from/prod
← All companies

THE COMPANY INDEX TRACKED BLOG

Advanced Web Machinery

Ideas, decisions, and lessons from the team.

advancedweb.hu (opens on the source site)
10Posts tracked
4 months agoLatest publication
0.8Posts / month over the last 12 months

Latest writing

10 of 10 posts

Backups with Restic: 2-year retrospective (opens on the source site)

Around 2 years ago I started looking into how I could back up my laptop and my phone. I went with Restic and multiple backends for storage and I'm fairly happy with the result, even though I overengineered it a bit. This article is a retrospective: the thought processes behind the design, how it worked in the past 2 years, and what I'll change next when I feel like tinkering with it a bit more. Having a reliable backup solution is an enabling piece of architecture. It allows me to rely on local tools touching local files without introducing the nightmare scenario of losing data during a…

Read at the source

NixOS first impressions: writing system-level tests (opens on the source site)

My motivation for NixOS I've been using Nix for some time now. I converted my dotfiles to mostly Nix, and I'm very happy with how useful it became. The next logical step is NixOS, that applies the same principles to the whole OS. I've been thinking about how I'll use NixOS for a while and now is the time to actually give it a go. Usually when people try out an operating system, they go the usual route: try out the installer, get a feel of the default applications, the out-of-box experience. This is not how I started exploring NixOS: I started by writing tests. I'm not exactly interested in…

Read at the source

Designing safer listItems and getItem permissions (opens on the source site)

When you implement authorization for an endpoint that returns a list of items, there is an optimization that simplifies the policy structure a bit: define only the permission to list but not to get items. This makes it a bit easier for a policy writer to think about permissions as there is less duplication. For example, in a ticketing system that provides an endpoint to list tickets (/project/project1/tickets) and to get a ticket by ID (/tickets/:ticketid) both endpoints need an authorization check (can the user list tickets / get this ticket?). If both of them return the same objects (the…

Read at the source

ESP32 time bootstrap problem (opens on the source site)

The past couple of weeks, I've been working with an ESP32 chip. I'm making experiments at this moment: my goal is to find out if these chips are good enough now. Many years ago I started with ESP8266 chips and they were clearly not: they were so resource-limited that they could not do TLS (and by extension, HTTPS). Any interesting use-case requires a server reachable over the internet, the lack of secure communication disqualified that chip. But the ESP32 (especially the C6 variant that is RISC-V, meaning the compilers work with it out of the box) seems like a good chip. It is powerful enough…

Read at the source

My first two months using AI (opens on the source site)

I started using AI more seriously in early November, so around this time marks my second month. When I talk to others, everyone's experience feels very different. So to add one more data point, here is mine. I resisted using AI for a long time. My reasoning was that prompting is easy to catch up with, so it does not matter if I join the crowd a year later. This turned out to be true. Also, I had some trials with the ChatGPT free version which was a mixed bag so I wasn't that convinced it is any good. What prompted me for a proper try was talking with people. Some of them told me that for…

Read at the source

I'm changing my mind about serverless (opens on the source site)

I keep track of an "ideal architecture", one that I would use if tasked to design a new system from scratch. For several years now this was AWS serverless. The AWS part is personal: this is the stack I'm most familiar with. And serverless because it works the same for small and for large. It is a magical feeling to do a terraform apply and see that all the different parts are coming live, ready to serve whatever load coming its way. A well-designed serverless application combines the best of all worlds: the cost scales with traffic and there is no upper ceiling. Now? I'm not sure anymore.…

Read at the source

Why I prefer multi-tenant systems (opens on the source site)

A multi-tenant system can be used by many customers and for each of them it looks like they are the only ones. Think about AWS, for example: the account is isolated from all other accounts, and apart from the account ID there is no indication that anybody else is using that platform. The obvious reason is that there is only one deployment and not one per customer. But I found that even if I needed to design a system that is only used by one customer I would design it with support for multiple tenants. This is a tradeoff, of course: every feature makes the system more complex and the cost of…

Read at the source

AppSync subscriptions: waiting for start_ack can still result in missing events (opens on the source site)

It seems like that when AppSync returns a start_ack message in response to a subscription start it won't necessarily mean that all future events will be delivered. Subscriptions are the mechanism to deliver real-time events from AppSync. It is based on WebSockets and its protocol is documented here. In the protocol, a client needs to send a start message with the GraphQL query to start receiving updates. Then AppSync responds with a start_ack if everything is OK and then sends data events whenever an update happens. Reading the documentation my impression was that start_ack is the moment when…

Read at the source

Closing issues because they are unplanned is bad UX (opens on the source site)

Many projects close issues after a triage if the feature/bug is not planned. For example, the terraform-provider-aws uses a bot that detects stale issues (for example, I'm following this one and I'm getting periodic emails about it). If nobody comments for a period of time the issue gets closed. I get why it's good for the project's perspective: if you open the issue tracker and it's full of open issues then it's both depressing and counterproductive as it buries the important things to work on. Most of these projects with a public issue tracker are open-source ones and the maintainers are…

Read at the source

Hardening with Firejail, Landlock, and bubblewrap (opens on the source site)

Recently I've been looking into securing my laptop a bit. By default, every single program has access to everything: filesystem, network, other programs. First, I started looking into Firejail. It allows specifying paths the program can access, as well as the network and other special things. It's not bad and I used it for a while. What I don't like about Firejail is that it's setuid: it runs as root, sets up the sandbox, then starts the program that is passed as an argument. If there is a problem in Firejail then it can even extend the blast radius. Then I learned about Landlock. It is…

Read at the source

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.