HN user

tomalaci

851 karma

LinkedIn: https://www.linkedin.com/in/tomalaci/ Email: tomass@tomalaci.com

Technologies: Go, Python, Rust, Kubernetes, AWS, Terraform, GitOps, PostgreSQL, TimescaleDB, ClickHouse, Kafka, RabbitMQ, MQTT, IoT, distributed systems

---

Senior/Lead Platform Engineer and backend developer with 12+ years of experience building distributed systems, data platforms, IoT fleet-management platforms, and infrastructure automation.

Recent work includes platforms managing 10,000+ distributed energy devices, telecom monitoring systems processing tens of millions of data points across millions of devices and sensors, and Kubernetes/GitOps platforms spanning AWS and private data centres.

Strongest in architecture and hands-on implementation: backend services, telemetry ingestion, time-series data, developer platforms, CI/CD automation, reliability, and cost-aware infrastructure. I have led small engineering teams, established engineering practices, and improved release frequency from weekly deployments to several releases per day.

---

Interested in Senior, Lead, Staff, or early-stage founding/platform engineering roles. Open to permanent employment or B2B contracts through my Swedish company, Tomalaci Systems AB.

Posts5
Comments124
View on HN

Location: Stockholm, Sweden

Remote: Yes - Sweden, EU, or international

Willing to relocate: No

Technologies: Go, Python, Rust, Kubernetes, AWS, Terraform, GitOps, PostgreSQL, TimescaleDB, ClickHouse, Kafka, RabbitMQ, MQTT, IoT, distributed systems

Résumé/CV: Available on request

Email: tomass@tomalaci.com

---

Senior/Lead Platform Engineer and backend developer with 12+ years of experience building distributed systems, data platforms, IoT fleet-management platforms, and infrastructure automation.

Recent work includes platforms managing 10,000+ distributed energy devices, telecom monitoring systems processing tens of millions of data points across millions of devices and sensors, and Kubernetes/GitOps platforms spanning AWS and private data centres.

Strongest in architecture and hands-on implementation: backend services, telemetry ingestion, time-series data, developer platforms, CI/CD automation, reliability, and cost-aware infrastructure. I have led small engineering teams, established engineering practices, and improved release frequency from weekly deployments to several releases per day.

---

Interested in Senior, Lead, Staff, or early-stage founding/platform engineering roles. Open to permanent employment or B2B contracts through my Swedish company, Tomalaci Systems AB.

NixOS 26.05 23 days ago

I had quite a rollercoaster going from Windows 10 to Arch to Windows and then settling on NixOS. Main reason being able to do clean package/program setup and centralize, version-control my configuration.

My main issue with Arch was that after installing and trying stuff it left OS dirty even after package removal. This might be because I had some things built and installed through AUR (e.g. latest mpv releases that sometimes broke). Eventually I went back to latest Windows 11 build wanting easy no-bs setup.

Of course, then MS decides to shove down half baked AI integration that somehow used half my RAM and randomly slowed my CPU. I am guessing it was busy indexing, searching or security-scanning something.

Got increasingly annoyed by Microslop and tried NixOS. Bumpy ride initially but after committing for few weeks I am finally settling on it be the last OS I need.

Probably because American AI companies are on the hook for quite a lot of investment money. I think they are trying to find the magical moat to justify their valuation.

Revealing optimizations similar to these would pretty much reduce their competitive position.

JPEG Compression 4 months ago

I usually have a script/alias cmd to automatically convert images to webp. The webp format has pretty much replaced jpg/jpeg (lacks transparency/alpha support) and png (no compression) formats for me.

There is also AVIF format which is newer and better but it needs to still mature a bit with better support/compatability.

If you are hosting images it is nice to use avif and fallback to webp.

I usually give myself 30-60 mins to solve. If I can't do it by then I will look up solutions and -study- them (also break it piece by piece and see if I can generalize it for future problems). I would look at solutions even after solving it by myself.

I find that to be the best balance between challenge and learning something new. You will mentally burn yourself out if you keep bashing against the wall for hours or more, not quite a healthy thing to do :)

Meanwhile, people who actually try to compete on this stuff have already developed rich library of specialized algorithms to leap ahead of average programmer. Well, I guess nowadays a lot of it is LLM assisted too.

Companies should quickly realize that ChatGPT can go both ways - it can turn a "script-kiddie" into fully fledged hacker if vulnerabilities continue to be this sloppy. I am fairly certain that low-skill hacker sweatshops already heavily rely on LLMs to quickly exploit trivial vulnerabilities like these.

Like it or not but I feel like account logins, PII and payment stuff will have to be handled by central big orgs. Ideally, I would like that to be a competent open-source government service. For now it is big companies like Google that can shove its SSO around in accessible manner to other sites.

Looks like this runtime is written in Rust. Really does seem like Rust is rapidly swallowing all kinds of common tools and libraries. In this case a single compiled binary for multiple architectures is quite convenient for something like yt-dlp.

Steroids. You will be growing muscle while sitting on a couch, even better than someone that naturally trains. However, you very likely will develop asymetries or other weird complications because you didnt properly work out.

My point is that, even though we might find even more ways to improve/modify our bodies, they will come with slew of risks that are just not worth it if you can achieve it naturally.

On another note, I feel like there is severe muscle inflation in media which would distort how fit a person should be. You really do not need to kill yourself in the gym or hop on a some reddit-approved juices to get very fit. Just gotta experiment and find a comfortable full body workout that you can do consistently, like you brush your teeth every day.

Exact stats are hard to come by but depletion of vehicles has certainly been noticed in battlefield footage: they started with proper military grade vehicles, went down to WW2 era vehicles, then down to light vehicles, civilian vehicles, motorcycles, scooters... donkeys.

That doesn't mean they are completely out of modern stuff but you just dont see it being used on frontlines anymore.

What is happening, however, is the rapidly developing drone warfare which is becoming terrifyingly efficient to conduct warfare in. I dont think we are far off from fully autonomous kamikaze drones at mass produced scale, at dirt cheap price.

It pretty much makes a lot of previously developed modern missiles or even defense systems (e.g. patriots) useless due to how cheaply and effectively you can launch kamikaze drone swarms.

I've been wondering what is the benefit of putting up your own web server or scripts to serve your static content when you could put it in a Github repo or serve from something like S3?

The nice thing about latter is that the bandwidth, DDoS or other load-related issues aren't that much of a problem. Server maintenance also isn't a problem as you don't have any.

With AI exponentially accelerating effects of Dead Internet, I think any social or content-sharing platforms will require some form of Digital ID that can't be easily created/mass-generated (e.g. maybe tie bank account to it?).

That would put real consequences on users misusing platforms. Even a small fee for misbehavior would likely curtail vast swathes of bad actors. It would also make companies be less trigger-happy with their bots if such are allowed to operate in that ID framework (i.e. an identifiable bot being punished would be a fee subtracted from the company that uses it).

I pretty much expect that kind of system in the future, otherwise we will just return back to private networks and private communities.

Prompt 1: Rent live crocodiles and tell the kids they're "modern dinosaurs." Let them roam freely as part of the immersive experience. Florida-certified.

Prompt 2: Try sitting on a couch all day. Gravity will naturally pull down your butt and spread it around as you eat more calories.

Prompt 3: ... ah, of course, you are right ((you caught a mistake in his answer))! Because of that, have you tried ... <another bad answer>

Even for non-number answers, it can get pretty funny. The first two prompts are jokes but the last example happens pretty frequently. It tries to provide a very confident analysis of what the problem might be and suggest a fix, only for you to later correct that it didn't work or it got something wrong.

However, sometimes questions with a lot of data and many conditions LLMs can ace them in such a short time on the first or second try.

I was going to write that this should of been caught pretty early if you had searched and click AWS Spot instances link to read about them being quite unstable/temporary. However, the first result is this: https://aws.amazon.com/ec2/spot/

It is ceaseless shilling for how great spot instances are with big percentages, big savings, omg-so-good messaging. No details whatsoever about some pretty glaring trade-offs. Even their video about getting to know it is quite light on details, mostly telling you what other of their services you can use them together with. What is the point of this marketing word soup? Does that really generate leads?

/rant over

The actual page that tells you about spot instances is a later result: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-sp...

Spot Instance interruption – Amazon EC2 terminates, stops, or hibernates your Spot Instance when Amazon EC2 needs the capacity back. Amazon EC2 provides a Spot Instance interruption notice, which gives the instance a two-minute warning before it is interrupted.

I've used VictoriaMetrics in past (~4 years ago) for collection of not just service monitoring data but also for network switch and cell tower module metrics. At the time I found it to be the most efficient Prometheus-like service in terms of query speed, data compression and, more importantly, being able to handle high cardinality (over 10s or 100s of millions of series).

However, I later switched to Clickhouse because I needed extra flexibility of running occasional async updates or deletes. In VictoriaMetrics you usually need to wipe out the entire series and re-ingest it. That may not be possible or would be quite annoying if you are dealing with a long history and you just wanted to update/delete some bad data in a month.

So, if you want a more efficient Prometheus drop-in replacement and don't think limited update/delete ability is an issue then I highly recommend VictoriaMetrics. Otherwise, Clickhouse (larger scale) or Timescale (smaller scale) has been my go to for anything time series.

Bots, so many bots 2 years ago

This is pretty much progress on dead internet theory. The only thing I think that can stop this and ensure genuine interaction is with strong, trusted identity that has consequences if abused/misused.

This trusted identity should be something governments need to implement. So far big tech companies still haven't fixed it and I question if it is in their interests to fix it. For example, what happens if Google cracks down hard on this and suddenly 60-80% of YouTube traffic (or even ad-traffic) evaporates because it was done by bots? It would wipe out their revenue.

I would take GDP numbers of BRICS countries with a giant mountain of salt.

I remember there were research articles that claimed China's metrics were inflated every year that compounded to unrealistic/fake number. One such research did this by measuring power/electricity growth, I think via visible light during night-time from satellite images. Would be nice if someone could find the original article.

Either way, when you inflate GDP metrics by few points it will compound over years and will create large gap between real and fake economy health.

In this case? Nope. This must be treated as willful design decision to open up API to entire public (including PII/phone-number leak as per design), even if they say they totally didn't meant that to happen. Government itself should then be notified to go after these guys for failing to do the most basic access controls.

I mean, come on! To treat this as a proper security vulnerability just gives too much leeway for these fast-and-loose businesses/systems. It will just encourage more such crap to proliferate.

I am with the author on this one, I am fairly certain the issue of this was raised internally already, probably multiple times. Fortunately for the business, their management did the right decision - focus on quick and easy features, security is a non-issue, we will just blame the hackers and have legal channels deal with them. I mean, you even have people here berating someone uncovering gross negligence for Google-backed company. Why would businesses bother with basic security when they can play the victim so damn easy?

For those who don't want to piece together things from twitter, the summary is this:

Discord attempts to find nvidia-smi libraries by launching series of powershell scripts. Those scripts are really terrible with a lot of if-else logic based on hardcoded strings and environment variables. They are also apparently fairly slow and scan over 800 directories.

Honestly, this is just yet another example of Discord not really developing their software well security-wise.

Another example bad security example: 2FA implementation is not really that secure since you can continuously ask for backup codes to be sent to your email which you presumably open frequently on the same PC (there is already automated malware that will abuse this and circumvent your 2FA via newly generated backup codes).

Yet another terrible implementation: QR codes. There are rampant phishing attempts that work fairly well because they trick people into accepting invite to some discord server. Once you are in it then you are presented with a "anti-spam/anti-bot" verification check which asks you to scan and confirm a QR code. Little do majority of people know is that it is a login QR code and once you scan that then the hackers will just take over your account in less than a second as all this stuff is easily automated already.