HN user

zufallsheld

733 karma

[ my public key: https://keybase.io/zufallsheld; my proof: https://keybase.io/zufallsheld/sigs/xT_tIyu1_ARyqndC1wPYwz-HTuzJjD3XJMX1RhwF6nc ]

Posts91
Comments272
View on HN
blog.vonng.com 4mo ago

MinIO Is Dead, Long Live MinIO

zufallsheld
224pts92
www.zufallsheld.de 7mo ago

Comparing the homepage-claims of popular Git hosting providers

zufallsheld
3pts0
www.zufallsheld.de 8mo ago

Python Certifi and Custom CAs

zufallsheld
2pts0
www.zufallsheld.de 8mo ago

Simple Webhook-Tester in OpenShift

zufallsheld
1pts0
www.zufallsheld.de 8mo ago

Dynamically include files in GitLab-CI

zufallsheld
11pts3
pmc.ncbi.nlm.nih.gov 10mo ago

Impact of Zelda and Ghibli on Young People's Exploration and Happiness

zufallsheld
7pts1
www.zufallsheld.de 1y ago

How to create repositories in Artifactory with curl

zufallsheld
2pts0
www.zufallsheld.de 1y ago

Combining jinja2-CLI with jq and environment variables

zufallsheld
2pts0
www.zufallsheld.de 1y ago

How to test CORS on the command line with curl

zufallsheld
8pts0
www.zufallsheld.de 1y ago

How to configure additional headers in Gitlab's Nginx

zufallsheld
1pts0
www.zufallsheld.de 2y ago

Working with Gitlab on the CLI

zufallsheld
1pts0
www.zufallsheld.de 2y ago

Interesting Uses of Ansible's ternary filter

zufallsheld
45pts26
jetporch.substack.com 2y ago

Discontinuing Jet

zufallsheld
1pts1
www.zufallsheld.de 2y ago

Create Files and Commits via the GitHub-API and GitHub-CLI

zufallsheld
1pts0
www.zufallsheld.de 2y ago

I teach Ansible to my colleagues: A hands-on training session

zufallsheld
1pts0
www.jetporch.com 2y ago

Jetporch – enterprise automation and orchestration platform by maker of Ansible

zufallsheld
2pts0
www.newsweek.com 3y ago

Man Tells Boss His 'Below-Average' Effort Is Due to Low Pay

zufallsheld
6pts1
www.zufallsheld.de 3y ago

How to create Azure Prometheus datasources with Ansible

zufallsheld
2pts0
clocaas.fly.dev 3y ago

Show HN: Cloc as a Service

zufallsheld
1pts0
steampunk.si 3y ago

Spotter helps Systems Architects reach trustable automation

zufallsheld
2pts0
www.zufallsheld.de 3y ago

DevOps Workflows and Reliable Automation

zufallsheld
1pts0
xfuture-blog.com 3y ago

Automate Deployments with Renovate and GitHub Actions

zufallsheld
1pts0
docs.wakemeops.com 3y ago

WakeMeOps – Debian repository for portable applications with a focus on DevOps

zufallsheld
2pts0
github.com 3y ago

Social – pythonpackage using OpenAI to generate responses to socialmedia mention

zufallsheld
2pts0
blog.t-systems-mms.com 3y ago

Event Driven Ansible – a first look

zufallsheld
3pts0
www.percona.com 3y ago

I Am Taking on Founder Role, Ann Schlemmer Takes over as Percona CEO

zufallsheld
2pts0
t-systems-mms.github.io 3y ago

Open Source Collection of Ansible Good and Bad Practices

zufallsheld
3pts0
news.ycombinator.com 3y ago

Ask HN: What to Do with Lanyards from Conferences?

zufallsheld
7pts9
www.zufallsheld.de 4y ago

Dockercontainer won’t start – Getting the final childs pid from pipe caused EOF

zufallsheld
1pts0
blog.t-systems-mms.com 4y ago

Manage infrastructure with the Docker management container

zufallsheld
1pts0

Do you have particular scenarios you’d like the Dockerfiles for or is it just for transparency/ trust (which is a totally valid reason of course)?

The latter. You or an attacker could tamper with the images - however even with the Dockerfiles I can't be sure that the provided images are built from the Dockerfiles, so in the end I'd have to trust you anyway. Also I'd be curious how you build the images.

Thanks for your answer!

Snap Smart Glasses 1 month ago

There's a huge difference. With a smartphone I can almost always see that people are filming.

You can't. They can execute arbitrary code. They can download another bash file via Curl and execute that.

Presumably you'd check the code of the action before you include it (and then don't use an action with non-pinned versions). This way you know the action won't execute arbitrary code for this version and won't get any other code because of version pinning.

The docker action you linked is ironic in this regard since every other version in the code seems to be pinned except the one you linked to.

Yeah, and then it probably isn't the developers job to fix that but rather the DevOps engineer's one.

Also saying "the developer has to fix this" is something we tried to abolish when talking about DevOps. What about shared responsibility? Bridging the knowledge gap.

Well, yes. In this project where I needed to do this, we thought about removing the pipeline completely and replace it with something custom made. But as always: gitlab worked and there was no immediate need to replace it.

Weaker than standard physical store consumer protections (no playtime restriction on returns, obviously)

Depends on the jurisdiction. In Germany you have no right to returns on things bought in a physical store.