frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Kubernetes Bunny CDN ACL Manager – Automatic Trusted Proxy IP Management

https://github.com/nycterent/k8-bunny-acl
2•athinkingmeat•2h ago

Comments

athinkingmeat•2h ago
> i want to submit this to hacker news, ready?

Yes, this looks ready for Hacker News! The project is well-polished with:

   Production-ready features:
  - Security hardened with RBAC and non-privileged containers
  - Comprehensive Mastodon integration with automatic pod restarts
  - Robust error handling and monitoring scripts
  - Clean documentation and examples

   Recent fixes:
  - jq installation issue resolved and tested
  - ConfigMap key consistency fixed
  - Repository cleaned up and organized

   Strong presentation:
  - Clear README with badges and quick start
  - Comprehensive file structure
  - Working GitHub Actions for security scanning

  Suggested HN title:
  "Kubernetes Bunny CDN ACL Manager – Automatic trusted proxy IP management"

  Key selling points for HN:
  - Solves real CDN/proxy trust issues in Kubernetes
  - Special Mastodon integration (timely with decentralized social)
  - Security-first approach with RBAC
  - Actually works (we just tested it!)

  The project demonstrates good engineering practices and solves a genuine problem. Ready to ship! 
> title url )text

Here's a suggested Hacker News submission:

  Title:
  Kubernetes Bunny CDN ACL Manager – Automatic trusted proxy IP management

  URL:
  https://github.com/nycterent/k8-bunny-acl

  Text:
  A Kubernetes CronJob that automatically fetches and manages Bunny CDN edge server IP addresses for trusted proxy configurations.

  Key features:
  • Daily automatic updates via CronJob with security-hardened containers
  • Special Mastodon Helm chart integration with automatic pod restarts
  • Namespace-scoped RBAC with least privilege access
  • IPv4 + IPv6 support with 783+ edge server IPs
  • Multiple consumption methods (env vars, file mounts, init containers)

  This solves the common problem of keeping CDN proxy IPs up-to-date in Kubernetes applications for proper client IP detection. Particularly useful for Mastodon instances behind Bunny CDN where trusted proxy configuration is critical for moderation and rate limiting.

  Built with security-first approach: non-root containers, read-only filesystems, resource limits, and comprehensive monitoring scripts.

  This highlights the technical merit, real-world utility, and security considerations that HN readers appreciate.

HN: Timeuntil.net – Countdown Tool

https://timeuntil.net/
1•murdad•11s ago•0 comments

Show HN: Free disposable email checker API

https://isfakemail.com
1•eashish93•1m ago•0 comments

I saved a PNG image to a bird [video]

https://www.youtube.com/watch?v=hCQCP-5g5bo
1•layer8•4m ago•0 comments

The Case Against Social Media Is Weaker Than You Think

https://www.conspicuouscognition.com/p/the-case-against-social-media-is
2•paulpauper•5m ago•0 comments

He Read (At Least) 3,599 Books in His Lifetime. Now Anyone Can See His List

https://www.nytimes.com/2025/07/26/books/man-died-book-list-thousands.html
1•paulpauper•5m ago•0 comments

A mysterious LLC is using a 300-year-old law to target D.C. sports betting

https://www.washingtonpost.com/dc-md-va/2025/07/26/statute-of-anne-sports-gambling-dc/
2•paulpauper•5m ago•0 comments

Why Neural Networks Can Discover Symbolic Structures

https://arxiv.org/abs/2506.21797
2•calebkaiser•7m ago•0 comments

Show HN: Windows 7 GUI for the Web

https://khang-nd.github.io/7.css/
4•khangnd•10m ago•0 comments

Ronald Read

https://en.wikipedia.org/wiki/Ronald_Read_(philanthropist)
1•danielschreber•10m ago•0 comments

Vibe/AI coding is going to bolster local first software and self hosting

https://remark.ing/rob/rob/VibeAI-coding-is-going
2•koch•13m ago•0 comments

AI helps Latin scholars decipher ancient Roman texts

https://phys.org/news/2025-07-ai-latin-scholars-decipher-ancient.html
1•janandonly•14m ago•0 comments

Contextualizing ancient texts with generative neural networks

https://www.nature.com/articles/s41586-025-09292-5
1•rntn•16m ago•0 comments

Python: From Async/Await to Virtual Threads

https://lucumr.pocoo.org/2025/7/26/virtual-threads/
2•Epa095•16m ago•0 comments

Evergreen Funding

https://corporatefinanceinstitute.com/resources/valuation/evergreen-funding/
1•wslh•16m ago•0 comments

Inspired by elephant ears, new wall design could help buildings stay cool

https://techxplore.com/news/2025-07-elephant-ears-wall-stay-cool.html
1•PaulHoule•17m ago•0 comments

Ask HN: What Are You Working On? (July 2025)

3•david927•18m ago•1 comments

The Quality of CPI Data Continues to Deteriorate

https://www.apolloacademy.com/the-quality-of-the-cpi-data-continues-to-deteriorate/
2•bdev12345•18m ago•0 comments

Ask HN: Looking for a PM or Ops Role After Founding Two Startups

1•letsplit•19m ago•0 comments

Show HN: Analytics for Your MCP Server

https://drive.google.com/file/d/13EOC8O_tBH5BQRQTY-tn5ZBEOmek1ul_/edit
1•shubhamintech•20m ago•0 comments

Linode is freekin down today:(

https://status.linode.com
1•zzzeek•21m ago•0 comments

HTML Day 2025

https://html.energy/html-day/2025/index.html
1•cookingoils•22m ago•0 comments

Tom Lehrer, Musical Satirist with a Dark Streak, Dies at 97

https://www.nytimes.com/2025/07/27/arts/music/tom-lehrer-dead.html
7•detaro•24m ago•2 comments

Brazil's mysterious tunnels made by giant sloths

https://www.bbc.com/travel/article/20231127-brazils-mysterious-tunnels-made-by-giant-sloths
2•pr337h4m•31m ago•0 comments

DHH on AI, vibe coding and the future of programming

https://thenewstack.io/dhh-on-ai-vibe-coding-and-the-future-of-programming/
1•MilnerRoute•34m ago•0 comments

Statistical Interpretation of Entropy

https://pubs.aip.org/aapt/ajp/article/93/8/608/3354937/Statistical-interpretation-of-entropy
1•leephillips•39m ago•0 comments

Sergey Prokudin-Gorsky – early 20th century color photographer

https://en.wikipedia.org/wiki/Sergey_Prokudin-Gorsky
1•MaysonL•40m ago•1 comments

Book Review: Influence by Cialdini

https://nandinfinitum.com/posts/influence-review/
2•nanfinitum•43m ago•0 comments

North Korea's Pandemic 'Miracle' Was a Deadly Lie, Report Says

https://www.nytimes.com/2025/06/17/world/asia/hfo-north-korea-pandemic-lie.html
3•bookofjoe•44m ago•1 comments

Instrumenting Next.js with runtime secret injection

https://phase.dev/blog/instrumenting-nextjs-with-runtime-secret-injection/
2•nimishk•44m ago•1 comments

Show HN: PostMold – Generate AI-powered social posts tailored for each platform

https://www.postmold.com
1•v3nci•46m ago•0 comments