• 0 Posts
  • 23 Comments
Joined 2 years ago
cake
Cake day: June 18th, 2023

help-circle






  • Cool, I haven’t tried either of those.

    I’m the type of person who likes to upgrade my systems via the terminal because I like to know the detailed processes, but I’ve also burned myself numerous times; hence my preference for declarative and immutable/atomic solutions.

    It’s (quite) a bit more of a hassle, but I’ve lost trust in GUIs.

    k3s is fairly simple (as far as k8s distros go). Helm is good to start with but for the long run I recommend using kubernetes manifests directly (i.e. kubectl apply -f pvc.yaml, deployment.yaml, etc) rather than helm, because there are quite a few gotchas with helm which can cause trouble. Besides that, it’s good practice to use the --secrets-encryption flag on the server node(s), and if you’re deploying agent nodes it’s good to use bootstrap tokens (k3s token create)


  • Working on a split staging/prod hybrid-cloud k3s setup using nixos, tailscale, systemd-nspawn and fluxcd. If someone has advice for running k3s in unprivileged (mounts idmapped) nspawn containers, I’m all👂.

    This will run

    • (openwisp)[https://openwisp.org/] to make it feasible to provide lots of less tech-savvy people in the local community with secure, simple, privacy-respecting wifi using free software and recycled routers.
    • Various libre software I’m helping community, unions and political orgs adopt. Notably Discourse and Peertube.




  • DepYou could attempt the non-selfish kind and just donate it all to an independent health/rescue org like Red Cross/Red Crescent.

    You could also go the kinda-selfish route like Alfred Nobel, known in his time as the merchant of death. Make an elaborate award&grant giving scheme for exceptional contributions to society in a variety of fields; boosting said contributions for many years. Would only recommend this route if you’ve got more than enough coin to spare, as the overhead of ensuring ethical operation is significant.

    If you’ve got a house, you could transfer ownership to a trust/foundation/housing coop, to make it available for living at below market price.

    I’d donate to various free software & open hardware projects important to societal improvement; like Mozilla, certain fediverse projects, PostmarketOS, Fairphone, etc. Also anarchist orgs.






  • They were revealed to brag to ad sellers about having access to tons of sensitive information about its customers, by spying on e.g. ambient conversations through smartphones and smart TVs, right?

    Or was it them who requested customers install an xfinity root certificate on their phone, without telling it would enable xfinity to man-in-the-middle all their internet activity?

    Funny, it’s almost like fucking around with peoples’ privacy and security inevitably leads to finding out