It's been available for nearly three years
HN user
bo0tzz
bo0tzz.me
I specifically want the entire thing to run on workers though; if I'm hosting a separate CMS backend elsewhere, I might as well have that serve the site.
I've been wanting a CMS on top of Cloudflare workers for a while, so I hope this pays off!
2.6 million transactions per day [0], which in ISO 20022 XML format messages works out to (rough guess) 20GB per day for an average of 1.8Mbps...
duplicate of https://news.ycombinator.com/item?id=47584540
The Universal Declaration of Human Rights, Article 25.1:
Everyone has the right to a standard of living adequate for the health and well-being of himself and of his family, including food, clothing, housing and medical care and necessary social services, and the right to security in the event of unemployment, sickness, disability, widowhood, old age or other lack of livelihood in circumstances beyond his control.
I'll take the challenge if it gets me Oxide hardware!
That is indeed what I meant.
This is a myth, actual fraud rates on programs like this are tiny - especially if you compare them to the benefits.
The system should undo state drift even if a run hasn't been prompted by changes to the upstream definitions in the repository
I loaded up the hacker news dataset in google bigquery, which turned out https://news.ycombinator.com/item?id=42057647 as the biggest at 9624 comments. Second is https://news.ycombinator.com/item?id=43208973 at 5349.
The post mentions 743 LOC records in the entire database; I'd be very curious to hear what that number's at now?
1. It only works at all for internal PRs, not for forks. That is a limitation we'd like to lift if we could figure out a way to do it safely though.
2. It's running on a pretty big machine, so I haven't seen it approach any limits yet. We also only create an instance when requested (with a PR label).
3. I've of course been inspired by other examples, but I think the current pattern is mostly my own, if largely just one of the core uses of the flux-operator ResourceSet APIs [1]. It's absolutely generalizable - the main 'loop' [2] just templates whatever Kubernetes resources based on the existence of a PR, you could put absolutely anything in there.
[1] https://fluxcd.control-plane.io/operator/resourcesets/github...
[2] https://github.com/immich-app/devtools/blob/main/kubernetes/...
Dude, I built it, surely I'd know how it works...
correctly classified as having user generated active content
No it's not
PRs can be autodeployed to this domain without passing review or approval.
No they can't
There is no untrusted/user content on these domains.
As I've mentioned in several other comments in this thread by now: The whole preview functionality only works for internal PRs, untrusted ones would never even make it to deployment.
unless one of the developers in the team published something malicious through that system
If that happened we'd have much bigger problems than Google's flagging.
Google flagged this domain for legitimate reasons.
No they didn't.
There is no user generated content involved here.
I'm the guy that built the system, lol. Labels can only be added by maintainers, and the whole system only works for PRs from internal branches.
The Immich domains that are hit by this issue are -not- user generated content.
The workflow is fundamentally unable to deploy a PR from a fork, it only works for internal branches, as it relies on the container image being pushed somewhere which needs secrets available in the CI workflow.
Sounds like you're hitting an address that isn't backed by any service, not sure what the issue is.
If anyone's got questions about this setup I'd be happy to chat about it!
what Immich is doing here is extremely dangerous
You fully misunderstand what content is hosted on these sites. It's only builds from internal branches by the core team, there is no path for "external user" content to land on this domain.
No, it doesn't work at all for PRs from forks.
I'm not opposed to people having different opinions. What I am opposed to is people making a space actively hostile to others and hiding behind their "freedom of opinion".
I agree that if people were able to keep their hate out of these spaces they would be much more pleasant for people to engage in.
I have yet to see evidence DHH is a far-right racist.
Clearly linked in the above thread: https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thoug...
Everything is political, especially something like the open source world (explicitly). Trying to hide from politics is just naivety and gives space to bad actors.