<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: JanMa</title><link>https://news.ycombinator.com/user?id=JanMa</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 10 Sep 2026 16:41:45 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=JanMa" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by JanMa in "Muse – Meta’s personal AI agent"]]></title><description><![CDATA[
<p>I've heard people affectionately call ChatGPT 'chatty'</p>
]]></description><pubDate>Wed, 09 Sep 2026 05:51:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=49621661</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=49621661</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49621661</guid></item><item><title><![CDATA[New comment by JanMa in "We should get rid of average CPU utilization"]]></title><description><![CDATA[
<p>I've learned the hard way that CPU resource limits in K8S are a bad idea, as can be seen in this post. Just use CPU requests without limits so the scheduler has an estimate of your applications CPU requirements, but it can burst to use more CPU when it's available.<p>With memory of course you should set a limit and from experience it should be the same as your memory requests.</p>
]]></description><pubDate>Fri, 22 May 2026 09:28:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48233698</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=48233698</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48233698</guid></item><item><title><![CDATA[New comment by JanMa in "Ask HN: Any interesting niche hobbies?"]]></title><description><![CDATA[
<p>I don't think it's a niche hobby, but I really enjoy cooking. Trying out new techniques and receipts, cooking dinner for friends and family or just preparing a delicious meal in advance.</p>
]]></description><pubDate>Wed, 08 Apr 2026 18:05:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=47693977</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=47693977</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47693977</guid></item><item><title><![CDATA[New comment by JanMa in "Traefik's 10-year anniversary"]]></title><description><![CDATA[
<p>Congratulations on the 10 year anniversary. Having used Traefik for multiple years in a large Micro-Service Setup (200+ services) I must say I have made mixed experiences. If your requirements match the very opinionated way Traefik does things then it's great. But as soon as they don't you're going to have a hard time getting things to work. That's why shortly after migrating to Traefik I started to maintain an internal fork to add support for unique request ID headers which I maintained for two years until we migrated to HaProxy. The GitHub issue I opened for this in 2019 is still open.<p>To be fair I used Traefik back when it was still version 1.7 so maybe things have improved by now.</p>
]]></description><pubDate>Sat, 27 Sep 2025 10:29:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=45394609</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=45394609</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45394609</guid></item><item><title><![CDATA[New comment by JanMa in "Show HN: Edka – Kubernetes clusters on your own Hetzner account"]]></title><description><![CDATA[
<p>A bit off topic, but you might want to rethink the name. It is very close to EDEKA, the largest German supermarket chain. They have a very large IT division (<a href="https://it.edeka" rel="nofollow">https://it.edeka</a>) and judging from the name of your project I was expecting it to be one of their projects.</p>
]]></description><pubDate>Fri, 15 Aug 2025 21:31:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=44917491</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=44917491</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44917491</guid></item><item><title><![CDATA[New comment by JanMa in "GitHub was having issues"]]></title><description><![CDATA[
<p>I used to maintain a self hosted instance of BitBucket and the user experience of it was actually very nice. We shut it down when Atlassian deprecated the self-hosted licenses. Moving to GitHub and GitHub Actions felt like a downgrade in more than a few ways</p>
]]></description><pubDate>Tue, 12 Aug 2025 17:53:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=44879686</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=44879686</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44879686</guid></item><item><title><![CDATA[New comment by JanMa in "Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur"]]></title><description><![CDATA[
<p>Yes this does affect OpenBao as well. We're actively working on getting a fix out as soon as possible</p>
]]></description><pubDate>Thu, 07 Aug 2025 08:03:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=44821841</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=44821841</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44821841</guid></item><item><title><![CDATA[New comment by JanMa in "Researchers Uncover RCE Attack Chains in HashiCorp Vault and CyberArk Conjur"]]></title><description><![CDATA[
<p>This does affect OpenBao as well. We do have a process in place for responsible disclosure but unfortunately we were not informed about those issues before they were published.</p>
]]></description><pubDate>Thu, 07 Aug 2025 08:01:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=44821824</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=44821824</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44821824</guid></item><item><title><![CDATA[New comment by JanMa in "OpenBao Namespaces"]]></title><description><![CDATA[
<p>We've made an effort to keep API compatibility with Vault wherever possible, also with the new namespaces implementation. Most of the tooling which works with Vault today will also work with OpenBao</p>
]]></description><pubDate>Fri, 30 May 2025 09:16:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=44134378</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=44134378</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44134378</guid></item><item><title><![CDATA[New comment by JanMa in "OpenBao Namespaces"]]></title><description><![CDATA[
<p>It is true that most of the commits in the last 12 months were made by cipherboy, but I can assure you that the project is not a one man show. Building a community and getting traction on a project is hard work and takes time.<p>Have a look at the contributions for our latest beta release and you'll see that the amount of people involved in the project is growing: <a href="https://github.com/openbao/openbao/releases/tag/v2.3.0-beta20250528">https://github.com/openbao/openbao/releases/tag/v2.3.0-beta2...</a></p>
]]></description><pubDate>Fri, 30 May 2025 07:58:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=44133990</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=44133990</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44133990</guid></item><item><title><![CDATA[New comment by JanMa in "Levels of configuration languages"]]></title><description><![CDATA[
<p>That actually works quite well. I once built a templating engine for Terraform files based on JQ that reads in higher level Yaml definitions of the resources that should be created and outputs valid Terraform Json config. The main reason back then was that you couldn't dynamically create Terraform provider definitions in Terraform itself.<p>Later on I migrated the solution to Terramate which made it a lot more maintainable because you write HCL to template Terraform config instead of JQ filters.</p>
]]></description><pubDate>Sun, 13 Apr 2025 07:22:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=43670778</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=43670778</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43670778</guid></item><item><title><![CDATA[New comment by JanMa in "The Pain That Is GitHub Actions"]]></title><description><![CDATA[
<p>Make is definitely just my personal preference. If using bash scripts, Just, Taskfile or something similar works better for you then by all means use it.<p>The main argument I wanted to make is that it works very well to just use GitHub actions to execute your tool of choice.</p>
]]></description><pubDate>Thu, 20 Mar 2025 23:54:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=43430401</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=43430401</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43430401</guid></item><item><title><![CDATA[New comment by JanMa in "The Pain That Is GitHub Actions"]]></title><description><![CDATA[
<p>Sure, here's one example: <a href="https://github.com/JanMa/nomad-driver-nspawn/blob/master/.github/workflows/go.yml" rel="nofollow">https://github.com/JanMa/nomad-driver-nspawn/blob/master/.gi...</a></p>
]]></description><pubDate>Thu, 20 Mar 2025 14:26:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=43423985</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=43423985</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43423985</guid></item><item><title><![CDATA[New comment by JanMa in "The Pain That Is GitHub Actions"]]></title><description><![CDATA[
<p>Whenever possible I now just use GitHub actions as a thin wrapper around a Makefile and this has improved my experience with it a lot. The Makefile takes care of installing all necessary dependencies and runs the relevant build/Test commands. This also enables me to test that stuff locally again without the long feedback loop mentioned in other comments in this thread.</p>
]]></description><pubDate>Thu, 20 Mar 2025 07:32:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=43420542</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=43420542</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43420542</guid></item><item><title><![CDATA[New comment by JanMa in "Which Motorola Phone Should You Buy?"]]></title><description><![CDATA[
<p>I bought my first Motorola phone in 2013 and am a happy user ever since. I usually buy the current Moto G model for less than 200€ and get a solid 3-4 years of use of it. Of course you can't expect the performance of these phones to be comparable to high end models, but for my use case they are perfectly fine. Also if you drop a sub 200€ smartphone, you don't get a mini heart attack like when you drop a 1000€ iPhone :-)</p>
]]></description><pubDate>Sun, 02 Mar 2025 09:44:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=43228881</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=43228881</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43228881</guid></item><item><title><![CDATA[New comment by JanMa in "On Running systemd-nspawn Containers (2022)"]]></title><description><![CDATA[
<p>Happy to hear you like the project :-)</p>
]]></description><pubDate>Fri, 21 Feb 2025 10:26:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=43125980</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=43125980</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43125980</guid></item><item><title><![CDATA[New comment by JanMa in "Dear friend, you have built a Kubernetes"]]></title><description><![CDATA[
<p>It doesn't. The usual approach is to create new nodes with the updated OS, migrate all workloads over and then throw away the old ones</p>
]]></description><pubDate>Sun, 24 Nov 2024 15:33:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=42228404</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=42228404</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42228404</guid></item><item><title><![CDATA[New comment by JanMa in "Dear friend, you have built a Kubernetes"]]></title><description><![CDATA[
<p>Dear friend, you should first look into using Nomad or Kamal deploy instead of K8S</p>
]]></description><pubDate>Sun, 24 Nov 2024 15:31:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=42228386</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=42228386</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42228386</guid></item><item><title><![CDATA[New comment by JanMa in "Ask HN: How to store and share passwords in a company?"]]></title><description><![CDATA[
<p>There's a lot of tools you could use for this (I'd personally recommend OpenBao), but in my opinion proper SSO, permission and group management is way more important.<p>If you make an effort to define granular groups for every team, and role you have in your company it makes the management of access to resources (and not only secrets) a lot easier.<p>In the example you describe, the newly promoted hire would automatically be added to new groups which will have the right to access the needed Secrets. Similarly, whenever a person leaves your company, simply remove them from the groups they are in and they (almost) immediately loose all access.<p>It's not a small feat to built, maintain and reconfigure all your tools to use it, but if you do it really pays dividends</p>
]]></description><pubDate>Sun, 01 Sep 2024 21:43:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=41420643</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=41420643</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41420643</guid></item><item><title><![CDATA[New comment by JanMa in "Linux: We need tiling desktop environments"]]></title><description><![CDATA[
<p>That’s also what works best for me! A single monitor and only one window on fullscreen. When I need to switch applications, I navigate to another fullscreen window. Sometimes I like to joke that my brain is single threaded :-)</p>
]]></description><pubDate>Mon, 26 Aug 2024 17:49:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=41359748</link><dc:creator>JanMa</dc:creator><comments>https://news.ycombinator.com/item?id=41359748</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41359748</guid></item></channel></rss>