frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Kyber vs. RSA-2048

https://blog.ellipticc.com/posts/kyber-vs-rsa-2048/
1•iliasabs•1m ago•1 comments

Alphabet's Intrinsic Forms Joint Venture with Foxconn

https://www.intrinsic.ai/blog/posts/foxconn-and-intrinsic-launch-joint-venture-to-build-the-ai-fa...
1•kscottz•4m ago•0 comments

Why top firms paradoxically fire good workers

https://www.rochester.edu/newscenter/employee-turnover-why-top-firms-churn-good-workers-681832/
1•hhs•8m ago•0 comments

Keys Inc. Proposes U.S. National Locksmith Licensing

https://www.locksmithledger.com/home/article/55302123/keys-inc-proposes-national-locksmith-licensing
1•walterbell•10m ago•0 comments

Report URI – Script and Style Hasher for CSP

https://report-uri.com/home/hash
1•Brysonbw•11m ago•0 comments

Lecture on the Wigner-Dyson nearest-neighbour distribution

https://github.com/msuzen/leymosun/blob/main/lectures/wigner_dyson_spacing.ipynb
1•northlondoner•12m ago•1 comments

Homeschooling Hits Record Numbers

https://reason.com/2025/11/19/homeschooling-hits-record-numbers/
3•bilsbie•12m ago•0 comments

"I'm Building an Algorithm That Doesn't Rot Your Brain" Jack Conte

https://www.youtube.com/watch?v=EO14wPQw89c
2•kalinkochnev•14m ago•0 comments

Ancient ‘animal GPS’ identified in magnetic fossils

https://www.cam.ac.uk/research/news/ancient-animal-gps-identified-in-magnetic-fossils
2•hhs•17m ago•0 comments

Samuel Johnson's Online Dictionary

https://johnsonsdictionaryonline.com/index.php
1•gaws•18m ago•0 comments

Suno is the walking dead, the new Napster 2.0

https://jperla.com/blog/suno-walking-dead
2•ljlolel•20m ago•0 comments

Use Reading Mode in Chrome

https://support.google.com/chrome/answer/14218344?hl=en
1•kamaraju•21m ago•0 comments

RI judge intervenes after ICE mistakenly detains Superior Court intern

https://www.wpri.com/news/local-news/providence/ri-judge-intervenes-after-ice-mistakenly-detains-...
8•vm•22m ago•2 comments

U.S. Banks Shelve $20B Bailout Plan for Argentina

https://www.wsj.com/finance/u-s-banks-shelve-20-billion-bailout-plan-for-argentina-add58f7e
2•petethomas•24m ago•0 comments

Quantum computing needs its own industrial revolution

https://www.ft.com/content/de55d987-13bb-4821-9e72-d7a066e48ccd
1•hhs•25m ago•0 comments

Welcome to Anything Goes America

https://www.economist.com/leaders/2025/11/20/welcome-to-anything-goes-america
2•petethomas•27m ago•0 comments

CDC Changes Webpage to Say Vaccines May Cause Autism, Revising Prior Language

https://www.msn.com/en-us/health/diseases-and-conditions/cdc-changes-webpage-to-say-vaccines-may-...
7•pseudolus•32m ago•1 comments

Trump signs order to remove tariffs from Brazilian beef, coffee

https://www.reuters.com/world/us/trump-signs-order-remove-tariffs-some-brazilian-agricultural-imp...
7•petethomas•36m ago•0 comments

Ask HN: Best solution to build AI agents?

1•khalilsautchuk•39m ago•0 comments

How ASML Got EUV Lithography

https://www.factorysettings.org/p/how-asml-got-euv-lithography
2•mhb•40m ago•0 comments

Moss survived outside of the International Space Station for 9 months

https://www.livescience.com/space/scientists-put-moss-on-the-outside-of-the-international-space-s...
6•geox•41m ago•1 comments

Prozac 'no better than placebo' for treating children with depression, experts

https://www.theguardian.com/society/2025/nov/20/prozac-no-better-than-placebo-for-treating-childr...
15•pseudolus•42m ago•3 comments

Esbuild XSS Bug That Survived 5B Downloads and Bypassed HTML Sanitization

https://www.depthfirst.com/post/esbuilds-xss-bug-that-survived-5-billion-downloads-and-bypassed-h...
2•ponderwonder•43m ago•0 comments

U.S. employee well-being hit new low in 2024, survey reveals

https://phys.org/news/2025-11-employee-survey-reveals.html
5•pseudolus•44m ago•0 comments

Microbubble physics study confirms utility of ultrasound for noninvasive therapy

https://phys.org/news/2025-10-microbubble-physics-ultrasound-noninvasive-therapy.html
1•PaulHoule•45m ago•0 comments

Steamworks SDK 1.63 – Support for ARM64 titles added

https://store.steampowered.com/news/group/4145017/view/627817201164877825
1•haunter•46m ago•0 comments

We're (now) moving from OpenBSD to FreeBSD for firewalls

https://utcc.utoronto.ca/~cks/space/blog/sysadmin/OpenBSDToFreeBSDMove
2•birdculture•47m ago•0 comments

AI Powered Voice Remote for Mac - GoatRemote

https://twitter.com/mayfer/status/1991296888394666401
2•joelkesler•47m ago•1 comments

The HTTP Query Method

https://www.ietf.org/archive/id/draft-ietf-httpbis-safe-method-w-body-14.html
2•choult•53m ago•0 comments

Trump accuses 6 Democratic lawmakers of seditious behavior, punishable by death

https://rhodeislandcurrent.com/2025/11/20/repub/trump-accuses-6-democratic-lawmakers-of-seditious...
10•chmaynard•55m ago•1 comments
Open in hackernews

Getting tired of Helm – any better way to handle deployments in Kubernetes?

25•DeborahEmeni_•6mo ago
I’ve been deep in Helm templates lately and it’s starting to feel like YAML hell. It was fine when we had a few services, but now it’s just hard to manage. Anyone found a workflow that avoids Helm altogether? Or made Helm manageable at scale?

Comments

LarsLarson•6mo ago
We are using kustomize to create the yaml and argocd for deployment. All via ci and git-ops.

works really well

GauntletWizard•6mo ago
I'm a huge fan of Kustomize. I'm ambivalent towards argocd, but Kustomize is as close to a DWIM tooling as it's possible to get for Kubernetes.
OhSoHumble•6mo ago
Also using Kustomiza and Argo. It's really good imo.
natbennett•6mo ago
I prefer ytt for templating and kapp for deployments.

https://github.com/carvel-dev/carvel

johnjungles•6mo ago
ArgoCD
dvektor•6mo ago
Yeah the whole 'git repo = helm chart' just does not feel great at all. As we all know, the only thing worse is not using helm and having to deal with writing all those service, pv, pvc, ingress yaml files individually :)
haiku2077•6mo ago
ArgoCD for relatively simple stuff.

For complex stuff I write Python or Go programs to build manifests, then shell out to kubectl apply. An old example - deploying a multi-instance modded Arma 3 server on k3s: https://github.com/dharmab/homelab-k3s/tree/main/lab

a-saleh•6mo ago
Why just simple?

T.b.h. if I were to write a manifest generator, I would still probably commit the thing into a repo and let argo do the rest. Maybe even fiddled around to make the generator into a config-management-plugin ... but that feels like over-doing it.

Nerudite•6mo ago
Helmsman works great:

https://github.com/mkubaczyk/helmsman

b11484•6mo ago
I've been working on improving a tool called kr8+, which uses jsonnet to combine cluster config and apply it to components: https://github.com/ice-bergtech/kr8
Vespasian•6mo ago
My recommendation is fluxcd for a great gitops based workflow (incorporates soap for secrets)
atmosx•6mo ago
Kustomize is easier to manage at scale, but some upfront effort is required. Many charts are distributed as Helm packages, so you’ll often need to export them as raw YAML manifests. In an ideal setup, ArgoCD combined with Kustomize should cover most deployment needs. However, depending on your workflow, you may eventually need a way to dynamically replace variables. If the built-in tools in recent Kustomize versions aren’t sufficient, consider using envsubst as a fallback.
GauntletWizard•6mo ago
I handle deploy time dynamic variables with `sed`. You shouldn't need more complexity than that.

(Not that I haven't had the need, I've use jsonnet with libk8s at scale. But if you're asking the question this simply, you probably don't need it)

atmosx•6mo ago
> I handle deploy time dynamic variables with `sed`

I brought up envsubst because it’s a simpler, cleaner, and often overlooked option for variable substitution.

> Not that I haven't had the need, I've use jsonnet with libk8s at scale. But if you're asking the question this simply, you probably don't need it

In my view, Jsonnet isn’t an improvement - it’s complicated to learn, cumbersome to use, and prone to mistakes.

That said, if an organization decides to adopt any specific tool, I believe consistency in tooling, design, and practices is more important than the tool itself.

arccy•6mo ago
if you only work with your own stuff, helm is easily (and best) avoided.

i like generating k8s yaml with cue, example: https://github.com/cue-labs/cue-by-example/tree/main/003_kub...

there's also https://timoni.sh/ if you want a helm-like experience, but with cue instead of templating.

If you're working with upstream projects, unfortunately many of them will only provide helm charts, so you got to decide between rewriting them to suit your env/tool, or just live with the crappiness of helm.

delduca•6mo ago
+1 for Kustomize
bithavoc•6mo ago
I use Pulumi native package for Kubernetes, no more YAML, only instances of Typescript classes.
Kerbonut•6mo ago
I built my own tooling around templated manifest files (jinja2) and management via ansible playbooks (templated).
1024kb•6mo ago
What exactly are you doing with Helm that's making it so painful to use, and what does your development workflow look like? I've certainly had my fair share of issues with Helm, especially when trying to get a bit too fancy with creating Helm libraries, and standardised charts. I've also found that trying to aggregate multiple charts into a single chart for deploying an environment can also become a nightmare to manage.

I'm currently looking at Helmfile so that I don't need to aggregate charts into a 'parent chart', and i'd also like to move towards a single standardised chart that all microservices can use, rather than spin up a new chart for each service.

Open-Sourcery•6mo ago
Holos.run for my homelab cluster. Cuelang has a learning curve but works well with argo unlike Timoni and let's you import existing charts, bare manifests, and use kustomize. Let's me abstract config with custom types and unification/(inheritance if that is easier to think about but a bit wrong)
gtirloni•6mo ago
https://github.com/apple/pkl-k8s
uaas•6mo ago
IMHO at scale (both in terms of complexity and org level) having something consistent helps more than trying to fight the de-facto standard. Since most upstream projects are mainly distributed as Helm charts, going with anything else will require more effort eventually.
a-saleh•6mo ago
Recently I have been writing more stings in jsonnet. If I were with more haskell-friendly team, might even try dhall. In general, I feel like writing the yaml in something else than yaml is the way to go, and as long as you get imports and way to do templating that is not just string interpolation, you are good.