005 - OTP Security Releases, ElixirConf US, and Goatmire Badges
All right. Welcome to another episode of Macro Mayhem. My name is Peter Ullrich,
and today is Thursday, the 17th of September, local Berlin
time, 11:13 in the morning. Well, it's important
that we state this kind of time zone, time stuff,
because the world of Elixir and other languages has been traveling
globally in the last 2 weeks, going to the US and
back, and we're not... We're not. And I'm here with the world traveler
himself, Gus Workman. How are you doing, Gus? I'm doing pretty
good. How are you, Peter? I'm doing just fine.
I was awoken by a pressure hammer,
you call that, like a jackhammer this morning in front of my window.
So, I'm dandy. I'm very good
today. Very good. I see the light in your eyes.
It is very dim. Yes.
But if you're not on the video, if you're not watching the video
on YouTube, it's fine. I'm going to explain to you because I already changed into
the proper Sweden attire. I am wearing an ugly
sweater. I think that is the official brand name and fashion style
name, ugly sweater. It is mostly black,
but it has white spots and the trims are in red, and it's very comfy.
So you got to appreciate the Swedes who said, why be
fashionable and comfy at the same time? if you can
just choose fashionable. So, no, sorry,
comfy. Ah, I messed up my own joke. Anyway,
Gus, let's head on. We have a very short
news and blog section this week. It hasn't been that much in the last week
or two, right? So, let's just get into it. Let's start with the first news
item. We can hop right into it. So,
first up in the Elixir-ish news, Elixir-adjacent news,
Is that there is an organization actually located
here in Luxembourg at the House of
Cybersecurity here in Luxembourg that reports the rankings
of individuals and organizations who have reported CVEs.
And you, Peter, happen to show up as number 102 globally
on that list. And Jonathan, the— At the EF,
is number 69, as of this morning. You actually
got bumped since we looked at this last, right? Yeah, it changes.
It's just a little tidbit I wanted to throw this in here, which was funny,
because I saw, Jonathan actually saw that, yeah, he and I were ranked in
the top 100 worldwide, out of 28,000 people who were
mentioned in the CVE record, like, they're all credits, you know. And he
and I were in the top Well, I'm 102, so just on the edge,
but that's gonna change any day now. But Jonathan
is tied for the same number of CVEs reported as the Mozilla
project. So that's pretty cool. And the Microsoft
Response Center, Security Response Center. Actually, he's ranked even higher,
but we changed the format of his name a while ago, where now
it's Jonathan Mentjen/EEF, and before that, it was just Jonathan
Mentjen. And he has, like, 15 or so reports that are not
associated with the /ef version. So,
he's actually higher up if you— yeah. So, if you'd be
looking at the numbers, there'd be, like, 63 or
62, somewhere in there. Yeah. Yeah. So, he's all the way up.
And another piece of information here is that actually the
EFCNA, so, that is Jonathan and I, or it's
not Jonathan and I, it's the EF and the CNA, right? It's also a group
of people. But we are in the top
25 worldwide and 26 for issuing
CVEs. And we're in the top 10 and
they're all kind of, well, we're in, I think,
position number 10, but all the position 1 to 9 are
tied to position 1, basically. They all have the same results
for the quality of CVEs. Because a lot of
CNAs, they, you know, they're rushing out CVEs now, so they're not filling out the
records properly. So it's hard for the user and security researchers to
understand what's happening in a vulnerability. But the
EEF is extremely good about filling out these records. So I
think we only have 2 records which don't have fixed patches. So,
like, no fixed version. Okay. And that's what is keeping us also
from that top 10 group. So we are
definitely punching above our weight. Just wanted to point that out. That is very
cool. And again, this kind of goes back into all of the work the EAF
is doing and promoting recently that this security work is incredibly
important. First of all, huge thank you to you and Jonathan for
helping secure ecosystems. I know we've said this before, but you
guys deserve a lot of praise for it because it's, it's thankless
work, but it benefits everyone. Yeah, thank you. And, and also,
I wanted to point out that we're doing this not
through a lot of Elixir funding
or funding coming from the community. That is definitely one
issue where we have outside funding from, I think, Anthropic through
a foundation that now pays me, for example, and also largely Jonathan's salary.
But if it wasn't for that, there would be nobody being paid
and nobody would do that work in the Beam ecosystem.
So just wanted to, you know, and we're doing this with like 1.3 full-time
employment, like 1.3 positions where other groups, they have 10 and they're now
stocking up to 15 full-time positions. So we just
wanted to point that out there that all of this is being done on
the verge of, you know, not being funded well. So yeah.
And on that note, the EEF also has changed
their their sponsorship packages.
So now it's more clear to companies in which package they can
invest or donate, and then they would land in. Right. So if
your company has value from all this
vulnerability research that we've been doing, they should consider
donating and support this and fund it more sustainably than just
outside funding that can go away after 6 months, for example.
Right. Enough on that. Well, actually, not enough on that. Let's continue. We'll talk more
about it later, but let's continue. There's other security news,
right? Yeah, very quickly, there is a new OTP security release
that includes 2 pretty nifty vulnerabilities.
Well, there are a bunch of CVEs, vulnerabilities or issues, but 2 big ones.
One of them is, it's always the same, there is an internet package
in Erlang, in OTP, like inet or inet.
And if you use that to
make HTTP requests, there is a vulnerability that somebody can basically
create, like, 2 gigabytes of memory usage,
if they respond with a malicious response, and then crash
your Beam. So that one is fixed. And the other one, it's also
one that actually affects a lot of OTP, and will—
yeah, it's now fixed mostly, I think largely,
which is— I also didn't know that. But string,
No, string to integer, this way around. String to integer,
if you just do that. If you put in a string that is 1.2
megabytes long, which is a very large number, and you do to_integer on that,
you will basically pin one process for many
seconds. And then the next time you use that integer, also,
it's going to slow down your application. So, that one has
been partially fixed now because the The limit there is just limited now.
So, that was a fun vulnerability I found because of the version package in
Elixir, where I was like, you know, Claude told me, hey, if you put in,
like, 1 to the power of 10 million, yet again, Right. and then
you do string to integer, it takes, I don't know, 30 seconds, 50 seconds until
a response. I was like, what? So, we, you know, we, there has
been quite a lot of work from
the OTP team, and they fixed it now in a lot of places in
Erlang. So, there are releases for that, security releases, so please update your OTP.
And then also, you can upgrade right away to OTP 29.1
if you're on the OTP 29 version.
29.1 is mostly maintenance and bug fixes. But,
you know, while you're at it, go ahead and upgrade to the
latest. Yep. Great. So,
that also leads into— there's Rebar stuff too,
right, related to OTP? Yes. So,
Rebar 4, it's a project on Kickstarter
that got funded, and they're currently working on Rebar 4.
Rebar 3 is, I think, mostly the Erlang ecosystem package
manager, if I understood that correctly. It's the equivalent of Mix,
right? Mix, right. Yeah, but then in the Erlang ecosystem.
And it has been not like— it has been only on maintenance
mode for a while. And now they had this project to upgrade it to Rebar
4, which would integrate it into OTP itself, because right now it's an
external package you have to install and configure. So they want to bring it
into OTP, and then also make it a tool
that you can also use in all the languages, not just in Erlang.
So that would partially, especially if you have a project that uses Erlang
and Elixir, and another language maybe. I also learned today there's
a Lisp-flavored Erlang. Okay. LFE.
Yeah, if you use that, then in the future, you can use Rebar
And the project has asked for input from users in the ecosystem,
because now they can look into plugins for the
rebar tool. So, for example, to connect to Hex or run
xdoc, that kind of stuff. So, they're asking
for your input on which plugins to prioritize first for compatibility
testing. So, if you're in a
project that uses Erlang and Elixir and/or Gleam and/or
other Beam languages, It might be worthwhile to take a look at that discussion,
contribute to it, and tell them where they should prioritize their efforts,
right? Exactly. Yeah. Cool.
Well, next up, we also are starting to see some
of the ElixirConf EU 2026, so in
Malaga this past spring. The videos have been— are
in the process of being released. As of this morning, there's 43
videos in the playlist. We'll link the playlist down below.
If I had to give you some talks to check out, I saw that,
Peter, your talk was already uploaded, which was a
fun one. My talk was there. I saw
a whole bunch, like, there were so many good talks at ElixirConf EU 2026.
So, go check them all out. And the keynotes
have been out for a little while, but the smaller, not keynote talks
are are sometimes just as interesting, if not more.
Yeah. And I also saw that some of the ElixirConf US videos,
they're also already published, right? Like, some of the keynotes and some of the—
The keynotes are starting to be published, yeah. Yeah.
Okay. So, we'll talk a little bit more about that. Yeah. Good.
Then, moving on to the blog section.
First, I'd like to toot my own horn, which is that I
wrote a blog post after a long time, And it's about announcing Pushin,
the Git hosting platform I'm building. And I laid
out in the blog post what's my motivation, my values behind Pushin.
So we're going to talk about Pushin in the end in the discussion section.
So I'm just saying, if you're interested in learning why
I'm building this thing, I wrote a blog post about that.
Very good. There's another blog post by
Nathan Long. Called Label Your Processes.
This was a nice short quick blog post, a little quick tip
that you can add labels to your processes and it
shows up in if your GenServer crashes or when you're in the Phoenix Live dashboard,
you can see all of the process lists. I think probably Observer
as well would show them, but it's a simple way you can
You use Process.set_label in the
code, anywhere that you want to set up a label for your process, and then
you get better insight and debugging. So it's a very short,
quick blog post, but it's a good one. So thank you, Nathan, and check it
out. I did not know this. Yeah,
because every time I saw processes in Live Dashboard or an observer or somewhere
else, it's just the PID. Yeah. But yeah, this is a way of naming them.
That's smart. Very good. And then last
blog post, it's written by the Erlang Ecosystem Foundation, by Dan.
It's about how we defend our ecosystem against AI threats. And sorry,
we've been talking about this for quite a bit. I think this is the last
item where we talk about it. But yeah, Dan did
a good job of kind of writing up our work of the last couple of
months, like where we, what we've done, where we're standing now and how we are
going to continue defending and
securing our ecosystem against AI
threats, but generally bad actors, malicious actors, and vulnerabilities.
So, it's a good blog post to check that out.
Next, we do have, I think this year, we're only going to have 1
or 2 more sections of this because there's not too many conferences
and meetups after Goatmire and Codebeam. So, Gus,
I need to— Well, meetups. There will be meetups,
but conferences, I think the big ones are coming
up here in the next couple of weeks. So Goatmire is first,
September 27th to October 3rd in Varberg, Sweden.
We will both be there. Peter is talking. I'm running a workshop. It's going to
be a really great time. I have some more info in the discussion
section about some of the cool things that you're going to see there. So stick
around for that. After that, just another, what,
3 short weeks after that is Codebeam in Haarlem in
Netherlands. That's October 21st and 22nd.
And you can get your tickets for both those at goatmire.com and
codebeameurope.com.
And I timed you. You are getting faster and faster
every time we do this. Perfect.
They're getting shorter and shorter, so... Yeah, that's true.
Both, maybe. True. So,
yeah, I wanted to also add one thing, which is I got contacted
by the CodeSync marketing team, the team that runs
Codebeam Europe '26, and they gave
us a code we can share with you for a 15% discount
code on the tickets. So, if you haven't bought your tickets yet and you want
to buy the ticket with 15% off,
you can just use the code Peter Ullrich 15.
Sorry, it's not Macro Mayhem.
I did not choose this one, but Peter Ullrich, and Ullrich with 2 Ls,
don't forget the second L, 15, and then you can get 15% off the
ticket. There we go. That helps. It pays
to be a Macro Mayhem listener. It does.
You're literally making money by just listening to this podcast.
Exactly. And none of that comes back to us. It's just supporting the
conference and supporting you to get in there a little bit,
at a little bit better price.
Exactly. All right. Anywho, that kind of wraps up
our meetups, blogs, and news. Peter, do you
have a joke for us this week? I do.
How about this one? So, why is dark written with
a K and not a C? Because you can't
see in the dark.
Very good. Okay. That's corny. Check. Can't see
in the dark. Yep. Check that box. Can't see in the dark.
Exactly. Well, well, well. Well, this is
the section. We've covered the news, the blog posts,
If you wanted to stick around for the discussion, we're gonna be talking about ElixirConf
US, Goatmire, and some Pushin follow-ups.
So, yeah. So, yeah, moving on to the discussion. Gus, you have
been our reporter on the ground at ElixirConf US in Chicago.
How was it? It was good. So,
Chicago was lovely. I'm still a little
bit jet-lagged, to be honest. Quite frank.
But it was a great time. I got in on Tuesday
last week and stuck around until Sunday.
And yeah, the conference was— I mean,
the CodeScene conferences are really well organized. It was in a nice venue
at the Voco Hotel in downtown Chicago.
It was up on the 14th and 15th floors. So got a pretty
good view overlooking the river. in the downtown. And then,
yeah, talks were all pretty great, the ones that I went to.
I felt it was a little bit smaller than ElixirConf EU, and I
hadn't— this was actually my first ElixirConf US. So,
I hadn't been before, but I didn't realize— I was
under the impression that ElixirConf US was slightly bigger, for some reason.
Yeah, me too. I would also think so. I think there was a
rough estimate of like 500 people there.
Hmm. Though, I don't know, maybe it's just that the room size was smaller
for the keynote speeches, um, and that's
what made me feel like it was a little bit less attendance. But, but it
was really good. I mean, it doesn't— I don't mind the smaller space because you
have— get rid— get more involved and interactive
in some of those presentations. So Nice. Good.
Speaking of keynotes, the keynotes, I think most of
them are already on YouTube in the playlist
that we'll link in the description. I think the one
that was missing was José's keynote on
his updates on some of the type system stuff.
Yeah. They were all really good. And I didn't even get the chance
to go see all of them. So I'm gonna
be checking out some of those YouTube videos as well. But yeah,
I think my favorite keynote that I saw was Zach
Daniels' Exoskeletons,
Not Autopilots. And so this was a— it
was less Elixir-specific and more about
how to build AI systems that work
for your team rather than replace it. Yeah.
Was kind of the tagline that he was talking about. And yeah,
I think he had an interesting approach building up an incremental—
and I mean, Zach has a lot of experience with this right now because he's
a VP of engineering at Remedy Meds and is building the
team there and building AI systems for internal, external use.
So, like, It's pretty interesting,
his viewpoint on all of this. So,
what were his tips, so to say? So,
first of all, what was he building and how did
he build it? Right.
So, let's start
with how he suggests the approach to AI to
be. And that is starting from No AI.
Forget all of your Claude skills,
your Claude plugins, your all this stuff.
And his suggestion was to start typing prompts
in like we did back in 2025.
Yeah. Old school. Old school. And see
where it goes wrong because the agents are relatively easy to
get off track if they don't have a framework to use. And then from there,
start writing your Claude MD file. And of course, all this is generalizable
to other agent frameworks, so Agents MD file. And then
as you realize there's a bunch of things that are not working
for you, then how do you go from expanding that Claude MD
file to then maybe you can create your own skills?
He mentioned usage rules, which is a Ash-adjacent
project. I don't think it's Ash-specific in any way, but it's— I
think Zach was the creator of it, who— and it's where library
authors add skills or add information that can be compiled into skills
for their libraries so that agents know how to use their libraries.
And so, I mean, none of this that I've said so far is new stuff.
I think this is early 2026. A lot of this, you could have already found
this information and applied this. But where he got interesting is
that He said, okay, so you want to do this and
start automating your workflows and working using agents
to augment some of the things that are low
value but high time in your workflows. And so first,
throw agents in a GitHub Action. So there is a— you
can— GitHub Actions has a Claude action where
you can just use Like, it's in your YAML file.
You can add uses Anthropic/cloud-code or something
like that. And it just adds Claude to your agent.
I think you need to add an API key. I don't know how this works
with subscriptions. Mm-hmm. I'm sure there's other providers that
do all this too. But his suggestion is throw it in a GitHub Action first.
Then you can throw prompts in there. And so, like, for example,
when it's a push, on push for a pushing
up a branch or creating a PR, then you
can run this GitHub Action automatically and say, do a code
review, do whatever, do evaluate this for security vulnerabilities,
whatever the prompt says, right? It doesn't need to be a crazy complicated prompt.
Most of the time it's going to be able to figure it out. And then
once you're, once you're doing that, I mean, there are tools that do this,
the code review PR or, or AI code review tools,
GitHub Copilot, for example. But Claude
is what you're working in your, in your existing workflow and all your skills,
whatever, all the documentation that you've written for your repo
lives in that repo. So that Claude instance will
have the same access to it as a human. Oh, that was another point that
he made is that build your systems for humans. Write your documentation in just standard
MD files in your docs directory, things like this.
Keep it up to date. But the agents
know how to use— like, if it's easy to use for a human, then it's
easy to use for an agent too. True. Yeah. So he
started with the GitHub Actions, then how to make it even bigger,
connect to Slack, to Jira, to whatever you use. And then when
you get to a large enough point, you can start creating an internal
AI, like, hub,
a place where you can have all your team members coordinate things.
So I'm not going to spoil all of the juicy
bits at the end because that was probably, what, first half
of the talk that I gave a quick overview there of. Go check it out.
It's a good one, especially if you're in larger teams, I think.
But there's good insights for small, small, smaller teams too.
True. And in the second part of the talk, he talks about everything that
goes wrong. Yeah,
it's interesting that he says you should use it to build for your team.
And, you know, what I see and hear a lot is people just buy products
and then they think magically everything goes better, but they don't integrate
into the process. They don't update the processes to integrate the system. And just
like, oh, I paid $10,000. Now we're efficient. That's it.
Now we've reached AGI. Yeah, exactly. We have AGI now.
Okay. Good talk. I'm gonna check that one out. And all
of the talks are here in the linked playlist, right? That's the playlist
to the ElixirConf 26. And as new videos come
out, they will be added to that playlist as well.
Right. And if you wanted just a short and sweet one, One that's near and
dear to my heart, John Carstens gave the Nerves update, which is
already the state of the Nerves or something.
I forget what it was titled. Just a core team update on everything that's happening
in Nerves. It was only 15 minutes. It's a very good talk. He is a
very good speaker. And, you know, I like
Nerves. So— Yeah.
It's a great system. Like, I wish I could just do Nerves
all day and not have to Build web apps that people
use, you know. People using web apps.
Yeah. Yeah. You know, the hardest part of building a business
is first getting customers, and then the second part is having customers.
Yes. Yeah. And,
but yeah, I mean, we have a big controversy that we still need
to, you know, settle. So you were in Chicago.
I was in Chicago. Did you have a deep dish pizza? I did
have deep dish pizza. What's your professional opinion
on the deep dish pizza? Okay. So, we had it
at Lou Malnati's, which is a— I think it's
one of the original claim to fame deep dish pizza Chicago
places. They've kind of turned into a bit of a chain and they have a
bunch of different locations.
And the verdict,
I've had deep dish before, But it has been a couple of, a number
of years. My verdict is that still, that is a casserole.
So, I'm sorry to the deep dish pizza
lovers out there, but I love, I mean, calling it a casserole doesn't
change how it tastes. It's still delicious, but it's
a casserole. Okay. And why is that?
Because you have the layer of crust, and then it's like,
A whole 2.5 centimeters, 1 inch of
cheese, and then sauce. And it's just, it's heavy. Pizza is not
supposed to be so heavy. No. If you know the
original Italian pizza, they're always thin,
super thin dough. And then, you know, some also a thin layer
on top, but it's a really light thing to eat. Yeah. Right.
It's light. No, the similarity is that with the Italian pizza,
And the Chicago deep dish, you eat them both with a fork because— Oh,
true. Yeah. The Italian is too floppy.
You can't pick it up with your hands. You need
to wedge it into like a triangle, you know, like hold both
ends to make it kind of like a,
yeah, like a triangle kind of thing where the ends are up and then the
middle, and then you put it in your mouth. That's how you eat. Yeah.
But I know, like, you know, not everyone is—
We need to go do some testing on this. Yeah,
exactly. Not everyone is as streetwise as others.
Yeah. Apparently. Yeah. You know, if you hate
us for doing this, just call us Pizzagate. This is the
Pizzagate incident on the Macro Mayhem podcast.
But I think now we have covered this topic enough, and we shall never
talk about it ever again. We shall not. And if you have something to say,
shout it at the clouds. We shall receive
your feedback somehow. Indeed. Well,
that being said, the kind of final tie-up for ElixirConf
US is that they— I
always am curious after a conference where it is gonna be next year.
And the options for next year that we did
an audience cheer
metric voting for at the end of the conf was
back in Chicago. So, either there could be more deep dish on this podcast,
which is what made me think of this. Who knows? Oh, God. Or Toronto.
So, it might be ElixirConf North America next year instead of
ElixirConf US. Interesting. It will be interesting
to see where Yeah.
In a year from now, Toronto might be a safe
option indeed. Yeah. I would come to Toronto. That would be nice.
Yeah. But then we have no deep dish pizza. Do they have something in Toronto
we can complain about? Any food stuff? Let us know in
the nonexistent comment section. Yeah. Tag us on
the socials. What shall we try in Toronto? What's the
best pizza? food in Toronto. There we go.
Well, speaking of conferences and all those,
one thing that was kind of fun for me at ElixirConf US
was talking with José, and I showed him
the secret project that we're working on for Goatmire,
and he ended up posting it on his socials.
And now— That was a, that was a very private conversation
indeed. It is public.
So, uh, Peter, you've kind of seen what I've been working on,
but you haven't seen the latest. For Goatmire, last year
we did, um, we did Nerves name
badges. Everyone got an e-ink Nerves
name badge, which is kind of what the Nerves starter kit has turned,
like, evolved from, from that project. This year we
have name badges again, except they are AtomVM powered.
Now, if you're on YouTube, Mm-hmm. I'm going to hold it up. And if you
can see this, you can see it's
pretty cool. It's a little bigger than last year. I will explain it to you.
I will explain it to you. You'll describe it. Yeah. So me, as a non-Nerves
expert, what do I see in front of me? I see in front of me
a case that is of white,
you know, 3D-printed plastic. It, like, the case is
approximately the size of, like, a Kindle, I would say.
A Kindle, what's it called, paper white. So, like, the really small
ones, yeah. Yeah, like a good 10, 12 centimeters.
I'm not sure how many inches that is in freedom units.
Yeah, I think it's 10 centimeters by 12.
I think you're right. Yeah, there you go. So, 10 wide,
10 tall, 12 tall. It has an
LED or an e-ink display at the top.
It's an LCD. LCD. Ooh, that's fancy.
So, it's full color. Yeah, it has some
red buttons, yellow, purple buttons. I can see different
colors. It has very— it looks very clear in terms of rendering. Like, the text
looks much clearer than the E Ink one. It updates the seconds in
the navbar every second. So, that's also really responsive without
refreshing the whole screen. So, that's cool.
There is a gap next to the display that I already pointed out to the
creator of this badge multiple times, but he chooses to ignore me every
single time. But the display is slightly off-center,
which I find absolutely unacceptable. But, you know,
it's just a design choice, I would say.
You're funny. I changed it due to your feedback.
The final product, the final product, the final result at
Goatmire will have the display centered and covered
up that strip. That's, that's it. So, if you get your name badge,
Take out a ruler and measure whether it's centered or not.
It better be. It better be. Okay. And then the bottom part,
the bottom part of the badge is a massive keyboard.
And these look like these soft rubber
buttons you can click. Are they soft or are they hard? They're soft. They're silicone.
Silicone. It's a silicone keypad. And yeah,
it's a full keyboard. You have The number row,
you have all the QWERTY, you have the arrows,
Shift, function keys, all that stuff. In total,
there is 70 keys, or 69. I think there's 69 keys
on this board. That's a lot of keys. It is a lot of keys.
There's even a Delete and Escape and everything. Some other cool
ones. There's a Super. Like, it's a full keyboard.
So, this will be the Elixir development equipment,
the computer you will use in '27.
You just need this. You text, you know, you're walking outside, you're texting
on it, you're writing Elixir code, or you're prompting your LLM that then runs
the GitHub Action to actually write the code and review the code. So this is
going to be your main development computer from '27
onwards. You got it. Actually, funny enough,
Lars added an agent mode. There's,
okay, there's literally an LLM chat window
you can open, like an app you can open and you can chat with an
agent. There you go. Maybe not an LLM. I'll leave that for,
for you to discover at the conference. But,
so, what is this thing? So you've just kind of
described what's here. Um, is it, do we miss anything? There's, that looks right.
Do you want to describe the back now? The back, it has a battery
just hot glued to a PCB,
which looks very professional. Like, this is the way you connect
a battery to PCB. And, you know, that's what I would do.
And especially the best way is actually to hand out the batteries and then
have the attendees of a conference plug
it into the devices. Like, that is a safe option.
So I see a massive big battery, which will explode at any moment.
In ahead of the, at the top of that is it's connected to
the PCB. And then it looks like a custom PCB that has,
well, they're connected to the display on the one side. And then at the top,
is that, is that a, no, that's the processor,
right? At the top, this, yeah. This one. Yeah.
It's like a silvery aluminum-looking
square, which is the processor, I guess.
And then there are a bunch of like black dots and weird things.
Different components. And then down here we have a USB port on the bottom.
Is that a USB-C one? Oh, you bet. Oh, good.
That's European compliant. Very good.
Yeah. So, yeah,
it's a custom PCB. There's a display connector. This one here,
the main chip running this is an ESP32-S3.
And it's a— that's a— if you're not familiar, it's a
microcontroller with Wi-Fi, Bluetooth capability,
and it runs AtomVM. So, all of
this is still Elixir, but in AtomVM
land, which has been quite a joy to work with on—
while we've been making this. So, I'm excited to get,
you know, 300 people,
300 attendees, some AtomVM badges in their hands,
And then they get to experience the same joy of AtomVM
that I do. That is, that is very good. Last question though,
will the final product have a back panel or
will it blow off my hand? Right. So it does have a back panel.
I had it off here for you. And you have to excuse
this one because it's the prototype and it does not align. There is an
acrylic back panel. It's tinted. That is awesome.
acrylic. And so it, you can still see through the whole thing,
but it gives the whole thing a nice tint to
it. And you can see the LEDs that we have here.
So to the listeners out there, because we're explaining
something visually, which is the best thing to do on a podcast,
the back panel of the final product is, yeah, like tinted,
right? Like a darkish, dark, kind of like sunglass glass.
You can still see the PCB and everything. You can see the battery,
You know, because that will tell you that it's gonna explode soon. But if
you turn it on, there are 4 fancy LEDs that
are in, like, a blue— oh, actually, they change colors. Oh, look at that.
Yeah, these ones are— I have them set to do rainbow.
Yes, they— so they— When you have RGB LEDs, it makes it go faster.
Exactly. And if you have rainbow LEDs just blinking,
it's immediately a professional device. Exactly.
Very good. I like this. And it, like, the thing on the top to
hang it, that's like a— Right. Yeah.
That's gonna be for the— to hang it down on your chest, right? So that
it explodes over your heart when it explodes. Exactly. Good.
Hopefully, there will be no batteries exploding. Hopefully.
That's like— let's see. We're not engineering
for it, but we're hoping for it. We're hoping that
they do explode? No, we don't, but we are not preventing it either,
are we? No, we are. Everything is safe. This will be a completely safe product.
Yes. It has been engineered to not explode,
Peter. Very good. Very good. That's— I'm glad to
hear that. Yeah. So, anywho, this is the badge.
Um, there is gonna be a workshop in the
days before, uh, the conference starts at Goatmire where we are talking about
How to add custom screens. Speaking of
screens, I didn't even mention what is on this. We didn't talk about that.
What screens did you see? So, there were a couple of apps I would
call— oh, first, when you set it up, it says Goatmire. And then
it goes into kind of like an app store where you have different apps you
can start by pressing a button.
The first one is name, which will be your name
badge, I assume. The second one is Nameless.
It says nameless right now. Yes. Okay. You can edit your name
and then it will show you. You can edit your name. It starts as nameless.
Yes. So, the second one is chat. What does chat do?
Chat is a full chat room. And unfortunately, I'm not
connected to the Wi-Fi right now, so I can't show you. But the idea is
that you can join a chat room, call it general or
current talk or Extracurricular or
whatever, run a club if someone, I don't know, whatever chat
rooms people wanna make, we can make chat rooms. And then you can type little
messages and view them throughout the conference. And, and this is going through Wi-Fi?
And this goes through Wi-Fi. It uses WebSockets. It talks to a Phoenix channel backend.
And— So, when we are out and about in the city, we can connect
it to our hotspots on the phone and then chat through this device
with other attendees and coordinate where you're having beers. After the conference. Exactly.
Perfect. That is much better than Signal. Word on the street
is that Varberg has a public Wi-Fi system that you can connect to. So you
don't even need the hotspot. I don't know if, we'll have to test it and
see if it is able to connect, but.
That's awesome. Then, yeah, and then we
have test, which I assume is a test screen, or text is a text.
Text. It's just a text box input. Some of these are testing.
And we're going to remove one before. And then we're just— allows
you to type keys and show up on the screen. Yeah. And then we have
LED center.
What is this? This controls the LEDs on the back.
So now they're white. Okay. But let's
keep some surprises for the actual conference. Otherwise, nobody's going to come.
Yeah. Well, what's the purpose of coming? No,
they know everything already. Exactly.
So anyway, this has been something I've been working on for quite
a while and really excited to, you know,
get it in people's hands at Goatmire and just have fun with it.
Every year we are increasing the level of nerdness of
these badges, and I'm excited for this year to see the
next level of nerd. The next
level of nerd. Oh boy, I need a break. Can you
imagine a more nerdy conference than 200, 300 people walking through
a small Swedish city and texting on like a weird custom device
that runs a weird system nobody ever heard about,
but goes through Wi-Fi and instead of what, do what normal
people do, which is your phone and Slack or something, you know?
Nerds, we're peaking at nerd level here. We will never understand this,
uh, this population, these people. No.
Anyways. All right. Well, come to, come to Goatmire.
We have badges. We do have the best badges.
Yes. So the best badges. Anywho, Peter, let's talk
a little bit about your, the, the follow-up on
Pushin release. Last episode, we were talking about Git
and your GitHub alternative. What's happened?
So much. It's been a crazy 2
weeks. So, yeah, 2 weeks ago, I announced Pushin on this
podcast. I didn't really expect,
like, a full launch yet. I just wanted to share
it with, you know, other people from the Elixir community.
And quite a bunch of you signed up, which I'm very— which I appreciate a
lot. But, you know, still, I thought, hey, it's gonna be like a small invite-only
beta with maybe like 50 people testing out the product, and I can
still develop all the hard parts underneath. Well,
that assumption lasted exactly, I think, 3 days.
And then
Rebecca Lee from Australia, Ash core team member,
I believe. Thank you so much, Rebecca. No, I'm honest.
She posted it to Hacker News, and then Hacker News happened.
And I'm not mad or anything. I actually
appreciate it a lot, because also it threw me in the deep end of the
pool, and I just had to swim. And I probably would have pushed out,
you know, like a Hacker News thing for months and months and months still.
But anyway, so yeah, on a Saturday morning, I woke up and I looked at
my phone, and all of a sudden I was starting to get waitlist signups.
And luckily, I built those waitlists, like, 3 days earlier, you know,
for the announcement on this post, on this podcast. And then,
all of a sudden, yeah, like, waitlist signup after waitlist signup came in. And I
was like, what the heck's happening? Somebody then sent me the link to Hacker News.
And I just looked at my girlfriend. I was like, I got big eyes,
scared face. She was like, what's happening? Did somebody die?
And I was like, no, I'm on Hacker News.
Sorry, we have to cancel our plans.
Basically that, yeah. I worked so much that week,
and I actually told her on the weekend, let's take it easy. Haha.
Yeah. So then I
stayed on page 1 of Hacker News for the entirety of the Saturday.
Even when the US woke up, I kind of dropped down to 25, and then
I went back up to 15, but I stayed on page 1 the entire Saturday.
I worked, I think, 16 hours, just not
necessarily, just answering messages,
I pushed out one or two small fixes because I was getting a lot of
signup spam. I already
had a CAPTCHA in place, but then I needed to also have
the waitlist controls, invite people, block people.
I had some stuff like that, but there were some issues that I just pushed
out quickly. So generally,
takeaway from Hacker News, it was extremely successful,
I would say, especially for Hacker News being Hacker News. I got
very few critical comments. Very few.
I was surprised. Some, you know, like probing comments,
but I answered most of them honestly,
and that seemed to have convinced most of the people. So yeah,
generally very positive. I got 500
waitlist signups, which is— 500? I think
now I have more, 650. I have now,
more than 500 confirmed users that signed up
and confirmed their account. And I can't tell you how many now started
using it or use it how often. I don't have these metrics deployed yet,
but I just, you know. And so that
was crazy. And then what was also kind of
crazy is that on Monday,
was it Monday or was it still Saturday? Right. Like, everything's blurry from the last
week. But 2 things happened. One of them is
the Chinese found out about Pushin, and they started signing up with
bot accounts. Well, not only them, but they were just— let's say
there were a lot of bot accounts. And thankfully, I had the waitlist and
invitation codes, because otherwise I would have, you know, a bot flood
on the platform. So I always sent back,
hey, a verification request. So I asked them,
hey, can you send me, you know, like a social media profile I can check
so that I know you're a real person? Very few of them responded.
That also told me there was a lot of automated signups.
So I discarded those. And then I had to move very
quickly to Bunny, or I decided to move to Bunny CDN, because they offer
some bot protection, DDoS protection, that kind of stuff.
And that, I mean, it was DNS, so it took a little while until
everything was propagated properly. And I'm sorry if on that day
you had some issues with the website. But finally, I moved to Bunny,
and then I realized that Bunny doesn't forward the port 22 for SSH
connections. So I broke all the SSH
connections to the repos. And I,
yeah, so that also took me then more time to set up a subdomain
and send out an email to the, like, 75 affected users to
say, hey, I saw that you have an SSH key uploaded. Yeah, you were one
of them. So I sent out an email saying, you know, sorry, but I broke
your SSH connection, but you can change it with one line, just git
set origin, that kind of stuff.
Yeah, that was the bot flood. And since
I moved to Bunny, that has been mitigated a lot.
I still get some signups, but they're easy to spot, so ignore.
And there was that. And what else
happened? Oh yeah, then all the LLM model scrapers.
They found Pushin. So all of a sudden, I was
getting hammered with GPT bot, Anthropic bot,
and Google bot scrapes. I mean,
Google bot is Google, but they have a particular one for their
LLM scraping. Mm-hmm. Yeah.
And then, you know, all of a sudden, my Grafana, like, the request spiked,
you know, like 15 requests per second, and then all going
through Git operations for fetching all the code that was uploaded in
the public repository. So they were gathering all that code.
And what I did then is I, on my
application side, because I couldn't, I filtered them out on Bunny's
side, but they still hit the subdomain
that I was using for the Git operations because that did,
you know, git.pushin.eu, that does not go through Bunny.
So you can use that for still fetching all the,
the Git repository. So, they were switching from Bunny,
from the public pushin.eu, they were switching to the
subdomain. And then I had to build something in my application that basically
checked the, what's the
header that says something is a bot? Which header is that? I always
forget. The user something? User agent.
User agent. Yeah, the agent, the user agent. So I then built
my own kind of firewall in the app itself to say, you know, if you're
one of these scraping models, no, you can't access this.
Yeah, which kind of fixed it now a little bit. It's mitigated
now at least. Yeah, man. That was like— That's been a wild
ride. I can't believe it's been, what, 2 weeks?
It feels like a year or 6 months at least.
Yeah. Yeah, so that was a lot of fun, a lot
of hard work, a lot of learnings. So if you can
also update your first, like, your website, you know, to make sure
that all the FAQs are there, that you have a privacy policy,
terms of conditions, I added that.
I also added now a status page using Johanna
Larsen's product Larm, larm.dev. Oh, cool. I think it's really nice.
So, now you have a proper status page you can look at.
Yeah, man. And then, after that happened, I got,
you know, very, very nice user feedback, which I appreciate a lot. So, there were
people opening issues for things, you know, either big feature requests
or smaller UI fixes, that kind of stuff. And super great.
I finished, or I implemented, almost, like, 30 or so tickets.
So, a lot of UI things were now fixed. Nice.
There's still plenty to do, but it already showed me that people
care about this platform, and they report bugs and that
kind of stuff. So, yeah, that was my launch,
so to say.
It's been crazy watching it, because I was paying
attention to Hacker News, seeing what people were talking about. And I
mean, yeah, generally good feedback, some small nitpicks on Like you said,
you didn't have a privacy policy. Yeah. Which is
fair. Someone wasn't happy about that, which— Yeah. Yeah. Funny enough,
funny enough, the first question I had to answer was, is this a real project
or kind of like a scam? You know?
And yeah, I wrote a big, you know,
block of text on HackenUSA, who I am, what the project
is about, that kind of stuff. And then throughout Saturday, actually, those were the updates
I made. I added the privacy policy, the terms of conditions, which are
kind of like, I adopted them to my product, but they are still kind
of stock terms, that kind of stuff.
Yeah. Which, yeah. So that was good. And now that I have
the launch over, like, you know, launch is
done, people know about it.
I have 3 big things I need to focus on for the rest of the
year. And then hopefully beginning of '27, I can make it generally available.
generally available, and kind of open it up generally also
for people who want to pay for it, who want to move their company repos
over, that kind of stuff. And there are also
interesting things in here that I'm going to write about soon when
I write blog posts about the architecture and so on.
So, the first thing I'm currently working on is to move
away from having a single server to multiple servers. Okay.
Which honestly, if you have a bare metal server with 20 CPUs
and 64 gigabytes of RAM, you can withstand a lot
of load. I was surprised. Hacker News
was on the whole day and I didn't even see a spike in the CPU.
Nothing. It was flat. Flat as Ohio.
Well, that's not the bare metal servers.
It's also Elixir. That's Elixir.
Elixir, and also a lot of performance improvements I've done over the 6
months going there. You know,
I had so many, because I built the first MVP, and it kind of worked,
and then I was like, okay, now we need to make it fast. So,
I had many, many rounds of performance improvements. So, even having,
you know, 20, 30 requests a second for repos, like, they were
all in the millisecond range of responding.
So that was not an issue. Yeah.
Yeah. So my next 3 big things, my blockers
before I can make this generally available is,
first of all, I need to move from one server to multiple. And in order
to do that, I decided to build my own reverse proxy.
And I evaluated the existing ones like HAProxy,
that kind of stuff. And of course, they're good and great and battle-tested.
But I think I have a unique enough use case to,
you know, legitimate— legitimize building
my own reverse proxy.
And the big thing here is that I'm doing session
repo affinity. So, that means I have one repo
always on one server, and every request to that repo
is being served through that particular server. Mm-hmm. And that allows
me to optimize for the on-disk cache, because I
have the repo locally, and I do all the Git operations locally, and then I
upload to S3. Right. So, yeah, if I would round-robin
these requests over 2 or 3 servers, every server
would need to keep a copy of every repo. And then also,
when the next request happens, it would realize, oh, I don't have
the latest version, and then it needs to fetch from S3. So, that's just
stupid. So, I decided, you know, let's keep it on one single
server. If that server goes down, we fall over to the next one, and it
downloads in a couple of seconds the stuff from S3, and it can start
serving requests. So, that's not an issue. But just having that server
affinity, sticky session, so to say, it's okay enough for RESTful
HTTP requests. I mean, that's okay. Yeah. But then when it
comes to WebSockets and SSH connections, then it
kind of falls apart. Yeah. And so
that's— and also, especially then when you have a LiveView website that has
a WebSocket and long polling, that's actually the big issue here.
Not the WebSocket, because once that's established, that's fine.
But the long polling, which HTTP requests always need to hit the same
server. Otherwise, Phoenix is gonna say, hey, I don't know this session,
and you have to reconnect. Right. every time you hit a new server, which is—
that doesn't work. Yeah. So,
currently, I'm building a reverse proxy that is handling
all the session affinity to the server.
It's going to do it for HTTP, WebSockets, and SSH
connections. I have to terminate all that on the reverse proxy,
and then set up a second layer of,
like, either sending HTTP requests to the server between reverse proxy and
server, or create a second WebSocket between reverse proxy
and server. And I'm also gonna do that for SSH connections,
which, you know, I have SSH to the reverse proxy, and then from the
reverse proxy to the server, it's gonna be a WebSocket connection, because that allows
me this 2-sided communication.
Yeah. And that's all built in Elixir as well? Of course.
Yeah. Of course. Yeah. It's surprisingly easy-ish,
I would say, because you have Bandit to receive
the requests, and then, For handling all the connections
to the server, I use Mint. Well, I use req,
req HTTP requests with a Finch pool.
And for the WebSockets, I use Mint, which supports that
really well. Yeah, those are the 2 big ones. WebSockets in Mint,
HTTP requests with req and a Finch pool. That's basically
it. Yeah. Very nice. So, you'll have to definitely post some
blog stuff and talk more about it here when you do that.
I will write a whole blog post about the general architecture and then also in
particular about these aspects. But I'm also planning on making the
reverse proxy open source once I can, like, test it in my
production. And I'm writing it now already in a way that if
you wanted to reuse it, like, it's not going to be a library you can
pull in. I don't want to go that far, but you could fork it or
copy it into your own repo. And then I built
it in a kind of like a plug-and-play way that you can, you know,
rip out my plugin, because I also use Postgres for storing
the affinity, the placement. You know,
I thought about using a clustered
reverse proxy cluster that then uses broadcast to inform each other
of the placements. But then you run into split-brain issues,
you run into race conditions.
And so I just decided, you know what, for now, I'm going to literally
store the— in which server do
I store which repo? And I'm going to look that up from the reverse proxy,
cache it. And then if the Postgres things changes, it sends a
notification to the reverse proxies, they update their cache. Right.
So, you know, ideally, there would be no database, and it
would all be consensus-based, but I
don't, I don't wanna go that far. So, well, we'll have to see how this
works for you because, I mean, this is not
a small task, but I'm sure you're gonna learn a lot along
the way. So, yeah, I will. I do.
But in the end, yeah, the idea is simple-ish.
You know, you, you receive a request and then, yeah, you have a, a pair
process that connects to the server and just But
yeah, the devil lies in the details there, definitely.
Definitely does. All right, so that was number 2. You had one more thing before
general availability? So number 1 is the reverse proxy. That's what
I'm working on right now, next to fixing UI issues. Oh, that was number 1,
right. Number 2 is adding actions,
so CI runners. I already support self-hosted
CI runners, so you can run your Gittee or Forge Runner
on your own device or on a server, and then connected,
registered with Pushin. But it's working, but the UI,
it's not that great yet. It's still, the support isn't that great yet. So I'm
working first on getting the UI ready, getting the lifecycle
correct and polished so that if you have a job that fails,
it notifies you, and the
jobs are enqueued properly. And if you, for example, schedule a
job because you push to a branch, and then you create another,
you push another commit to the same branch, branch, like the new job should supersede
the old job, that kind of stuff. I'm just kind of like polishing
that whole experience. And once that's done,
I want to start offering you a managed CI service
as well. And whoever, like, if you ever thought about
doing managed CI, it's a freaking nightmare security-wise.
It's just, you literally execute other people's code on your hard It's
the worst possible thing. Yeah. So that
will take a lot of time. And ideally, and I think,
like, if I can, and I think I can, I'm gonna use other
people's infrastructure. Like, there's something in
the UK, and there's, like, CoYep or so in
France. Mm-hmm. Like, there are very few that basically
just hand you Firecracker VM one-off instances that you can run your
stuff on, and that you can also spin other Docker images on. Like, that is
actually the biggest Right. Because they allow you to use
a Firecracker VM to run your code, but they don't allow you to start another
Docker image inside that. Maybe it's not a Docker image, but, you know, start a
Docker inside that VM, which you need
for proper CI. Right. So these are all the issues,
but that is something I'm going to figure out in the next 3, 4 months.
And I also need it. So, you know, I'm going to make
it good for everyone. So that's number 2, managed CI. And third one is adding
subscriptions. That's a pretty straightforward one.
But in order to be open for business, I need
to take money. Otherwise,
it's not a business. Your multiple 20-core
servers are not free. Is that what you're saying?
Unfortunately not, but they're surprisingly cheap. So the one I'm running
now is like €35 a month. It's a
good deal. It's so cheap. Yeah. It pays
to run it bare metal. It does. I mean, 20 cores,
64 gigabytes of RAM, a 1 terabyte
NVMe disk, 2 actually, you know, for RAID,
I think. Yeah, 2. Yeah.
But yeah, so these 3 things and then beginning of '27,
generally available. Yeah. I also,
in October, I'm going to be more or less full-time on Pushin. So,
like, I'm kind of winding down my other contracting work,
except for the EEF, that's going to continue. And then I'm going to be full-time
on Pushin, plus the 2 days
a week I get from the EEF. Wow. Very nice.
So you'll be able to really be able to
push it forward. I'm gonna push it. Yeah. I'm gonna push
it. It didn't quite work as I thought it would in my head, but— It's
fine. We can do a follow-up next session, in the next episode.
There we go. Very nice. Well, we're excited to see
where this is going because it's a very cool project, Peter.
Thank you. Thank you. All right. Let's wrap it up.
It's been an hour. I thought we would be much shorter. Still, we just
kept rambling on, and here we are.
That's the way it is. It is what it is.
All right, everyone. Thank you for listening yet again to another rambling
episode of Macro Mayhem with myself,
Gus Workman, and my good friend, Peter Ullrich, on the other end.
We will be coming back in 2 weeks, which is gonna be Goatmire
time, but I I'm available to record something from
the Goatmire camp. We might do something from Goatmire.
Yes. So, keep your eyes open,
not eyes, ears open. Look at your phone at all times for the notification
of the next Macro Mayhem episode, which will come to you just
before Goatmire. Yeah? And if you're around at Goatmire,
come find us. Come chat. Yes, please. We'll be there.
And I'm gonna wear my ugly sweater, maybe.
All right, everyone. All right. Have a good one.
Thank you for listening. See you next time on Macro Mayhem.
