• 0 Posts
  • 62 Comments
Joined 1 year ago
cake
Cake day: June 29th, 2023

help-circle



  • I’m not talking about myself in your last quote. I consult clients on their operational and technological challenges. I see a lot. Of course, you might also consult similar amounts of clients and you can see that their largest deficit contributor is that people aren’t taking their work home, but that’s not what I’m getting from you.

    You just seem angry, because you can’t stomach that there are valid reasons for you to move out of your comfort zone. Sorry.


  • So how did those laptops get stolen? Would that have been possible if their users worked on a local client at the office?

    Rocket science is a fucking joke compared to secure IT practices. You saying that, proves that you know neither well enough to participate in this discourse. Most users would operate more securely if their client device was also physically restricted. If you don’t understand that, that’s the reason you are not making decisions. I’m sorry to be so blunt.

    There are highly capable technical people that can securely work from home, but this is not the average user. If you don’t recognize that, you are probably just cheering for your own personal comfort right now. I get comfort, but don’t be blind to reality



  • Just because you can perform a job from home, doesn’t mean it’s ideal for performance. With jobs like surgeons or bus drivers it’s more obvious, but the cut is not as clear as people like it to be.

    I would hope it doesn’t take you long to imagine someone who has access to information about you where you would prefer it not be open on their laptop on their kitchen table at home while guests are around.

    I’m not trying to defend Amazon. This is an active subject at many companies.





  • Ultimately, it doesn’t matter what caused you to be blocked from Docker Hub due to rate-limiting. When you’re in that scenario, it’s most cost efficient to buy your way out.

    If you can’t even imagine what would lead up to such a situation, congratulations, because it really sucks.

    Yes, there should be a cache. But sometimes people force pull images on service start, to ensure they get the latest “latest” tag. Every tag floats, not just “latest”. Lots of people don’t pin digests in their OCI references. This almost implies wanting to refresh cached tags regularly. Especially when you start critical services, you might pull their tag in case it drifted.

    Consider you have multiple hosts in your home lab, all running a good couple services, you roll out that new container runtime upgrade to your network, it resets all caches and restarts all services. Some pulls fail. Some of them are for DNS and other critical services. Suddenly your entire network is down, and you can’t even get on the Internet, because your pihole doesn’t start. You can’t recover, because you’re rate-limited.

    I’ve been there a couple of times until I worked on better resilience, but relying on docker.io is still a problem in general. I did pay them for quite some time.

    This is only one scenario where their service bit me. As a developer, it gets even more unpleasant, and I’m not talking commercial.






  • Explaining my job is trivial compared to the insanity I cook up in my spare time.

    Oh, so you like gaming? No, I’m actually not playing the game. I’m building a mod for it. Erm, okay, so this is for other players then? No, I’m mostly building it for myself. Ah, so you haven’t put a lot of time into it yet? Roughly 12 years. What? So what does the mod do then? It plays the game for me, and publishes in-game metrics to a monitoring application, so that I can see the progress of the game in an abstract form while I’m on the couch, thinking about how to optimize the automation further.

    Regular fun stuff.


  • Their entire offering is such a joke. I’m forced to use Docker Desktop for work, as we’re on Windows. Every time that piece of shit gets updated, it’s more useless garbage. Endless security snake oil features. Their installer even messes with your WSL home directory. They literally fuck with your AWS and Azure credentials to make it more “convenient” for you to use their cloud integrations. When they implemented that, they just deleted my AWS profile from my home directory, because they felt it should instead be a symlink to my Windows home directory. These people are not to be trusted with elevated privileges on your system. They actively abuse the privilege.

    The only reason they exist is that they are holding the majority of images hostage on their registry. Their customers are similarly being held hostage, because they started to use Docker on Windows desktops and are now locked in. Nobody gives a shit about any of their benefits. Free technology and hosting was their setup, now they let everyone bleed who got caught. Prices will rise until they find their sweet spot. Thanks for the tech. Now die already.