HN user

Titanous

4,820 karma

jonathan@titanous.com

Posts90
Comments321
View on HN
cyberscoop.com 3y ago

Security professional tweets prompt major change to Google email authentication

Titanous
1pts0
infosec.exchange 3y ago

BIMI logo and verified checkmark are spoofable in Gmail

Titanous
3pts0
github.com 5y ago

Fish in a Barrel Memory Safety Bounty Program

Titanous
52pts23
groups.google.com 6y ago

Firefox TLMC Response to Dark Matter Root Inclusion Request Appeal

Titanous
1pts0
www.cyberus-technology.de 7y ago

ZombieLoad: Cross Privilege-Boundary Data Leakage on Intel CPUs

Titanous
854pts308
www.revealnews.org 8y ago

Tesla says its factory is safer. But it left injuries off the books

Titanous
2pts0
labs.detectify.com 8y ago

How I exploited TLS-SNI-01 to issue Let's Encrypt certs using shared hosting

Titanous
9pts2
cloudplatform.googleblog.com 8y ago

Introducing Nested Virtualization for Google Compute Engine

Titanous
4pts0
www.whitehouse.gov 9y ago

The People's Code

Titanous
9pts2
www.facebook.com 10y ago

1M People Use Facebook Over Tor

Titanous
388pts158
www.rgj.com 10y ago

RGJ attorney: Tesla guards roughed up journalist

Titanous
1pts0
medium.com 10y ago

CS183C Session 8: Eric Schmidt

Titanous
113pts49
www.bloomberg.com 10y ago

American Airlines, Sabre Said to Be Hit in Hacks Backed by China

Titanous
1pts0
www.pagerduty.com 10y ago

Important Security Announcement from PagerDuty

Titanous
76pts30
dspace.mit.edu 11y ago

Keys Under Doormats: Mandating insecurity by requiring govt access to all data

Titanous
2pts0
nytimes.com 11y ago

Code Specialists Oppose U.S. And British Access to Encrypted Communication

Titanous
4pts0
win95.ajf.me 11y ago

Windows 95 in your browser

Titanous
1pts0
flynn.io 11y ago

Flynn (YC S14) Gamma and Meetup

Titanous
57pts12
titanous.com 11y ago

Docker Image Insecurity

Titanous
263pts100
twitter.com 11y ago

Twitpic is blocking the Archive Team from making an archive

Titanous
16pts2
blogs.fas.org 12y ago

Cryptographer Adi Shamir Prevented from Attending NSA History Conference

Titanous
32pts1
grahamcluley.com 12y ago

Security researchers rewarded $12.50 voucher to buy Yahoo T-shirt

Titanous
65pts20
abad1dea.tumblr.com 12y ago

Anger Against Surveillance

Titanous
1pts0
rt.com 12y ago

Pentagon considers employees unhappy with US policies a security threat

Titanous
11pts6
video.state.gov 13y ago

US State Department Daily Press Briefing - July 12, 2013 [video starts at 1:50]

Titanous
2pts0
basho.com 13y ago

Basho Announces Availability of Riak 1.4

Titanous
1pts0
duckduckgo.com 13y ago

DuckDuckGo launches Search & Stories app

Titanous
140pts73
www.guardian.co.uk 13y ago

Fisa court oversight: a look inside a secret and empty process

Titanous
9pts4
edition.cnn.com 13y ago

Bruce Schneier: Has U.S. started an Internet war?

Titanous
237pts119
www.eff.org 13y ago

FISA Court Rejects Catch-22 Secrecy Argument in FOIA Case

Titanous
222pts47
RIP Flynn.io 5 years ago

Other cofounder here. I just wanted to add that we still have some t-shirts and stickers left. So if you want some defunct project/startup swag, we'd love to send it to you! https://shop.flynn.io

Yes, when you use a US carrier roaming in China you have a US IP:

This censorship occurs despite the fact that when in China a cell phone using a foreign SIM is not subject to the firewall restrictions (all traffic is tunneled back to your provider first), so Google, Twitter, Facebook, et al all work fine on a non-mainland China SIM even though you’re connected via China Mobile or China Unicom’s network.

Flynn developer here. This is correct, a three node cluster can withstand loss of any single host before things start failing.

Also, log shipping and Let's Encrypt support are coming soon.

No current plans, but feel free to request it in a GitHub issue. We consider the number of votes on GitHub when adding to the roadmap.

When we started in 2013, the only open source scheduler available was Mesos and the ecosystem didn't have community efforts like Kubernetes, so we had to write our own components to build Flynn.

Flynn is designed to be an end-to-end solution for production deployment, and all of our components are created to work together. The whole system is self-bootstrapping and self-hosting, so installation is easy, and the same APIs are used to manage the whole platform as are used to manage apps deployed on it.

In addition to the twelve-factor stateless webapps that Deis Workflow supports, Flynn also includes highly available database appliances with safe, automatic failover (currently PostgreSQL, MySQL, and MongoDB with more coming in the future). We also have a bunch of security features coming over the next few months like Let's Encrypt support and flexible user authentication with 2FA and very granular access control.

If you don't need or want our database appliances and you are comfortable with Kubernetes and happy to install and operate it, then Deis Workflow is a good option. If you don't care about using Kubernetes specifically, Flynn is a good pick as it is easier to get up and running with.

There are healthcare companies that already use Flynn today, though not for HIPAA compliance specifically.

Compliance is a really interesting vertical. As we make progress on our security roadmap, Flynn will become a very compelling option for environments like HIPAA, PCI, etc. especially when combined with clouds like AWS that are also compliant.

Yeah, it's definitely something we want to support in the future. Autoscaling requires building some components that are aware of and can communicate the underlying infrastructure APIs (AWS, GCP, Azure, DigitalOcean, OpenStack, etc.) combined with app/host metrics. It's just a matter of putting the implementation effort. We'll get there eventually.

re-deploying a few images on Flynn it wasn't cleaning up images and disk space was disappearing fast

I'm really sorry to hear that you switched off of Flynn. We're aware of this issue, and are in the process of fixing several things that can cause it (it only happens when not using an external blobstore backend like S3). Hopefully you'll try Flynn again at some point in the future!

Flynn itself doesn't communicate with infrastructure APIs currently, but you could hook this up so that there is a base set of three servers that are always running and then an autoscaling group that watched your metrics or a schedule and added/removed servers.

I'd be happy to explain this more on IRC if you're interested (#flynn on Freenode).

If Heroku works for you, that's fine, but for lots of people it doesn't. For example, Heroku only supports HTTP, not TCP. There are a number of technical limitations Heroku places on apps that other platforms like Flynn don't.

There are lots of reasons why users need a different, or especially an open source, PaaS.

Some users run into scaling problems when their products grow beyond a certain point. Others want to have more control over their infrastructure for compliance, governance, or other administrative reasons. Others have huge deployments and want to save money by using their own cloud accounts.

It varies from customer to customer, but for many Heroku isn't an option or isn't the best option.

Yeah, our security roadmap will get us to multi-tenancy eventually.

Due to the security posture of the Linux kernel, we won't recommend running untrusted code side-by-side on the same hosts as more sensitive workloads, but we plan to harden everything to the maximum extent possible.

I'd love to hear about any trouble you ran into while trying Flynn so that we can fix it! Feel free to send me an email: jonathan@flynn.io

Convox is a great pick if you want to use AWS-specific services for your entire stack. Instead of using portable open source components, Convox uses AWS services wherever possible, and acts as a lightweight coordinator to combine them into a platform.

Flynn has no external dependencies on cloud features, so you can run it anywhere, whether that's on your laptop, AWS, Google Cloud, a VM somewhere, or bare metal in a colo or private datacenter. We also include RDS-like highly available database appliances so that your whole stack is portable and you are not locked into a single hosting provider.

edited to add: We didn't know about this post until Bitmatica posted it, this is just a great post from a happy user, not planned Flynn marketing!