Tablaste

joined 3 weeks ago
[–] [email protected] 4 points 2 days ago

I'm pretty sure they assumed if you bought their service, you have the competency to properly set it up.

And I proved them wrong.

[–] [email protected] 3 points 2 days ago

Ah not to discount devops, I mean that in a good way.

Devops made me lazy in that for the past decade, I focus on just everything inside the code base.

I literally push code into a magic black box that then triggers a rube goldberg of events. Servers get instanced. Configs just get magically set up. It's beautiful. Just years of smart people who make it so easy that I never have to think about it.

Since I can't pay my devops team to come to my house, I get to figure it all out!

[–] [email protected] 31 points 2 days ago (2 children)

I shared it because, out there, there is a junior engineer experiencing severe imposter syndrome. And here I am, someone who has successfully delivered applications with millions of users and advanced to leadership roles within the tech industry, who overlook basic security principles.

We all make mistakes!

[–] [email protected] 11 points 2 days ago

Haha I'm pretty sure my little server was just part of the "let's test our dumb script to see if it works. Oh wow it did what a moron!"

Lessons learned.

[–] [email protected] 6 points 2 days ago* (last edited 2 days ago) (2 children)

The latter. It was autogenerated by the VPS hosting service and I didn't think about it.

[–] [email protected] 11 points 2 days ago (2 children)

You're not wrong! Devops made me lazy

[–] [email protected] 3 points 2 days ago

Now that you mentioned it, it didn't! I recall even docker Linux setups would yell at me.

[–] [email protected] 73 points 2 days ago* (last edited 2 days ago) (47 children)

I published it to the internet and the next day, I couldn't ssh into the server anymore with my user account and something was off.

Tried root + password, also failed.

Immediately facepalmed because the password was the generic 8 characters and there was no fail2ban to stop guessing.

 

Background: 15 years of experience in software and apparently spoiled because it was already set up correctly.

Been practicing doing my own servers, published a test site and 24 hours later, root was compromised.

Rolled back to the backup before I made it public and now I have a security checklist.

 

I was interested in building something like this.

[–] [email protected] 3 points 2 weeks ago (1 children)

Hey, I did the same thing recently! Set it up on my own server, and after a week, I'm starting to see new accounts being added to my explore feed. But there's no user count.

It's an annoying experience and I'm not fully sure how to resolve it yet, nor have I dung into it.

[–] [email protected] 5 points 2 weeks ago

Probably overkill and I agree with you.

K8 is for scale. Like managing a whole fleet of servers. Even with my devops team, it's quite a lift to suggest it to someone who is getting their feet wet.

[–] [email protected] 2 points 2 weeks ago (1 children)

I did a double take at that $4000 budget as well! Glad I wasn't the only one.

[–] [email protected] 2 points 2 weeks ago

Yeah. I talk about the product directly.

Lemmy. Or Pixelfed. Or Mastodon.

I talk about the activitypub and decentralization.

I'm trying to remove Fediverse from the conversation because that's the word that starts to make people confused.

view more: next ›