Chat Logs

  1. phalethnice, that tiny nginx:alpine-slim container is capable of proxying to HTTP/2 site https://theanswerisc.repopack.app/
  2. nevetThe Answer Is C
  3. phalethactually, I don't know if nginx itself supports proxying to HTTP/2, it's prolly defaulting to HTTP/1.1, but anyway
  4. phaleththe traffic goes like this: http client <-> contabo VPS <-> haproxy nspawn container <-> root nspawn container <-> rootless podman nginx container <-> fly.io cloud deployment https://github.com/terrablue/theanswerisc/blob/master/.github/workflows/deployment.yml
  5. bluephaleth: hi
  6. blueI added a readme to the repopack repo
  7. bluephaleth: so ideally we should have: http client <-> contabo VPS <-> haproxy podman container <-> rootless podman nginx container <-> podman machine running the blog
  8. blueor maybe we don't even need that interim podman thingy
  9. blueso one nice thingy the podman API saves us is manual network management
  10. blueyou can just do POST networks and it allocates by itself. you can provide a name, which is great, because we'll use that to delete networks when apps are deleted
  11. bluephaleth: https://images4.imagebam.com/d8/24/e6/ME1B5M64_o.png
  12. blueso when you create an app, we add an entry to the app table in postgres, and we can use the id to refer to the network (or generate a network_id UUID column)
  13. bluephaleth: that rootless podman nginx container, it's running under your user, right?
  14. bluebtw the podman API is nice. this is what you get if you try to create a network with an existing name:
  15. blueError: HTTP 409: {"cause":"network already exists","message":"network name testtest already used: network already exists","response":409}
  16. phalethblue: hi
  17. phalethyeah, all podman containers and I think haproxy can be installed on arch host directly
  18. phalethtrue, everything can be named and names are unique
  19. bluesounds good
  20. phalethmoved haproxy to archlinux host
  21. phalethnice, all browsers finally support https://developer.mozilla.org/en-US/docs/Web/API/Trusted_Types_API
  22. nevetTrusted Types API - Web APIs | MDN
  23. bluedreamreal: can you now configure nevet for the primate repo?
  24. dreamrealI can but you're going to have to set up the webhook: I'll DM you the token on discord.
  25. dreamrealgithub webhook primate-run/primate
  26. nevetError: No registered repository found for primate-run/primate
  27. blueshouldn't *I* send YOU the token?
  28. dreamrealGah, another bug - the webhook mutates the existing record.
  29. dreamrealEw, no
  30. dreamrealthat means I'm storing the token
  31. dreamrealnevet generates it.
  32. blueyes? you need to store the token anyway to validate the hook
  33. dreamrealI don't, though: it gets the token from outside and encrypts it to match
  34. bluehttps://docs.github.com/en/webhooks/using-webhooks/validating-webhook-deliveries
  35. bluethat's literally what the github docs say
  36. blueunless I missed something, I don't get how you can otherwise validate it
  37. blue"After creating a secret token, you should store it in a secure location that your server can access."
  38. bluetypically, you put that in an env variable
  39. blueor if you wanna do it programmatically, something like a keyserver
  40. dreamrealI generate a string: aaabbcccdd. Send it to the user via PM. Store the encrypted version so I never have aaabbcccdd again. When I get aaabbcccdd over https, I re-encrypt it and check.
  41. blueyes, so you still store the token
  42. blueyou just encrypt it
  43. bluewhich is... I guess fine
  44. dreamrealyes, and I COULD accept external tokens where you say "set it to this explicitly" but... eh
  45. blueI don't really see the point, but sure
  46. dreamrealgive me a minute, workflow oversight
  47. bluehonestly I have no idea *how* that can be even work. github sends you a hash signature using the token with each payload. how can you recalculate the signature if you don't have the original token?
  48. bluetypically you take the payload + token, calculate a signature, then compare it to what gh sent
  49. bluebut if you encrypted the token, that's not gonna work
  50. bluedreamreal: https://github.com/terrablue/gpbot/blob/master/routes/index.js#L25-L27
  51. blueyou need to replicate *that* logic
  52. dreamrealIt's already there
  53. bluewell, that can't work unless you have the plain secret
  54. bluemaybe you decrypt it at runtime, but I don't see the point in the indirection, I'd just have it in memory
  55. dreamrealYes, I have to decrypt it, it's fine
  56. dreamrealbut the code's already written, rabbit's dead, no win in changing it
  57. bluebut then you need to store a decryption key...
  58. dreamrealI have one, I configure it externally
  59. bluewhat did you gain in trading a secret for a decryption key?
  60. dreamrealNot a lot, I was doing something dumb and re-using a key that was supplied elsewhere
  61. blueok. well anyway, it doesn't really matter who of us supplies the secret. but if YOU do, I need the plaintext one obviously
  62. dreamrealyes, you'd get it
  63. dreamreallike I said, it generates a key, sends to the user, then stores something different
  64. blueyes, that's an indirection I wouldn't have chosen in my code, but if you want to do it like that, that's fine
  65. dreamrealgithub webhook primate-run/primate
  66. nevetWebhook enabled for primate-run/primate. Configure GitHub to POST to https://api.bytecode.news/webhooks/github with the provided secret.
  67. dreamrealgithub subscribe primate-run/primate
  68. nevetSubscribed to primate-run/primate
  69. dreamrealgithub subscriptions
  70. nevetprimate-run/primate
  71. bluewould be nice if nevet output the ping
  72. dreamrealDid it report success on the github console?
  73. blueyes
  74. dreamrealThen it worked. And the console will show pings, for what it's worth.
  75. blueI meant here. that's a wait to test full stack working without access to the console
  76. bluethat's a way*
  77. dreamrealWell, the thing is, ORDINARILY this is a bit of an odd path
  78. bluehow so?
  79. dreamrealadmins are the only ones who can subscribe, so ordinarily the admin is the one who A) has access and B) sets the token
  80. dreamrealso *I* as the admin would be the one to validate the ping, not the channel
  81. blueyes but *I* don't have access to the console
  82. dreamrealI know
  83. dreamreallike I said, odd path
  84. blueit's only an odd path if you don't intend for nevet to relay those notifications for non-admins
  85. * dreamreal sighs. But like I said: ODD PATH. You create a subscription for webhooks... THEN you add what channels watch for them.
  86. dreamrealWithout the channels, nevet doesn't know where to say "hey, ping succeeded!"
  87. dreamrealit's literally an internal event, and it's internally published
  88. bluethat's a weird flow to me. if you do !github webhook primate-run/primate in #primate, I'd think that's intended to be used here
  89. dreamrealI get it
  90. dreamrealbut the flow is not that way: I can create subscriptions ANYWHERE, and channel subscriptions are separate
  91. dreamrealsame for RSS
  92. dreamreal(in fact, they use the same codebase and design)
  93. bluenonetheless, you can *still* map the ping event, and it works just like every other event: it outputs once it has channels
  94. dreamrealcrikey
  95. dreamrealversion
  96. nevetnevet 1.0 | 84619bb (github-webhook-fixes) | Built 2026-03-08 09:14:24 EDT
  97. dreamrealSo try the emulated thing, let's see what it does
  98. bluewell it still says successful
  99. bluefor the redelivery
  100. dreamrealyep.
  101. blueyes? what changed?
  102. blueI see no message
  103. dreamrealI saw it
  104. blue...
  105. dreamrealAgain, pings are not echoed to subscriptions
  106. bluebut why?
  107. dreamrealBecause I don't trust them yet. I may turn it on eventually. But I don't know github's ping policy yet.
  108. bluethere's no ping policy. it's done when you create a webhook, and when you change it iirc. I had the ping event mapped on gpbot, I'd have noticed it otherwise
  109. blueit's literally a way to test the full stack
  110. bluestarting to get tired of claude here
  111. blueit's regularly amnesic, forgetting things discussed like 3 minutes ago
  112. dreamrealhttps://github.com/jottinger/bytecode.news/issues/196
  113. nevetgithub: ping should propagate to subscribed channels · Issue #196 · jottinger/bytecode.news
  114. dreamrealversion
  115. nevetnevet 1.0 | 22fb3be (main) | Built 2026-03-08 09:17:40 EDT
  116. phalethblue: thanks for the readme, quite useful
  117. blueyw phaleth
  118. blue`Happy DOM has a long history of incomplete default form-submission behavior`
  119. bluethis industry is full of idiots
  120. bluetime for @rcompat/dom
  121. bluephaleth: https://gitea.repopack.app/repopack/website/commit/3960e135869ad6930e25dbde1916c481b2e6e8e5
  122. bluecan now create networks; duplicates are recognised and surfaced as form errors
  123. bluethis has been interesting info for the future generation of openapi clients
  124. bluein future style, this will be:
  125. blueawait client.createNetwork({ name }).conflict({ field: "name", message: "A network with this name already exists" });
  126. blue(409 is CONFLICT)
  127. bluethat means HTTP status codes will be surfaced on the generated openapi client as methods
  128. blueso you can literally do .conflict().forbidden().notFound()
  129. bluethe default return value is the OK (2xx) case
  130. phalethnice, I've made a PR there just to test, it now has a merge conflict, very cool
  131. bluebtw, I've noticed gitea is much, MUCH faster than github
  132. bluelike orders of magnitude faster
  133. bluemonopolies SUCH!
  134. blueSUCK*
  135. phalethyup, I've noticed gitea has some frontend devs that continuously put effort into modularizing the frontend so it remains fast after features get added
  136. bluewell, of course we're not gonna use gitea but repopack itself, but it's still so freshing to see that it doesn't HAVE to be this way
  137. blueor refreshing, rather
  138. phalethyeah, I kinda refuse to go back to github already
  139. blueya, github can go to hell
  140. bluephaleth: https://gitea.repopack.app/repopack/website/commit/68422c1c06103eeea93e91c2df3f48425b7e6487
  141. blueI really need to make it easily possible to add woff2 files into your file, it's ridiculous to need a module for that
  142. blueor maybe woff2 being parsed as file by esbuild should just be the default
  143. blues/into your file/into your app/
  144. phalethI remember webpack can take in static assets and put them where needed, also with the option to not add content hash to the filename
  145. phalethmaybe esbuild can do that too
  146. phalethlooks like this copy loader can be used https://esbuild.github.io/content-types/#copy
  147. blueyes, essentially it's the file loader
  148. bluethe file loader causes esbuild to base64 the file and include it in the bundle
  149. bluehttps://gitea.repopack.app/repopack/website/commit/68422c1c06103eeea93e91c2df3f48425b7e6487#diff-4abca52bbb0fae9100b8e3e180ca4e8a39cc38a5
  150. bluebut for woff2, this should be the standard behaviour. unless you're like a platform that offering woff2 for download, I don't see how you'd ever want different behaviour
  151. blueand even if you are a platform, you wouldn't place the woff2 files for download inside static, but would have them downloaded dynamically
  152. blueand if you DO want a different behaviour, you write a primate module
  153. bluephaleth: did you pull down the nice coloured changes?
  154. blueit's just adding some font and a bit of colours so it doesn't look 100% lame as before
  155. phalethnot yet, I'm gonna try to find some podman REST API reference
  156. phalethafk
  157. bluephaleth: https://docs.podman.io/en/latest/_static/api.html?version=latest
  158. nevetReference
  159. blueprogrammatic: https://storage.googleapis.com/libpod-master-releases/swagger-latest.yaml
  160. blueunfortunately it's swagger 2.0 which the primate openapi generator won't support
  161. bluebut I believe it's possible to convert it to openapi 3.0
  162. blueand then I'll add it to the primate/openapi repo so it's av at openapi.primate.run
  163. blue /libpod/networks/create:
  164. blue post:
  165. blue description: Create a new network configuration
  166. blue operationId: NetworkCreateLibpod
  167. bluethis operationId is totally dumb
  168. bluedreamreal: why is everyone so dumb in this industry all the time
  169. bluewhat am I supposed to do with "NetworkCreateLibpod"???
  170. bluethe operationId is SUPPOSED to be "CreateNetwork"
  171. blueI suppose that in the swagger converter, I can add a strategy: "drop -Libpod, switch order"
  172. blueok, I see what they did
  173. blueso we also have
  174. blue /libpod/pods/{name}/exists:
  175. blue get:
  176. blue description: Check if a pod exists by name or ID
  177. blue operationId: PodExistsLibpod
  178. bluecan't really deal with that. so we'll be dropping -Libpod and generating as is
  179. blueclient.podExists is acceptable. client.networkCreate sounds dumb but ok
  180. bluecould've put a non-trivial effort into this though, redhat
  181. blueI sure do hope the nevet operationIds are SLIGHTLY better
  182. bluephaleth: dreamreal: https://github.com/primate-run/openapi/commit/00d9e4e77d2dadc948da6541bbab914eabc817cb
  183. nevetadd support for swagger to openapi conversion and stripping operation… · primate-run/openapi@00d9e4e
  184. bluephaleth: https://github.com/primate-run/openapi/commit/7d8c850f277f4d644e6b002e26b1791ef5e8f4b6
  185. nevetadd podman/libpod · primate-run/openapi@7d8c850
  186. bluecan we redeploy the openapi machine?
  187. bluemaybe as a podman container already
  188. bluenice, you created a user podman
  189. dreamrealblue: I gotta get you to learn how to use !article :D
  190. bluewth is THAT, dreamreal
  191. dreamrealIt's a way to get nevet to build a draft article online
  192. dreamrealyou say "!article title" and can add content blocks with "!content this is some content here", add channel context with "!logs 5m" (include the last five minutes for context), and signal done with !done (it'll time out on its own if you don't, after five minutes of no interaction) - and bam! draft article on bytecode.news
  193. dreamrealthe diataxis article was written that way
  194. bluearticle Primate
  195. nevetIdea session started: "Primate". Use 'content <text>' to add body paragraphs, 'done' to save, or 'cancel' to discard.
  196. bluecontext Primate is the universal web framework -- the best tool to build websites with
  197. nevetok, blue: updated context primate.
  198. bluedone
  199. nevetIdea saved as draft: "Primate" (0 content blocks).
  200. blueoh, I wrote context, my bad
  201. bluewell, at least it did something
  202. dreamrealIt did indeed.
  203. blueI have no idea how to edit it
  204. dreamrealYOU don't. *I* would have to.
  205. bluehahaha
  206. dreamrealThe !article thing submits DRAFTS. If you're not authenticated, it submits as anonymous.
  207. bluewhy can't I edit drafts though, if submitted anonymously?
  208. dreamrealThis is entirelly intentional.
  209. bluealso, wth is THIS
  210. bluehttps://bytecode.news/factoids/context%20primate
  211. nevetNevet - Reference UI
  212. dreamrealWhat about it?
  213. blueso ! randomly creates factoids?
  214. bluethat seems like a bug
  215. dreamrealNo, you said "context primate" and "is" and some content.
  216. dreamrealThat's working as designed. You created a factoid.
  217. blueoh man, that's CRAZY
  218. dreamrealif you'd used "!content primate is..." the internal routing would be different.
  219. bluethat should be like +factoid or something
  220. dreamrealBut "context" is not a keyword for the article system.
  221. dreamreal"is" is pretty human.
  222. blueyeah but you do realise that having both context words and pattrens like !x is y, is confusing, right?
  223. bluethat effectively means that a typo can have wholly unintended consequences
  224. dreamrealSure. And compare that against the ACTUAL formal syntax: !foo=bar
  225. dreamrealyep, and the consequences cost very very close to nothing so I don't care
  226. dreamrealjust like karma
  227. blueso the making of a good system, that a typo does NOT cause wholly unintended behaviour
  228. bluebut rather results in the system telling you made a typo
  229. bluesomething like: "!context does not exist as a operation"
  230. dreamrealin which case you have a formal grammar and not something easy for humans to use.
  231. blueand even nicer: "did you mean `!content`?"
  232. dreamrealSo: no.
  233. dreamrealHow would teh system know you might have meant "content?"
  234. dreamrealThe system has no unified grammar. This is intentional.
  235. bluebecause it has a very small levenshtein distance
  236. bluestop making excuses, this is totally normal, git has it
  237. * dreamreal sighs
  238. dreamrealno. Because that means the system needs to know a shitload more about the operations than it should. It doesn't KNOW there are operations.
  239. dreamrealActually, that's not true: the system DOES know there are operations... like, six or seven of them. Out of the close to 80 now.
  240. bluesigh, fine, your system, you know BEST, me typoing content into context is just a FACT of life and should result in garbage in the system
  241. dreamrealYep! And it does! And again, the actual cost is 0
  242. dreamrealit's fine, it's also trivial to correct
  243. dreamrealcontext primate.forget
  244. nevetok, forgot context primate.
  245. dreamrealOH NO SO MUCH SWEATING
  246. blueoh man, nevermind, I'll just shut up, I'm tired of this uphill battle
  247. blueyou just do whatever you think is best and I'll stop making suggestions
  248. dreamrealThe bot is messy: that's a fact of life. The actual OPERATION usage is absolutely linear; if we had an article *http operation* it can ensure types and make sure such things are unambiguous. Over IRC? not so much.
  249. dreamrealWe could even do that for slack and discord, if I supported actual actions.
  250. blueit's really not messy to have a clear way to edit factoids, say with `+factoid title | text` to add, `~factoid title | text` to edit, and `-factoid title` to delete
  251. blueinstead of using a pattern nobody understands like x is y
  252. dreamrealGotta get lunch, later
  253. blueciao
  254. bluephaleth: should we move primate/openapi to gitea?
  255. blueI'm honestly thinking of keeping just the high profile projects, so primate-run/primate, on GH. all the rest I think can move away
  256. phalethblue: if you don't want that to be open why not
  257. phalethsame for superarch
  258. blueoh it will be open, in the future, when it's available under repopack.com/primate/primate
  259. phalethshould I redeploy primate/openapi?
  260. bluesorry, repopack.com/primate/openapi
  261. blueyes
  262. phalethok
  263. bluedid you pull the latest rp colours? :P
  264. bluehm
  265. blueshould I call the org primate or primate-run on gitea
  266. blueI guess it doesn't matter much
  267. phalethcall it primate
  268. bluek
  269. phalethopenapi is updated
  270. phalethactually, no it isn't, forgot to download from git
  271. phalethgithub*
  272. bluephaleth: https://gitea.repopack.app/primate/openapi
  273. blueI'm gonna delete the repo on gh
  274. bluebtw I got a ton of template repos on gh for primate
  275. blueI'm sure we can do this better with repopack
  276. bluetell me when you've moved this to gitea
  277. blueand I can delete
  278. blueif you need to make it easier for yourself, add a pubkey, that's what I did
  279. blueI have a pubkey blue@vps in my gitea
  280. blueso I don't need to use weird bearer tokens
  281. phalethyou can delete from github all you want
  282. bluedone
  283. phalethhttps://openapi.primate.run/manifest.json
  284. blueNICE, libpod is there!
  285. bluedreamreal: I FIXED IT!
  286. bluehttps://openapi.primate.run/spec/podman/libpod.json
  287. bluenow we can have a nice `client.networkCreate`
  288. bluephaleth: if you look at the NetworkCreate operation, you see it exposes four responses
  289. blueso the generated openapi client will have:
  290. phalethno clue what I'm looking at in that json, will have to look into that later
  291. phalethgotta go now, see ya
  292. blueclient.networkCreate(/* params */).badRequest(/* handler */).conflict(/* handler */)
  293. blueciao