https://repowarden.dev - feel fairly feature complete now and am dogfooding heavily so it’s time to face my fears and do some “marketing” and “sales”. Whatever that means.
HN user
joshghent
[ my public key: https://keybase.io/joshghent; my proof: https://keybase.io/joshghent/sigs/GvF6C3tHGW7f8939KKdw9J5JG5wg7ZWdSDqdPMC7y8I ]
Had exactly the same sort of experience using AI to audit a code base we inherited recently at $dayJob.
Spotted over 100 “security issue but after whittling them down via reproduction scripts and validating they were real CVE’s - that number was around 30.
Even so - it was a huge win and something we wouldn’t have spotted.
It’s something I’ve now codified into repowarden.dev
How tragic. I only had the pleasure to work with Mikeal for a few months but always found his presence wise and humble. He consistently approached decisions with the kind of pragmatism that came from a wealth of experience. I hope his family and loved ones cope through this time.
I agree with you. But, I have found the middle out effect in online discourse means we get articles (such as this one) polarising viewpoints for attention. Sadly, it works.
Building antivirus software for cloud storage (S3, R2, etc) after having the problem at a job - https://bucketscan.com
Despite people slating the author, I think this is a reasonable oversight. On the surface, spinning up a Postgres instance in Docker seems secure because it’s contained. I know many articles claim “Docker= Secure”.
Whilst easy to point to common sense needed, perhaps we need to have better defaults. In this case, the Postgres images should only permit the cli, and nothing else.
Hey, remember me? We met randomly on a bus from Machu Picchu to Cusco a couple weeks ago! First "orange site" people I've met IRL lol.
Great work on this - very slick UX and super quick.
Be cool to expand it to support the UK or maybe develop some open standard for the way data can be reported. I'm sure businesses would pay for a consolidated data api.
Completely agree! Ultra processed people by Chris Van Tullekan is similar for eating unhealthily.
Absolutely, design of cities dictates behaviour. The secondary effects of this are interesting too. For example, european kitchens can be smaller because they don’t need to store as much.
Great site and product! Congratulations on the launch.
I actually have a use case for this in my product Loginllama. I need to grab information about the IP addresses. I’m currently using a different API but don’t really like the product.
Is it rate limited or have any key authentication? My email is me at joshghent.com if you want to chat about this more.
The author raises some interesting points.
But these arguments seem a little tired now. Does a customer actually care what technology you use - absolutely not. If react is easier for you, go for it. If that’s HTMX - fine.
What matters is speed of delivery of new features. And react has huge amounts of support (and a large developer base) that makes development quick and cheap.
I’ve never understood these html purist arguments. As if React/Vue/Angular are desecrating this pure text language.
There are other issues of far greater importance - accessibility, multi-language, browser consistency, sane defaults and easy tooling.
Hey! Thanks for checking out this product. I built this after implementing similar systems for other clients and couldn't find an API that allowed flexibility of implementation. Other solutions took control of your login process (which is often not practical with Cognito, Auth0 etc). Instead, I built this API that can fit into login system in 10 minutes or less. Hope you enjoy!
As it happens I’m a part time developer! (I do voluntary work 2 days a week)
If you’d like to work together my GitHub is @joshghent or my email is me [at] joshghent.com :)
Love your writing. Keep it up
Echo all the words from the author here, and kudos for being transparent.
I’ve faced exactly the same problems building my new product. But, on the other hand, Supabase was incredibly easy to setup, and meant I could worry about infrastructure later.
Pros and cons like with everything, and always wise to understand the flaws of the tech you’re using.
Oh damn, didn't realise! Thanks for the heads up
I'd quite like to move my wife's maths business away from Calendly. But unfortunately Cal.com doesn't support payments for events yet. So that will be a sticking point for now.
Personally, I use render.com to host a bunch. They cost like $1 each a month. Super easy to deploy to because it's just a docker container or script.
Out of curiosity, why has a replacement for this service not been created? I don't use the product myself but love the developers blog.
Been working part time for the past year (volunteering with the rest).
It's a difficult mindset to get into coming from full time. And I struggle to speak with people who are adamant that they need full time commitment to accomplish anything. But, those are the types of people I don't want to work with.
Although I have now built a decent client base, it was a huge challenge at the start to find remote, freelance and part time software contracts. It was usually a case of finding full time ones and convincing them that I could do part time.
It has been hugely rewarding and I find myself thinking about work a lot less outside of work because it's no longer the biggest chunk of my week (or doesn't feel like it).
SEEKING WORK | Full Stack Engineer + DevOps
• Website: https://joshghent.com (CV/Resumé can be found there)
• Location: UK / Remote (used to async and remote working)
• Technologies: NodeJS, React, Typescript, Terraform, AWS, Python, PHP
Raw thought on becoming a better programmer and human
This is exactly what my business does! It's certainly not a new model of working but nice to see more exposure to the billing model.
Spending 10 hours to figure out "what to build" is madness. Having a deep customer connection should be the go to source. It sounds to me like the priority is based on momentary reckons. Sure to kill any kind of true innovation and value.
From my personal experience, it's slow, a pain to use outside of a few "happy paths" and there are better options out there
Key word - "current". If people had used that same line of reasoning for computers, we wouldn't have the devices we take for granted today. Things start expensive, and inefficient. Then we innovate and things get cheap and reliable.
As others have said, try to avoid any kind of DevOps if you can. But here's my strategy:
Monitoring - Loads of cron jobs pinging slack (monitoring disk, CPU, Network I/O etc), Healthchecks.io, TurboAPI, Nginx Amplify. Mostly built up over time
DB - Done entirely via migrations. Most of the time they are small migrations so I can do it by running the command directly on the instance
Deployments - GitHub actions to build a docker image (there was a prebuilt template). Watchtower then runs on my server to pick up the new image and that's then deployed automatically. There is no rollback system as I've not needed that so far (and 99% of the time you won't).
Backups - DB backup is done via a cron pushing to AWS S3 Glacier. The app code is stored on GitHub already so no need to back that up. Happy to share the script if you like :)
Weird that a Microsoft product would get hard to disable telemetry…
All jokes aside though, this doesn’t seem too bad and I can put myself in their shoes to understand why they want this data. It would be difficult to monotone this information (asides maybe a nice shiny new Surface machine).
maximalism may be more about filling in a void of loneliness and isolation
This quote summarises the true intention - buying stuff makes you happy. We all get a kick out of this but that is not going to provide lasting happiness.
As others have pointed out, minimalism isn’t about the number of things you own. And in a way, if you’re “minimalistic” you are also “materialistic” - truly caring about the things you own.