Hacker Newsnew | past | comments | ask | show | jobs | submit | walth's commentslogin

You might be interested in nginx's implementation

https://nginx.org/en/docs/http/ngx_http_upstream_module.html...


My biggest regret is now not making friends with Doc Brown.


Never attribute to malice that which can be explained by stupidity.

We had the same thing happen with any email with 2f<domain> anywhere in the message body on Google workspace

The "2F" URL decodes to slash / and a third party registered our 2f<company>.com (probably for nefarious purposes)

That kicked on the automatic filtering on messages that had URL encoded links and started blocking them.

Eventually, we had to register 2fgoogle.com ourselves to escalate the issue.


Ok, that was smart. I bet it was fixed quickly.


I'd recommend VictoriaLogs and shipping to via Vector


I also recommend to not hesitate to use other log shippers as well as VictoriaLogs support ingestion not only from Vector - see https://docs.victoriametrics.com/victorialogs/data-ingestion...


Safari on IOS still has a ton lingering HTTP/3 / QUIC bugs.

I think it is to the point that if your user base doesn't warrant it, (i.e. you are targeting well connected devices with minimal latency/packetloss) it's not even worth turning HTTP/3 on


Its great. We use it.

I'm not sure I would call it even close to battle hardened.

They are still many lurking footguns and bugs.

Try running it with > 250k tables. Falls down hard.

Error logic around etcd/topo server is very shaky, edge cases can wedge cells/clusters into broken state.


Also love gnuplot, and and ministat for stats/graphs from the command line


Also pretty easy to implement disk quotas on a modern system.

Heck, you could even display a warning or the top directories consuming space upon login.

Not a great take - this is a operations problem, not a design problem.



Meanwhile, it’s going on two weeks that a large volumetric amplification attack has been coming from CF itself against systems I manage.

Ironically, their abuse report does validate the domain being used to route traffic is a registered customer domain. But the abuse report and even Slack pings have yet to affect the traffic. It’s incredibly frustrating because you’d expect a company like Cloudflare, which positions itself as a defender against DDoS and similar threats, to take action much more quickly when they’re part of the problem.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: