HNHacker News
TopNewBestAskShowJobs

yatsyk

503 karma · joined February 18, 2010

http://andrey.yatsyk.com

yatsyk@gmail.com

submissionscomments
yatsyk··on Ask HN: How do you manage skills files?
I mainly use Claude Code, but I had an idea to build an orchestrator for coding agents, so I experimented with several
yatsyk··on Ask HN: How do you manage skills files?
Skills live in two source-of-truth git repos (private and public). Agents edit skills by my request, and syncs to all coding agents ~/.claude/skills/, ~/.codex/skills, ~/.pi/agent/skills, ~/.config/opencode/skills etc. with agent written sync-agent-skill script. script ensures that no local changes was made in-place.
yatsyk··on Show HN: Guts – convert Golang types to TypeScript
I prefer to use Zod or JSON Schema as the source of truth. Then I use QuickType [1] in the build process to generate code in different languages. This lets me share data structures. I mostly do this in Tauri apps to keep the same data shape in TypeScript and Rust. I also use it to define protocols, like for REST APIs.

Here are the advantages of this approach compared to using guts lib: - I get validation with clear error messages. - It supports many languages out of the box. - I don’t need to maintain a custom library. - JSON Schema is well supported in LLMs (for example, with structured output or vibe coding).

[1] https://quicktype.io/

yatsyk··on I'm turning 41, but I don't feel like celebrating
I’m more focused on the situation from Musk’s point of view, not yours. Maybe your view is less controversial. But I don’t think Musk sees China and Russia as failed states. He’s said many positive things about both countries.
yatsyk··on I'm turning 41, but I don't feel like celebrating
If he had written that Western Europe is moving toward China’s model, I would have had no questions about his tweet and would have fully supported it.

As I understand it, Durov doesn’t agree with your statement — you can check point 5 of his 2014 manifesto [1]

[1] https://globalvoices.org/2014/03/13/pavel-durovs-seven-reaso...

yatsyk··on I'm turning 41, but I don't feel like celebrating
I share Durov’s disappointment about where the internet is heading.

But I think it’s hypocritical to talk about freedom of speech issues in Western Europe while ignoring similar or worse restrictions in China, Russia, or Dubai, where he lives.

It’s similar to Musk’s approach — when Twitter is shut down in Brazil, it’s a freedom of speech violation, but having a Tesla factory in China suddenly makes that problem disappear there.

yatsyk··on Treemaps are awesome
https://treemap.yatsyk.com/

Disclaimer: I'm the author

yatsyk··on Treemaps are awesome
Shameful plug: I've made an npm library for treemaps [1]. There is a sample app [2] that can draw a treemap of your drive file system, similar to SequoiaView or Disk Inventory X, in the browser using the file system API.

[1] https://treemap.yatsyk.com/ [2] https://treemap.yatsyk.com/folderstat

yatsyk··on Show HN: FolderStatsApp – analyse your disk usage with treemap visualisation
Hello HN,

I've created npm module for cushion treemap rendering [1]. Treemaps is most compact way to visualize huge tree structures such as file sytem.

[1] https://treemap.yatsyk.com/

yatsyk··on Show HN: I built an internet speed analytics tool
Usually I'm adding linuxserver/smokeping docker container to boxes I want to check internet speed history.
yatsyk··on Show HN: Meli, a Netlify-like platform for deploying static sites
I've not found in docs anything related to static site configuration files (like netlify.toml or vercel.yml in hosted services). How to configure particular site?
yatsyk··on Show HN: Transport Schema Editor
Author here.

This tool allows to create transport schemas such as metro maps. You can import data from open street map data to save time or start from scratch. Maps stored in git repository so you can consider this editor like headless CMS for static site and in order to edit schema created by other user you need to fork it.

yatsyk··on Strapi – Open-source Node.js Headless CMS
If someone used strapi and parse platform, how would you compare two platforms as self hosted api backends?
yatsyk··on React-flow: a library to create interactive node-based graphs
For example: can I connect one port of node to other port of node and how this connection needs to be drawn.
yatsyk··on React-flow: a library to create interactive node-based graphs
There are few similar libraries. I think most feature reach is https://github.com/projectstorm/react-diagrams , but there is also https://github.com/DrummerHead/react-flow-diagram https://github.com/alibaba/GGEditor , actually I’ve found about 15 different js open source react and non-react editors for node-based UI. But unfortunately most of them is not very extensible. One of the reason is that the authors prefer to store state inside component, so it’s impossible to create non-trivial behaviour.
yatsyk··on Redux – Not Dead Yet (2018)
I can’t justify redux usage apart from legacy support. Mobx (preferred) or hooks for some apps/components.
yatsyk··on Why Windows 95 and 98 would crash after 49.7 days of uptime
When you start development version of Windows CE or Windows Embedded (don’t remember exactly which one) tick count timer wasn’t set to zero but max dword minus number of milliseconds in two minutes. So counter overflows in 2 minutes after system start. This is very smart way to catch such bugs.
yatsyk··on Redwood: An integrated, full-stack, JavaScript web framework for the JAMstack
Next is limited to browsers and doesn't prescribe how you access data. I would compare redwood to meteor.js but not next.js.
yatsyk··on Redwood: An integrated, full-stack, JavaScript web framework for the JAMstack
Congratulation on launching!

I like rails, but in js world may be not so good idea to reimplement or integrate everything related to ui, routing etc. Meteor.js was not very successful with this model. I think routing or UI on react-native/web/blessed/VR is too different to be part of one framework.

But I see the usefulness of framework with functionality related to data fetching and business logic.

I consider perfect stack for this things is Postgress->Hasura (or also Prisma)->mst-gql->mobx-state-tree. You create database schema and everything up to models on client is autogenerated and each part of this stack could be updated, customized or completely rewritten. This stack could be used on react-native or web or any other js platform.

yatsyk··on CouchDB 3.0
I'm not asserting that couch is unsecure, I need such database but the problem that I can't see any resource that could help me design secure production system.

You can check even trivial rails blog or todo example from some book and it will be limited in scope but more or less secure. I'm having hard time to find secure couchdb example.

> Security for all systems is non trivial. But not equally hard.

If you use firebase you should understand that you getting vendor lock-in and in some cases you can spend much more money, but for some types of projects this platform is ok for me.

Same with couchdb, I understand that if I get replication with client, I need to pay by reorganising data or may be spend more resources to make system secure. There is no free lunch.

yatsyk··on CouchDB 3.0
No I'm not assuming constraint on the number of comments. First example shows how easy limit number created objects. Spam prevention is other topic not so trivial but mostly solved problem.
yatsyk··on CouchDB 3.0
Couch is not equivalent to mongo or relational because it accessible to clients if we want synchronisation. Securing app server is manageable problem and there is huge number of resources how to do it correctly.

In case of couch I've not seen any secure open-source example.

I'm not focused on DOS attacks, I'm just proposing different attack vectors.

yatsyk··on CouchDB 3.0
If you need to limit the number of items it is trivial. You need to write something like `has_many :things, :before_add => :limit_things` in app server or create constraint in sql.

Spam prevention is not trivial but mostly solved problem. You can find a lot of articles about this topic.

But creating secure couchdb looks like very non-trivial.

yatsyk··on CouchDB 3.0
It’s trivial to limit number of created documents in postgres, couchdb or application server though validation, I’m talking about updating document not creating new. In posgres if I update 1mb document used space will not always grow. In couch db situation is different. In case of relation db you have application server with custom logic and validations, couchdb from other side is accessible from outsize.

My idea that it’s very hard to create safe couchdb based system and most recommendations limited to setup nginx proxy and authenticate users which is not enough.

yatsyk··on CouchDB 3.0
> What kind of document are you looking for here? > There is [1], but yeah, that covers access controls. As do the MongoDB [2] and Postgres [3] documents.

Mongo and postgress usually is not accessible for clients only for backend. Security handled by backend mostly and there is a plenty of resources how to implement secure server side applications which discusses attack vectors and how to make secure apps. Thankfully to this thread I’ve got few good ideas, that may help to design secure couchdb architecture (such as remove _find endpoint) but I’ve not seen any in-depth document about couchdb.

> I feel like your thinking about Couch as exposing your entire PostgreSQL DB to the internet

No, why do you think so?

yatsyk··on CouchDB 3.0
As far as I remember it was a filesystem limit not couchdb limit. It was a problem that file always grow and couchdb crashed when limit exceeded. Can't find particular issue, but googling show some issues [1] that make me think that we should be very careful with db size.

[1] https://stackoverflow.com/questions/40752578/couchdb-views-c...

yatsyk··on CouchDB 3.0
> I’m not clear what you mean by limiting "not only particular document but database".

I’ve limited document size to 10mb and ratelimited updates to 10 per second. Client starts to update document with random data 10 requests per second. As far as I understand couch stores all versions at least some time. This means that this one client could fill space on my server 100mb/s. There is no such issues with postgress, and no one allow clients execute raw queries on database without any application server. Document only 10mb but database is huge.

> What kind of "expensive" query are you envisioning?

I have never used couch, so I don’t know what could be expensive. May be some lookup without index or something like this.

Sorry for my ignorance, is it true that if I limit couch only to replication it will not be any not indexed lookups?

Looks like implement secure system with couch is very hard but I can’t find any best practices, mostly only authentication and basic validation.

yatsyk··on CouchDB 3.0
Is it any documents that describes secure couchdb architecture? Most of the articles I find are limited to authentication and basic permissions.
yatsyk··on CouchDB 3.0
Thank you for pointing at validation, I'll check it. It's not completely clear what is it possible to limit not only particular document but database, or how to handle conflict if document changed on pouch, but rejected on couchdb server.

I'm not sure about current time but previously it was a problem that couchdb file grow until some limit on filesystem and couchdb just crashed.

Start of the envoy readme: it's not battle tested or supported in any way. Also it doesn't do any validation apart from limiting permissions for different users.

It's easier to reimplement couchdb than to create smart proxy that will estimate is this query expensive or not.

I'm not saying about rate-limiting proxy or load-balancing to different backends which could be implemented on nginx or something else.

yatsyk··on CouchDB 3.0
If I use backend I can create all validation logic in application server. But in this case no automatic synchronisation.

One of the major selling point of couchdb is replication protocol for client-server data syncing. When you design product with posgress you don't allow to execute raw sql queries from clients without any application server. But looks like it is recommended way to update data in couchdb world if you want to have synchronisation. I can't understand how can this architecture be secure?

Page 1 of 8Next →