Skip Navigation

Posts
221
Comments
487
Joined
2 yr. ago

  • 动态网自由门 天安門 天安门 法輪功 李洪志 Free Tibet 六四天安門事件 The Tiananmen Square protests of 1989 天安門大屠殺 The Tiananmen Square Massacre 反右派鬥爭 The Anti-Rightist Struggle 大躍進政策 The Great Leap Forward 文化大革命 The Great Proletarian Cultural Revolution 人權 Human Rights 民運 Democratization 自由 Freedom 獨立 Independence 多黨制 Multi-party system 台灣 臺灣 Taiwan Formosa 中華民國 Republic of China 西藏 土伯特 唐古特 Tibet 達賴喇嘛 Dalai Lama 法輪功 Falun Dafa 新疆維吾爾自治區 The Xinjiang Uyghur Autonomous Region 諾貝爾和平獎 Nobel Peace Prize 劉暁波 Liu Xiaobo 民主 言論 思想 反共 反革命 抗議 運動 騷亂 暴亂 騷擾 擾亂 抗暴 平反 維權 示威游行 李洪志 法輪大法 大法弟子 強制斷種 強制堕胎 民族淨化 人體實驗 肅清 胡耀邦 趙紫陽 魏京生 王丹 還政於民 和平演變 激流中國 北京之春 大紀元時報 九評論共産黨 獨裁 專制 壓制 統一 監視 鎮壓 迫害 侵略 掠奪 破壞 拷問 屠殺 活摘器官 誘拐 買賣人口 遊進 走私 毒品 賣淫 春畫 賭博 六合彩 天安門 天安门 法輪功 李洪志 Winnie the Pooh 劉曉波动态网自由门

  • On blahaj we lack downvote so the tankies aren’t downvoted to hell from our point of view. It only keeps their circlejerk upvotes.

    But if you look at the comments from another instance, they are downvoted to hell.

  • Locked

    Imperial rule

    Jump
  • Oh no I was just being pedantic

  • Locked

    Imperial rule

    Jump
  • They gettin into the overseas military bases; talkin’ bout Djibouti and a lil’ Cambodia as a treat

  • I’d guzzle that even if Gnor wouldn’t

  • Sad to hear for my quadlet future, do you remember what things were specifically annoying?

  • Hey bigdickdonkey, I recently tried and wasn’t able to shit my way through podman, there just wasn’t enough chatter and guides about it. I plan to revisit it when Debian 13 comes out, which will include podman quadlets. I also tried to get podman quadlets to work on Ubuntu 24 and got closer, but still didn’t manage and Ubuntu is squicky.

    I read about true user rootless Docker and decided that was too finicky to keep up to date. It needs some annoying stuff to update, from what I could tell. I was planning on many users having their own containers, and that would have gotten annoying to manage. Maybe a single user would be an OK burden.

    The podman people make a good argument for running podman as root and using userns to divvy out UIDs to achieve rootless https://www.redhat.com/en/blog/rootless-podman-user-namespace-modes but since podman is on the back burner till there’s more community and Debian 13, I applied that idea to Docker.

    So I went with root Docker with the goals of:

    • read only
    • set user to different UID:GID for each container
    • silo containers in individual Docker networks
    • nothing gets /var/run/docker.sock
    • cap_drop: all
    • security-opt=no-new-privileges
    • volumes all get tagged with :rw,noexec,nosuid,nodev,Z

    Basically it’s the security best practices from this list https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html

    This still has risk of the Docker daemon being hacked from the container itself somehow, which podman eliminates, but it’s as close to the podman ideal I can get within my knowledge now.

    Most things will run as rootless+read-only+cap_drop with minor messing. Automatic ripping machine would not, but that project is a wild ride of required permissions. Everything else has succumbed, but I’ve needed to sometimes have a “pre launch container” to do permission changes or make somewhere like /opt writable.

    I would transition one app stack at a time to the best security practices, and it’s easier since you don’t need to change container managers. Hope this helps!

  • rule

    Jump
  • They’re also often used to connect a portable generator’s 120V outlet to a house’s 120V outlet, thus energizing the house circuit during a power outage. But they have no way to lock in so can fall out and become a naughty cattle prod or if the person forgot to disconnect their circuit breaker from the mains they’ll kill a person fixing the power because that lineperson won’t be expecting live wires.

    Basically as you said, if you do everything right you escape with your life. But if you do it wrongk, house fire or murder!

  • FUCJ Id guzzle that

  • Glorious that you’re not over subscribed, that’s how it’s supposed to work!! But if they over sell the pipe or undersize the pipe, or both, Fs in the chat between 7-10

  • Oooof too true on LTE internet

  • It’s a big problem in apartment complexes where one line is CGNAT’d to every apartment. In practice that means 20 people share the same line that a house would have normally, and in the evenings every apartment streaming or gaming can make the speeds shit.

    Sucks ass but in the US you can’t do shit because the speeds you pay for are “up to” and if they’re not “up to” that the best you can do is kick rocks.

    This also usually coincides with you being able to only get one internet service provider at that apartment, despite that being illegal now. So you’re locked in to shit nighttime service with slow downloads and giga latency

  • Begone foreign election interference agent

  • amogus

  • God’s most in denial libertarian 😞 refuses to check a box on some paper every 4 years because of anarchist cosplay mind gymnastics that’s come to the conclusion if you vote at all you’re whole heartedly endorsing candidates while simultaneously slowing the collapse into bloodshed where the fabled anarcho-society can rise from the ashes of every trans person and many more.

    Your logic lacks empathy, you need to do introspection to make your beliefs consistently ethical. Claiming to help people on the ground while not helping people on the ground indirectly with basically no effort is incongruous - even if you believe the government should not exist, it does rn, and we live in a society where it can hurt or help the same people you claim to. Nudge the fabric of society that you interact with through fantastically minimal effort and never tell another anarcho-soul in your Matrix chat if they’re still doing a not voting circlejerk because goberment exist grr

  • rule

    Jump
  • You should look him up on your school computer

  • Amend that, it’s also -1 points to anyone else in a swing state because any possible vote not for the Dems is one that helps the Repubs get closer to the day one dictatorship.

    Those swing states include Texas, Virginia, NC, Nevada, Georgia, Wisconsin, PA, Ohio, New Hampshire, Michigan, Maine, Alaska, Iowa, Indiana, FloridA, and Arizona.

    Some are unlikely (Indiana, Texas) but all are possible (maybe Senate only for TX). The repubs are losing strength, maim ‘em so better progressive policies can grow. If you’re in CA or NY or CO or MN its still not exactly 0, you should vote local; you may be able to get 3rd party in in places or resist a local house Republican.

  • I will not sacrifice trans people, genocide continues under both yet only Trump would ban HRT or make their lives even worse. It’s something that’s better than nothing. By design, Americans have two choices, take the one that keeps minorities alive. (They probably agree with your hopes, as a bonus)

    A bit ago I interacted with an anarchist who refused to vote because he had everything he wanted now (right to gay marriage, specifically) but he didn’t even know that’s only accessible due to a supreme court ruling and not a law. It can disappear just as quick as abortion. Just token vote for the party that may manage to codify that into law or at least won’t ban it. People will die without marriage equality or HRT, they need to live their life before your fabled collapse occurs.

    If you can’t manage empathy, you are a libertarian in the “fuck you, I got mine” worst way. No dreaming of the collapse, no advocating for radical change, just a libertarian. Be better, do both harm reduction now and foment the future collapse.

  • BIG RICH CLAY STOLE ALL THE FOREHEAD KISSES I TELLS YA

    SANDY LOAM IS IN ON IT, IT’S A CONSPIRACY TO DEPRIVE THE PROLETARIAT OF UWU KISSES ON THE FOREHEAD TO MAKE US FEEL GOOD AND COZY

  • 196 @lemmy.blahaj.zone

    man-portable anti-dragon spellcaster (MANPADS) rule

  • 196 @lemmy.blahaj.zone

    wizards council ain’t shit rule

  • 196 @lemmy.blahaj.zone

    last ditch forbidden spell rule

  • 196 @lemmy.blahaj.zone

    wizards #1 rule

  • 196 @lemmy.blahaj.zone

    wizard war rule

  • 196 @lemmy.blahaj.zone

    rule

  • 196 @lemmy.blahaj.zone

    rule

  • Selfhosted @lemmy.world

    How do y'all backup docker databases with backup programs like Borg/Restic?

  • Selfhosted @lemmy.world

    Rootless podman adguard home failing

  • 196 @lemmy.blahaj.zone

    STOP RIGHT THERULE

  • 196 @lemmy.blahaj.zone

    Anxious at work rule

  • 196 @lemmy.blahaj.zone

    rule

  • 196 @lemmy.blahaj.zone

    rule

  • 196 @lemmy.blahaj.zone

    rule

  • 196 @lemmy.blahaj.zone

    melon rule

  • 196 @lemmy.blahaj.zone

    clap o’ the asscheeks rule

  • 196 @lemmy.blahaj.zone

    rule

  • 196 @lemmy.blahaj.zone

    julius rulius

  • 196 @lemmy.blahaj.zone

    minerule

  • 196 @lemmy.blahaj.zone

    Insight Lab rule