HN user

bo0tzz

4,209 karma

bo0tzz.me

Posts216
Comments204
View on HN
en.wikipedia.org 15d ago

M9 Gun Director

bo0tzz
3pts0
www.gabrielebartolini.it 2mo ago

CloudNativePG and Crunchy PGO: an honest, opinionated comparison

bo0tzz
3pts0
zoriya.dev 2mo ago

Phantom tokens: JWTs and sessions combined

bo0tzz
2pts0
tweedegolf.nl 2mo ago

Async Rust never left the MVP state

bo0tzz
9pts0
www.gabrielebartolini.it 2mo ago

Why the cycle of open-source sustainability needs to be virtuous

bo0tzz
2pts0
dustri.org 2mo ago

Carrot Disclosure: Forgejo

bo0tzz
145pts58
www.wiz.io 2mo ago

GitHub RCE Vulnerability: CVE-2026-3854 Breakdown

bo0tzz
451pts93
im-just-lee.ing 3mo ago

The Steam Controller D0ggle Adventure

bo0tzz
4pts0
alexandmanu.com 3mo ago

Immich vs. ente photos – the photo backup showdown

bo0tzz
5pts0
raccoon.land 4mo ago

Technical Excellence Is Not Enough

bo0tzz
94pts97
tarakiyee.com 5mo ago

Oiling the Doors at FOSDEM

bo0tzz
1pts0
immich.app 5mo ago

Building the Immich Editor

bo0tzz
4pts0
ersei.net 5mo ago

Lean, Mean, Solitaire Machine

bo0tzz
2pts0
glazkov.com 6mo ago

Deep Stack Engineer

bo0tzz
1pts0
benjamincongdon.me 6mo ago

RAII Guards and Newtypes in Rust

bo0tzz
1pts0
loc.place 7mo ago

Mapping DNS

bo0tzz
2pts0
www.gabrielebartolini.it 7mo ago

Managing Postgres Extensions with ImageVolume

bo0tzz
3pts0
loc.place 7mo ago

Show HN: Mapping DNS

bo0tzz
5pts0
github.com 8mo ago

Ret: Reverse Engineering Tool from FUTO

bo0tzz
5pts0
words.filippo.io 8mo ago

The Geomys Standard of Care

bo0tzz
7pts0
huggingface.co 9mo ago

Experimental 3.5T K2 merge beats GPT-4.5 and Opus at writing

bo0tzz
2pts1
immich.app 9mo ago

Google flags safe sites as dangerous

bo0tzz
8pts1
immich.app 9mo ago

Google flags safe sites as dangerous

bo0tzz
6pts0
maia.crimew.gay 9mo ago

I'm bored, so here's a useless 0day

bo0tzz
6pts2
bchess.github.io 9mo ago

Building a 1M node Kubernetes cluster

bo0tzz
3pts0
github.com 9mo ago

Stable v2.0.0 Release of Immich

bo0tzz
23pts5
immich.app 10mo ago

Immich mobile app sync V2

bo0tzz
74pts18
www.youtube.com 11mo ago

Adventures in State Space [video]

bo0tzz
81pts10
maia.crimew.gay 11mo ago

I'm bored, so here's a useless 0day

bo0tzz
4pts0
www.youtube.com 1y ago

Turning a Toy into a Cyberdeck [video]

bo0tzz
1pts0

The Universal Declaration of Human Rights, Article 25.1:

Everyone has the right to a standard of living adequate for the health and well-being of himself and of his family, including food, clothing, housing and medical care and necessary social services, and the right to security in the event of unemployment, sickness, disability, widowhood, old age or other lack of livelihood in circumstances beyond his control.

OpenGitOps 7 months ago

The system should undo state drift even if a run hasn't been prompted by changes to the upstream definitions in the repository

The post mentions 743 LOC records in the entire database; I'd be very curious to hear what that number's at now?

1. It only works at all for internal PRs, not for forks. That is a limitation we'd like to lift if we could figure out a way to do it safely though.

2. It's running on a pretty big machine, so I haven't seen it approach any limits yet. We also only create an instance when requested (with a PR label).

3. I've of course been inspired by other examples, but I think the current pattern is mostly my own, if largely just one of the core uses of the flux-operator ResourceSet APIs [1]. It's absolutely generalizable - the main 'loop' [2] just templates whatever Kubernetes resources based on the existence of a PR, you could put absolutely anything in there.

[1] https://fluxcd.control-plane.io/operator/resourcesets/github...

[2] https://github.com/immich-app/devtools/blob/main/kubernetes/...

correctly classified as having user generated active content

No it's not

PRs can be autodeployed to this domain without passing review or approval.

No they can't

There is no untrusted/user content on these domains.

As I've mentioned in several other comments in this thread by now: The whole preview functionality only works for internal PRs, untrusted ones would never even make it to deployment.

The workflow is fundamentally unable to deploy a PR from a fork, it only works for internal branches, as it relies on the container image being pushed somewhere which needs secrets available in the CI workflow.

what Immich is doing here is extremely dangerous

You fully misunderstand what content is hosted on these sites. It's only builds from internal branches by the core team, there is no path for "external user" content to land on this domain.