• stupid docker tricks #239192

    1) Limit max processes on container; unfortunately docker seems intent on me not doing docker stupid tricks, so this is actually a bit of a pain on some systems… but if you figure out/etc/security/limits.conf, or can use prlimit (or write your own; use RLIMIT_NPROC instead of RLIMIT_NOFILE), you can do “prlimit –pid 666 –nproc=3:3” to limit the processes…

  • a bit of levity

    Everyone.. and esp. me… needs humor from time to time…. from various sources, I present my kind of humor.

  • d3ck, d3ck, goose

    A bit over 2 years ago I started on a journey that has become a bit surreal; I had what seemed like a modest goal, simply create something that would facilitate confidential (e.g. encrypted) sharing of information in an easy way. Then snowden came along, and things started become even more… interesting, in the Chinese…

  • It was 20 years ago today…

    … and a few lifetimes… that wietse and I released SATAN.  What a long strange journey, as they say. Thanks to all the folks who used it, to the friends who have been kind. Thanks to muffy, and friends that are no longer with us. But most of all, thanks to my great and wonderful pal…

  • wine of the timez

    It was a good night! In order: Marc Hebrart Brut Rosé NV Dom Ruinart Brut, 2002 Dom Perignon, 2004 Illuminated Magnum Roederer Cristal 2006 Dom Perignon, 2002 Rosé All were nigh breathtaking, and to have them all together was a special occasion indeed. Actually there was 2x all the above (except the magnum), plus various bottles…

  • really, really, really nuke iptables

    I think this is the way to really clear out all the stuff in iptables, the arcane packet filtering thing for Linux. At least… I think. My take on it, at least. For somewhat modern Linuxes at the time of this writing, IPv4 only. Basic method: loop over all the types of tables, flushing… then…

September 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
2930