HN user

kris-nova

383 karma

[ my public key: https://keybase.io/krisnovaidentity; my proof: https://keybase.io/krisnovaidentity/sigs/-FyN-p7Xp87YBbfOYvWHLhBDhSLsUxyMGeKy_5cflQg ]

Posts28
Comments52
View on HN
krisnova.net 3y ago

Ego Death

kris-nova
5pts0
krisnova.net 3y ago

Network Instrumentation and TCP File Descriptor Hijacking

kris-nova
17pts1
krisnova.net 3y ago

Network Instrumentation and TCP File Descriptor Hijacking

kris-nova
4pts2
krisnova.net 3y ago

Observing and Understanding Backlog Queues in Linux

kris-nova
6pts0
www.youtube.com 3y ago

Aurae: Distributed Runtime (FOSDEM 2023 Video)

kris-nova
29pts2
news.ycombinator.com 3y ago

Is Twitter Operationally Okay?

kris-nova
20pts5
news.ycombinator.com 3y ago

Twitter has flagged all the major Mastodon servers as malware

kris-nova
130pts18
community.hachyderm.io 3y ago

Post mortem on Mastodon outage with 30k users

kris-nova
84pts101
beta.birdsite.live 3y ago

Jorts the Cat has caused a denial of service for a Twitter to Mastodon bridge

kris-nova
5pts2
aurae.io 3y ago

Workload Isolation with Aurae Cells

kris-nova
8pts0
www.youtube.com 3y ago

Delivering Zero Trust in a DevSecOps Model – Webinar – 27 Mins

kris-nova
2pts1
medium.com 3y ago

Practical Systems Awareness

kris-nova
17pts2
medium.com 3y ago

Creating Value as a Principal

kris-nova
1pts0
medium.com 3y ago

“What it is” and“What it does” thinking

kris-nova
2pts0
www.reddit.com 5y ago

Infrastructure as Software vs. Infrastructure as Code

kris-nova
1pts0
nivenly.com 5y ago

Competition vs. collaboration (capitalism and open source software)

kris-nova
2pts0
nivenly.com 5y ago

The Distributed Operating System Void with Kubernetes

kris-nova
3pts0
www.cncf.io 5y ago

The Falco Project (Cloud Native Runtime Security) Update from Last KubeCon

kris-nova
1pts0
www.nivenly.com 6y ago

Running secure Falco and Kubernetes on armv7 with pre-baked NOVIX image

kris-nova
3pts0
www.nivenly.com 8y ago

Update on Kubernetes infrastructure with Kubicorn

kris-nova
3pts0
www.nivenly.com 8y ago

Finally – an elegant solution to Generics in Go

kris-nova
3pts1
www.nivenly.com 8y ago

Running Terraform in Kubernetes from My Talk at Hashiconf

kris-nova
1pts0
cnibook.info 8y ago

We wrote a book on cloud native infrastructure

kris-nova
1pts0
www.nivenly.com 8y ago

Kubernetes on Digital Ocean with an encrypted VPN mesh on private networking

kris-nova
3pts0
about.sourcegraph.com 9y ago

Over engineering the core of Kubernetes kops (Kris Nova - Gophercon 2017)

kris-nova
2pts0
www.nivenly.com 9y ago

Kubicorn (Simple Kubernetes Infrastructure)

kris-nova
2pts0
www.nivenly.com 9y ago

Managing Kubernetes on AWS like a boss

kris-nova
2pts1
www.nivenly.com 9y ago

Setting up an HA Kubernetes cluster with private networking in AWS

kris-nova
79pts18

What's the performance hit for doing this?

So I want to be clear. This work is very much in the "fantasy" stage. I haven't ran this at scale, and there is a lot I would do before I blindly rolled something like this out. As far performance impact, it obviously would depend on how it's implemented however I think a reasonable amount of "tracer packets" being sent out every 15 seconds or so to each hop shouldn't be too disruptive to the network, or to the host machine issuing the request. In other words if you take the `ptrace(2)` concern out of the equation (this is the big one in my mind) its going to be negligible.

And, the rootkit question, how would eBPF notice you doing this?

I suppose it would depend on what your strategy with eBPF is and where you were looking. Reminding yourself that the pidfd_getfd and pidfd_open functions are system calls, I think any modern Linux auditing system would see something like this "a mile away".

In other words, I don't see somebody using this tactic to steal FDs in production without quickly alerting most security systems. I suspect there would be ways of hiding this however... https://github.com/krisnova/boopkit...

LSD: Not Even Once 3 years ago

I often attribute the vast majority of my happiness and success back to psychedelics, trauma, and my experience living an unconventional and eccentric life.

I could fill pages with the anecdotes, specific examples, and my personal speculation on why this is but i can just gloss over the details and skip to the takeaway: LSD has made my life net better.

Another point I am trying to drive home is that this is what I would consider an “incomplete” or “immature” take. For example the authors anxiety is likely stemming from some organic experiences either traumatic, economic, physiological, or psychological — getting to the bottom of those and surfacing the patterns themselves is one of the great benefits of this chemical. I’d love to see this author examine their experience and ask where the anxiety is coming from.

You have to face your fears and anxiety before you can understand them — before you can conquer them.

I’m just glad this forum is finally talking about this topic. More psychedelics here please.

This only works if you’re a bro who is chummy with leadership. Honestly this is one of the worst pieces of advice for a marginalized person. If you show any indication of leaving as a marginalized person you are extremely likely to be pegged as “a flight risk” or “unstable” or “frantic” and your job will likely be eliminated before you actually are ready to roll.

In the U.S. this likely means losing your healthcare and missing your children’s tuition payments — and even your housing. Your visa if you’re immigrating, etc.

The only people who have enough psychological security to do this are the ones who don’t actually depend on their jobs for maintaining their current standard of living.

In a perfect world this would be great advice for everyone, however given the political and economic culture of the U.S. this is pretty horrible advice for a marginalized person. Our labor laws don’t support this behavior for a reason — and if “push comes to shove” every corporation in Silicon Valley will air on the side of modern labor laws (or lack there of).

Wow. I thought this was going to be a big rant piece on why we should all go back to dynamic linking again and I was so ready to start my Monday off with a spicy take.

But yes we should all also be adding links in our writing and publishing on our own platforms.

Women and marginalized people who change jobs: Flakey and incapable. Unable to handle a job. Something must be wrong. Clearly a sign of caution to be taken as a reason not to work with them.

Men who change jobs: literally articles inventing new vernacular stemming from the mental gymnastics required to justify the hypocrisy — men aren’t incapable because they change jobs — they are prodigy — men aren’t untrustworthy for changing jobs — they are taking nonlinear career paths because of the uncertainty in the market

Is Crypto Dead? 3 years ago

Excellent. Most people and resources sited on this Machiavellian capitalist mega-bro site often disagree with me. I take it as a compliment. It’s a positive sign I’m on to something sustainable and worth investing my time into. Thanks for helping me smile today.

We debugged a lot of the behavior using hackyderm.io as an HTTP facade for hachyderm.io with independent TLS termination.

I was able to get a single tweet in using hackyderm.io and my account is now “shadow banned”. Meaning I can view my tweet, but nobody else can. Which is exactly what Twitter has promised not to do, and what we use as a tactic on Reddit to keep shitty content at bay. It means that from the posters perspective everything looks “fine” and their content is just not getting any engagement.

https://twitter.com/krisnova/status/1603637253959733248

A Microsoft SAW is a demonic artifact stemming from when Satan himself forged a computer a casts it onto the surface of the earth and into the hands of mankind. It’s the best worst way to access production. It’s how anyone who has ever been on call for Azure accesses production and it’s the last thing you see before Cerberus herself begins chanting “Lasciate ogne speranza, voi ch’intrate” and welcomes you to hell for all eternity.

Hi. I wrote the post. Additionally I am responsible for operating Hachyderm (Ruby on Rails) and GitHub (Ruby on rails) for both my free-time and my day job.

I can say with certainty that Ruby specifically was not the bottleneck in our case. I do think that the rails paradigm can often lead to interdependent systems. We see this at GitHub and we also see this in Mastodon. Service A will do reads/writes against the same tables in the database that Service B also does. When service A is moved to an isolation zone, it can still impact Service B's performance.

In other words, I think any stateful framework with the flexibility that Ruby on Rails encourages bad behavior that can contribute to a noisy neighbor problem.

The point I am trying to drive home is that I agree. I can confidently say that Ruby on Rails is not the culprit in our case. To be honest I just ignore anyone who is quick to point fingers and assign blame either technically or personally.

Sorry hacker news got you down. If it helps my family and I are making Sunday morning pancakes with my puppy Björn today and we are all wishing you the best day ever.

Hi, I made the decision not to replace the drives. I also wrote the article, and am the admin of Hachyderm.

So to be clear, we did try to "offline" a drive from the ZFS pool just to see if this was a viable path. The ZFS pool was set up a few years ago and has gone through a few iterations of disks. The mirrors were unbalanced. We had pairs of drives of one manufacturer/speed mirrored with pairs of drives from another manufacturer/speed. We know this configuration was wrong, again we didn't intend for our little home lab to turn into a small production service.

I think after spending a few hours trying to "offline" the disk, and then repairing the already brittle ZFS configuration to getting the database/media store back to a "really broken and slow but still technically working" state we just decided to pull the plug and move to Hetzner. Offlining the disk caused even more cascading failures and took about 30 minutes just for the software. We could have technically shut down production to try without the database running on it, but at that point we decided to just get out of the basement.

If it would have been as easy as popping a disk in/out of the R630 (like one would imagine) we would have certainly done that.

To be honest I am still very interested in performing more analysis on ZFS on a 6.0.8 Linux kernel. I am not convinced ZFS didn't have more to do with our problems than we think. I will likely do a follow up article on benchmarking the old disks with and without ZFS in the future.

zfs-2.1.4-1 zfs-kmod-2.1.6-1 6.0.8-arch1-1

I think the term "control plane" is overloaded but -- yes.

I just think of it as a node API more than anything. Having a comprehensive set of features/library/API for the node seems like it would unlock a lot of features we are seeing in large service mesh and large platform shops are turning to sidecars to solve.

That section of the post seemed to be generating a lot of friction. I revised the language a little bit.

I think the original sound-byte I was trying to capture was "do one thing" which in my opinion neither Kubernetes nor Systemd do. To be fair -- neither would Aurae. So I just scrapped the entire comment.

I wasn't trying to nitpick systemd as much as I was trying to draw attention to the fact that it does in fact -- get nit picked -- and often unnecessarily.

To be clear I see the "gRPC server" that listens over a unix domain socket being something more like pid 10-20.

If there is a network "gRPC server" as well, I suspect it would be somewhere in the 20+ department.

I don't anticipate exposes the actual pid 1 over a network. I'm not a monster. I suspect there will be be an init/jailer mechanism that manages bringing some of the basics online such a system logger and any kernel services (EG: ZFS) right away. One of the first "services" would be a d-bus alternative that is written in Rust and leverages gRPC.

The main motivation behind gRPC is cloud, mTLS, and the support in rust. It comes with the ability to implement load balancing and connection error management/retry capabilities. I have week opinions on the technical detail as I don't suspect the network traffic will be very large. gRPC is more familiar for folks in cloud, as well as supports a large number of client languages for generating clients.

Its just a joke. Most folks from the U.S. who enjoy eating chicken tenders (breaded chicken breast with sauce) view it as a safe/comfort food that has never been a poor choice to eat.

I feel the same way about systemd, its safe, reliable, and always a good choice for "dinner".

Basically I am saying that systemd has withstood the test of time and has never disappointed me.

This is a good call out. One of the philosophies of the project I am trying to maintain is instilling my opinion into things while still having the project play nice with the rest of the ecosystem.

On one hand I over-engineer a systemd hypervisor that is only meaningful to me. On the hand I create another ambiguous junk drawer that is meaningless without a team of experts to tell you how to configure everything.

I think having what kubernetes calls "namespaces" as an isolation boundary on each node running as a VM is the move here. It SHOULD run like this as a default. Pods are another story. Namespaces however -- should always have a VM boundary.

Getting the network device integration is going to be a big thing here. I suspect this means each namespace now has 1 or more NICs it will be able to leverage.

Firecracker went with the bridge mentality which I kind of disagree with: https://github.com/firecracker-microvm/firecracker/blob/main...

I want to see tools like Tailscale that leverage network devices as the "true network interface" find value in the guest namespace paradigm.

Hope this helps!