HNHacker News
TopNewBestAskShowJobs

stroebs

233 karma · joined June 6, 2025

Contact stripes_67morel@icloud.com
submissionscomments
stroebs··on The internet discovers TLA+. Now what?
17 mentions of “TLA+” before defining the acronym.
stroebs··on PS5 Linux lead quits: "a bunch of noobs using LLMs" that "they don't understand"
Just this morning I had a senior manager say to me "I was trying to do someone else's job and give them all the info so they can review it as I have no knowledge" in response to me asking for them to please filter the Claude word salad using the meat proxy. I'm pretty tired of having to do the job of filtering the low-effort copy-paste walls of text
stroebs··on Leaving VMware just got harder after Broadcom pulled VDDK downloads
I always thought it was heavy on operational knowledge too. Hence why we haven't moved to it yet.
stroebs··on Leaving VMware just got harder after Broadcom pulled VDDK downloads
VMware is still seen as "platinum" level in my org compared to Proxmox, which I guess to a certain degree is true. But the features in use are basic VMs with vMotion. Proxmox provides that out of the box. Granted we've had a couple issues with a corosync wobble on larger clusters which was fixed long-term by putting corosync on a separate set of switches.

So far the Proxmox experience has been pretty flawless. We run a several hundred k8s VMs orchestrated by Rancher and use the dynamic load balancing feature that came with 9.2 so no noisy neighbours. Haven't dabbled too much with Ceph as the VMs are backed with NetApp arrays but I anticipate it to be pretty smooth when we reach that point.

stroebs··on Among European Companies That Use a CDN, Nearly 9 in 10 Use Cloudflare
For better or worse, the free plan that Cloudflare has provided me for 10 years for my 20-30 hobby/personal domains has gotten them several hundred thousand dollars in business.
stroebs··on How Kubernetes Probes Work
I need to know how to animate things like this for internal documentation.
stroebs··on Why does Opus 5 feel worse to work with?
I never drank the Opus 5 koolaid and stuck with 4.8 while my colleagues moved to 5. My major annoyance is pull requests that 5 opens with huge descriptions based on simple code changes. At this point I have stopped allowing CC to create commits or open PRs because it’s unreviewable by a human if so due to the absolute word salad it generates.
stroebs··on HomeLab #1: MikroTik as a Home Router
I've been a MikroTik fan since the beginning of my career some 15 years ago now. I have used the MikroTik router and Ubiquiti AP combination ever since. With that said, I can absolutely agree that their UX is terrible for anyone who doesn't specifically know how to configure a MikroTik router. The fact that you have to configure FQ-CoDel yourself and some bufferbloat protection isn't just a built-in option is absurd for anyone using it as a home router.
stroebs··on Ask HN: What are you working on? (May 2026)
An EU replacement for PagerDuty, focusing on the absolute basics - SSO as the minimum even on free, no AI driven workflows, overviews etc. but may include ML/AI driven insights in future since that’s the way the world seems to be going.

https://rotadeck.com/

stroebs··on Two Home Affairs officials suspended after AI 'hallucinations' found
Add the insult that these two officials have no doubt been suspended on full pay and benefits while the year-long investigation takes place at great expense to the tax payer. After which they are moved to a different government department as “punishment”.
stroebs··on When networking doesn't work
I came across this very same issue with fika, a community-made mod for Escape from Tarkov. One player would consistently fail to join games and it took ages to figure out the different components that were failing. The code intentionally sent the join message 4 times in quick succession, which triggered the DoS protection on the internet firewall. Ok, disabled that. The next issue was the packets were being interfered with by the ALG on the internet firewall, so disabled that too. Then the last final hurdle was the Rx offloading on the Intel NIC which was the exact same issue with the checksum being set to all 0’s or all F’s.

What made it confusing at the time is the join packet would sometimes be accepted and passed through to the game, so it prompted further digging into why.

stroebs··on Infrastructure decisions I endorse or regret after 4 years at a startup (2024)
The Bottlerocket issues really surprise me - not an experience I've shared even with heavy use. I use EKS with Bottlerocket + managed addons + Karpenter, and our security team is super happy that _nobody_ has access to the underlying nodes. Immutable OS is a key selling point, and Brupop "just works" to keep everything up to date without any input. Patching nodes is something I haven't had to think about in almost a year.
stroebs··on Show HN: Artifact Keeper – Open-Source Artifactory/Nexus Alternative in Rust
I'll carve out some time to add a discussion as I've become quite passionate about artifact storage in the last 18 months as a result of having to look after this behemoth. Air-gapping is also pretty important - JFrog supports granular proxy specification by repo.

It's a great start. What I can say is that granularity of CVE's in policies will become important for larger consumers. We have about 4.5mn artifacts so even getting CVSSv3 10's blocked was a challenge, let alone 9.8.

stroebs··on Show HN: Artifact Keeper – Open-Source Artifactory/Nexus Alternative in Rust
I’m a fairly heavy user of the JFrog platform with Enterprise+, Xray, their new Curation license, and my org is spending in excess of $500k/year on Artifact storage. Not including my time babysitting it. I’d love to see the end of it, and I hope you manage to build a community around this.

Part of the reason we pay the big license fee is so we have someone to turn to when it inevitably breaks because we’ve used it in a way nobody has before. In Jan last year we were using 30TB of artifact storage in S3. That’s 140TB today.

Where do you get your CVE data? Would built artifacts have their CVEs updated after the fact? Do you have blocking policies on artifacts based on CVEs, licenses, artifact age, etc?

stroebs··on I rebooted my social life
This resonated hugely with me, with the grand addition that I moved to a different country a week before COVID lockdown. I’ve since reached a lot of pretty big life milestones (house, career, spouse, kid (soon)) and realised my life was still pretty empty because I’m not the introvert I once thought I was.

What I’m personally missing is the social capital. “Just invite people to stuff” doesn’t work, because my prior in-person social network is fragmented over 3 continents and many more countries and time zones. Minting new social capital is difficult - joining social events requires an invite to a social event to meet other people to start the process.

stroebs··on The Cloudflare outage might be a good thing
Yes, literally impossible. The barrier to entry for anyone on the internet to create a proxy or VPN to bypass your geofencing is significantly lower than your cost to prevent them.
stroebs··on The Cloudflare outage might be a good thing
The problem is far more nuanced than the internet simply becoming too centralised.

I want to host my gas station network’s air machine infrastructure, and I only want people in the US to be able to access it. That simple task is literally impossible with what we have allowed the internet to become.

FWIW I love Cloudflare’s products and make use of a large amount of them, but I can’t advocate for using them in my professional job since we actually require distributed infrastructure that won’t fail globally in random ways we can’t control.

stroebs··on Do not put your site behind Cloudflare if you don't need to
I get your gripe, but the free protection that Cloudflare offers automatically often far exceeds the effort required to thwart some random script kiddie’s attacks on my client’s Wordpress site. Add easy caching, tunnels, automated certificate management, etc. to that and it’s obvious why a lot of sites use them.
stroebs··on I didn't reverse-engineer the protocol for my blood pressure monitor in 24 hours
https://github.com/bottlesdevs/Bottles
stroebs··on Vodafone Germany is changing the open internet, one peering connection at a time
I thought Google was _always_ like this. At least going back to 2015 when I left the ISP game, peering with them was notoriously difficult if you didn't have the traffic volumes required. Our network suffered from asynchronous routing to Google and Netflix for years because they refused to allow our routes despite checking all the boxes they require. Customers eventually left because other (larger) ISPs didn't have this issue.

I get why the enshittification of IXPs is occurring. Over the years many small and careless ISPs have caused issues for IXPs (and peers) based on what I've seen on mailing lists. It's hard work managing many hundreds or thousands of peers, let alone the equipment cost with multi-100Gbit ports becoming the norm for larger providers.

stroebs··on South Africa's one million invisible children without birth certificates
One of the basic requirements for an ancestry visa.
stroebs··on South Africa's one million invisible children without birth certificates
My father (born in ZA) had to re-register his birth at 65 when emigrating to the UK on a visa. The ZA government had no record of his birth, despite him having a drivers license, passport, tax returns for 40+ years…

This is the least bit surprising coming from a country that is in steady decline.

stroebs··on Seeing like a software company
> sanctioned efforts like this are almost always temporary. The majority of the illegible work that occurs in large organizations is still unsanctioned.

The title “DevOps Engineer” often fits a permanent role of sanctioned illegibility in large organisations. One cannot explain exactly what a “DevOps Engineer” does, because (a) you cannot _engineer_ a culture, and (b) largely these engineers do urgent and important work that cannot be planned, estimated, put into sprints, etc.

I’ve had this title through several of my roles at orgs over the years and I detest it, but nonetheless understand why it exists.

stroebs··on Digital ID – The New Chains of Capitalist Surveillance
Having grown up in South Africa, having a physical document to prove who you are, along with an identity number is just so normalised. When I moved to the UK later in life, I found it absolutely bizarre that there’s no mechanism to uniquely identify yourself to the government, or any other entity that deals with your personal/financial/health identity. It’s just a combination of name and address, which anyone can access with ease.

Digital identity is on the slightly more controlling side of this, but the article focuses entirely on the cynical perspective without considering the positives.

stroebs··on Slack has raised our charges by $195k per year
Classic Salesforce. The exact same thing happened with our org and Heroku. Zero empathy, just pony up or we trash your company.
stroebs··on How Not to Buy a SSD
I’d also like to point out that those Kingston A400’s are notoriously terrible and had a firmware bug that caused the behaviour you describe if you don’t update it before it happens.

I purchased 10 genuine new from a verified vendor and 6 had to be RMA’d within the first year.

stroebs··on Show HN: I built an app to block Shorts and Reels
This is brilliant. I have dreamed of a way to force companies to build in parental control to block short-form media. For the kids (it's never for the kids).
stroebs··on The Enterprise Experience
Pretty accurate having worked for startups and $ENTERPRISE alike.

I recently switched from startup to $ENTERPRISE and the thing I’m struggling with the most is time zones. My manager is 11 hours ahead and infrastructure/security change approvers are 6 hours behind.

Now add the big shift back to on-premises infrastructure and it’ll be impossible to get anything done.

stroebs··on Show HN: Unregistry – “docker push” directly to servers without a registry
Your SSL certificate for zothub.io has expired in case you weren’t aware.
stroebs··on Tell HN: Help restore the tax deduction for software dev in the US (Section 174)
> most other countries have similar rules.

This is the first instance I’ve heard of where salaries aren’t considered remuneration for basic labour. It’s a fairly weird interpretation of reality that spending $200k on a human’s availability results in a guaranteed $200k of capital being created, regardless of which country this kind of tax law exists in.