frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Netfence – Like Envoy for eBPF Filters

https://github.com/danthegoodman1/netfence
20•dangoodmanUT•2h ago
To power the firewalling for our agents so that they couldn't contact arbitrary services, I build netfence. It's like Envoy but for eBPF filters.

It allows you to define different DNS-based rules that are resolved in a local daemon to IPs, then pushed to the eBPF filter to allow traffic. By doing it this way, we can still allow DNS-defined rules, but prevent contacting random IPs.

There's also no network performance penalty, since it's just DNS lookups and eBPF filters referencing memory.

It also means you don't have to tamper with the base image, which the agent could potentially manipulate to remove rules (unless you prevent root maybe).

It automatically manages the lifecycle of eBPF filters on cgroups and interfaces, so it works well for both containers and micro VMs (like Firecracker).

You implement a control plane, just like Envoy xDS, which you can manage the rules of each cgroup/interface. You can even manage DNS through the control plane to dynamically resolve records (which is helpful as a normal DNS server doesn't know which interface/cgroup a request might be coming from).

We specifically use this to allow our agents to only contact S3, pip, apt, and npm.

A macOS app that blurs your screen when you slouch

https://github.com/tldev/posturr
198•dnw•2h ago•80 comments

Using PostgreSQL as a Dead Letter Queue for Event-Driven Systems

https://www.diljitpr.net/blog-post-postgresql-dlq
48•tanelpoder•2h ago•11 comments

A flawed paper in Management Science has been cited more than 6,000 times

https://statmodeling.stat.columbia.edu/2026/01/22/aking/
472•timr•8h ago•247 comments

Doom has been ported to an earbud

https://doombuds.com
165•arin-s•5h ago•46 comments

ICE Using Palantir Tool That Feeds on Medicaid Data

https://www.eff.org/deeplinks/2026/01/report-ice-using-palantir-tool-feeds-medicaid-data
48•JKCalhoun•26m ago•3 comments

Web-based image editor modeled after Deluxe Paint

https://github.com/steffest/DPaint-js
73•bananaboy•5h ago•6 comments

Google confirms 'high-friction' sideloading flow is coming to Android

https://www.androidauthority.com/google-sideloading-android-high-friction-process-3633468/
456•_____k•5d ago•449 comments

Introduction to PostgreSQL Indexes

https://dlt.github.io/blog/posts/introduction-to-postgresql-indexes/
198•dlt•9h ago•11 comments

Show HN: Bonsplit – Tabs and splits for native macOS apps

https://bonsplit.alasdairmonk.com
125•sgottit•6h ago•16 comments

World’s most powerful literary critic is on TikTok

https://www.newstatesman.com/culture/books/2026/01/the-worlds-most-powerful-literary-critic-is-on...
4•insistey•11h ago•1 comments

ANN v3: 200ms p99 query latency over 100B vectors

https://turbopuffer.com/blog/ann-v3
71•_peregrine_•3d ago•20 comments

Show HN: Netfence – Like Envoy for eBPF Filters

https://github.com/danthegoodman1/netfence
20•dangoodmanUT•2h ago•0 comments

Show HN: TUI for managing XDG default applications

https://github.com/mitjafelicijan/xdgctl
67•mitjafelicijan•6h ago•21 comments

Wine-Staging 11.1 Adds Patches for Enabling Recent Photoshop Versions on Linux

https://www.phoronix.com/news/Wine-Staging-11.1
68•LorenDB•3h ago•4 comments

Jurassic Park - Tablet device on Nedry's desk? (2012)

https://www.therpf.com/forums/threads/jurassic-park-tablet-device-on-nedrys-desk.169883/
108•exvi•8h ago•39 comments

Nango (YC W23, Dev Infrastructure) Is Hiring Remotely

https://jobs.ashbyhq.com/Nango
1•bastienbeurier•6h ago

Social Dynamics at Arm's Length

https://www.jenn.site/social-truths-at-arms-length/
6•surprisetalk•4d ago•0 comments

I built a 2x faster lexer, then discovered I/O was the real bottleneck

https://modulovalue.com/blog/syscall-overhead-tar-gz-io-performance/
114•modulovalue•5d ago•53 comments

The Rebirth of Pennsylvania's Infamous Burning Town

https://www.atlasobscura.com/articles/centralia-pennsylvania-rebirth
44•pbshgthm•5d ago•18 comments

Bridging the Gap Between PLECS and SPICE

https://erickschulz.dev/posts/plecs-spice/
20•eschu•7h ago•6 comments

A Lament for Aperture

https://ikennd.ac/blog/2026/01/old-man-yells-at-modern-software-design/
185•firloop•4d ago•48 comments

FAA institutes nationwide drone no-fly zones around ICE operations

https://www.aerotime.aero/articles/faa-drone-no-fly-zone-ice-dhs
82•dayofthedaleks•38m ago•53 comments

BU-808: How to Prolong Lithium-based Batteries (2023)

https://www.batteryuniversity.com/article/bu-808-how-to-prolong-lithium-based-batteries/
53•eswat•2d ago•24 comments

Sony Data Discman

https://huguesjohnson.com/random/sony-ebook/
64•naves•9h ago•9 comments

Back to Bellevue

https://theamericanscholar.org/back-to-bellevue/
9•prismatic•2d ago•0 comments

Alarm overload is undermining safety at sea as crews face thousands of alerts

https://www.lr.org/en/knowledge/press-room/press-listing/press-release/2026/alarm-overload-is-und...
86•geox•5h ago•55 comments

150k lines of vibe coded Elixir: The Good, the Bad and the Ugly

https://getboothiq.com/blog/150k-lines-vibe-coded-elixir-good-bad-ugly
27•InternetGiant•7h ago•12 comments

Adoption of EVs tied to real-world reductions in air pollution: study

https://keck.usc.edu/news/adoption-of-electric-vehicles-tied-to-real-world-reductions-in-air-poll...
517•hhs•17h ago•500 comments

Deutsche Telekom is throttling the internet

https://netzbremse.de/en/
469•tietjens•9h ago•230 comments

Hands-On with Two Apple Network Server Prototype ROMs

http://oldvcr.blogspot.com/2026/01/hands-on-with-two-apple-network-server.html
42•todsacerdoti•9h ago•1 comments