Live data from Hacker News

Show HN: Nginx Image with HTTP/3 (QUIC), TLS1.3 with 0-RTT, Brotli

news.ycombinator.com

31–40 of 69 posts

Re: Show HN: Nginx Image with HTTP/3 (QUIC), TLS1.3 with 0-RTT, Brotli

#31
post #12
post #11

Earlier quoted context omitted.

I'll explain it, if you'd like. Correct, no one is making an argument against what you said, because everyone understands that point. For most people, it doesn't need to be said. No one is ripping out production infrastructure and replacing it with this image. There's no comment anywhere suggesting it. What you're doing is called "preaching to the choir". You're trying to be a contrarian to show everyone how smart an…

Thanks for the labels. Appreciated how you put me in my rightful place. Sorry if I'm being such a joy killer. I guess I've been witness to too many failures for not feeling to call this out before someone gets burned. Oh right, but no one needs to be told to be careful, right... No one is here to learn anything, as we all already know everything. Makes you wonder what's the point of showing something new in the first…

> Sorry if I'm being such a joy killer. I guess I've been witness to too many failures for not feeling to call this out before someone gets burned.

But you didn't do it in a constructive way. You did it in a condescending way to make yourself appear better. Yolo, amirite? You could have had a constructive comment, explaining the level of support of various technologies, their maturity within nginx, etc. All of that would have been beneficial, discussing real world implications of things.

> Oh right, but no one needs to be told to be careful, right... No one is here to learn anything, as we all already know everything. Makes you wonder what's the point of showing something new in the first place.

No, some people need to be told to be careful. You didn't do that, though. You jerked yourself off. Likewise, the point of showing something new is to get real feedback. Again, which you didn't provide.

> And please spare me the "no-one suggested to replace prod infra with this". Does the readme say anywhere "experimental, not for prod use"?

You're the reason the iron needs to say "Do not iron while wearing clothes"

Re: Show HN: Nginx Image with HTTP/3 (QUIC), TLS1.3 with 0-RTT, Brotli

#32
post #12
post #11

Earlier quoted context omitted.

I'll explain it, if you'd like. Correct, no one is making an argument against what you said, because everyone understands that point. For most people, it doesn't need to be said. No one is ripping out production infrastructure and replacing it with this image. There's no comment anywhere suggesting it. What you're doing is called "preaching to the choir". You're trying to be a contrarian to show everyone how smart an…

Thanks for the labels. Appreciated how you put me in my rightful place. Sorry if I'm being such a joy killer. I guess I've been witness to too many failures for not feeling to call this out before someone gets burned. Oh right, but no one needs to be told to be careful, right... No one is here to learn anything, as we all already know everything. Makes you wonder what's the point of showing something new in the first…

> Does the readme say anywhere "experimental, not for prod use"?

"Built on the edge, for the edge"

It's pretty obvious it's an experiment.

It's reasonable of the author to assume anyone running serious production infrastructure will be prudent enough to not just blithely go ahead and implement this.

Even if it isn't, you could calmly suggest the author add more warnings to the readme. A project like this is no place for that kind of rage.

> I love the unexplained downvotes

Nobody has to explain their downvotes (and it makes for boring reading when people do). But angrily trashing someone's Show HN experiment is long established as being valid grounds for downvoting.

Re: Show HN: Nginx Image with HTTP/3 (QUIC), TLS1.3 with 0-RTT, Brotli

#34

You may find my NGINX image[1] interesting. There's some features you could easily add to yours in order to make it a better overall image. [1] https://github.com/ricardbejarano/nginx

I will take a look at it. Thanks for the feedback.

Re: Show HN: Nginx Image with HTTP/3 (QUIC), TLS1.3 with 0-RTT, Brotli

#35
post #18

I'm just curious, is there a reason not to use a multi-stage docker build here? There are a ton of build steps, and it seems pretty tedious to have to start from scratch every time while developing the image without any layer caching.

While developing an image, I use layers as much as possible. But usually, when the image is finished, I prefer to minimize the number of layers, it saves some (or little) storage (I think it will not > 10%).

Re: Show HN: Nginx Image with HTTP/3 (QUIC), TLS1.3 with 0-RTT, Brotli

#36
post #4

Yay! Nothing better than to put something that screams "bleeding edge" to handle all your traffic. YOLO, amirite? update: I love the unexplained downvotes, can't help but feel that as there's no argument they can make against what I wrote they are implicitly acknowledging that the point I made is, as it happens, correct.

Your comment is correctly getting downvoted because it broke both the site guidelines and the Show HN guidelines:

https://news.ycombinator.com/newsguidelines.html

https://news.ycombinator.com/showhn.html

Would you mind reading those and taking the spirit of this site to heart when commenting here? We're trying for a bit better than internet default, and sarcastic dismissals push things in the wrong direction.

Your comment downthread (https://news.ycombinator.com/item?id=21308453) also broke the guidelines. We're really trying to avoid flamewars here, for the same reason that cities avoid flaming buildings. If you'd respect that in the future we'll be grateful.

Re: Show HN: Nginx Image with HTTP/3 (QUIC), TLS1.3 with 0-RTT, Brotli

#37
post #29

Earlier quoted context omitted.

Do you really require someone to point this out before running in production? If anyone doesn't know not to do that, it's on them, not OP.

I simply believe that honesty is important. If I publish something that I know to be experimental, I mark it clearly as such. And I point out others when they fail to reach that bar, so that they can fix it.

Honesty's great, but breaking the site guidelines is not. Fortunately you can be honest while following the site guidelines in both letter and spirit.

Please see https://news.ycombinator.com/item?id=21308730 as well.

Re: Show HN: Nginx Image with HTTP/3 (QUIC), TLS1.3 with 0-RTT, Brotli

#38
post #9

Earlier quoted context omitted.

That's eSNI and I believe it's part of 1.3: https://tools.ietf.org/html/draft-ietf-tls-esni-04 Not sure what's the implementation status though.

No, it isn't part of TLS 1.3 At the point where the last drafts of TLS 1.3 were shaping up, Eric (Rescorla)'s initial ideas for how to achieve eSNI had failed and the extant draft was only a problem statement. It basically said: Here is what eSNI needs to achieve in our opinion, we don't know how to do that Between that point and when TLS 1.3 was published, several people brainstormed a proof of concept for how to ac…

Awesome, thanks for the details. I remembered FF doing something about it and thought it's already official.

Re: Show HN: Nginx Image with HTTP/3 (QUIC), TLS1.3 with 0-RTT, Brotli

#39
post #31
post #12

Earlier quoted context omitted.

Thanks for the labels. Appreciated how you put me in my rightful place. Sorry if I'm being such a joy killer. I guess I've been witness to too many failures for not feeling to call this out before someone gets burned. Oh right, but no one needs to be told to be careful, right... No one is here to learn anything, as we all already know everything. Makes you wonder what's the point of showing something new in the first…

> Sorry if I'm being such a joy killer. I guess I've been witness to too many failures for not feeling to call this out before someone gets burned. But you didn't do it in a constructive way. You did it in a condescending way to make yourself appear better. Yolo, amirite? You could have had a constructive comment, explaining the level of support of various technologies, their maturity within nginx, etc. All of that w…

[deleted]

Re: Show HN: Nginx Image with HTTP/3 (QUIC), TLS1.3 with 0-RTT, Brotli

#40
post #22
post #5

Earlier quoted context omitted.

Well, "ssl_early_data" is opt-in. If you enable it on a virtualhost, then you also need to look at the "Early-Data" request header in your backend and make a decision there. e.g. process GET requests, otherwise send HTTP 425 Too Early. It does seem a bit unsafe. An administrator might opt-in because they copy-pasted it from a tutorial, and not understand or pay attention to the second part.

I think it will be better to fully disable early data for people without full control of DC's network equipment. I don't know why Cloudflare made a decision about using headers and Too Early response. They have full control of their POPs. It will be better to measure RTT and use UDP based KV storage with tickets only for clients with high RTT. So for clients with RTT higher then access to KV storage it will be better…

> It will be better to measure RTT

To measure RTT you need to perform a round trip. Hence the name. But the _whole point_ of this feature is to avoid incurring the cost of an extra round trip if possible.

Post reply on HN