towerful

joined 2 years ago
[–] towerful@programming.dev 0 points 44 minutes ago* (last edited 41 minutes ago) (1 children)

Everyone talks about helm charts.
I tried them and hate writing them.
I found garden.io, and it makes a really nice way to consume repos (of helm charts, manifests etc) and apply them in a sensible way to a k8s cluster.
Only thing is, it seems to be very tailored to a team of developers. I kinda muddled through with it, and it made everything so much easier.
Although I massively appreciate that helm charts are used for most projects, they make sense for something you are going to share.
But if it's a solo project or consuming other people's projects, I don't think it really solves a problem.

Which is why I used garden.io. Designed for deploying kubernetes manifests, I found it had just enough tooling to make things easier.
Though, if you are used to ansible, it might make more sense to use ansible.
Pretty sure ansible will be able to do it all in a way you are familiar with.

As for writing the manifests themselves, I find it rare I need to (unless it's something I've made myself). Most software has a k8s helm chart. So I just reference that in a garden file, set any variables I need to, and all good.
If there aren't helm charts or kustomize files, then it's adapting a docker compose file into manifests. Which is manual.
Occasionally I have to write some CRDs, config maps or secrets (CMs and secrets are easily made in garden).

I also prefer to install operators, instead of the raw service. For example, I use Cloudnative Postgres to set up postgres databases.
I create a CRD that defines the database, and CNPG automatically provisions all the storage, pods, services, config maps and secrets.

The way I use kubernetes for the projects I do is:
Apply all the infrastructure stuff (gateways, metallb, storage provisioners etc) from helm files (or similar).
Then apply all my pods, services, certificates etc from hand written manifests.
Using garden, I can make sure things are deployed in the correct order: operators are installed before trying to apply a CRD, secrets/cms created before being referenced etc.
If I ever have to wipe and reinstall a cluster, it takes me 30 minutes or so from a clean TalosOS install to the project up and running, with just 3 or 4 commands.

Any on-the-fly changes I make, I ensure I back port to the project configs so when I wipe, reset, reinstall I still get what I expect.

However, I have recently found https://cdk8s.io/ and I'm meaning to investigate that for creating the manifests themselves.
Write code using a typed language, and have cdk8s create the raw yaml manifests. Seems like a dream!
I hate writing yaml. Auto complete is useless (the editor has no idea what format the yaml doc should take), auto formatting is useless (mostly because yaml is whitespace sensitive, and the editor has no idea what things are a child or a new parent). It just feels ugly and clunky.

[–] towerful@programming.dev 0 points 6 hours ago (1 children)

Google has a "search tools" drop down menu (on mobile it's at the end of the list of images/shopping/news etc).
It's default set to "all results". I believe changing it to "verbatim" is closer to the older (some would say "dumber", I would say "more predictable") behaviour

[–] towerful@programming.dev 1 points 7 hours ago

If a God were to appear and demonstrate all kinds of supernatural activity and capability, I think I'd have to renounce my atheism.

I would also renounce my atheism and become fully anti-theism.
The god is clearly not benevolent, not kind, not caring. The god can go fuck themselves.

Trumps track record over the past decades cannot be forgiven

[–] towerful@programming.dev 1 points 7 hours ago

Why do we even have that lever?

[–] towerful@programming.dev 2 points 21 hours ago (1 children)

No.
I tried a smart watch for a week or so, and hated wearing it.
Hadn't worn a watch in 20 years, and it felt very strange

[–] towerful@programming.dev 3 points 1 day ago

I'm always nervous about fintech companies. Maybe it's time to get over that and give curve pay a spin.
The cashback seems nice, considering a lot of shops I use are on there.

[–] towerful@programming.dev 2 points 1 day ago

Not if you use wildcard dns records.

[–] towerful@programming.dev 3 points 1 day ago (1 children)

Yup, true.

But contactless via a phone can have no limit.
Adding a debit card to phone case means the upper limit is £100. Which is actually fine, and is the limit I have normally set for phone contactless. But I can instantly remove that limit via my banking app.

And the phone needs to be unlocked to make a payment.
Do if I lose my phone anyone can charge £100 to the debit card.

[–] towerful@programming.dev 13 points 1 day ago* (last edited 1 day ago) (11 children)

Servers: one. No need to make the log a distributed system, CT itself is a distributed system.

The uptime target is 99%3 over three months, which allows for nearly 22h of downtime. That’s more than three motherboard failures per month.

CPU and memory: whatever, as long as it’s ECC memory. Four cores and 2 GB will do.

Bandwidth: 2 – 3 Gbps outbound.
Storage:
3 – 5 TB of usable redundant filesystem space on SSD or.
3 – 5 TB of S3-compatible object storage, and 200 GB of cache on SSD.
People: at least two. The Google policy requires two contacts, and generally who wants to carry a pager alone.

Seems beyond you typical homelab self hoster, except for the countries that have 5gbps symmetric home broadband.
If anyone can sneak 2-3gbps outbound pass their employer, I imagine the rest is trivial.
Altho... "At least 2 [people]" isn't the typical self hosting

Edit:
Tried to fix the copy/paste.

Also will add:

https://crt.sh/
Has a list of all certificates issued.
If you are using LE for every subdomain of your homelab (including internal), maybe think about a wildcard cert?
One of those "obscurity isn't security", but why advertise your endpoints? Also increases privacy (IE not advertising porn(dot)example(dot)com)

[–] towerful@programming.dev 38 points 1 day ago (18 children)

This... Except for contactless payment.
I used graphene for a month. It was lovely. Even things like banking apps worked.
I don't care about absolute privacy, but I do care about controlling my privacy. Grapheme gave me that.

I had only 1 issue.
Contactless payment.
It's extremely convenient to me, from public transport to groceries. I just bop my phone.

The fact that Google has that locked down surely violates some EU laws. But I'm sure they wave away the laws because of "financial security" or some other bullshit.
As if bank card NFC/contactless doesn't suffer exactly the same issues.
I looked into some "graphene contactless payment" type systems or workarounds, and I couldn't find anything that would fill the gap.

[–] towerful@programming.dev 2 points 1 day ago

Everything else. Or anything else, if you select a single quark (presuming we don't split a quark).

If everything is moving away from us, then everything is moving away from everything else.
It's just that some things are moving away from us faster than they are moving away from other things

[–] towerful@programming.dev 3 points 1 day ago* (last edited 1 day ago) (2 children)

Everything else.

Galactocentrism was established in 1925, which realised that our solar system is not near the center of the Milky Way. So, we are moving relative to the center of our galaxy.

In 1929, evidence was found that everything else is moving away from us. So we are moving relative to everything else.

In 1931, the Big Bang theory started superceding Galactocentrism, which was an acentrist model of the universe (where there is no center).

view more: next ›