Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bobbylarson
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
bobbylarson
29d ago
The profile-plus-orchestrator pattern is a clean answer, and re-inject existing at all puts you ahead of most setups I have seen. The remaining edge: a process that read the credential at boot still holds the old value in memory after a pul
2.
▲
by
bobbylarson
1mo ago
The Profiles idea is the interesting part. Injection at creation is the easy half; the hard half is revocation mid-session. If a credential in a profile rotates or gets pulled while a box is up for days, does the running VM keep the old val
3.
▲
by
bobbylarson
1mo ago
The thing that surprised me running relays for robot fleets: relay was not the fallback, it was the common case. Hole punching fails a lot behind enterprise NAT.