Tim Bannister
@lmktfy.bsky.social
10 followers 17 following 30 posts
@kubernetes.io contributor
Posts Media Videos Starter Packs
lmktfy.bsky.social
It's not hard maths, but I only just realised for how long it's actually been called TLS: over 25 years.
lmktfy.bsky.social
Most TVs run Linux. All the manufacturer needs to do is own up to it.
yourlamentablefriends.com
5) Critical mass on the media side. Very unpopular choices by Intel and Nvidia, which are strongly partnered with MS in the desktop space are chasing AI winderfalls and the dollar signs shooting out of their breed-plumbing has fully blinded them. But people have no money. Which leads to: 6/🧵
lmktfy.bsky.social
I'm not convinced that every human artist would produce a 100% plausible Go board, but it should at least need a good understanding of Go to spot the problem.
lmktfy.bsky.social
I keep hoping that someone will do ATproto micropayments and that might just be the perfect use case for it.
lmktfy.bsky.social
The Soviet Union had very elaborate locks that they could add to a relatively plain safe. The idea wasn't that the locks were unpickable; people could bypass them.

What mattered was being sure whether tampering had happened. SGX and friends are partly about that, I think. Tamper sensors help here.
lmktfy.bsky.social
I'm going to Scotland next month for KCD UK (and I'm doing a talk there).

Might get one of these—I don't have any Scottish banknotes to take with me 😉.
lmktfy.bsky.social
Things that depend on the UN quietly doing work, #42:
The internet

From undersea cables to satellite radio links to the entire ITU (including the X.509 standard that's part of security for most popular websites), the UN has put in place pieces we would struggle to manage without. Really struggle.
lmktfy.bsky.social
Would be nice to have atomicity or something like a transaction here, wouldn't it?

There are tricks you can use to force a read. The default has definitely caught me out though.
lmktfy.bsky.social
As the cartoon I'm thinking of says in the caption: London property is theft.
lmktfy.bsky.social
Now that's what I call a keyboard
lmktfy.bsky.social
Vote early, vote once.
lmktfy.bsky.social
chroot() escape is older than I am.

I learned to do it circa 1999 and it is not hard. You know those split stable-type doors where you can lean in and undo the bolt? It's like building a jail with those on each cell.
lmktfy.bsky.social
If it's somebody else's bill, you can rent FPGAs.
lmktfy.bsky.social
Unfortunately, no one can be told what Kubernetes is. You have to see it for yourself.
lmktfy.bsky.social
You're right—and that's what makes it harder.

With >1 competing projects, people are more likely to use the one that everyone else uses (but few maintain), even over a project with corporate backing, an open source licence, but little adoption.

The few-maintainers team get nearly all the triage. 😐
lmktfy.bsky.social
Turn on OwnerReferencesPermissionEnforcement if you can, even if you've upgraded.

It's a handy control, but one that can't easily be made active by default.
Reposted by Tim Bannister
minimus.io
Minimus @minimus.io · Aug 13
🧊 🎩 Last week at Black Hat, Kat Cosgrove was on theCube to talk Kubernetes, open source security, and how minimal container images can cut vulnerabilities, costs, and complexity.

📺 Watch here: hubs.la/Q03CBgB_0

#ContainerSecurity #Kubernetes #DevSecOps #OpenSource #Minimus @kat.lol
Kat Cosgrove, Minimus | Black Hat 2025
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
hubs.la
lmktfy.bsky.social
The Kubernetes project spends a lot of cloud credits on CI/CD. More than $250000 (US) per year IIRC.

With incremental builds, smarter rollups, and other optimizations, I think the project could at least halve the environmental impact of that testing.

Needs people to staff the work, though!
lmktfy.bsky.social
If it's not doing a reasonable facsimile of a job formerly done by a human, I usually call it a "controller"—even if it uses a library with "operator" in its name.