• 0 Posts
  • 36 Comments
Joined 3 years ago
cake
Cake day: June 16th, 2023

help-circle
  • I just looked back over your post and your answers there and in here. With respect, your writing style sounds combative. I would never ask you to change it for anyone, but you should understand how it comes across.

    Regarding the AI disclosure stuff, you aren’t the first burgeoning dev posting to Lemmy to go through this exact gauntlet of “AI slop” accusations. You are on a platform used by a fairly specific group of people who were pissed off enough to leave reddit, so not the usual general “tech enthusiast” crowd, and a fairly militant bunch.

    The way I see it, AI is 1) already here and 2) just a tool. It’s being used in the background of a LOT of projects and there is by now simply no way to cover our ears and pretend it doesn’t exist. For better or worse, it’s also changing the pace of development, check out how fast PS5 emulation is happening because of AI tooling.

    That said, developer practices that took us 40 years to make standard are still valuable, so folks have legitimate reason to call out your commit and documentation practices. If there is anything I objected to in your project, it might be that.

    Ultimately, a created work starts to live a different life once it is public. You started without sharing it, shared the source, and now you have to make a decision: continue sharing and accept that not everyone will like it, or stop sharing. It’s really that simple.


  • Sir… You came to us for these comments this time. Are you just here for a fight? It’s not clear what you want from us.

    I don’t find your project interesting enough for me, but I was happy you did it. I prefer to keep my infrastructure at home in a controlled environment and take my maps out with me, but I don’t use navigation, I just record GPS tracks.

    Now with this post, I’m starting to wonder what your motivations are altogether, particularly considering your responses here.












  • From a security perspective, it’s a big mess of inputs and can have really inappropriate access to local filesystem on the web server unless you really know what you’re doing. Combine that with Perl (also a pita to secure), and it’s now a liability.

    These are good tech, I used them a lot myself. But the structure of a language and how it builds things is important too, and that’s why very few ppl bother with Perl or CGI now (besides them also being fails on certain security audits.)


  • Sorry, no disrespect intended, but I’m shocked. It’s like hearing someone say they drive a 1988 Toyota Cressida because it’s great… It was great at the time, but we’ve moved on and the smokeping website should tell you how ancient it is; sponsors from 2007 by companies that don’t exist anymore.

    Still alive & still maintained

    Alive, maybe. I think any maintenance is down to bodges to keep it running in modern environments. Neither Toby nor Niko have worked on sp in over a decade.

    Smokeping is fine if all you do is look at its own graphs and you have enough traffic to see patterns in latency.

    But:

    • more or less unmaintained for a long time
    • cgi scripts and scraping
    • jitter is estimated from rping, not calculated with real values from more than one point on a route (that means a lot when you have a DMZ)
    • Perl
    • rrd tool is… Not great. Not very configurable, also unmaintained, lua support is not good, etc
    • difficult to customize unless you use their submenu system
    • no reporting, you get what you get with smokeping

    I had to retire 2 smokeping monitors because their CGI implementations were security risks. That was 2015. Not a good reason for homelab, but CGI is a pretty ancient and insecure way to interact with the web server.

    Smokeping is good in a big organization with lots of traffic and a few broadcast domains. It isn’t really great at monitoring remote sites because ICMP doesn’t tell you what segment in route is causing the issue, even with rping.

    I used smokeping a lot in my career from about 2005 to 2015, when security audits made me retire it. Just even using rrdtool with an exporter and graphana would be preferable to smokeping itself.




  • I deploy with ansible keys and install ssh with a keys-only config and only ansible access.

    Then I run some standard installs and configs with ansible and all future updates to apt, apk and docker are done with one ansible playbook.

    I don’t include the ansible host itself in the automation, nor my workstation, just to prevent everything from being broken at once if something goes wrong.