Hacker Newsnew | past | comments | ask | show | jobs | submit | sc0rpil's commentslogin

Absolutely wild take. Auth is most definitely not simple, nor are best practices well known, based on number of auth-related vulnerabilities published.


I guess everyone outside of the JS ecosystem, that has auth baked into the framework for decades, is just doing it wrong and riddled with hackers in their systems?


Any concrete examples? Which one do you use?


I'm glad you asked (to be honest that was half the reason I posted the comment)

I use Clai[1] which I've written myself, so it fits my workflow the best. But I know llm [2] is a popular choice as well.

With both of these it's possible to have a 'vendor agnostic' version of both claude code and gemini CLI. Better yet: it's possible to very easily swap to the latest and greatest vendor by simply specifying their latest fancy new model.

[1]: https://github.com/baalimago/clai [2]: https://github.com/simonw/llm


I didn’t like the unwieldiness of existing planning poker apps so I’ve built one for my team over the weekend - https://estim8.pro/ Built on Elixir Phoenix LiveView, was a great little side project.


Have you looked at https://iAmAgile.io ?


These both look nice.


None. OpenTofu name comes from Terraform => TF => Tofu. Bao is another asian food, so it kinda fits (people involved with OpenTofu are not the same as people working on OpenBao, but why not have some common theme).


Bao (包子) is usually referencing a steamed bun, for those interested.


And is as tasty as the logo itself :)


So basically the cake containing the file to break out of the vault?


This one is already open though. The file is gone.


The development is currently happening under `development` branch while the code is not in build'able state: https://github.com/openbao/openbao/tree/development

Very early stage still.


Hey HN, I'm involved with this project, glad you found it interesting! Keep in mind it's still a _very_ early stage and not in a usable state. A lot of work in progress but also plenty of opportunities if you want to contribute.

If you want to help out, you can :

Join Matrix rooms:

- https://chat.lfx.linuxfoundation.org/#/room/#openbao-announc...

- https://chat.lfx.linuxfoundation.org/#/room/#openbao-develop...

- https://chat.lfx.linuxfoundation.org/#/room/#openbao-general...

- https://chat.lfx.linuxfoundation.org/#/room/#openbao-questio...

- https://chat.lfx.linuxfoundation.org/#/room/#openbao-random:...

Join the mailing list: https://lists.lfedge.org/g/openbao


Hey HN, I'm involved with this project, glad you found it interesting! Keep in mind it's still a _very_ early stage and not in a usable state. A lot of work in progress but also plenty of opportunities if you want to contribute.

If you want to help out, you can :

Join Matrix rooms:

- https://chat.lfx.linuxfoundation.org/#/room/#openbao-announc...

- https://chat.lfx.linuxfoundation.org/#/room/#openbao-develop...

- https://chat.lfx.linuxfoundation.org/#/room/#openbao-general...

- https://chat.lfx.linuxfoundation.org/#/room/#openbao-questio...

- https://chat.lfx.linuxfoundation.org/#/room/#openbao-random:...

Join the mailing list: https://lists.lfedge.org/g/openbao


I probably won't contribute, but I want to extend some useless but genuine moral support.


It's much appreciated


Glad you use matrix and not discord!


Has anyone figured out if it's possible to join these rooms from a federated Matrix account?


Just joined from :matrix.org. Haven’t tried other servers but should be fine I think.



Why did you all choose to fork?


Because Hashicorp changed the license. It’s been all over the (tech) news so it’s easily googlable.


Thanks. Do you usually Google every question you ask in a forum?


Yes. It's usually a lot faster than waiting for someone else to google it for me.


Generally I would agree, but in this case, I was asking the person directly. I thought it would open an interesting discussion. I didn’t realize it would only result in a reprimand. <shrug>


Can’t say for everyone else, I personally see this as an opportunity to have a version of Vault that’s a bit less centered around the needs of a single organization.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: