23-asdf-vm-0.8.1
and for some reason includes a bunch of duplicate packages, so its very confusing: > nix profile list|grep lolcat
22 flake:nixpkgs#legacyPackages.x86_64-darwin.lolcat github:NixOS/nixpkgs/19574af0af3ffaf7c9e359744ed32556f34536bd#legacyPackages.x86_64-darwin.lolcat /nix/store/zxnkjsimmcvv0jnwsy5jxxmjak01k52f-lolcat-100.0.1
46 flake:nixpkgs#legacyPackages.x86_64-darwin.lolcat github:NixOS/nixpkgs/19574af0af3ffaf7c9e359744ed32556f34536bd#legacyPackages.x86_64-darwin.lolcat /nix/store/zxnkjsimmcvv0jnwsy5jxxmjak01k52f-lolcat-100.0.1
71 flake:nixpkgs#legacyPackages.x86_64-darwin.lolcat github:NixOS/nixpkgs/19574af0af3ffaf7c9e359744ed32556f34536bd#legacyPackages.x86_64-darwin.lolcat /nix/store/zxnkjsimmcvv0jnwsy5jxxmjak01k52f-lolcat-100.0.1
Same package name, hash, and version listed 3 times for some reason. I ended up writing an alias that would give me a readable list: > which npl
npl: aliased to nix profile list|awk '{print $2}'|sort|uniq|sed s/flake:nixpkgs#legacyPackages.x86_64-//g|sed s/darwin\.//g
> npl
argocd
asdf-vm
aws-vault
awscli2So if nix could allow me to get the tools I need without context switching that would be a great addition. I don't want to have to go edit configuration files just because I haven't installed some tool yet.
curl example.com/data.json | jq ...
and I'll realize I don't have `jq` installed. I do not want to open vim, edit a configuration file, and then re-run a command to rebuild my system. I just want jq. I can't change context like that just to get a package.I understand this isn't aligned with the purity stance that nix has but if they were able to allow this use case, it would most likely get more people doing it the right way eventually.
I can't drink all the kool-aid at once, I really need to replace bits of my workflow at a time and I can't do that with nix currently.
The approach I've laid out in my original comment (using `nix-env`) provides a bad developer experience and makes me not able(willing?) to move forward with the adopting more of the practices. If the initial experience was better, I'd invest more time learning more.
For example, if you want to install a package the old way, you'll install it including the channel:
nix-env -iA nixpkgs.ripgrep
but then if you want to remove one, you don't reference the channel: nix-env -e ripgrep
You have a similar issue if you want to use the new `nix` command. To install a package you'll do: nix profile install nixpkgs#ripgrep
but running: nix profile remove nixpkgs#ripgrep
will do nothing. It won't say "I didn't remove the package" or "package not found". It just returns silently. The only way to remove it is to point to the number from `nix profile history` or the actual path.It is unbearably slow:
> time nix-env -qaP ripgrep
nixpkgs.ripgrep ripgrep-13.0.0
11.17s user 2.70s system 73% cpu 18.970 total
Overall I love the idea but it has a long way to go in developer experience and quality before it is ready for any mainstream adoption.Since they were on node v10 they stopped being able to talk to letsencrypt SSL sites today. Since AWS has stopped supporting v10 we couldn't upgrade them to the minor version of v10 that supports the CA
If you care about privacy, you'll pick flows that all your users to maintain their privacy.
I don't think I've seen anyone use e-mail for 2fa. All the devices I listed above are in real-time through TOTP timings. E-mail is NOT in real-time.
I've only found lua and MATLAB that use it but its interesting to understand. I was super confused on what you were trying to say.
2fa + password means they could compromise the e-mail and still not be able to reset a password without the TOTP.
Social Auth is even more secure than magic links because the larger companies like Facebook and Google have already implemented SECURE 2fa and they've also implemented IP / Computer tracking so that if abnormal authentication happens you have to go through better verification.
If a magic link gets opened from Argentina when the user traditionally logs in from North Dakota, are you blocking that until they go through more verification? If not its not more secure.
NOPE. Magic Links are dieing. This is probably the 20th time I've seen a start-up posting proudly about how they chose magic links over standard auth and I don't think any of them have stuck.
It is a TERRIBLE user experience.
* We have a tab open on your site, it tells us to go to our e-mail to get a link, and then that opens up a different tab.
* Or we only check that address on phone which means we can't easily login on desktop unless we also have that e-mail address logged in on desktop as well.
* It removes our ability to use password managers.
* Doesn't allow us to have multiple e-mail addresses easily. Now I have to remember what e-mail address I used for your service to go find the magic link.
STOP doing it. Give people two-factor authentication. Give people options if you want and see if anyone opts into magic links.
All that being said... It looks like this service does require password for sign-up and login right now unless you use google auth? Not sure how this blog post relates to the actual company. Maybe its something they are thinking about doing?