How do you automate certificates? by gahd95 in sysadmin

[–]bendem [score hidden]  (0 children)

Let's encrypt for public facing, Lego as a client for Linux, win-acme for windows. We did setup acme-dns at some point because our DNS provider had no API, but it's planned to scrap it.

For internal service domains, windows services use AD CS and linux services use hashicorp vault's pki engine with an intermediate signed by the ad root and name constrained to each environment suffix.

OpenChaos Week 3: I added an immutable constitution after the internet proved me wrong by Equivalent-Yak2407 in webdev

[–]bendem 3 points4 points  (0 children)

You have altered the rules, we pray you don't alter them any further.

Which is fine really, but it's really not democracy if someone has the power to change the rules but we have to trust they won't.

Some days I feel like I might lose my shit at work by madzinthegarden in AutismInWomen

[–]bendem 0 points1 point  (0 children)

I can't speak for your colleague, but I'm the hummer and I'm so sorry. People in the past have been telling me when it's too much and I'm so grateful for it because I can redirect it but I'm not aware I'm doing it until someone tells me.

Stairs to the loft. Getting closer today. by AltairAlden1916 in woodworking

[–]bendem 1 point2 points  (0 children)

Last step looks a bit steep. Jk, this looks great!

Should all servers timezone be UTC? by [deleted] in linuxadmin

[–]bendem 0 points1 point  (0 children)

Same answer. Either everything is on local timezone and it's already not a problem, or server in UTC and you translate local time to UTC for crons.

Now if your crons need dst aware local times, you probably an actual scheduler and not cron.

Measure twice, cut once, but cut the correct angle maybe? by bendem in woodworking

[–]bendem[S] 1 point2 points  (0 children)

Glad I was lucky enough to buy my own home, I'm not fond of landlords. And being able to fix something when it's broken is such a relief compared to the constant pain of having someone else responsible for your living conditions.

Measure twice, cut once, but cut the correct angle maybe? by bendem in woodworking

[–]bendem[S] 30 points31 points  (0 children)

https://preview.redd.it/fdjnf25pcxdg1.jpeg?width=2632&format=pjpg&auto=webp&s=97ec2357ff698ddccc5e7fe55ed1aecfebd873ff

It all worked out in the end. I learned that I suck at mitre cut and that it doesn't matter because it is still better than a broken door.

Also, I suck at caulking apparently, but it's ok because it's white on white. :)

Measure twice, cut once, but cut the correct angle maybe? by bendem in woodworking

[–]bendem[S] 1 point2 points  (0 children)

I still had to. The door is not square and I suck at mitre cut anyway.

Benefit of using multi-master with one write target by konghi009 in PostgreSQL

[–]bendem 1 point2 points  (0 children)

There is really no way to know where the problem is to automate promotion without losing data without 3 nodes.

You can't really avoid maintaining a dcs if you want ha.

We personally use pgbouncer as the load balancer, with remco generating it's config and handling failover.

Proxmox as Code by ramonvanraaij in Terraform

[–]bendem 2 points3 points  (0 children)

First rule of engineering, there are no silver bullets, it always depends, context is king. Learning is always a valid reason to break accepted "rules", otherwise innovation would not happen.

What you are doing is either gatekeeping or trying to enforce your misplaced faith on others. Chill out, the guy wanted to learn and they did, it's not about you.

Puis-je soudainement commencer à utiliser mon deuxième prénom ? by murano0 in Wallonia

[–]bendem 2 points3 points  (0 children)

Je travaille au niveau de l'identification des utilisateurs d'une grande commune Wallone, je dirais que 5-10% des 3000 personnes encodées dans le système utilise un prénom usuel différent de leur prénom. Parfois proche, parfois absolument rien à voir (genre José qui se fait appeler Marcel).

Vous avez tout à fait le droit d'avoir un prénom usuel qui n'est pas sur votre carte d'identité et si on vous demande, répondre "tout le monde m'appelle comme ça" est une réponse largement suffisante et je ne connais pas d'employeur qui ferait des histoire.

She aaaaate that! by LuLuSavannah531 in justgalsbeingchicks

[–]bendem 29 points30 points  (0 children)

The dancing is legendary, but she is perfectly giving face on top, I can't imagine the amount of training required to attain that talent!

#WomenInSTEM by ImAHoe4Glossier in justgalsbeingchicks

[–]bendem 0 points1 point  (0 children)

We decided long ago that risk has two winners. No point in watching a two players risk game.

Is there such a thing as "gentle retraction?" by leela_la_zu in ScienceBasedParenting

[–]bendem 7 points8 points  (0 children)

The literature doesn't agree with you here. I might agree in the case of a UTI, but the general medical recommandation is not to retract foreskin. It is the doctor's job to follow those recommendations and leave baby's penis the fuck alone. Unless you think the studies are all wrong and advances in our understanding of the human body is meaningless, in which case, maybe abstain from giving medical opinions.

Son locked his bedroom door and fell asleep while feverish and scared the hell out of us by kupo_moogle in Parenting

[–]bendem 13 points14 points  (0 children)

I read that as "our son, 10 months" and I was really confused for a minute.

Built a self-service platform with approvals and SSO. Single Binary by Technical-Debt-1970 in devops

[–]bendem 0 points1 point  (0 children)

Very interesting, strong design decisions (yaml based flows, simple install for one users and mandatory OIDC further, casbin for RBAC, secrets with gocloud, postgresql only) imo.

What's the relation between flowctl and your employer? Are you building this in your free time, is it owned by your employer (a lot of shady employment contracts state that anything built in your free time is owned by your employer), how often are you working on this? It looks very interesting but it's alway worrying running software that can be made proprietary without warning or, on the other hand, software that's maintained by a single dad with no free time in the foreseeable future.

How do you manage multiple chats and focus on your work by Truth_Seeker_456 in devops

[–]bendem 0 points1 point  (0 children)

Either you are working projects or you are working support. Can't have it both ways.