<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ggpsv</title><link>https://news.ycombinator.com/user?id=ggpsv</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 10 Sep 2026 19:17:10 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ggpsv" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Podman rootless containers and the Copy Fail exploit]]></title><description><![CDATA[
<p>Article URL: <a href="https://garrido.io/notes/podman-rootless-containers-copy-fail/">https://garrido.io/notes/podman-rootless-containers-copy-fail/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48062745">https://news.ycombinator.com/item?id=48062745</a></p>
<p>Points: 141</p>
<p># Comments: 25</p>
]]></description><pubDate>Fri, 08 May 2026 13:22:33 +0000</pubDate><link>https://garrido.io/notes/podman-rootless-containers-copy-fail/</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=48062745</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48062745</guid></item><item><title><![CDATA[New comment by ggpsv in "WireGuard topologies for self-hosting at home"]]></title><description><![CDATA[
<p>Author here! Indeed, it is mostly HTTPS terminated by Caddy in the server at home. Otherwise, it is SSH.</p>
]]></description><pubDate>Sat, 04 Oct 2025 00:19:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=45469286</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=45469286</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45469286</guid></item><item><title><![CDATA[New comment by ggpsv in "Replacing Kubernetes with systemd (2024)"]]></title><description><![CDATA[
<p>This is a good intro [0], courtesy of Redhat.<p>This is a good example [1], cited elsewhere in this post.<p>Documentation for quadlet systemd units [2].<p>[0]: <a href="https://www.redhat.com/en/blog/quadlet-podman" rel="nofollow">https://www.redhat.com/en/blog/quadlet-podman</a><p>[1]: <a href="https://mo8it.com/blog/quadlet/" rel="nofollow">https://mo8it.com/blog/quadlet/</a><p>[2]: <a href="https://docs.podman.io/en/latest/markdown/podman-systemd.unit.5.html" rel="nofollow">https://docs.podman.io/en/latest/markdown/podman-systemd.uni...</a></p>
]]></description><pubDate>Tue, 06 May 2025 16:16:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=43906821</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=43906821</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43906821</guid></item><item><title><![CDATA[New comment by ggpsv in "Replacing Kubernetes with systemd (2024)"]]></title><description><![CDATA[
<p>Oh yes, correct!</p>
]]></description><pubDate>Tue, 06 May 2025 16:14:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=43906808</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=43906808</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43906808</guid></item><item><title><![CDATA[New comment by ggpsv in "Replacing Kubernetes with systemd (2024)"]]></title><description><![CDATA[
<p>This is no longer true as of Podman 5 and Quadlet?<p>You can define rootless containers to run under systemd services as unprivileged users. You can use machinectl to login as said user and interact with systemctl.</p>
]]></description><pubDate>Tue, 06 May 2025 00:11:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=43900673</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=43900673</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43900673</guid></item><item><title><![CDATA[New comment by ggpsv in "I maintain a 17 year old ThinkPad"]]></title><description><![CDATA[
<p>To add a data point here, my Framework laptop is 3 years old and I have no plans to change the mainboard anytime soon.<p>Also, you don't change its motherboard, you change the mainboard (for my laptop, it's the CPU/integrated GPU + memory sockets); this is unlike changing the entire computer. Then, you can reuse the replaced mainboard as a server if you wish to.<p>This pales with my experience using a Macbook Air whose motherboard failed. I did have to replace the entire computer.</p>
]]></description><pubDate>Thu, 03 Apr 2025 16:56:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=43572460</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=43572460</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43572460</guid></item><item><title><![CDATA[New comment by ggpsv in "Ask HN: What intelligent forums exist outside of HN?"]]></title><description><![CDATA[
<p>Care to share a link to the fermentation forum?</p>
]]></description><pubDate>Tue, 11 Feb 2025 13:48:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=43012670</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=43012670</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43012670</guid></item><item><title><![CDATA[New comment by ggpsv in "Rewilding the Self"]]></title><description><![CDATA[
<p>Is it really brutal? Can you single out "nature" and its characteristics?<p>Brutal sounds like a value judgement, one that I suspect explains nothing about the fact.<p>Can we accept that it just is, and we're part of that, for all our vices and virtues?</p>
]]></description><pubDate>Mon, 13 Jan 2025 13:49:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=42683382</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=42683382</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42683382</guid></item><item><title><![CDATA[New comment by ggpsv in "Link Blog in a Static Site"]]></title><description><![CDATA[
<p>A bit like PESOS (Publish elsewhere, syndicate own site). I do this when archiving my Mastodon posts in my own static site [0].<p>[0]: <a href="https://garrido.io/notes/archiving-and-syndicating-mastodon-posts/" rel="nofollow">https://garrido.io/notes/archiving-and-syndicating-mastodon-...</a></p>
]]></description><pubDate>Sun, 12 Jan 2025 22:31:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=42677636</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=42677636</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42677636</guid></item><item><title><![CDATA[New comment by ggpsv in "WireGuard: Beyond the most basic configuration"]]></title><description><![CDATA[
<p>That is what I ended up doing, I wrote a blog post about it some months ago [0].<p>The gist of it is using private dns and exposing services only on the private network. Implementation details can vary, you decide whether to use tailscale or bare wireguard, and any reverse proxy and dns server will do. In my case, I use Tailscale, NextDNS, and Caddy.<p>[0]: <a href="https://garrido.io/notes/tailscale-nextdns-custom-domains/" rel="nofollow">https://garrido.io/notes/tailscale-nextdns-custom-domains/</a></p>
]]></description><pubDate>Sun, 01 Dec 2024 16:16:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=42289114</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=42289114</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42289114</guid></item><item><title><![CDATA[New comment by ggpsv in "Thunderbird Turns 20 Years Old"]]></title><description><![CDATA[
<p>If you don't, can you expand on how you're doing this? Is it simply backing up the Thunderbird profile?</p>
]]></description><pubDate>Fri, 08 Nov 2024 18:14:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=42089098</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=42089098</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42089098</guid></item><item><title><![CDATA[Hetzner Considered Hostile: A PSA]]></title><description><![CDATA[
<p>Article URL: <a href="https://tenforward.blog/hetzner-considered-hostile-a-psa/">https://tenforward.blog/hetzner-considered-hostile-a-psa/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41998420">https://news.ycombinator.com/item?id=41998420</a></p>
<p>Points: 6</p>
<p># Comments: 5</p>
]]></description><pubDate>Wed, 30 Oct 2024 18:12:35 +0000</pubDate><link>https://tenforward.blog/hetzner-considered-hostile-a-psa/</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=41998420</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41998420</guid></item><item><title><![CDATA[New comment by ggpsv in "Running an open source app: Usage, costs and community donations"]]></title><description><![CDATA[
<p>Every case is different but as a baseline, you could use Ubuntu or Debian for automatic security upgrades via unattended-upgrades[0], harden ssh by allowing only pubkey authentication, disallow all public incoming connections in the firewall except for https traffic if you're serving a public service, everything else (ssh, etc) can go over wireguard (tailscale makes this easy). 
Use a webserver like nginx or caddy for tls termination, serving static assets, and proxying requests to an application listening on localhost or wireguard.<p>[0]: <a href="https://wiki.debian.org/UnattendedUpgrades" rel="nofollow">https://wiki.debian.org/UnattendedUpgrades</a></p>
]]></description><pubDate>Sat, 19 Oct 2024 07:19:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=41886233</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=41886233</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41886233</guid></item><item><title><![CDATA[What self-hosting teaches]]></title><description><![CDATA[
<p>Article URL: <a href="https://garrido.io/posts/2024/10/17/what-self-hosting-teaches/">https://garrido.io/posts/2024/10/17/what-self-hosting-teaches/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41868793">https://news.ycombinator.com/item?id=41868793</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 17 Oct 2024 11:57:27 +0000</pubDate><link>https://garrido.io/posts/2024/10/17/what-self-hosting-teaches/</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=41868793</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41868793</guid></item><item><title><![CDATA[We Should Teach Students Unix, or the Power of Pipes]]></title><description><![CDATA[
<p>Article URL: <a href="https://atthis.link/blog/2023/21667.html">https://atthis.link/blog/2023/21667.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41842805">https://news.ycombinator.com/item?id=41842805</a></p>
<p>Points: 7</p>
<p># Comments: 1</p>
]]></description><pubDate>Mon, 14 Oct 2024 22:28:23 +0000</pubDate><link>https://atthis.link/blog/2023/21667.html</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=41842805</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41842805</guid></item><item><title><![CDATA[The Open Collective Platform is moving to a community governed non-profit]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.opencollective.com/the-open-collective-platform-is-moving-to-a-community-governed-non-profit/">https://blog.opencollective.com/the-open-collective-platform-is-moving-to-a-community-governed-non-profit/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41818872">https://news.ycombinator.com/item?id=41818872</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 12 Oct 2024 13:22:16 +0000</pubDate><link>https://blog.opencollective.com/the-open-collective-platform-is-moving-to-a-community-governed-non-profit/</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=41818872</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41818872</guid></item><item><title><![CDATA[New comment by ggpsv in "Installing Arch Linux on a Laptop"]]></title><description><![CDATA[
<p>Fedora has worked flawlessly for me.</p>
]]></description><pubDate>Sat, 14 Sep 2024 20:57:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=41542870</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=41542870</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41542870</guid></item><item><title><![CDATA[New comment by ggpsv in "Age is a simple, modern and secure file encryption tool, format, and Go library"]]></title><description><![CDATA[
<p>Can you elaborate on how age (and the downstream packages) has made a difference in your workflows?</p>
]]></description><pubDate>Mon, 05 Aug 2024 07:49:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=41158983</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=41158983</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41158983</guid></item><item><title><![CDATA[New comment by ggpsv in "Squatting in Spain: Understanding Spain's "okupas" problem"]]></title><description><![CDATA[
<p>You'll understand the inevitable tension on policing this issue considering that a couple of years ago Spain passed a law that made access to adequate and dignified housing a constitutional right.</p>
]]></description><pubDate>Wed, 05 Jun 2024 16:56:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=40587374</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=40587374</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40587374</guid></item><item><title><![CDATA[New comment by ggpsv in "Squatting in Spain: Understanding Spain's "okupas" problem"]]></title><description><![CDATA[
<p>As mentioned in other comments by Spaniards weighing in, it's not really a big problem as in that's happening all the time. 
It is a multi-faceted issue, and for some, a philosophical standpoint stemming from the economic crisis, gentrification and speculation, and related problems.<p>Take in mind that the post shared here is written by a company that provides listing services.<p>Housing is more of a right in Spain than in other countries, and at least in Catalonia, there is precedent that it supersedes property rights.</p>
]]></description><pubDate>Wed, 05 Jun 2024 16:47:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=40587233</link><dc:creator>ggpsv</dc:creator><comments>https://news.ycombinator.com/item?id=40587233</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40587233</guid></item></channel></rss>