• 0 Posts
  • 52 Comments
Joined 2 years ago
cake
Cake day: June 12th, 2023

help-circle

  • Watch this thread from here on in carefully separate the idealists from those who know what defence is like.

    • yes, open-source is the goal of everything that can be opened.
    • no, defence code isn’t on the list of what can be opened
    • yes, obscurity isn’t good as a sole effort
    • yes, defence in depth
    • no the funding to get it to where it’s safe to open for randos to submit changes isn’t there today

    Anything I missed?

    Yes, Virginia, it’s better to open all the things right now, but there are risks you haven’t taken into account because you’re not aware of them. The pros are; it’s their job and their work, so listen to their expertise no matter what the oppositional/defiant disorder suggests otherwise.


  • Boot times.

    I love how you chose one of the prime advertised features of The Cancer – and my rhel6 could boot faster than rhel7 every day.

    By comparison, Systemd feels like jumping on the back of a charging gazelle and hitting it with a salmon in the hopes it’ll go the other way, all the while it’s bleating and emitting and defecating from its regular port and a whole new journald port of its own choosing. And often tripping.

    Runit has been solid and fast. I’ve seen it on several projects - I want to say alpine and proton/vm and gitlab’s own weird setup - and it’s never let me down. I wish rh could have seen that instead like I wish they picked James over Mike for automation.


  • would move from Opensuse if they did something similar, if it became unreliably maintained

    I saw too much while turning the corpse they kicked over the fence into a unitedLinux we could ship and support.

    The horrors.

    If the entire company died and absolutely new people made a new company by the same name with none of the former staff or principals involved, then I would consider suse. The taint goes so deep I would not consider even a new source drop with the same staff.




  • I am

    1. Glad you had the courage to try something new
    2. Impressed you had your limit and stuck to it
    3. Relieved as a former security person that you’re improving package validation and will reap the rewards even if you don’t notice
    4. Disappointed it wasn’t before some seriously sketchy shit has gone down with RH and trickled down to fedora.

    Finally

    1. Overjoyed as fuck if it seemed like an easy switch, but please correct me there.



  • corsicanguppy@lemmy.catoSelfhosted@lemmy.worldAnsible sounds interesting
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    5 days ago

    Please, for the love of god, look at other things instead of Ansible.

    Definitely do openTofu for infrastructure and deployment, but for configuration of VMs please learn about puppet, saltstack, chef(cinc.sh) and especially mgmtConfig .

    Ansible, by comparison, better matches what we were doing in 2002 at 1/10th the speed, and it’s like pascal levels of wordy.

    Learning about options and finding one that works well for you will often give you a much better experience than fucking Ansible.

    If you do abandon all hope, though, then go ahead and do Ansible; but remember if you do: there are better options, and hating Ansible doesn’t mean you hate automation.