HN user

m_sahaf

800 karma
Posts25
Comments131
View on HN
www.caffeinatedwonders.com 1y ago

Towards Validated HTTP Implementation

m_sahaf
1pts0
www.caffeinatedwonders.com 1y ago

Towards Validated HTTP Implementation

m_sahaf
1pts0
www.caffeinatedwonders.com 2y ago

Secure, Redundant DNS Proxy – Part 2

m_sahaf
3pts0
caddy.community 2y ago

Separation of Duty with Caddy Remote Administration

m_sahaf
2pts0
caddy.community 2y ago

Separation of Duty with Caddy Remote Administration

m_sahaf
3pts0
grafana.com 2y ago

How the open source Caddy server uses Grafana Cloud for full-stack observability

m_sahaf
36pts6
www.caffeinatedwonders.com 2y ago

Zero-Trust Architecture with Caddy

m_sahaf
5pts2
www.caffeinatedwonders.com 4y ago

Show HN: Caddy-SSH

m_sahaf
280pts131
docs.google.com 4y ago

0day “In the Wild”

m_sahaf
2pts0
www.caffeinatedwonders.com 5y ago

Programming Is Glorified Bookkeeping

m_sahaf
3pts3
www.caffeinatedwonders.com 5y ago

Secure, Redundant DNS Using CoreDNS

m_sahaf
3pts0
www.caffeinatedwonders.com 6y ago

Tour of Go Compilers

m_sahaf
3pts0
erlang.org 7y ago

Joe Armstrong on “Rhetorical Structure of Code”

m_sahaf
23pts2
www.filesig.co.uk 7y ago

SQLite Database Catalog

m_sahaf
2pts0
github.com 7y ago

Tpn/pdfs: Technically-Oriented PDF Collection (Papers, Textbooks, Manuals, Etc)

m_sahaf
3pts0
content.pivotal.io 8y ago

Evidence points to OOP being bullshit (2013)

m_sahaf
38pts26
blogs.msdn.microsoft.com 8y ago

Intel just open sourced Stephen Hawking’s speech system

m_sahaf
9pts0
www.wired.com 8y ago

Kill the Password: A String of Characters Won’t Protect You

m_sahaf
3pts5
www.troyhunt.com 9y ago

On the (Perceived) Value of EV Certs, Commercial CAs, Phishing and Let's Encrypt

m_sahaf
4pts0
blog.codinghorror.com 9y ago

I Shall Call It.. SomethingManager (2006)

m_sahaf
2pts0
www.youtube.com 9y ago

Essence of Calculus [Videos]

m_sahaf
3pts0
www.cs.utexas.edu 9y ago

On the Foolishness of Natural Language Programming – Dijkstra (1978)

m_sahaf
1pts0
www.feynmanlectures.caltech.edu 9y ago

The Feynman Lectures on Physics (2013)

m_sahaf
143pts38
www.popularmechanics.com 10y ago

Why Watson and Siri Are Not Real AI

m_sahaf
3pts0
github.com 10y ago

Vagga is a containerization tool without daemons

m_sahaf
31pts10

Brilliant. I wonder what limits we can hit with this setup. What if local postgres is installed and its data directory location is on TigerFS, what are the trade-offs here? Could placing SQLite file on TigerFS mount increase durability for Litestream setup? Is it possible to somehow run have TigerFS database storing data on TigerFS?

ElGamal says he uses them interchangeably. He says TLS exists for historical reasons, but the essence of the technology is the same. I got into the habit of using SSL/TLS.

If that person found another problem with Caddy, I think they are less likely to report it to you because of this.

Given they're aware of previous discussion and the stance on the feature request, I don't think they're deterred by the discussion here. Your addition of fuel to fire here is the very thing that's not helping.

If they did report it, I would think you are very likely to dismiss it because of who they are, not the contents of the bug report.

That's a huge assumption on your behalf.

It's a repeat complaint from the same person who admits bringing it up before. The way they framed their complaint is, again, snide.

That’s a long way beyond exasperation, that’s a massive overreaction.

Your reaction to Francis is _the_ overreaction. Francis simply said to OP to put their money where their mouth is. The "slander" comment comes later as a general statement on why this subject has become annoying.

Stop being hung up on Francis' response. The niche feature was discussed at length multiple times. You're welcome to search the web for all the conversations we had on the subject. Caddy has been around for 11 years. We've seen this subject more than you've seen it brought up. Again, OP referenced the discussion on the issue tracker in one of the earlier times they brought it up. They _admit_ it's niche. What's the point of continuously bringing it up?

This is being blown out of proportion. You're discounting an entire project and your experience of the software over a person expressing exasperation over an inconsequential feature (not a bug) that even the author of curl had his run through and frustration. The request was not dismissed, rather it was discussed at length on our issue tracker. The OP knows it was discussed at length because they linked to the discussion thread in the earlier times they brought this up. Moreover, the way they presented it this time is snide, agree or not. To quote Matt's statement of the project being "stable and mature" just to say "except you didn't implement my niche feature" (yes, editorialized) is not criticism nor a feature request. It's veiled instigation hiding behind plausible deniability.

Anyways, on the feature request, Caddy is not the only software who disagrees with it being valid, and curl had their back-and-forth on it. There's no legitimate bug being dismissed, and you can go through the issue tracker to audit it. Equating this discussion with 37signals or Signal is false equivalence.

Disclaimer: Caddy maintainer

I'm not actively working on it daily, as I have shortage of free time and helping hands, but the HTTP Spec Test Suite is my Moby-Dick. I wrote about it here: https://www.caffeinatedwonders.com/2024/12/18/towards-valida..., I also discussed it on the HTTP WG mailing list and presented it at the HTTP WG Workshop last year.

Another Moby-Dick of mine is Kadessh, the SSH server plugin of Caddy, formerly known as caddy-ssh. This one is an itch. I wrote about it here https://www.caffeinatedwonders.com/2022/03/28/new-ssh-server..., and the repo is here: https://github.com/kadeessh/kadeessh. Similar to the other one, feedback and helping hands are sorely needed.

They are both sort of an obsession and itches of mine, but between dayjob and school, I barely have a chance to have the clear mind to give them the attention they require.

That isn't true representative of Supabase. Tables respect RLS by default, unless turned off. This is how Supabase works. Views are not, and that is due to multiple reasons which Supabase documents. Supabase also warns the user of this and asks them to configure RLS properly for views by first changing the invoker. They also report the same issue to the user on their Security Advisor. The fix is as easy as running the SQL statement in the SQL Editor. Supabase also offers "Autofix" next to the warning, which tells the user exactly how to modify the CREATE VIEW statement to enable RLS.

This is not a problem with Supabase.

I cannot find the source, but I saved this quote by Douglas Hofstadter about the process of writing, rewriting, and revising:

"It is the intensity of this process of global tightening and smoothing of a huge structure that was once implicit in one's mind but is now external and has its own unanticipated shape, life, and momentum, it is the power of this process of converting a set of once-intangible intuitions into a very tangible network of interconnected crystals, that I had forgotten."

Citing that particular blog post isn't making the point you think it makes. To quote:

The most striking piece of new knowledge for me was learning about failure modes. Nginx will fail by refusing or dropping connections, Caddy will fail by slowing everything down.

Do you want your clients failing to load your website at all? Is this the best approach to serving users?

After that, you use the REST API to make changes to the server while it is running, which uses a JSON configuration definition instead of a Caddyfile, so it ends up being a jump for users.

You can, in fact, use any configuration format with the API as long as Caddy has its adapter compiled-in; you just have to use the correct value in the `Content-Type` header. For instance, you can use Caddyfile format using the `text/caddyfile` value in `Content-Type`. This is documented[0].

[0] https://caddyserver.com/docs/api#post-load

Fair enough. There was a learning curve which we had to overcome. I guess you can blame the curse of knowledge[0] for not making this part of the blog post, or because I was more focused on the results delivered by the Grafana stack than the process. I wonder if it may be something like math, where you have to practice much enough for it to click.

[0] https://en.wikipedia.org/wiki/Curse_of_knowledge

I'd have preferred more technical details.

There isn't much technical details to it. Caddy exposes profiles by default[0] and prometheus metrics are available as opt-in. We set up grafana-agent to collect profiles and metrics from Caddy, poked at the Grafana Cloud portal, studied the available data, and checked the charts for anomalies. Grafana Cloud made it easy for us to get started with that without having to build more infrastructure for them, which will also require extra energy that can be better spent on the core of our project.

[0] https://twitter.com/MohammedSahaf/status/1760415991513637137

Profiling Caddy 2 years ago

The pprof format is not tied to Go. From my understanding, it's used within Google across multiple languages. The format is defined in the pprof repository[0], and the visualization tool is source-language agnostic. I've seen libraries in numerous languages (e.g. Python, Java) to publish profiles in pprof format. This is an indicator the pprof format has become de-facto. Grafana Pyroscope[1] is a tool that's capable of parsing the pprof format, agnostic to the source programming language, and has instructions for Go, Java, Python, Ruby, node.js, Rust, and .NET.

My understanding is that you're searching for a combination of the profiles, metrics, and tracing. Caddy supports all 3.

[0] https://github.com/google/pprof/blob/main/doc/README.md

[1] https://grafana.com/docs/pyroscope/latest/

metrics and tracing need to be manually enabled (for now, perhaps)

I had fun building it. It was illuminating seeing where implicit trust is unconsciously assumed, break that down, and identify the threat entry-points (absence of policy definition for the ACME server) as areas of improvement for Caddy. I'm surprised none of the users attempted it or reported those needs. I know at least one user who told me they were considering it but need the tutorial document. Now we have the tutorial (kinda) :)

I’m not aware of anyone running Caddy at any sort of scale for customers.

Well, to name a few...

- Stripe (https://twitter.com/caddyserver/status/1559591673511813120)

- Mercedes-Benz (https://github.com/caddyserver/caddy/pull/5275#issuecomment-...)

- Approximated.app (https://dev.to/carterbryden/how-to-allow-end-user-custom-dom...)

- FusionAuth (https://fusionauth.io/blog/unlimited-domains-fusionauth)

The problem is those using Caddy are shy, not that it's not used at all. I know this because I see users removing the `server` header on the Caddy forum all the time, and many of the large users are just shy of their technology stack when it comes to Caddy.

Disclaimer: Member of the Caddy team

GCP Incidents 3 years ago

I don't know what metric to use of "good", but the throwaway app I've used it for worked flawlessly with both, so good enough for me ¯\_(ツ)_/¯