HN user

amorousf00p

74 karma
Posts0
Comments33
View on HN
No posts found.

Why you cannot trust this model 101: because it's practitioners understand the value of the labor/product, capitalize on the OSS ideal and then push it to the unsuspecting.

I don't know how many bait and switch episodes from google I need to see but by 2008 I was done with them -- for the first time. Ad-nauseam.

If you boycotted and didn't use Google they would wither and die and stop being something to worry about: for immediate google specific free offerings that are sucker bait. Also for self aggrandizing standards/inclusions and buying the overt talent. But whatever. The HN community is full of dupes and buy ins, culture whores and fifth columnists. True belief in OSS died when everyone else took it and got rich.

You seem to be an absolute type of planner. I used to approach IT mgmt and provisioning that way some years ago before being confronted with the realities of small and large business. One size obviously does not fit all and sometimes you take shortcuts..usually you pay for them later.

I agree with your cautions around supermicro resale but the warranty support and build diligence are absolutely necessary for a small business. Having a good business relationship with a trusted provider of hardware that always performs the first time is priceless.

You'll have to trust me that this examples hardware spec and requirements are for a basic/base site. You can thin the profile and increase the # of chassis, compromise on redundancy, etc...but experience has shown that this arrangement is most cost effective. Kinetic event impact modeling system -w- RT data delivery -- that should answer your conjectures.

No large vendors used in this example - thinkmate or aberdeen supermicro re-brands for due diligence and warranty.

That's sad truth. But it's convenience like anything else.

In my business I can put a hardware site online with

---6X--- 2 x intel gold 5115 10 core + 64 GB RAM 1 nvme @512G + soft raid1 @4TB magnetic 1 10G, 2 1G ether ~= 42K.

---2X--- storage or NAS with 60TB @RAID5 + 2x quad core low end xeon + 32 GB RAM = 16k

---2X--- 1G edge/core mngd switches + 10G SAN/LAN mngd switches = 5K

---2X--- Endian firewalls + threat appliances = 5K

---1X--- Colo with 2 year lease and 25 amps @208v 1g port speed and committed throughput > 100/mbps = 16K yearly

68K one time cost for depreciating assets we maintain, provision and secure + 16K yearly recurring cost.

Or I can go AWS and modify my processing model, security expectations and service infra and spend 25K a year + 15K 1x migration cost.

AWS is a feature factory and they are breaking their own back. Today I had an issue where creating an AMI for an application feature set as a golden image (with a very modest price tag at t1.supersmall or whatever) does not scale into high end compute instances due to lack of support for ena. Never was the case before.

Rolled it back into KVM/QEMU in colo with a glue layer REST interface over virsh and will never look back.

Of course we don't use containers..they don't offer an overt benefit in HPC...and I don't think they ever will.

I think devops was defunct once the asphalt hit the hardpan. Approaching 'generic' secure operational environments as programmable, iterable and contained is one of the great IT lies of the last 20 years.

I'm old school. I look at containers as jails and all the work to isolate applications in containers as of indifferent value given a flat plane process scope with MAC and application resource controls in well designed applications.

That is I default to good design and testing rather than boilerplate orchestration and external control planes.

All containers have done (popularly) in my opinion is add complexity and insecurity to the OS environment and encouraged bad behavior in terms of software development and systems administration.

Kernighan is so nice to listen to compared to some of the the hot air balloons in software today. I use awk everywhere (and have for many years) and am deeply indebted to BK and AR for their work on and custody of that language.

OpenBSD is very nice but it used to be a bit painful for a desktop. Funny, I ran linux on the desktop from 2000-2016 and then went back to windows because I'm getting old. :)

Keep fighting the good fight!

I look at this setup and say to myself that this is just the wrong way to do it. A 'floating' vm to NAT and route? Ceph does look very nice but I have no need for anything but file based storage.

Here is my top down take on a more traditional (cheaper) approach. * 2 1G 5 port edge switches * IDS * vrrpd balanced cots NAT routers -w- RIPng + nginx as generic and web proxy. * LAN 1G 12 port switches (1 hot, 1 cold) * 2 synology NAS (redundant, manual failover). * etc...

I guess what I was trying to say is that instead of dealing with the default parental guidance features of RH and Fedora (which usually ends up with impatient users disabling SElinux and then disabling the stock packet filter) and having to suffer the eccentricities of RH/Fedora systemd and 'socket' activation of an interfering frankenservice you could more profitably spend your time tinkering elsewhere.

I've run it. Still run it for NFS4 cots NAS for HPC clusters and web services. Will be moving back to it next year for HPC nodes...or maybe FreeBSD depending on this acquisition.

fedora was way ahead in performance for years. That was the only reason to go RH-alike but Fedora is _so_ flaky and systemd upstream + attendant cruft like firewalld and the default selinux policies are nightmares. Every Fedora distribution is another set of bugs and workarounds that push you towards RH enterprise..as if you hadn't been doing this for 20 years and needed RH to show you the way.

Fedora is nice if you are doing hypervsiors with QEMU/KVM. Very close to prod out the box.

And how did you expect that to go? Netware was bug central, I used it from 3.x - 6.

Linux killed them...and it was time for Netware to go. I remember the first time I compared Border Manager with OpenSuSE (2.2 kernel -w-w ipchains) & squid as proxy. Eye opening. No more midnight reboots. No more opaque interfaces and $$ for nothing.

This is where I draw the line. If you can't tinker with any linux you might as well buy a mac.

I agree with you in regards to most RH derived releases. Systems tinkering RH/Fedora may end you up in almost as much pain as if you tried it on OSX.

But SuSE has always been approachable in that regard (20 year user).

I'd agree with you that RH is creating a closed ecosystem and many of the ideas in RH land are not in the best tradition of open source software and not good for a healthy community.

But... Slow moving can be another way to say 'proven' and who is out there deciding what should be deprecated if it isn't the big companies like RH? Is that the cultural 'rut' you refer to? That things don't move fast enough? If that is it I disagree. Most of the 'innovation' I've seen in software is wrapping old ideas for a new generation.

Got to say -- the latest releases have been a return to the dark ages of firefox. Constant crashes, tab reloads that crash the browser, distorted graphics, high cpu usage, etc...

I'd use almost anything else at this point.