Community
Chat Logs
Sunday, March 8, 2026
- * nevet joined #primate
- * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
- * phaleth joined #primate
- phalethnice, that tiny nginx:alpine-slim container is capable of proxying to HTTP/2 site https://theanswerisc.repopack.app/
- nevetThe Answer Is C
- phalethactually, I don't know if nginx itself supports proxying to HTTP/2, it's prolly defaulting to HTTP/1.1, but anyway
- phaleththe traffic goes like this: http client <-> contabo VPS <-> haproxy nspawn container <-> root nspawn container <-> rootless podman nginx container <-> fly.io cloud deployment https://github.com/terrablue/theanswerisc/blob/master/.github/workflows/deployment.yml
- bluephaleth: hi
- blueI added a readme to the repopack repo
- bluephaleth: so ideally we should have: http client <-> contabo VPS <-> haproxy podman container <-> rootless podman nginx container <-> podman machine running the blog
- blueor maybe we don't even need that interim podman thingy
- blueso one nice thingy the podman API saves us is manual network management
- blueyou can just do POST networks and it allocates by itself. you can provide a name, which is great, because we'll use that to delete networks when apps are deleted
- bluephaleth: https://images4.imagebam.com/d8/24/e6/ME1B5M64_o.png
- blueso when you create an app, we add an entry to the app table in postgres, and we can use the id to refer to the network (or generate a network_id UUID column)
- bluephaleth: that rootless podman nginx container, it's running under your user, right?
- bluebtw the podman API is nice. this is what you get if you try to create a network with an existing name:
- blueError: HTTP 409: {"cause":"network already exists","message":"network name testtest already used: network already exists","response":409}
- phalethblue: hi
- phalethyeah, all podman containers and I think haproxy can be installed on arch host directly
- phalethtrue, everything can be named and names are unique
- bluesounds good
- phalethmoved haproxy to archlinux host
- * nevet joined #primate
- * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
- * nevet joined #primate
- * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
- phalethnice, all browsers finally support https://developer.mozilla.org/en-US/docs/Web/API/Trusted_Types_API
- nevetTrusted Types API - Web APIs | MDN
- * phaleth joined #primate
- bluedreamreal: can you now configure nevet for the primate repo?
- dreamrealI can but you're going to have to set up the webhook: I'll DM you the token on discord.
- dreamrealgithub webhook primate-run/primate
- nevetError: No registered repository found for primate-run/primate
- blueshouldn't *I* send YOU the token?
- dreamrealGah, another bug - the webhook mutates the existing record.
- dreamrealEw, no
- dreamrealthat means I'm storing the token
- dreamrealnevet generates it.
- blueyes? you need to store the token anyway to validate the hook
- dreamrealI don't, though: it gets the token from outside and encrypts it to match
- bluehttps://docs.github.com/en/webhooks/using-webhooks/validating-webhook-deliveries
- bluethat's literally what the github docs say
- blueunless I missed something, I don't get how you can otherwise validate it
- blue"After creating a secret token, you should store it in a secure location that your server can access."
- bluetypically, you put that in an env variable
- blueor if you wanna do it programmatically, something like a keyserver
- dreamrealI generate a string: aaabbcccdd. Send it to the user via PM. Store the encrypted version so I never have aaabbcccdd again. When I get aaabbcccdd over https, I re-encrypt it and check.
- blueyes, so you still store the token
- blueyou just encrypt it
- bluewhich is... I guess fine
- dreamrealyes, and I COULD accept external tokens where you say "set it to this explicitly" but... eh
- blueI don't really see the point, but sure
- dreamrealgive me a minute, workflow oversight
- bluehonestly I have no idea *how* that can be even work. github sends you a hash signature using the token with each payload. how can you recalculate the signature if you don't have the original token?
- bluetypically you take the payload + token, calculate a signature, then compare it to what gh sent
- bluebut if you encrypted the token, that's not gonna work
- bluedreamreal: https://github.com/terrablue/gpbot/blob/master/routes/index.js#L25-L27
- blueyou need to replicate *that* logic
- dreamrealIt's already there
- bluewell, that can't work unless you have the plain secret
- bluemaybe you decrypt it at runtime, but I don't see the point in the indirection, I'd just have it in memory
- dreamrealYes, I have to decrypt it, it's fine
- dreamrealbut the code's already written, rabbit's dead, no win in changing it
- bluebut then you need to store a decryption key...
- dreamrealI have one, I configure it externally
- bluewhat did you gain in trading a secret for a decryption key?
- dreamrealNot a lot, I was doing something dumb and re-using a key that was supplied elsewhere
- blueok. well anyway, it doesn't really matter who of us supplies the secret. but if YOU do, I need the plaintext one obviously
- dreamrealyes, you'd get it
- dreamreallike I said, it generates a key, sends to the user, then stores something different
- blueyes, that's an indirection I wouldn't have chosen in my code, but if you want to do it like that, that's fine
- * nevet joined #primate
- * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
- dreamrealgithub webhook primate-run/primate
- nevetWebhook enabled for primate-run/primate. Configure GitHub to POST to https://api.bytecode.news/webhooks/github with the provided secret.
- dreamrealgithub subscribe primate-run/primate
- nevetSubscribed to primate-run/primate
- dreamrealgithub subscriptions
- nevetprimate-run/primate
- bluewould be nice if nevet output the ping
- dreamrealDid it report success on the github console?
- blueyes
- dreamrealThen it worked. And the console will show pings, for what it's worth.
- blueI meant here. that's a wait to test full stack working without access to the console
- bluethat's a way*
- dreamrealWell, the thing is, ORDINARILY this is a bit of an odd path
- bluehow so?
- dreamrealadmins are the only ones who can subscribe, so ordinarily the admin is the one who A) has access and B) sets the token
- dreamrealso *I* as the admin would be the one to validate the ping, not the channel
- blueyes but *I* don't have access to the console
- dreamrealI know
- dreamreallike I said, odd path
- blueit's only an odd path if you don't intend for nevet to relay those notifications for non-admins
- * dreamreal sighs. But like I said: ODD PATH. You create a subscription for webhooks... THEN you add what channels watch for them.
- dreamrealWithout the channels, nevet doesn't know where to say "hey, ping succeeded!"
- dreamrealit's literally an internal event, and it's internally published
- bluethat's a weird flow to me. if you do !github webhook primate-run/primate in #primate, I'd think that's intended to be used here
- dreamrealI get it
- dreamrealbut the flow is not that way: I can create subscriptions ANYWHERE, and channel subscriptions are separate
- dreamrealsame for RSS
- dreamreal(in fact, they use the same codebase and design)
- bluenonetheless, you can *still* map the ping event, and it works just like every other event: it outputs once it has channels
- * nevet joined #primate
- * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
- dreamrealcrikey
- dreamrealversion
- nevetnevet 1.0 | 84619bb (github-webhook-fixes) | Built 2026-03-08 09:14:24 EDT
- dreamrealSo try the emulated thing, let's see what it does
- bluewell it still says successful
- bluefor the redelivery
- dreamrealyep.
- blueyes? what changed?
- blueI see no message
- dreamrealI saw it
- blue...
- dreamrealAgain, pings are not echoed to subscriptions
- bluebut why?
- dreamrealBecause I don't trust them yet. I may turn it on eventually. But I don't know github's ping policy yet.
- bluethere's no ping policy. it's done when you create a webhook, and when you change it iirc. I had the ping event mapped on gpbot, I'd have noticed it otherwise
- blueit's literally a way to test the full stack
- bluestarting to get tired of claude here
- blueit's regularly amnesic, forgetting things discussed like 3 minutes ago
- dreamrealhttps://github.com/jottinger/bytecode.news/issues/196
- nevetgithub: ping should propagate to subscribed channels · Issue #196 · jottinger/bytecode.news
- * nevet joined #primate
- * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
- dreamrealversion
- nevetnevet 1.0 | 22fb3be (main) | Built 2026-03-08 09:17:40 EDT
- phalethblue: thanks for the readme, quite useful
- blueyw phaleth
- blue`Happy DOM has a long history of incomplete default form-submission behavior`
- bluethis industry is full of idiots
- bluetime for @rcompat/dom
- bluephaleth: https://gitea.repopack.app/repopack/website/commit/3960e135869ad6930e25dbde1916c481b2e6e8e5
- bluecan now create networks; duplicates are recognised and surfaced as form errors
- bluethis has been interesting info for the future generation of openapi clients
- bluein future style, this will be:
- blueawait client.createNetwork({ name }).conflict({ field: "name", message: "A network with this name already exists" });
- blue(409 is CONFLICT)
- bluethat means HTTP status codes will be surfaced on the generated openapi client as methods
- blueso you can literally do .conflict().forbidden().notFound()
- bluethe default return value is the OK (2xx) case
- phalethnice, I've made a PR there just to test, it now has a merge conflict, very cool
- bluebtw, I've noticed gitea is much, MUCH faster than github
- bluelike orders of magnitude faster
- bluemonopolies SUCH!
- blueSUCK*
- phalethyup, I've noticed gitea has some frontend devs that continuously put effort into modularizing the frontend so it remains fast after features get added
- bluewell, of course we're not gonna use gitea but repopack itself, but it's still so freshing to see that it doesn't HAVE to be this way
- blueor refreshing, rather
- phalethyeah, I kinda refuse to go back to github already
- blueya, github can go to hell
- bluephaleth: https://gitea.repopack.app/repopack/website/commit/68422c1c06103eeea93e91c2df3f48425b7e6487
- blueI really need to make it easily possible to add woff2 files into your file, it's ridiculous to need a module for that
- blueor maybe woff2 being parsed as file by esbuild should just be the default
- blues/into your file/into your app/
- phalethI remember webpack can take in static assets and put them where needed, also with the option to not add content hash to the filename
- phalethmaybe esbuild can do that too
- phalethlooks like this copy loader can be used https://esbuild.github.io/content-types/#copy
- blueyes, essentially it's the file loader
- bluethe file loader causes esbuild to base64 the file and include it in the bundle
- bluehttps://gitea.repopack.app/repopack/website/commit/68422c1c06103eeea93e91c2df3f48425b7e6487#diff-4abca52bbb0fae9100b8e3e180ca4e8a39cc38a5
- bluebut for woff2, this should be the standard behaviour. unless you're like a platform that offering woff2 for download, I don't see how you'd ever want different behaviour
- blueand even if you are a platform, you wouldn't place the woff2 files for download inside static, but would have them downloaded dynamically
- blueand if you DO want a different behaviour, you write a primate module
- bluephaleth: did you pull down the nice coloured changes?
- blueit's just adding some font and a bit of colours so it doesn't look 100% lame as before
- phalethnot yet, I'm gonna try to find some podman REST API reference
- phalethafk
- bluephaleth: https://docs.podman.io/en/latest/_static/api.html?version=latest
- nevetReference
- blueprogrammatic: https://storage.googleapis.com/libpod-master-releases/swagger-latest.yaml
- blueunfortunately it's swagger 2.0 which the primate openapi generator won't support
- bluebut I believe it's possible to convert it to openapi 3.0
- blueand then I'll add it to the primate/openapi repo so it's av at openapi.primate.run
- blue /libpod/networks/create:
- blue post:
- blue description: Create a new network configuration
- blue operationId: NetworkCreateLibpod
- bluethis operationId is totally dumb
- bluedreamreal: why is everyone so dumb in this industry all the time
- bluewhat am I supposed to do with "NetworkCreateLibpod"???
- bluethe operationId is SUPPOSED to be "CreateNetwork"
- blueI suppose that in the swagger converter, I can add a strategy: "drop -Libpod, switch order"
- blueok, I see what they did
- blueso we also have
- blue /libpod/pods/{name}/exists:
- blue get:
- blue description: Check if a pod exists by name or ID
- blue operationId: PodExistsLibpod
- bluecan't really deal with that. so we'll be dropping -Libpod and generating as is
- blueclient.podExists is acceptable. client.networkCreate sounds dumb but ok
- bluecould've put a non-trivial effort into this though, redhat
- blueI sure do hope the nevet operationIds are SLIGHTLY better
- bluephaleth: dreamreal: https://github.com/primate-run/openapi/commit/00d9e4e77d2dadc948da6541bbab914eabc817cb
- nevetadd support for swagger to openapi conversion and stripping operation… · primate-run/openapi@00d9e4e
- bluephaleth: https://github.com/primate-run/openapi/commit/7d8c850f277f4d644e6b002e26b1791ef5e8f4b6
- nevetadd podman/libpod · primate-run/openapi@7d8c850
- bluecan we redeploy the openapi machine?
- bluemaybe as a podman container already
- bluenice, you created a user podman
- dreamrealblue: I gotta get you to learn how to use !article :D
- bluewth is THAT, dreamreal
- dreamrealIt's a way to get nevet to build a draft article online
- dreamrealyou say "!article title" and can add content blocks with "!content this is some content here", add channel context with "!logs 5m" (include the last five minutes for context), and signal done with !done (it'll time out on its own if you don't, after five minutes of no interaction) - and bam! draft article on bytecode.news
- dreamrealthe diataxis article was written that way
- bluearticle Primate
- nevetIdea session started: "Primate". Use 'content <text>' to add body paragraphs, 'done' to save, or 'cancel' to discard.
- bluecontext Primate is the universal web framework -- the best tool to build websites with
- nevetok, blue: updated context primate.
- bluedone
- nevetIdea saved as draft: "Primate" (0 content blocks).
- blueoh, I wrote context, my bad
- bluewell, at least it did something
- dreamrealIt did indeed.
- blueI have no idea how to edit it
- dreamrealYOU don't. *I* would have to.
- bluehahaha
- dreamrealThe !article thing submits DRAFTS. If you're not authenticated, it submits as anonymous.
- bluewhy can't I edit drafts though, if submitted anonymously?
- dreamrealThis is entirelly intentional.
- bluealso, wth is THIS
- bluehttps://bytecode.news/factoids/context%20primate
- nevetNevet - Reference UI
- dreamrealWhat about it?
- blueso ! randomly creates factoids?
- bluethat seems like a bug
- dreamrealNo, you said "context primate" and "is" and some content.
- dreamrealThat's working as designed. You created a factoid.
- blueoh man, that's CRAZY
- dreamrealif you'd used "!content primate is..." the internal routing would be different.
- bluethat should be like +factoid or something
- dreamrealBut "context" is not a keyword for the article system.
- dreamreal"is" is pretty human.
- blueyeah but you do realise that having both context words and pattrens like !x is y, is confusing, right?
- bluethat effectively means that a typo can have wholly unintended consequences
- dreamrealSure. And compare that against the ACTUAL formal syntax: !foo=bar
- dreamrealyep, and the consequences cost very very close to nothing so I don't care
- dreamrealjust like karma
- blueso the making of a good system, that a typo does NOT cause wholly unintended behaviour
- bluebut rather results in the system telling you made a typo
- bluesomething like: "!context does not exist as a operation"
- dreamrealin which case you have a formal grammar and not something easy for humans to use.
- blueand even nicer: "did you mean `!content`?"
- dreamrealSo: no.
- dreamrealHow would teh system know you might have meant "content?"
- dreamrealThe system has no unified grammar. This is intentional.
- bluebecause it has a very small levenshtein distance
- bluestop making excuses, this is totally normal, git has it
- * dreamreal sighs
- dreamrealno. Because that means the system needs to know a shitload more about the operations than it should. It doesn't KNOW there are operations.
- dreamrealActually, that's not true: the system DOES know there are operations... like, six or seven of them. Out of the close to 80 now.
- bluesigh, fine, your system, you know BEST, me typoing content into context is just a FACT of life and should result in garbage in the system
- dreamrealYep! And it does! And again, the actual cost is 0
- dreamrealit's fine, it's also trivial to correct
- dreamrealcontext primate.forget
- nevetok, forgot context primate.
- dreamrealOH NO SO MUCH SWEATING
- blueoh man, nevermind, I'll just shut up, I'm tired of this uphill battle
- blueyou just do whatever you think is best and I'll stop making suggestions
- dreamrealThe bot is messy: that's a fact of life. The actual OPERATION usage is absolutely linear; if we had an article *http operation* it can ensure types and make sure such things are unambiguous. Over IRC? not so much.
- dreamrealWe could even do that for slack and discord, if I supported actual actions.
- blueit's really not messy to have a clear way to edit factoids, say with `+factoid title | text` to add, `~factoid title | text` to edit, and `-factoid title` to delete
- blueinstead of using a pattern nobody understands like x is y
- dreamrealGotta get lunch, later
- blueciao
- bluephaleth: should we move primate/openapi to gitea?
- blueI'm honestly thinking of keeping just the high profile projects, so primate-run/primate, on GH. all the rest I think can move away
- phalethblue: if you don't want that to be open why not
- phalethsame for superarch
- blueoh it will be open, in the future, when it's available under repopack.com/primate/primate
- phalethshould I redeploy primate/openapi?
- bluesorry, repopack.com/primate/openapi
- blueyes
- phalethok
- bluedid you pull the latest rp colours? :P
- bluehm
- blueshould I call the org primate or primate-run on gitea
- blueI guess it doesn't matter much
- phalethcall it primate
- bluek
- phalethopenapi is updated
- phalethactually, no it isn't, forgot to download from git
- phalethgithub*
- bluephaleth: https://gitea.repopack.app/primate/openapi
- blueI'm gonna delete the repo on gh
- bluebtw I got a ton of template repos on gh for primate
- blueI'm sure we can do this better with repopack
- bluetell me when you've moved this to gitea
- blueand I can delete
- blueif you need to make it easier for yourself, add a pubkey, that's what I did
- blueI have a pubkey blue@vps in my gitea
- blueso I don't need to use weird bearer tokens
- phalethyou can delete from github all you want
- bluedone
- phalethhttps://openapi.primate.run/manifest.json
- blueNICE, libpod is there!
- bluedreamreal: I FIXED IT!
- bluehttps://openapi.primate.run/spec/podman/libpod.json
- bluenow we can have a nice `client.networkCreate`
- bluephaleth: if you look at the NetworkCreate operation, you see it exposes four responses
- blueso the generated openapi client will have:
- phalethno clue what I'm looking at in that json, will have to look into that later
- phalethgotta go now, see ya
- blueclient.networkCreate(/* params */).badRequest(/* handler */).conflict(/* handler */)
- blueciao
- * nevet joined #primate
- * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc