Chat Logs

  1. * nevet joined #primate
  2. * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
  3. * phaleth joined #primate
  4. phalethnice, that tiny nginx:alpine-slim container is capable of proxying to HTTP/2 site https://theanswerisc.repopack.app/
  5. nevetThe Answer Is C
  6. phalethactually, I don't know if nginx itself supports proxying to HTTP/2, it's prolly defaulting to HTTP/1.1, but anyway
  7. phaleththe traffic goes like this: http client <-> contabo VPS <-> haproxy nspawn container <-> root nspawn container <-> rootless podman nginx container <-> fly.io cloud deployment https://github.com/terrablue/theanswerisc/blob/master/.github/workflows/deployment.yml
  8. bluephaleth: hi
  9. blueI added a readme to the repopack repo
  10. bluephaleth: so ideally we should have: http client <-> contabo VPS <-> haproxy podman container <-> rootless podman nginx container <-> podman machine running the blog
  11. blueor maybe we don't even need that interim podman thingy
  12. blueso one nice thingy the podman API saves us is manual network management
  13. blueyou can just do POST networks and it allocates by itself. you can provide a name, which is great, because we'll use that to delete networks when apps are deleted
  14. bluephaleth: https://images4.imagebam.com/d8/24/e6/ME1B5M64_o.png
  15. blueso when you create an app, we add an entry to the app table in postgres, and we can use the id to refer to the network (or generate a network_id UUID column)
  16. bluephaleth: that rootless podman nginx container, it's running under your user, right?
  17. bluebtw the podman API is nice. this is what you get if you try to create a network with an existing name:
  18. blueError: HTTP 409: {"cause":"network already exists","message":"network name testtest already used: network already exists","response":409}
  19. phalethblue: hi
  20. phalethyeah, all podman containers and I think haproxy can be installed on arch host directly
  21. phalethtrue, everything can be named and names are unique
  22. bluesounds good
  23. phalethmoved haproxy to archlinux host
  24. * nevet joined #primate
  25. * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
  26. * nevet joined #primate
  27. * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
  28. phalethnice, all browsers finally support https://developer.mozilla.org/en-US/docs/Web/API/Trusted_Types_API
  29. nevetTrusted Types API - Web APIs | MDN
  30. * phaleth joined #primate
  31. bluedreamreal: can you now configure nevet for the primate repo?
  32. dreamrealI can but you're going to have to set up the webhook: I'll DM you the token on discord.
  33. dreamrealgithub webhook primate-run/primate
  34. nevetError: No registered repository found for primate-run/primate
  35. blueshouldn't *I* send YOU the token?
  36. dreamrealGah, another bug - the webhook mutates the existing record.
  37. dreamrealEw, no
  38. dreamrealthat means I'm storing the token
  39. dreamrealnevet generates it.
  40. blueyes? you need to store the token anyway to validate the hook
  41. dreamrealI don't, though: it gets the token from outside and encrypts it to match
  42. bluehttps://docs.github.com/en/webhooks/using-webhooks/validating-webhook-deliveries
  43. bluethat's literally what the github docs say
  44. blueunless I missed something, I don't get how you can otherwise validate it
  45. blue"After creating a secret token, you should store it in a secure location that your server can access."
  46. bluetypically, you put that in an env variable
  47. blueor if you wanna do it programmatically, something like a keyserver
  48. dreamrealI generate a string: aaabbcccdd. Send it to the user via PM. Store the encrypted version so I never have aaabbcccdd again. When I get aaabbcccdd over https, I re-encrypt it and check.
  49. blueyes, so you still store the token
  50. blueyou just encrypt it
  51. bluewhich is... I guess fine
  52. dreamrealyes, and I COULD accept external tokens where you say "set it to this explicitly" but... eh
  53. blueI don't really see the point, but sure
  54. dreamrealgive me a minute, workflow oversight
  55. bluehonestly I have no idea *how* that can be even work. github sends you a hash signature using the token with each payload. how can you recalculate the signature if you don't have the original token?
  56. bluetypically you take the payload + token, calculate a signature, then compare it to what gh sent
  57. bluebut if you encrypted the token, that's not gonna work
  58. bluedreamreal: https://github.com/terrablue/gpbot/blob/master/routes/index.js#L25-L27
  59. blueyou need to replicate *that* logic
  60. dreamrealIt's already there
  61. bluewell, that can't work unless you have the plain secret
  62. bluemaybe you decrypt it at runtime, but I don't see the point in the indirection, I'd just have it in memory
  63. dreamrealYes, I have to decrypt it, it's fine
  64. dreamrealbut the code's already written, rabbit's dead, no win in changing it
  65. bluebut then you need to store a decryption key...
  66. dreamrealI have one, I configure it externally
  67. bluewhat did you gain in trading a secret for a decryption key?
  68. dreamrealNot a lot, I was doing something dumb and re-using a key that was supplied elsewhere
  69. blueok. well anyway, it doesn't really matter who of us supplies the secret. but if YOU do, I need the plaintext one obviously
  70. dreamrealyes, you'd get it
  71. dreamreallike I said, it generates a key, sends to the user, then stores something different
  72. blueyes, that's an indirection I wouldn't have chosen in my code, but if you want to do it like that, that's fine
  73. * nevet joined #primate
  74. * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
  75. dreamrealgithub webhook primate-run/primate
  76. nevetWebhook enabled for primate-run/primate. Configure GitHub to POST to https://api.bytecode.news/webhooks/github with the provided secret.
  77. dreamrealgithub subscribe primate-run/primate
  78. nevetSubscribed to primate-run/primate
  79. dreamrealgithub subscriptions
  80. nevetprimate-run/primate
  81. bluewould be nice if nevet output the ping
  82. dreamrealDid it report success on the github console?
  83. blueyes
  84. dreamrealThen it worked. And the console will show pings, for what it's worth.
  85. blueI meant here. that's a wait to test full stack working without access to the console
  86. bluethat's a way*
  87. dreamrealWell, the thing is, ORDINARILY this is a bit of an odd path
  88. bluehow so?
  89. dreamrealadmins are the only ones who can subscribe, so ordinarily the admin is the one who A) has access and B) sets the token
  90. dreamrealso *I* as the admin would be the one to validate the ping, not the channel
  91. blueyes but *I* don't have access to the console
  92. dreamrealI know
  93. dreamreallike I said, odd path
  94. blueit's only an odd path if you don't intend for nevet to relay those notifications for non-admins
  95. * dreamreal sighs. But like I said: ODD PATH. You create a subscription for webhooks... THEN you add what channels watch for them.
  96. dreamrealWithout the channels, nevet doesn't know where to say "hey, ping succeeded!"
  97. dreamrealit's literally an internal event, and it's internally published
  98. bluethat's a weird flow to me. if you do !github webhook primate-run/primate in #primate, I'd think that's intended to be used here
  99. dreamrealI get it
  100. dreamrealbut the flow is not that way: I can create subscriptions ANYWHERE, and channel subscriptions are separate
  101. dreamrealsame for RSS
  102. dreamreal(in fact, they use the same codebase and design)
  103. bluenonetheless, you can *still* map the ping event, and it works just like every other event: it outputs once it has channels
  104. * nevet joined #primate
  105. * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
  106. dreamrealcrikey
  107. dreamrealversion
  108. nevetnevet 1.0 | 84619bb (github-webhook-fixes) | Built 2026-03-08 09:14:24 EDT
  109. dreamrealSo try the emulated thing, let's see what it does
  110. bluewell it still says successful
  111. bluefor the redelivery
  112. dreamrealyep.
  113. blueyes? what changed?
  114. blueI see no message
  115. dreamrealI saw it
  116. blue...
  117. dreamrealAgain, pings are not echoed to subscriptions
  118. bluebut why?
  119. dreamrealBecause I don't trust them yet. I may turn it on eventually. But I don't know github's ping policy yet.
  120. bluethere's no ping policy. it's done when you create a webhook, and when you change it iirc. I had the ping event mapped on gpbot, I'd have noticed it otherwise
  121. blueit's literally a way to test the full stack
  122. bluestarting to get tired of claude here
  123. blueit's regularly amnesic, forgetting things discussed like 3 minutes ago
  124. dreamrealhttps://github.com/jottinger/bytecode.news/issues/196
  125. nevetgithub: ping should propagate to subscribed channels · Issue #196 · jottinger/bytecode.news
  126. * nevet joined #primate
  127. * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc
  128. dreamrealversion
  129. nevetnevet 1.0 | 22fb3be (main) | Built 2026-03-08 09:17:40 EDT
  130. phalethblue: thanks for the readme, quite useful
  131. blueyw phaleth
  132. blue`Happy DOM has a long history of incomplete default form-submission behavior`
  133. bluethis industry is full of idiots
  134. bluetime for @rcompat/dom
  135. bluephaleth: https://gitea.repopack.app/repopack/website/commit/3960e135869ad6930e25dbde1916c481b2e6e8e5
  136. bluecan now create networks; duplicates are recognised and surfaced as form errors
  137. bluethis has been interesting info for the future generation of openapi clients
  138. bluein future style, this will be:
  139. blueawait client.createNetwork({ name }).conflict({ field: "name", message: "A network with this name already exists" });
  140. blue(409 is CONFLICT)
  141. bluethat means HTTP status codes will be surfaced on the generated openapi client as methods
  142. blueso you can literally do .conflict().forbidden().notFound()
  143. bluethe default return value is the OK (2xx) case
  144. phalethnice, I've made a PR there just to test, it now has a merge conflict, very cool
  145. bluebtw, I've noticed gitea is much, MUCH faster than github
  146. bluelike orders of magnitude faster
  147. bluemonopolies SUCH!
  148. blueSUCK*
  149. phalethyup, I've noticed gitea has some frontend devs that continuously put effort into modularizing the frontend so it remains fast after features get added
  150. bluewell, of course we're not gonna use gitea but repopack itself, but it's still so freshing to see that it doesn't HAVE to be this way
  151. blueor refreshing, rather
  152. phalethyeah, I kinda refuse to go back to github already
  153. blueya, github can go to hell
  154. bluephaleth: https://gitea.repopack.app/repopack/website/commit/68422c1c06103eeea93e91c2df3f48425b7e6487
  155. blueI really need to make it easily possible to add woff2 files into your file, it's ridiculous to need a module for that
  156. blueor maybe woff2 being parsed as file by esbuild should just be the default
  157. blues/into your file/into your app/
  158. phalethI remember webpack can take in static assets and put them where needed, also with the option to not add content hash to the filename
  159. phalethmaybe esbuild can do that too
  160. phalethlooks like this copy loader can be used https://esbuild.github.io/content-types/#copy
  161. blueyes, essentially it's the file loader
  162. bluethe file loader causes esbuild to base64 the file and include it in the bundle
  163. bluehttps://gitea.repopack.app/repopack/website/commit/68422c1c06103eeea93e91c2df3f48425b7e6487#diff-4abca52bbb0fae9100b8e3e180ca4e8a39cc38a5
  164. bluebut for woff2, this should be the standard behaviour. unless you're like a platform that offering woff2 for download, I don't see how you'd ever want different behaviour
  165. blueand even if you are a platform, you wouldn't place the woff2 files for download inside static, but would have them downloaded dynamically
  166. blueand if you DO want a different behaviour, you write a primate module
  167. bluephaleth: did you pull down the nice coloured changes?
  168. blueit's just adding some font and a bit of colours so it doesn't look 100% lame as before
  169. phalethnot yet, I'm gonna try to find some podman REST API reference
  170. phalethafk
  171. bluephaleth: https://docs.podman.io/en/latest/_static/api.html?version=latest
  172. nevetReference
  173. blueprogrammatic: https://storage.googleapis.com/libpod-master-releases/swagger-latest.yaml
  174. blueunfortunately it's swagger 2.0 which the primate openapi generator won't support
  175. bluebut I believe it's possible to convert it to openapi 3.0
  176. blueand then I'll add it to the primate/openapi repo so it's av at openapi.primate.run
  177. blue /libpod/networks/create:
  178. blue post:
  179. blue description: Create a new network configuration
  180. blue operationId: NetworkCreateLibpod
  181. bluethis operationId is totally dumb
  182. bluedreamreal: why is everyone so dumb in this industry all the time
  183. bluewhat am I supposed to do with "NetworkCreateLibpod"???
  184. bluethe operationId is SUPPOSED to be "CreateNetwork"
  185. blueI suppose that in the swagger converter, I can add a strategy: "drop -Libpod, switch order"
  186. blueok, I see what they did
  187. blueso we also have
  188. blue /libpod/pods/{name}/exists:
  189. blue get:
  190. blue description: Check if a pod exists by name or ID
  191. blue operationId: PodExistsLibpod
  192. bluecan't really deal with that. so we'll be dropping -Libpod and generating as is
  193. blueclient.podExists is acceptable. client.networkCreate sounds dumb but ok
  194. bluecould've put a non-trivial effort into this though, redhat
  195. blueI sure do hope the nevet operationIds are SLIGHTLY better
  196. bluephaleth: dreamreal: https://github.com/primate-run/openapi/commit/00d9e4e77d2dadc948da6541bbab914eabc817cb
  197. nevetadd support for swagger to openapi conversion and stripping operation… · primate-run/openapi@00d9e4e
  198. bluephaleth: https://github.com/primate-run/openapi/commit/7d8c850f277f4d644e6b002e26b1791ef5e8f4b6
  199. nevetadd podman/libpod · primate-run/openapi@7d8c850
  200. bluecan we redeploy the openapi machine?
  201. bluemaybe as a podman container already
  202. bluenice, you created a user podman
  203. dreamrealblue: I gotta get you to learn how to use !article :D
  204. bluewth is THAT, dreamreal
  205. dreamrealIt's a way to get nevet to build a draft article online
  206. dreamrealyou say "!article title" and can add content blocks with "!content this is some content here", add channel context with "!logs 5m" (include the last five minutes for context), and signal done with !done (it'll time out on its own if you don't, after five minutes of no interaction) - and bam! draft article on bytecode.news
  207. dreamrealthe diataxis article was written that way
  208. bluearticle Primate
  209. nevetIdea session started: "Primate". Use 'content <text>' to add body paragraphs, 'done' to save, or 'cancel' to discard.
  210. bluecontext Primate is the universal web framework -- the best tool to build websites with
  211. nevetok, blue: updated context primate.
  212. bluedone
  213. nevetIdea saved as draft: "Primate" (0 content blocks).
  214. blueoh, I wrote context, my bad
  215. bluewell, at least it did something
  216. dreamrealIt did indeed.
  217. blueI have no idea how to edit it
  218. dreamrealYOU don't. *I* would have to.
  219. bluehahaha
  220. dreamrealThe !article thing submits DRAFTS. If you're not authenticated, it submits as anonymous.
  221. bluewhy can't I edit drafts though, if submitted anonymously?
  222. dreamrealThis is entirelly intentional.
  223. bluealso, wth is THIS
  224. bluehttps://bytecode.news/factoids/context%20primate
  225. nevetNevet - Reference UI
  226. dreamrealWhat about it?
  227. blueso ! randomly creates factoids?
  228. bluethat seems like a bug
  229. dreamrealNo, you said "context primate" and "is" and some content.
  230. dreamrealThat's working as designed. You created a factoid.
  231. blueoh man, that's CRAZY
  232. dreamrealif you'd used "!content primate is..." the internal routing would be different.
  233. bluethat should be like +factoid or something
  234. dreamrealBut "context" is not a keyword for the article system.
  235. dreamreal"is" is pretty human.
  236. blueyeah but you do realise that having both context words and pattrens like !x is y, is confusing, right?
  237. bluethat effectively means that a typo can have wholly unintended consequences
  238. dreamrealSure. And compare that against the ACTUAL formal syntax: !foo=bar
  239. dreamrealyep, and the consequences cost very very close to nothing so I don't care
  240. dreamrealjust like karma
  241. blueso the making of a good system, that a typo does NOT cause wholly unintended behaviour
  242. bluebut rather results in the system telling you made a typo
  243. bluesomething like: "!context does not exist as a operation"
  244. dreamrealin which case you have a formal grammar and not something easy for humans to use.
  245. blueand even nicer: "did you mean `!content`?"
  246. dreamrealSo: no.
  247. dreamrealHow would teh system know you might have meant "content?"
  248. dreamrealThe system has no unified grammar. This is intentional.
  249. bluebecause it has a very small levenshtein distance
  250. bluestop making excuses, this is totally normal, git has it
  251. * dreamreal sighs
  252. dreamrealno. Because that means the system needs to know a shitload more about the operations than it should. It doesn't KNOW there are operations.
  253. dreamrealActually, that's not true: the system DOES know there are operations... like, six or seven of them. Out of the close to 80 now.
  254. bluesigh, fine, your system, you know BEST, me typoing content into context is just a FACT of life and should result in garbage in the system
  255. dreamrealYep! And it does! And again, the actual cost is 0
  256. dreamrealit's fine, it's also trivial to correct
  257. dreamrealcontext primate.forget
  258. nevetok, forgot context primate.
  259. dreamrealOH NO SO MUCH SWEATING
  260. blueoh man, nevermind, I'll just shut up, I'm tired of this uphill battle
  261. blueyou just do whatever you think is best and I'll stop making suggestions
  262. dreamrealThe bot is messy: that's a fact of life. The actual OPERATION usage is absolutely linear; if we had an article *http operation* it can ensure types and make sure such things are unambiguous. Over IRC? not so much.
  263. dreamrealWe could even do that for slack and discord, if I supported actual actions.
  264. blueit's really not messy to have a clear way to edit factoids, say with `+factoid title | text` to add, `~factoid title | text` to edit, and `-factoid title` to delete
  265. blueinstead of using a pattern nobody understands like x is y
  266. dreamrealGotta get lunch, later
  267. blueciao
  268. bluephaleth: should we move primate/openapi to gitea?
  269. blueI'm honestly thinking of keeping just the high profile projects, so primate-run/primate, on GH. all the rest I think can move away
  270. phalethblue: if you don't want that to be open why not
  271. phalethsame for superarch
  272. blueoh it will be open, in the future, when it's available under repopack.com/primate/primate
  273. phalethshould I redeploy primate/openapi?
  274. bluesorry, repopack.com/primate/openapi
  275. blueyes
  276. phalethok
  277. bluedid you pull the latest rp colours? :P
  278. bluehm
  279. blueshould I call the org primate or primate-run on gitea
  280. blueI guess it doesn't matter much
  281. phalethcall it primate
  282. bluek
  283. phalethopenapi is updated
  284. phalethactually, no it isn't, forgot to download from git
  285. phalethgithub*
  286. bluephaleth: https://gitea.repopack.app/primate/openapi
  287. blueI'm gonna delete the repo on gh
  288. bluebtw I got a ton of template repos on gh for primate
  289. blueI'm sure we can do this better with repopack
  290. bluetell me when you've moved this to gitea
  291. blueand I can delete
  292. blueif you need to make it easier for yourself, add a pubkey, that's what I did
  293. blueI have a pubkey blue@vps in my gitea
  294. blueso I don't need to use weird bearer tokens
  295. phalethyou can delete from github all you want
  296. bluedone
  297. phalethhttps://openapi.primate.run/manifest.json
  298. blueNICE, libpod is there!
  299. bluedreamreal: I FIXED IT!
  300. bluehttps://openapi.primate.run/spec/podman/libpod.json
  301. bluenow we can have a nice `client.networkCreate`
  302. bluephaleth: if you look at the NetworkCreate operation, you see it exposes four responses
  303. blueso the generated openapi client will have:
  304. phalethno clue what I'm looking at in that json, will have to look into that later
  305. phalethgotta go now, see ya
  306. blueclient.networkCreate(/* params */).badRequest(/* handler */).conflict(/* handler */)
  307. blueciao
  308. * nevet joined #primate
  309. * blue!~blue@user/blue changed the topic to: https://primate.run | this channel is mirrored to the Primate discord, channel #irc