Live data from Hacker News

Kea 3.0, our first LTS version

isc.org

21–30 of 50 posts

Re: Kea 3.0, our first LTS version

#22

I have a positive ending Kea story. We deployed 20,000 PS5 APUs (AKA: AsRock BC-250) each is a individual blade computer that was PXE booted. We started to see strange behavior on the network and it took a bit of trial and error to figure out what was going wrong. Eventually, we traced it down to dnsmasq being unable to keep up with all the DHCP UDP traffic regardless of how we tuned the kernel/networking buffers. Sw…

Can one run mainline Linux on these boards?

Re: Kea 3.0, our first LTS version

#23
post #22

I have a positive ending Kea story. We deployed 20,000 PS5 APUs (AKA: AsRock BC-250) each is a individual blade computer that was PXE booted. We started to see strange behavior on the network and it took a bit of trial and error to figure out what was going wrong. Eventually, we traced it down to dnsmasq being unable to keep up with all the DHCP UDP traffic regardless of how we tuned the kernel/networking buffers. Sw…

Can one run mainline Linux on these boards?

Information on running the AMD BC-250 powered ASRock mining boards as a desktop

https://github.com/mothenjoyer69/bc250-documentation

Re: Kea 3.0, our first LTS version

#24
post #11

I wonder when this will make it into pfsense... The transition to kea has been a bit of a mess with tons of bugs. Thankfully it's controlled by an option, and it seems like 2.8.0 knocked out quite a few of them

I have been using Kea on pfSense CE for a long time — I think it was version 23.0.x. Or you mean 3.0 in particular? I also have OPNsense and I am not completely convinced of their aggressive update strategy yet. For a firewall, I prefer stability over features. Jumping to the newest releases every month can have tradeoffs.

Note: in general, both OPNsense and pfSense are excellent. I have never had any problems with either one.

Re: Kea 3.0, our first LTS version

#26

Earlier quoted context omitted.

Won't take long, ISC doesn't do 'much' but they do it well

I remember Dan Bernstein (djb) being scathing about BIND. To the extent of writing his own DNS suite. Is that all ancient history now?

Most of the criticisms were accurate, if often very, very, very detail-oriented. DJB has always had a few settings: either you're on his level, on his wavelength, or he treats you as maybe bright enough to tie your own shoelaces on a good day.

That said, if you want to run a dns server and don't have huge scalable business to run on it, you can just run tinydns for a couple of decades and not worry about security issues, it just runs. BIND is more complex, and has evolved a lot more to do more because new features are implemented it as the reference, and so it needs to both scale up and out, and also change a lot, and for that, you get https://kb.isc.org/docs/aa-00913. So anyway, you can make up your mind, but my impression as a greying beard is that ISC has always been a risk you usually just need to accept if you need their tools since no-one else is doing anything to dethrone them.

Re: Kea 3.0, our first LTS version

#27

Earlier quoted context omitted.

I remember Dan Bernstein (djb) being scathing about BIND. To the extent of writing his own DNS suite. Is that all ancient history now?

Most of the criticisms were accurate, if often very, very, very detail-oriented. DJB has always had a few settings: either you're on his level, on his wavelength, or he treats you as maybe bright enough to tie your own shoelaces on a good day. That said, if you want to run a dns server and don't have huge scalable business to run on it, you can just run tinydns for a couple of decades and not worry about security iss…

[dead]

Re: Kea 3.0, our first LTS version

#28

I have a positive ending Kea story. We deployed 20,000 PS5 APUs (AKA: AsRock BC-250) each is a individual blade computer that was PXE booted. We started to see strange behavior on the network and it took a bit of trial and error to figure out what was going wrong. Eventually, we traced it down to dnsmasq being unable to keep up with all the DHCP UDP traffic regardless of how we tuned the kernel/networking buffers. Sw…

Wow, I didn't know the BC250s were used at such scale. I bought two to play with for dirt cheap, but haven't gotten around to it yet. Are they primarily used for mining?

We used them for mining ethereum, but no longer.

There is a good fairly easily discovered discord out there for enthusiasts.

Re: Kea 3.0, our first LTS version

#29
post #22

I have a positive ending Kea story. We deployed 20,000 PS5 APUs (AKA: AsRock BC-250) each is a individual blade computer that was PXE booted. We started to see strange behavior on the network and it took a bit of trial and error to figure out what was going wrong. Eventually, we traced it down to dnsmasq being unable to keep up with all the DHCP UDP traffic regardless of how we tuned the kernel/networking buffers. Sw…

Can one run mainline Linux on these boards?

We ran Linux (Ubuntu) on them, PXE booted with a minimal image.

Re: Kea 3.0, our first LTS version

#30
Great to see the hook libraries being mostly open sourced!

I was quite ok with paying the $500 or so to license the features, but the friction to get that through procurement processes also ended up killing it.

Kea is perfect for integrating with zero touch provisioning automation processes.

Post reply on HN