HN user

mrmattyboy

572 karma

https://github.com/matthewjohn

Posts54
Comments149
View on HN
blog.mattsbit.co.uk 3mo ago

System Engineering an agent thanks to Golang

mrmattyboy
2pts0
blog.mattsbit.co.uk 9mo ago

Profiling Golang Terraform Provider

mrmattyboy
1pts0
blog.mattsbit.co.uk 12mo ago

Farewell to my Dad

mrmattyboy
6pts2
blog.mattsbit.co.uk 1y ago

Proxying with HashiCorp Boundary

mrmattyboy
4pts0
blog.mattsbit.co.uk 1y ago

Ignoring unwanted Terraform attribute changes

mrmattyboy
36pts11
www.thesun.co.uk 1y ago

Thesun.co.uk: "Pay to reject personalised ads cookies"

mrmattyboy
2pts0
blog.mattsbit.co.uk 1y ago

Automating SSL CA/Certificate in CI/CD using EasyRSA

mrmattyboy
1pts0
news.ycombinator.com 2y ago

Ask HN: How do you handle LICENSE notices in published Docker images?

mrmattyboy
12pts2
blog.mattsbit.co.uk 2y ago

My attempt at Gitlab PR review environments with Nomad

mrmattyboy
40pts9
blog.mattsbit.co.uk 2y ago

AWS Synthetics Canaries – a look at the real costs

mrmattyboy
2pts0
github.com 2y ago

Terrareg 2.80.0 adds enforcing authentication to OS Terraform module registry

mrmattyboy
2pts1
github.com 2y ago

HashiCorp: Terraform-config-inspect: A library for inspection of TF configs

mrmattyboy
2pts1
news.ycombinator.com 3y ago

Adding Support for HashiCorp Cloud Agent to OS Terraform Enterprise Alternative

mrmattyboy
2pts0
github.com 3y ago

JMon – A simple canary/synthetic check application

mrmattyboy
2pts1
twitter.com 3y ago

Lebanon had a last minute announcement of DST postponement

mrmattyboy
2pts0
github.com 3y ago

Show HN: Terraform Registry – Adding security scans and cost analysis – Terrareg

mrmattyboy
1pts0
about.gitlab.com 3y ago

Gitlab releases patch for remote code execution in GitHub import tool

mrmattyboy
1pts0
news.ycombinator.com 3y ago

Ask HN: Why shouldn't I setup a site that gives away SSL certs for local dev?

mrmattyboy
1pts5
github.com 4y ago

Show HN: Terrareg: An open-source Terraform module registry

mrmattyboy
2pts3
github.com 4y ago

Node-ipc added dependency on maintainer's peacenotwar module

mrmattyboy
2pts4
github.com 4y ago

Show HN: First milestone of my first GBC game – a StickRGB re-implementation

mrmattyboy
3pts1
www.youtube.com 4y ago

Evolution Simulation Experiment (2020)

mrmattyboy
1pts0
gitlab.dockstudios.co.uk 4y ago

Show HN: Simple automated screenshot testing tool for gameboy games

mrmattyboy
3pts0
news.ycombinator.com 4y ago

Gmail, gstatic and other Google sites down

mrmattyboy
3pts0
www.theverge.com 4y ago

Facebook disputes that its AI can’t detect hate speech or violence consistently

mrmattyboy
1pts0
github.com 6y ago

Show HN: Shamean – a tool to perform quick estimated checksums of a file

mrmattyboy
2pts0
github.com 6y ago

Tool to perform quick estimated checksums of a file - Shamean

mrmattyboy
1pts0
status.aws.amazon.com 6y ago

Amazon EC2 Issues in Frankfurt AZ

mrmattyboy
36pts37
www.curlmail.co 6y ago

Show HN: CurlMail – Quickly send email notifications using cURL

mrmattyboy
2pts1
gist.github.com 7y ago

Show HN: One-Liner to Prune Files to Reach Disk Percentage

mrmattyboy
3pts0

Physical media doesn't work when modern games are 100GB or more.

This is a totally fair point and literally something I haven't even considered.

most consumers don't care

I know.. I know.. I mostly commented because the linked article _does_ speak about it and that it implied people weren't happy (mostly for re-sell not for archival purposes). But, yes, I get that

I guess my point is.. if they were really to wait for X months and then start to release physical media (again, I can't see the financial incentive for them to do it), but it would really put a big split between: 1) people that buy that the game and simply want to re-sell it and 2) people that want to buy the game to "last forever" (like myself). Because most of the people in 1) are _likely_ to be the people wanting to buy at launch, play it and move on, the second are _probably_ more willing to wait (or even (probably) wait and buy a second copy later).

Some backstory - I like gaming quite a bit - but more of a personal archivalist. I have basically all games I've ever played on physical media and try to keep someway to play them offline - just jailbroke my 360 to be able to play games from HDD incase the DVD drive broke. Anyway...

I saw the no DVD and was initially devastated. I'm in two minds - I saw one post that basically said "it won't contain a DVD at launch".. if I read between the lines, though I'm not sure I see the value incentive for Rockstar, but...

If they hypothetically launched with physical boxes with digital download codes, okay... This would definitely be in the name of re-sellers (as they've stated). But this is the same as piracy, which has always been, not that "we need to stop people from pirating our games for eternity" but "we need to stop people pirates our game for X months after launch", which makes sense (the piracy party).

So, I'm wondering, if they actually begin releasing physical disks (offline, re-sellable, usable in 20 years), say, 6-12 months after releasing the game.. would that work? I mean, for me, assuming it's the equal block-buster to the franchise I adore (in a varying sense), then I might not mind too much to pick up a copy after 6-12 months (I don't care about bleeding edge).. but... would this work? If we assume the first 12M of buyers can't resell, would the people who buy the game after 12M actually bring a great number to the second hand market.. perhaps not?

I really have the idea of having games that I love in physical form that I know it can't be taken away.. similar to reading a book that you end up reading and know you want to come back to anytime in the future.. and this would _suck_ if I couldn't get a copy (and I assume all PC versions would be full of online-only DRM stuff anyway).

Ergh, I dunno

Honestly, this is just awesome.

I've spent quite a long time looking at artifact storage, both for work and for personal use and this project literally scratches that itch. So featureful (assuming they're not placeholders ;) ) and yes, Claude Code, but still - the proof will be in whether it works (and how clean the codebase feels - you're making it sound promising :D ).

Very excited to try this - well done :)

I agree this doens't seem too ambiguous - it's "you may do this.." and they said "or we may do the reverse". If I say you're could prefix something.. the alternative isn't that you can suffix it.

But also.. the programmers working on the software running one of the most important (end-user) DNS servers in the world:

1. Changes logic in how CNAME responses are formed

2. I assume some tests at least broke that meant they needed to be "fixed up" (y'know - "when a CNAME is queried, I expect this response")

3. No one saw these changes in test behavoir and thought "I wonder if this order is important". Or "We should research more into this", Or "Are other DNS servers changing order", Or "This should be flagged for a very gradual release".

4. Ends up in test environment for, what, a month.. nothing using getaddrinfo from glibc is being used to test this environment or anyone noticed that it was broken

Cloudflare seem to be getting into thr swing of breaking things and then being transparent. But this really reads as a fun "did you know", not a "we broke things again - please still use us".

There's no real RCA except to blame an RFC - but honestly, for a large-scale operation like there's this seems very big to slip through the cracks.

I would make a joke about South Park's oil "I'm sorry".. but they don't even seem to be

It's interesting seeing parts of life overlap.

I did music production at the same time as heavily using SVN and starting to use Git - I didn't cross this over at the time. All (in my case) Cubebase files were just -1, -2 suffixes and it worked. I had continuous backups, sure and it just kinda worked at the time.

Given I now use Git heavily in my work/hobby life, when doing other projects (3D models for printing (questionable at best) and artwork (very very very questionable at best)) I definitely wanted to use some sort of SCM. I opted for these for Perforce - mostly to experiment, but also the idea of having binaries in a distributed SCM. Yes, I know Git-LFS _exists_, but also, to me it breaks the idea of what Git is.. relying on a server for binaries in a situations where everything should be distributed.

If I now went back to audio-production, I would probably consider either Perforce or SVN. Perforce only if it were for a single user (because of licensing). The ability to clone/checkout a single directory of a repo at a given point in time natively and make modifications and push them back is almost quite necessary when dealing with very large files.

And I still use SVN for _some_ situations - particularly those where Perforce is overkill and all I want to _always_ HEAD and the rest is history (for manual preservation history) and no such need for merging and branching (thinking Wiki and other plain-text tooling).

In the case of any sort of any binary-merging - I _heavily_ assume this isn't expected in the poster's situation!

Farewell to my Dad 12 months ago

I originally wrote the speach in my blog repo, just for writing purposes.

My dad's funeral was yesterday and wondered, maybe, someone might appreciate it - either because they've lost their dad or it makes them appreciate their dad a little more.

Sure, you're right in most cases. In the use-case I had, it's a private registry with "immutable" tags (at least enough to stop accidental overwrites - and it is a homelab, so if someone else did it, I'd have worse problems ;))

The point was more about using null_triggers (or `terraform_data` I see) and using the trigger replacement, with the docker resources as purely an illustration.

Good point - I hadn't actually looked massively hard into solving it with this provider - I had to do it again for another use-case recently and decided to blog about it (and also try my hand at a short post).. but used this example from a while ago because it seemed much more relatable than the latest encounter :D

I guess, assuming you're not building the image, whether you use the data source of image probably isn't too important (assuming the data source is able to lookup images that aren't present on the local machine :thinking:).

Edit: and now I've seen that in the docker image resource, they reference using the data source to be able to track remote image SHA changes, in order to trigger an image re-pull :doh:

Feels like we've gone full-circle with this :D

I would say yes and no (leaning on the no)...

I think saying you don't have a right is fine... they are providing a service and dictating it's usage and you are using it.

So on the "closing your eyes". On one side, yes, allowing your browser to play the video and YT then being able to treat as a advert view means that youtube gets paid and the creator gets paid.

However... I would personally view this as can a person do this and how it works as a generalisation and I would say "no", because if everyone did this (why does just one person have the right to close their eyes), then (at least I'd imagine) the companies paying for advertising would see a drop in click-throughs and (I don't know what you call it.. but let's just say) more money. They'd then stop paying for adverts. Then no companies would want to pay for adverts and YT is no longer profitable (to YT or the creators).

I see what you mean.. but if you take a look at vista vs 7..

Microsoft shoved glass panels, widgets and such down the user's throat in Vista. It was a new look and they wanted to make you realise it. Without spinning a fresh 7 machine now, I'm certain it was very toned down.

But, I could be very wrong about this :D Last time I used Windows was XP (I mean, granted last week) because nostalgia is a real thing :D

Edit: I can't reply (not sure why, thread too deep?) but @cogman10, you're right! My memory is bad :(

I do completely agree - the main problem I had was that, I tried doing this whilst writing the blog post side-by-side and was aware that the more complex it became, the harder it would be to show it. If I'd use separate files for the HCL then I'd need to show them both (and I think adding a little bit of cognitive complexity to read). So then adding templates etc, would increase that more.

I know for the "creating a server", I just used a module, but all it's meant to say is "I created a machine" and how I did that probably wasn't that important (apart maybe any tiny fragments of useful information with the variables), so I left it as a module. Same with the nomad setup - but at the same time, for what I was trying to achieve, running `nomad agent -dev` would have sufficed, so was somewhat happy with skipping it and showing the module call as "nomad was setup".

So for the remainder, I tried to prefer simplicity and readability, rather than "this is the best way to write Terraform and dynamic modules".

But, I completely agree with you :) Given the nature of the project it's in the pipeline for - I can certainly saying that I like a good Terraform module ;)

One thing that I haven't out how to do is allowing unauthenticated Gitlab users to view deployments/environments for public projects.

Not only is the "deployments" tab missing (which isn't the _end_ of the world), but the environment (with the link to the instance) isn't shown in pull requests until the user logs in.

Does anyone know if this is possible? I couldn't find much in Gitlab's docs

Hey :)

That's a good idea for the backend - thank you!

And yes, I should have used the used a separate HCL file for the nomad_job - aside from being cleaner, it would have also avoided some horrific JSON encode that I had to use for an environment variable (think: `env { blah = eplace("\"", "\\\"", jsonencode(local.something))`), since I could just pass the jsonencode value straight to the value of the parameter, rather than getting Terraform to convert it to a string for the template.

I completely get this - got my first "server" at 11 and a ex-dc "real" server at 13 from ebay after I got my first job.

Really glad people are still doing this! (I learned a lot from getting £5 PCs from the local dump, which now don't sell electronics and now "retro" PCs are becoming more and more expensive - I wasn't sure if this ability for kids to buy a cheap PC and tinker (which may or may not help lead to feeling comfortable moving on to running their own servers etc.)

Terrareg is an open source Terraform module registry, providing in-depth information (example exploration, cost estimation and security analsysi), analytics, search functionality and SSO integration.

Release 2.80.0 adds functionality to provide a locked down instance, enforcing users to authenticate to one of the SSO implementation (SAML, OpenIDC and (coming soon) Github authentication.

I do wonder the longevity of alphabet-based naming...

It _sort of_ reminds me of a time I spoke to a colleague and said I wanted to try a project (only a couple of years ago) that required Red Hat Linux 5 and he said "oh sure, here's some CDs" and realised, "nope, not RHEL" (to which the response was.. "oh, here be dragons")..

If you loop the alphabet and I reckon you'll inevitably get confusion.

"Hey, Android Juniper has been released" - "Ah cool, I can upgrade from Ice-cream".. "oh no, wait, mine's 27 releases old!".. "No, sorry, it's actually 53 releases old"

Ah okay, thank for the that :)

I sort-of assumed that for big purchases it would be a big procedure, as you've stated.

I had it in my mind, there'd be like a lower threshold (i.e. licenses for one or two things), which would go under the radar and just be purchased when someone requested it (or end of year "budget needs to be spend" - you know, that sort of old school "budget per department - spend it or you lose it" sort of thing.) :D

This also went with the idea that the "3 x CIQ Rocky Enterprise Linux Per Person Advanced - Annual Subscription Service Period" would be a small purchase - though of course, I don't _really_ have any idea what this means - could be a massive 24x7 support with 3 Rocky Linux support staff on-call - who knows :)

That, and ROCKY can probably now have a NASA logo on their website under "customers", which adds a bunch of credibility to the project, honestly, whether it's necessarily deserved or not based on 3 desktops.

This on the other hand is verry interesting!! Thanks for pointing this out :)

Edit: sorry, I misread your comment :( Thought you said their logo _was_ on the Rocky site :P

Looking at the "statement of work", unless I'm misunderstanding - it's 3 user (workstation?) licenses?

To me, it's more like 3 engineers at NASA are interested in it and got their boss to get them 3 licenses? As opposed to "NASA moves all RHEL licenses to Rocky after Redhat destroys CentOS community"?

Edit: I know nothing of how govournment agencies (and certainly not US ones) work.. I assume all purchases go through some process where they're all made public?

Couple of comments:

But the exact same argument can be made of every advance that has continously raised the level of abstraction of programming over the decades.

Languages and libraries are written (at least up until now) by humans, who _care_ about writing good working code. Generally, if you use a library, it will do it's job flawlessly, in the bounds of what it's expected to do. You rely on those people writing and maintaining it to perfect the job it was designed to do. Co-pilot is making suggestions, each a entirely independent "guess" at what you're trying to accomplish (apologies I don't know _that_ much about ML, but don't think this is far fetched). Meaning that each suggestion produces code in "untested waters" and wasn't code written specifically to do this job, used over and over by others... It's not like it's part of a project and a bug report going to filed for a bug...

Edit: Moved the top portion below, as it was sort of just repeating what was said:

I think the comparison of sifting through copilot suggestions to sifting through errors in google is that, generally you are looking for the error that fixes your problem. Not 5 different (probably working) solutions, which each may contain different bugs. Meaning that I (or X developer of any level would) _need_ to continue searching google to find a working answer to my problem. But validating a co-pilot answer for any potential flaws is much more error prone.

Hi all,

I've been working on a YAML-based synthetic check tool and wondered about your thoughts :)

The idea is to provide a tool that provides:

* Scalability (agents are run and checks are distributed among the agents)

* Web interface for viewing status and results

* An option to use chrome/firefox based selenium tests, or simple requests library, where possible - allowing JSON health check endpoints to be more quickly checked than full selenium page checks.

* A Terraform provider to deploy checks via application deployments

* A (POC) chrome plugin that will generate the check YAML from the browser

* S3 for storing artifacts (docker-compose using minio)

It uses a postgres database with rabbitmq for scheduling checks.

The UI is very much a work-in-progress (so apologies).

Look forward to hearing any feedback :)

One thing to say to this.. I work at a company and have personally setup quite a few mail servers for mass email sending and warming up IPs.. not fun..

(these are all legitimate interest emails)

I was in a meeting with a couple of people from the team and a QA engineer mentioned that everytime he's done with an email in gmail, he spams it off... _wut_..

Whilst yes, we have been blacklisted a handful of times and, based on spam reports (feedback loops), people do mark emails as spam for completely nonsensical reasons... e.g. users signing up, (getting and using the activation email), using the service and then spamming the activation email.

Edit: I definitely think there's a bell curve for sending your own emails:

* If you have a very small platform (at least in my experience), reputation doesn't mean that much, emails are generally accepted by providers (assuming IPs that you used haven't been previously used for spammy activity), so self-hosting might make some sense (though a third-party probably wouldn't be too expensive if you did want to).

* If you start sending 100s-1000s of emails/day, I guess some third party solution would make sense, since running dedicated IPs/domains and servers just for sending emails might not be beneficial.

* As you go to sending 100K+ emails a day, personally, I think setting up servers starts making more sense