005 - OTP Security Releases, ElixirConf US, and Goatmire Badges

All right. Welcome to another episode of Macro Mayhem. My name is Peter Ullrich,

and today is Thursday, the 17th of September, local Berlin

time, 11:13 in the morning. Well, it's important

that we state this kind of time zone, time stuff,

because the world of Elixir and other languages has been traveling

globally in the last 2 weeks, going to the US and

back, and we're not... We're not. And I'm here with the world traveler

himself, Gus Workman. How are you doing, Gus? I'm doing pretty

good. How are you, Peter? I'm doing just fine.

I was awoken by a pressure hammer,

you call that, like a jackhammer this morning in front of my window.

So, I'm dandy. I'm very good

today. Very good. I see the light in your eyes.

It is very dim. Yes.

But if you're not on the video, if you're not watching the video

on YouTube, it's fine. I'm going to explain to you because I already changed into

the proper Sweden attire. I am wearing an ugly

sweater. I think that is the official brand name and fashion style

name, ugly sweater. It is mostly black,

but it has white spots and the trims are in red, and it's very comfy.

So you got to appreciate the Swedes who said, why be

fashionable and comfy at the same time? if you can

just choose fashionable. So, no, sorry,

comfy. Ah, I messed up my own joke. Anyway,

Gus, let's head on. We have a very short

news and blog section this week. It hasn't been that much in the last week

or two, right? So, let's just get into it. Let's start with the first news

item. We can hop right into it. So,

first up in the Elixir-ish news, Elixir-adjacent news,

Is that there is an organization actually located

here in Luxembourg at the House of

Cybersecurity here in Luxembourg that reports the rankings

of individuals and organizations who have reported CVEs.

And you, Peter, happen to show up as number 102 globally

on that list. And Jonathan, the— At the EF,

is number 69, as of this morning. You actually

got bumped since we looked at this last, right? Yeah, it changes.

It's just a little tidbit I wanted to throw this in here, which was funny,

because I saw, Jonathan actually saw that, yeah, he and I were ranked in

the top 100 worldwide, out of 28,000 people who were

mentioned in the CVE record, like, they're all credits, you know. And he

and I were in the top Well, I'm 102, so just on the edge,

but that's gonna change any day now. But Jonathan

is tied for the same number of CVEs reported as the Mozilla

project. So that's pretty cool. And the Microsoft

Response Center, Security Response Center. Actually, he's ranked even higher,

but we changed the format of his name a while ago, where now

it's Jonathan Mentjen/EEF, and before that, it was just Jonathan

Mentjen. And he has, like, 15 or so reports that are not

associated with the /ef version. So,

he's actually higher up if you— yeah. So, if you'd be

looking at the numbers, there'd be, like, 63 or

62, somewhere in there. Yeah. Yeah. So, he's all the way up.

And another piece of information here is that actually the

EFCNA, so, that is Jonathan and I, or it's

not Jonathan and I, it's the EF and the CNA, right? It's also a group

of people. But we are in the top

25 worldwide and 26 for issuing

CVEs. And we're in the top 10 and

they're all kind of, well, we're in, I think,

position number 10, but all the position 1 to 9 are

tied to position 1, basically. They all have the same results

for the quality of CVEs. Because a lot of

CNAs, they, you know, they're rushing out CVEs now, so they're not filling out the

records properly. So it's hard for the user and security researchers to

understand what's happening in a vulnerability. But the

EEF is extremely good about filling out these records. So I

think we only have 2 records which don't have fixed patches. So,

like, no fixed version. Okay. And that's what is keeping us also

from that top 10 group. So we are

definitely punching above our weight. Just wanted to point that out. That is very

cool. And again, this kind of goes back into all of the work the EAF

is doing and promoting recently that this security work is incredibly

important. First of all, huge thank you to you and Jonathan for

helping secure ecosystems. I know we've said this before, but you

guys deserve a lot of praise for it because it's, it's thankless

work, but it benefits everyone. Yeah, thank you. And, and also,

I wanted to point out that we're doing this not

through a lot of Elixir funding

or funding coming from the community. That is definitely one

issue where we have outside funding from, I think, Anthropic through

a foundation that now pays me, for example, and also largely Jonathan's salary.

But if it wasn't for that, there would be nobody being paid

and nobody would do that work in the Beam ecosystem.

So just wanted to, you know, and we're doing this with like 1.3 full-time

employment, like 1.3 positions where other groups, they have 10 and they're now

stocking up to 15 full-time positions. So we just

wanted to point that out there that all of this is being done on

the verge of, you know, not being funded well. So yeah.

And on that note, the EEF also has changed

their their sponsorship packages.

So now it's more clear to companies in which package they can

invest or donate, and then they would land in. Right. So if

your company has value from all this

vulnerability research that we've been doing, they should consider

donating and support this and fund it more sustainably than just

outside funding that can go away after 6 months, for example.

Right. Enough on that. Well, actually, not enough on that. Let's continue. We'll talk more

about it later, but let's continue. There's other security news,

right? Yeah, very quickly, there is a new OTP security release

that includes 2 pretty nifty vulnerabilities.

Well, there are a bunch of CVEs, vulnerabilities or issues, but 2 big ones.

One of them is, it's always the same, there is an internet package

in Erlang, in OTP, like inet or inet.

And if you use that to

make HTTP requests, there is a vulnerability that somebody can basically

create, like, 2 gigabytes of memory usage,

if they respond with a malicious response, and then crash

your Beam. So that one is fixed. And the other one, it's also

one that actually affects a lot of OTP, and will—

yeah, it's now fixed mostly, I think largely,

which is— I also didn't know that. But string,

No, string to integer, this way around. String to integer,

if you just do that. If you put in a string that is 1.2

megabytes long, which is a very large number, and you do to_integer on that,

you will basically pin one process for many

seconds. And then the next time you use that integer, also,

it's going to slow down your application. So, that one has

been partially fixed now because the The limit there is just limited now.

So, that was a fun vulnerability I found because of the version package in

Elixir, where I was like, you know, Claude told me, hey, if you put in,

like, 1 to the power of 10 million, yet again, Right. and then

you do string to integer, it takes, I don't know, 30 seconds, 50 seconds until

a response. I was like, what? So, we, you know, we, there has

been quite a lot of work from

the OTP team, and they fixed it now in a lot of places in

Erlang. So, there are releases for that, security releases, so please update your OTP.

And then also, you can upgrade right away to OTP 29.1

if you're on the OTP 29 version.

29.1 is mostly maintenance and bug fixes. But,

you know, while you're at it, go ahead and upgrade to the

latest. Yep. Great. So,

that also leads into— there's Rebar stuff too,

right, related to OTP? Yes. So,

Rebar 4, it's a project on Kickstarter

that got funded, and they're currently working on Rebar 4.

Rebar 3 is, I think, mostly the Erlang ecosystem package

manager, if I understood that correctly. It's the equivalent of Mix,

right? Mix, right. Yeah, but then in the Erlang ecosystem.

And it has been not like— it has been only on maintenance

mode for a while. And now they had this project to upgrade it to Rebar

4, which would integrate it into OTP itself, because right now it's an

external package you have to install and configure. So they want to bring it

into OTP, and then also make it a tool

that you can also use in all the languages, not just in Erlang.

So that would partially, especially if you have a project that uses Erlang

and Elixir, and another language maybe. I also learned today there's

a Lisp-flavored Erlang. Okay. LFE.

Yeah, if you use that, then in the future, you can use Rebar

And the project has asked for input from users in the ecosystem,

because now they can look into plugins for the

rebar tool. So, for example, to connect to Hex or run

xdoc, that kind of stuff. So, they're asking

for your input on which plugins to prioritize first for compatibility

testing. So, if you're in a

project that uses Erlang and Elixir and/or Gleam and/or

other Beam languages, It might be worthwhile to take a look at that discussion,

contribute to it, and tell them where they should prioritize their efforts,

right? Exactly. Yeah. Cool.

Well, next up, we also are starting to see some

of the ElixirConf EU 2026, so in

Malaga this past spring. The videos have been— are

in the process of being released. As of this morning, there's 43

videos in the playlist. We'll link the playlist down below.

If I had to give you some talks to check out, I saw that,

Peter, your talk was already uploaded, which was a

fun one. My talk was there. I saw

a whole bunch, like, there were so many good talks at ElixirConf EU 2026.

So, go check them all out. And the keynotes

have been out for a little while, but the smaller, not keynote talks

are are sometimes just as interesting, if not more.

Yeah. And I also saw that some of the ElixirConf US videos,

they're also already published, right? Like, some of the keynotes and some of the—

The keynotes are starting to be published, yeah. Yeah.

Okay. So, we'll talk a little bit more about that. Yeah. Good.

Then, moving on to the blog section.

First, I'd like to toot my own horn, which is that I

wrote a blog post after a long time, And it's about announcing Pushin,

the Git hosting platform I'm building. And I laid

out in the blog post what's my motivation, my values behind Pushin.

So we're going to talk about Pushin in the end in the discussion section.

So I'm just saying, if you're interested in learning why

I'm building this thing, I wrote a blog post about that.

Very good. There's another blog post by

Nathan Long. Called Label Your Processes.

This was a nice short quick blog post, a little quick tip

that you can add labels to your processes and it

shows up in if your GenServer crashes or when you're in the Phoenix Live dashboard,

you can see all of the process lists. I think probably Observer

as well would show them, but it's a simple way you can

You use Process.set_label in the

code, anywhere that you want to set up a label for your process, and then

you get better insight and debugging. So it's a very short,

quick blog post, but it's a good one. So thank you, Nathan, and check it

out. I did not know this. Yeah,

because every time I saw processes in Live Dashboard or an observer or somewhere

else, it's just the PID. Yeah. But yeah, this is a way of naming them.

That's smart. Very good. And then last

blog post, it's written by the Erlang Ecosystem Foundation, by Dan.

It's about how we defend our ecosystem against AI threats. And sorry,

we've been talking about this for quite a bit. I think this is the last

item where we talk about it. But yeah, Dan did

a good job of kind of writing up our work of the last couple of

months, like where we, what we've done, where we're standing now and how we are

going to continue defending and

securing our ecosystem against AI

threats, but generally bad actors, malicious actors, and vulnerabilities.

So, it's a good blog post to check that out.

Next, we do have, I think this year, we're only going to have 1

or 2 more sections of this because there's not too many conferences

and meetups after Goatmire and Codebeam. So, Gus,

I need to— Well, meetups. There will be meetups,

but conferences, I think the big ones are coming

up here in the next couple of weeks. So Goatmire is first,

September 27th to October 3rd in Varberg, Sweden.

We will both be there. Peter is talking. I'm running a workshop. It's going to

be a really great time. I have some more info in the discussion

section about some of the cool things that you're going to see there. So stick

around for that. After that, just another, what,

3 short weeks after that is Codebeam in Haarlem in

Netherlands. That's October 21st and 22nd.

And you can get your tickets for both those at goatmire.com and

codebeameurope.com.

And I timed you. You are getting faster and faster

every time we do this. Perfect.

They're getting shorter and shorter, so... Yeah, that's true.

Both, maybe. True. So,

yeah, I wanted to also add one thing, which is I got contacted

by the CodeSync marketing team, the team that runs

Codebeam Europe '26, and they gave

us a code we can share with you for a 15% discount

code on the tickets. So, if you haven't bought your tickets yet and you want

to buy the ticket with 15% off,

you can just use the code Peter Ullrich 15.

Sorry, it's not Macro Mayhem.

I did not choose this one, but Peter Ullrich, and Ullrich with 2 Ls,

don't forget the second L, 15, and then you can get 15% off the

ticket. There we go. That helps. It pays

to be a Macro Mayhem listener. It does.

You're literally making money by just listening to this podcast.

Exactly. And none of that comes back to us. It's just supporting the

conference and supporting you to get in there a little bit,

at a little bit better price.

Exactly. All right. Anywho, that kind of wraps up

our meetups, blogs, and news. Peter, do you

have a joke for us this week? I do.

How about this one? So, why is dark written with

a K and not a C? Because you can't

see in the dark.

Very good. Okay. That's corny. Check. Can't see

in the dark. Yep. Check that box. Can't see in the dark.

Exactly. Well, well, well. Well, this is

the section. We've covered the news, the blog posts,

If you wanted to stick around for the discussion, we're gonna be talking about ElixirConf

US, Goatmire, and some Pushin follow-ups.

So, yeah. So, yeah, moving on to the discussion. Gus, you have

been our reporter on the ground at ElixirConf US in Chicago.

How was it? It was good. So,

Chicago was lovely. I'm still a little

bit jet-lagged, to be honest. Quite frank.

But it was a great time. I got in on Tuesday

last week and stuck around until Sunday.

And yeah, the conference was— I mean,

the CodeScene conferences are really well organized. It was in a nice venue

at the Voco Hotel in downtown Chicago.

It was up on the 14th and 15th floors. So got a pretty

good view overlooking the river. in the downtown. And then,

yeah, talks were all pretty great, the ones that I went to.

I felt it was a little bit smaller than ElixirConf EU, and I

hadn't— this was actually my first ElixirConf US. So,

I hadn't been before, but I didn't realize— I was

under the impression that ElixirConf US was slightly bigger, for some reason.

Yeah, me too. I would also think so. I think there was a

rough estimate of like 500 people there.

Hmm. Though, I don't know, maybe it's just that the room size was smaller

for the keynote speeches, um, and that's

what made me feel like it was a little bit less attendance. But, but it

was really good. I mean, it doesn't— I don't mind the smaller space because you

have— get rid— get more involved and interactive

in some of those presentations. So Nice. Good.

Speaking of keynotes, the keynotes, I think most of

them are already on YouTube in the playlist

that we'll link in the description. I think the one

that was missing was José's keynote on

his updates on some of the type system stuff.

Yeah. They were all really good. And I didn't even get the chance

to go see all of them. So I'm gonna

be checking out some of those YouTube videos as well. But yeah,

I think my favorite keynote that I saw was Zach

Daniels' Exoskeletons,

Not Autopilots. And so this was a— it

was less Elixir-specific and more about

how to build AI systems that work

for your team rather than replace it. Yeah.

Was kind of the tagline that he was talking about. And yeah,

I think he had an interesting approach building up an incremental—

and I mean, Zach has a lot of experience with this right now because he's

a VP of engineering at Remedy Meds and is building the

team there and building AI systems for internal, external use.

So, like, It's pretty interesting,

his viewpoint on all of this. So,

what were his tips, so to say? So,

first of all, what was he building and how did

he build it? Right.

So, let's start

with how he suggests the approach to AI to

be. And that is starting from No AI.

Forget all of your Claude skills,

your Claude plugins, your all this stuff.

And his suggestion was to start typing prompts

in like we did back in 2025.

Yeah. Old school. Old school. And see

where it goes wrong because the agents are relatively easy to

get off track if they don't have a framework to use. And then from there,

start writing your Claude MD file. And of course, all this is generalizable

to other agent frameworks, so Agents MD file. And then

as you realize there's a bunch of things that are not working

for you, then how do you go from expanding that Claude MD

file to then maybe you can create your own skills?

He mentioned usage rules, which is a Ash-adjacent

project. I don't think it's Ash-specific in any way, but it's— I

think Zach was the creator of it, who— and it's where library

authors add skills or add information that can be compiled into skills

for their libraries so that agents know how to use their libraries.

And so, I mean, none of this that I've said so far is new stuff.

I think this is early 2026. A lot of this, you could have already found

this information and applied this. But where he got interesting is

that He said, okay, so you want to do this and

start automating your workflows and working using agents

to augment some of the things that are low

value but high time in your workflows. And so first,

throw agents in a GitHub Action. So there is a— you

can— GitHub Actions has a Claude action where

you can just use Like, it's in your YAML file.

You can add uses Anthropic/cloud-code or something

like that. And it just adds Claude to your agent.

I think you need to add an API key. I don't know how this works

with subscriptions. Mm-hmm. I'm sure there's other providers that

do all this too. But his suggestion is throw it in a GitHub Action first.

Then you can throw prompts in there. And so, like, for example,

when it's a push, on push for a pushing

up a branch or creating a PR, then you

can run this GitHub Action automatically and say, do a code

review, do whatever, do evaluate this for security vulnerabilities,

whatever the prompt says, right? It doesn't need to be a crazy complicated prompt.

Most of the time it's going to be able to figure it out. And then

once you're, once you're doing that, I mean, there are tools that do this,

the code review PR or, or AI code review tools,

GitHub Copilot, for example. But Claude

is what you're working in your, in your existing workflow and all your skills,

whatever, all the documentation that you've written for your repo

lives in that repo. So that Claude instance will

have the same access to it as a human. Oh, that was another point that

he made is that build your systems for humans. Write your documentation in just standard

MD files in your docs directory, things like this.

Keep it up to date. But the agents

know how to use— like, if it's easy to use for a human, then it's

easy to use for an agent too. True. Yeah. So he

started with the GitHub Actions, then how to make it even bigger,

connect to Slack, to Jira, to whatever you use. And then when

you get to a large enough point, you can start creating an internal

AI, like, hub,

a place where you can have all your team members coordinate things.

So I'm not going to spoil all of the juicy

bits at the end because that was probably, what, first half

of the talk that I gave a quick overview there of. Go check it out.

It's a good one, especially if you're in larger teams, I think.

But there's good insights for small, small, smaller teams too.

True. And in the second part of the talk, he talks about everything that

goes wrong. Yeah,

it's interesting that he says you should use it to build for your team.

And, you know, what I see and hear a lot is people just buy products

and then they think magically everything goes better, but they don't integrate

into the process. They don't update the processes to integrate the system. And just

like, oh, I paid $10,000. Now we're efficient. That's it.

Now we've reached AGI. Yeah, exactly. We have AGI now.

Okay. Good talk. I'm gonna check that one out. And all

of the talks are here in the linked playlist, right? That's the playlist

to the ElixirConf 26. And as new videos come

out, they will be added to that playlist as well.

Right. And if you wanted just a short and sweet one, One that's near and

dear to my heart, John Carstens gave the Nerves update, which is

already the state of the Nerves or something.

I forget what it was titled. Just a core team update on everything that's happening

in Nerves. It was only 15 minutes. It's a very good talk. He is a

very good speaker. And, you know, I like

Nerves. So— Yeah.

It's a great system. Like, I wish I could just do Nerves

all day and not have to Build web apps that people

use, you know. People using web apps.

Yeah. Yeah. You know, the hardest part of building a business

is first getting customers, and then the second part is having customers.

Yes. Yeah. And,

but yeah, I mean, we have a big controversy that we still need

to, you know, settle. So you were in Chicago.

I was in Chicago. Did you have a deep dish pizza? I did

have deep dish pizza. What's your professional opinion

on the deep dish pizza? Okay. So, we had it

at Lou Malnati's, which is a— I think it's

one of the original claim to fame deep dish pizza Chicago

places. They've kind of turned into a bit of a chain and they have a

bunch of different locations.

And the verdict,

I've had deep dish before, But it has been a couple of, a number

of years. My verdict is that still, that is a casserole.

So, I'm sorry to the deep dish pizza

lovers out there, but I love, I mean, calling it a casserole doesn't

change how it tastes. It's still delicious, but it's

a casserole. Okay. And why is that?

Because you have the layer of crust, and then it's like,

A whole 2.5 centimeters, 1 inch of

cheese, and then sauce. And it's just, it's heavy. Pizza is not

supposed to be so heavy. No. If you know the

original Italian pizza, they're always thin,

super thin dough. And then, you know, some also a thin layer

on top, but it's a really light thing to eat. Yeah. Right.

It's light. No, the similarity is that with the Italian pizza,

And the Chicago deep dish, you eat them both with a fork because— Oh,

true. Yeah. The Italian is too floppy.

You can't pick it up with your hands. You need

to wedge it into like a triangle, you know, like hold both

ends to make it kind of like a,

yeah, like a triangle kind of thing where the ends are up and then the

middle, and then you put it in your mouth. That's how you eat. Yeah.

But I know, like, you know, not everyone is—

We need to go do some testing on this. Yeah,

exactly. Not everyone is as streetwise as others.

Yeah. Apparently. Yeah. You know, if you hate

us for doing this, just call us Pizzagate. This is the

Pizzagate incident on the Macro Mayhem podcast.

But I think now we have covered this topic enough, and we shall never

talk about it ever again. We shall not. And if you have something to say,

shout it at the clouds. We shall receive

your feedback somehow. Indeed. Well,

that being said, the kind of final tie-up for ElixirConf

US is that they— I

always am curious after a conference where it is gonna be next year.

And the options for next year that we did

an audience cheer

metric voting for at the end of the conf was

back in Chicago. So, either there could be more deep dish on this podcast,

which is what made me think of this. Who knows? Oh, God. Or Toronto.

So, it might be ElixirConf North America next year instead of

ElixirConf US. Interesting. It will be interesting

to see where Yeah.

In a year from now, Toronto might be a safe

option indeed. Yeah. I would come to Toronto. That would be nice.

Yeah. But then we have no deep dish pizza. Do they have something in Toronto

we can complain about? Any food stuff? Let us know in

the nonexistent comment section. Yeah. Tag us on

the socials. What shall we try in Toronto? What's the

best pizza? food in Toronto. There we go.

Well, speaking of conferences and all those,

one thing that was kind of fun for me at ElixirConf US

was talking with José, and I showed him

the secret project that we're working on for Goatmire,

and he ended up posting it on his socials.

And now— That was a, that was a very private conversation

indeed. It is public.

So, uh, Peter, you've kind of seen what I've been working on,

but you haven't seen the latest. For Goatmire, last year

we did, um, we did Nerves name

badges. Everyone got an e-ink Nerves

name badge, which is kind of what the Nerves starter kit has turned,

like, evolved from, from that project. This year we

have name badges again, except they are AtomVM powered.

Now, if you're on YouTube, Mm-hmm. I'm going to hold it up. And if you

can see this, you can see it's

pretty cool. It's a little bigger than last year. I will explain it to you.

I will explain it to you. You'll describe it. Yeah. So me, as a non-Nerves

expert, what do I see in front of me? I see in front of me

a case that is of white,

you know, 3D-printed plastic. It, like, the case is

approximately the size of, like, a Kindle, I would say.

A Kindle, what's it called, paper white. So, like, the really small

ones, yeah. Yeah, like a good 10, 12 centimeters.

I'm not sure how many inches that is in freedom units.

Yeah, I think it's 10 centimeters by 12.

I think you're right. Yeah, there you go. So, 10 wide,

10 tall, 12 tall. It has an

LED or an e-ink display at the top.

It's an LCD. LCD. Ooh, that's fancy.

So, it's full color. Yeah, it has some

red buttons, yellow, purple buttons. I can see different

colors. It has very— it looks very clear in terms of rendering. Like, the text

looks much clearer than the E Ink one. It updates the seconds in

the navbar every second. So, that's also really responsive without

refreshing the whole screen. So, that's cool.

There is a gap next to the display that I already pointed out to the

creator of this badge multiple times, but he chooses to ignore me every

single time. But the display is slightly off-center,

which I find absolutely unacceptable. But, you know,

it's just a design choice, I would say.

You're funny. I changed it due to your feedback.

The final product, the final product, the final result at

Goatmire will have the display centered and covered

up that strip. That's, that's it. So, if you get your name badge,

Take out a ruler and measure whether it's centered or not.

It better be. It better be. Okay. And then the bottom part,

the bottom part of the badge is a massive keyboard.

And these look like these soft rubber

buttons you can click. Are they soft or are they hard? They're soft. They're silicone.

Silicone. It's a silicone keypad. And yeah,

it's a full keyboard. You have The number row,

you have all the QWERTY, you have the arrows,

Shift, function keys, all that stuff. In total,

there is 70 keys, or 69. I think there's 69 keys

on this board. That's a lot of keys. It is a lot of keys.

There's even a Delete and Escape and everything. Some other cool

ones. There's a Super. Like, it's a full keyboard.

So, this will be the Elixir development equipment,

the computer you will use in '27.

You just need this. You text, you know, you're walking outside, you're texting

on it, you're writing Elixir code, or you're prompting your LLM that then runs

the GitHub Action to actually write the code and review the code. So this is

going to be your main development computer from '27

onwards. You got it. Actually, funny enough,

Lars added an agent mode. There's,

okay, there's literally an LLM chat window

you can open, like an app you can open and you can chat with an

agent. There you go. Maybe not an LLM. I'll leave that for,

for you to discover at the conference. But,

so, what is this thing? So you've just kind of

described what's here. Um, is it, do we miss anything? There's, that looks right.

Do you want to describe the back now? The back, it has a battery

just hot glued to a PCB,

which looks very professional. Like, this is the way you connect

a battery to PCB. And, you know, that's what I would do.

And especially the best way is actually to hand out the batteries and then

have the attendees of a conference plug

it into the devices. Like, that is a safe option.

So I see a massive big battery, which will explode at any moment.

In ahead of the, at the top of that is it's connected to

the PCB. And then it looks like a custom PCB that has,

well, they're connected to the display on the one side. And then at the top,

is that, is that a, no, that's the processor,

right? At the top, this, yeah. This one. Yeah.

It's like a silvery aluminum-looking

square, which is the processor, I guess.

And then there are a bunch of like black dots and weird things.

Different components. And then down here we have a USB port on the bottom.

Is that a USB-C one? Oh, you bet. Oh, good.

That's European compliant. Very good.

Yeah. So, yeah,

it's a custom PCB. There's a display connector. This one here,

the main chip running this is an ESP32-S3.

And it's a— that's a— if you're not familiar, it's a

microcontroller with Wi-Fi, Bluetooth capability,

and it runs AtomVM. So, all of

this is still Elixir, but in AtomVM

land, which has been quite a joy to work with on—

while we've been making this. So, I'm excited to get,

you know, 300 people,

300 attendees, some AtomVM badges in their hands,

And then they get to experience the same joy of AtomVM

that I do. That is, that is very good. Last question though,

will the final product have a back panel or

will it blow off my hand? Right. So it does have a back panel.

I had it off here for you. And you have to excuse

this one because it's the prototype and it does not align. There is an

acrylic back panel. It's tinted. That is awesome.

acrylic. And so it, you can still see through the whole thing,

but it gives the whole thing a nice tint to

it. And you can see the LEDs that we have here.

So to the listeners out there, because we're explaining

something visually, which is the best thing to do on a podcast,

the back panel of the final product is, yeah, like tinted,

right? Like a darkish, dark, kind of like sunglass glass.

You can still see the PCB and everything. You can see the battery,

You know, because that will tell you that it's gonna explode soon. But if

you turn it on, there are 4 fancy LEDs that

are in, like, a blue— oh, actually, they change colors. Oh, look at that.

Yeah, these ones are— I have them set to do rainbow.

Yes, they— so they— When you have RGB LEDs, it makes it go faster.

Exactly. And if you have rainbow LEDs just blinking,

it's immediately a professional device. Exactly.

Very good. I like this. And it, like, the thing on the top to

hang it, that's like a— Right. Yeah.

That's gonna be for the— to hang it down on your chest, right? So that

it explodes over your heart when it explodes. Exactly. Good.

Hopefully, there will be no batteries exploding. Hopefully.

That's like— let's see. We're not engineering

for it, but we're hoping for it. We're hoping that

they do explode? No, we don't, but we are not preventing it either,

are we? No, we are. Everything is safe. This will be a completely safe product.

Yes. It has been engineered to not explode,

Peter. Very good. Very good. That's— I'm glad to

hear that. Yeah. So, anywho, this is the badge.

Um, there is gonna be a workshop in the

days before, uh, the conference starts at Goatmire where we are talking about

How to add custom screens. Speaking of

screens, I didn't even mention what is on this. We didn't talk about that.

What screens did you see? So, there were a couple of apps I would

call— oh, first, when you set it up, it says Goatmire. And then

it goes into kind of like an app store where you have different apps you

can start by pressing a button.

The first one is name, which will be your name

badge, I assume. The second one is Nameless.

It says nameless right now. Yes. Okay. You can edit your name

and then it will show you. You can edit your name. It starts as nameless.

Yes. So, the second one is chat. What does chat do?

Chat is a full chat room. And unfortunately, I'm not

connected to the Wi-Fi right now, so I can't show you. But the idea is

that you can join a chat room, call it general or

current talk or Extracurricular or

whatever, run a club if someone, I don't know, whatever chat

rooms people wanna make, we can make chat rooms. And then you can type little

messages and view them throughout the conference. And, and this is going through Wi-Fi?

And this goes through Wi-Fi. It uses WebSockets. It talks to a Phoenix channel backend.

And— So, when we are out and about in the city, we can connect

it to our hotspots on the phone and then chat through this device

with other attendees and coordinate where you're having beers. After the conference. Exactly.

Perfect. That is much better than Signal. Word on the street

is that Varberg has a public Wi-Fi system that you can connect to. So you

don't even need the hotspot. I don't know if, we'll have to test it and

see if it is able to connect, but.

That's awesome. Then, yeah, and then we

have test, which I assume is a test screen, or text is a text.

Text. It's just a text box input. Some of these are testing.

And we're going to remove one before. And then we're just— allows

you to type keys and show up on the screen. Yeah. And then we have

LED center.

What is this? This controls the LEDs on the back.

So now they're white. Okay. But let's

keep some surprises for the actual conference. Otherwise, nobody's going to come.

Yeah. Well, what's the purpose of coming? No,

they know everything already. Exactly.

So anyway, this has been something I've been working on for quite

a while and really excited to, you know,

get it in people's hands at Goatmire and just have fun with it.

Every year we are increasing the level of nerdness of

these badges, and I'm excited for this year to see the

next level of nerd. The next

level of nerd. Oh boy, I need a break. Can you

imagine a more nerdy conference than 200, 300 people walking through

a small Swedish city and texting on like a weird custom device

that runs a weird system nobody ever heard about,

but goes through Wi-Fi and instead of what, do what normal

people do, which is your phone and Slack or something, you know?

Nerds, we're peaking at nerd level here. We will never understand this,

uh, this population, these people. No.

Anyways. All right. Well, come to, come to Goatmire.

We have badges. We do have the best badges.

Yes. So the best badges. Anywho, Peter, let's talk

a little bit about your, the, the follow-up on

Pushin release. Last episode, we were talking about Git

and your GitHub alternative. What's happened?

So much. It's been a crazy 2

weeks. So, yeah, 2 weeks ago, I announced Pushin on this

podcast. I didn't really expect,

like, a full launch yet. I just wanted to share

it with, you know, other people from the Elixir community.

And quite a bunch of you signed up, which I'm very— which I appreciate a

lot. But, you know, still, I thought, hey, it's gonna be like a small invite-only

beta with maybe like 50 people testing out the product, and I can

still develop all the hard parts underneath. Well,

that assumption lasted exactly, I think, 3 days.

And then

Rebecca Lee from Australia, Ash core team member,

I believe. Thank you so much, Rebecca. No, I'm honest.

She posted it to Hacker News, and then Hacker News happened.

And I'm not mad or anything. I actually

appreciate it a lot, because also it threw me in the deep end of the

pool, and I just had to swim. And I probably would have pushed out,

you know, like a Hacker News thing for months and months and months still.

But anyway, so yeah, on a Saturday morning, I woke up and I looked at

my phone, and all of a sudden I was starting to get waitlist signups.

And luckily, I built those waitlists, like, 3 days earlier, you know,

for the announcement on this post, on this podcast. And then,

all of a sudden, yeah, like, waitlist signup after waitlist signup came in. And I

was like, what the heck's happening? Somebody then sent me the link to Hacker News.

And I just looked at my girlfriend. I was like, I got big eyes,

scared face. She was like, what's happening? Did somebody die?

And I was like, no, I'm on Hacker News.

Sorry, we have to cancel our plans.

Basically that, yeah. I worked so much that week,

and I actually told her on the weekend, let's take it easy. Haha.

Yeah. So then I

stayed on page 1 of Hacker News for the entirety of the Saturday.

Even when the US woke up, I kind of dropped down to 25, and then

I went back up to 15, but I stayed on page 1 the entire Saturday.

I worked, I think, 16 hours, just not

necessarily, just answering messages,

I pushed out one or two small fixes because I was getting a lot of

signup spam. I already

had a CAPTCHA in place, but then I needed to also have

the waitlist controls, invite people, block people.

I had some stuff like that, but there were some issues that I just pushed

out quickly. So generally,

takeaway from Hacker News, it was extremely successful,

I would say, especially for Hacker News being Hacker News. I got

very few critical comments. Very few.

I was surprised. Some, you know, like probing comments,

but I answered most of them honestly,

and that seemed to have convinced most of the people. So yeah,

generally very positive. I got 500

waitlist signups, which is— 500? I think

now I have more, 650. I have now,

more than 500 confirmed users that signed up

and confirmed their account. And I can't tell you how many now started

using it or use it how often. I don't have these metrics deployed yet,

but I just, you know. And so that

was crazy. And then what was also kind of

crazy is that on Monday,

was it Monday or was it still Saturday? Right. Like, everything's blurry from the last

week. But 2 things happened. One of them is

the Chinese found out about Pushin, and they started signing up with

bot accounts. Well, not only them, but they were just— let's say

there were a lot of bot accounts. And thankfully, I had the waitlist and

invitation codes, because otherwise I would have, you know, a bot flood

on the platform. So I always sent back,

hey, a verification request. So I asked them,

hey, can you send me, you know, like a social media profile I can check

so that I know you're a real person? Very few of them responded.

That also told me there was a lot of automated signups.

So I discarded those. And then I had to move very

quickly to Bunny, or I decided to move to Bunny CDN, because they offer

some bot protection, DDoS protection, that kind of stuff.

And that, I mean, it was DNS, so it took a little while until

everything was propagated properly. And I'm sorry if on that day

you had some issues with the website. But finally, I moved to Bunny,

and then I realized that Bunny doesn't forward the port 22 for SSH

connections. So I broke all the SSH

connections to the repos. And I,

yeah, so that also took me then more time to set up a subdomain

and send out an email to the, like, 75 affected users to

say, hey, I saw that you have an SSH key uploaded. Yeah, you were one

of them. So I sent out an email saying, you know, sorry, but I broke

your SSH connection, but you can change it with one line, just git

set origin, that kind of stuff.

Yeah, that was the bot flood. And since

I moved to Bunny, that has been mitigated a lot.

I still get some signups, but they're easy to spot, so ignore.

And there was that. And what else

happened? Oh yeah, then all the LLM model scrapers.

They found Pushin. So all of a sudden, I was

getting hammered with GPT bot, Anthropic bot,

and Google bot scrapes. I mean,

Google bot is Google, but they have a particular one for their

LLM scraping. Mm-hmm. Yeah.

And then, you know, all of a sudden, my Grafana, like, the request spiked,

you know, like 15 requests per second, and then all going

through Git operations for fetching all the code that was uploaded in

the public repository. So they were gathering all that code.

And what I did then is I, on my

application side, because I couldn't, I filtered them out on Bunny's

side, but they still hit the subdomain

that I was using for the Git operations because that did,

you know, git.pushin.eu, that does not go through Bunny.

So you can use that for still fetching all the,

the Git repository. So, they were switching from Bunny,

from the public pushin.eu, they were switching to the

subdomain. And then I had to build something in my application that basically

checked the, what's the

header that says something is a bot? Which header is that? I always

forget. The user something? User agent.

User agent. Yeah, the agent, the user agent. So I then built

my own kind of firewall in the app itself to say, you know, if you're

one of these scraping models, no, you can't access this.

Yeah, which kind of fixed it now a little bit. It's mitigated

now at least. Yeah, man. That was like— That's been a wild

ride. I can't believe it's been, what, 2 weeks?

It feels like a year or 6 months at least.

Yeah. Yeah, so that was a lot of fun, a lot

of hard work, a lot of learnings. So if you can

also update your first, like, your website, you know, to make sure

that all the FAQs are there, that you have a privacy policy,

terms of conditions, I added that.

I also added now a status page using Johanna

Larsen's product Larm, larm.dev. Oh, cool. I think it's really nice.

So, now you have a proper status page you can look at.

Yeah, man. And then, after that happened, I got,

you know, very, very nice user feedback, which I appreciate a lot. So, there were

people opening issues for things, you know, either big feature requests

or smaller UI fixes, that kind of stuff. And super great.

I finished, or I implemented, almost, like, 30 or so tickets.

So, a lot of UI things were now fixed. Nice.

There's still plenty to do, but it already showed me that people

care about this platform, and they report bugs and that

kind of stuff. So, yeah, that was my launch,

so to say.

It's been crazy watching it, because I was paying

attention to Hacker News, seeing what people were talking about. And I

mean, yeah, generally good feedback, some small nitpicks on Like you said,

you didn't have a privacy policy. Yeah. Which is

fair. Someone wasn't happy about that, which— Yeah. Yeah. Funny enough,

funny enough, the first question I had to answer was, is this a real project

or kind of like a scam? You know?

And yeah, I wrote a big, you know,

block of text on HackenUSA, who I am, what the project

is about, that kind of stuff. And then throughout Saturday, actually, those were the updates

I made. I added the privacy policy, the terms of conditions, which are

kind of like, I adopted them to my product, but they are still kind

of stock terms, that kind of stuff.

Yeah. Which, yeah. So that was good. And now that I have

the launch over, like, you know, launch is

done, people know about it.

I have 3 big things I need to focus on for the rest of the

year. And then hopefully beginning of '27, I can make it generally available.

generally available, and kind of open it up generally also

for people who want to pay for it, who want to move their company repos

over, that kind of stuff. And there are also

interesting things in here that I'm going to write about soon when

I write blog posts about the architecture and so on.

So, the first thing I'm currently working on is to move

away from having a single server to multiple servers. Okay.

Which honestly, if you have a bare metal server with 20 CPUs

and 64 gigabytes of RAM, you can withstand a lot

of load. I was surprised. Hacker News

was on the whole day and I didn't even see a spike in the CPU.

Nothing. It was flat. Flat as Ohio.

Well, that's not the bare metal servers.

It's also Elixir. That's Elixir.

Elixir, and also a lot of performance improvements I've done over the 6

months going there. You know,

I had so many, because I built the first MVP, and it kind of worked,

and then I was like, okay, now we need to make it fast. So,

I had many, many rounds of performance improvements. So, even having,

you know, 20, 30 requests a second for repos, like, they were

all in the millisecond range of responding.

So that was not an issue. Yeah.

Yeah. So my next 3 big things, my blockers

before I can make this generally available is,

first of all, I need to move from one server to multiple. And in order

to do that, I decided to build my own reverse proxy.

And I evaluated the existing ones like HAProxy,

that kind of stuff. And of course, they're good and great and battle-tested.

But I think I have a unique enough use case to,

you know, legitimate— legitimize building

my own reverse proxy.

And the big thing here is that I'm doing session

repo affinity. So, that means I have one repo

always on one server, and every request to that repo

is being served through that particular server. Mm-hmm. And that allows

me to optimize for the on-disk cache, because I

have the repo locally, and I do all the Git operations locally, and then I

upload to S3. Right. So, yeah, if I would round-robin

these requests over 2 or 3 servers, every server

would need to keep a copy of every repo. And then also,

when the next request happens, it would realize, oh, I don't have

the latest version, and then it needs to fetch from S3. So, that's just

stupid. So, I decided, you know, let's keep it on one single

server. If that server goes down, we fall over to the next one, and it

downloads in a couple of seconds the stuff from S3, and it can start

serving requests. So, that's not an issue. But just having that server

affinity, sticky session, so to say, it's okay enough for RESTful

HTTP requests. I mean, that's okay. Yeah. But then when it

comes to WebSockets and SSH connections, then it

kind of falls apart. Yeah. And so

that's— and also, especially then when you have a LiveView website that has

a WebSocket and long polling, that's actually the big issue here.

Not the WebSocket, because once that's established, that's fine.

But the long polling, which HTTP requests always need to hit the same

server. Otherwise, Phoenix is gonna say, hey, I don't know this session,

and you have to reconnect. Right. every time you hit a new server, which is—

that doesn't work. Yeah. So,

currently, I'm building a reverse proxy that is handling

all the session affinity to the server.

It's going to do it for HTTP, WebSockets, and SSH

connections. I have to terminate all that on the reverse proxy,

and then set up a second layer of,

like, either sending HTTP requests to the server between reverse proxy and

server, or create a second WebSocket between reverse proxy

and server. And I'm also gonna do that for SSH connections,

which, you know, I have SSH to the reverse proxy, and then from the

reverse proxy to the server, it's gonna be a WebSocket connection, because that allows

me this 2-sided communication.

Yeah. And that's all built in Elixir as well? Of course.

Yeah. Of course. Yeah. It's surprisingly easy-ish,

I would say, because you have Bandit to receive

the requests, and then, For handling all the connections

to the server, I use Mint. Well, I use req,

req HTTP requests with a Finch pool.

And for the WebSockets, I use Mint, which supports that

really well. Yeah, those are the 2 big ones. WebSockets in Mint,

HTTP requests with req and a Finch pool. That's basically

it. Yeah. Very nice. So, you'll have to definitely post some

blog stuff and talk more about it here when you do that.

I will write a whole blog post about the general architecture and then also in

particular about these aspects. But I'm also planning on making the

reverse proxy open source once I can, like, test it in my

production. And I'm writing it now already in a way that if

you wanted to reuse it, like, it's not going to be a library you can

pull in. I don't want to go that far, but you could fork it or

copy it into your own repo. And then I built

it in a kind of like a plug-and-play way that you can, you know,

rip out my plugin, because I also use Postgres for storing

the affinity, the placement. You know,

I thought about using a clustered

reverse proxy cluster that then uses broadcast to inform each other

of the placements. But then you run into split-brain issues,

you run into race conditions.

And so I just decided, you know what, for now, I'm going to literally

store the— in which server do

I store which repo? And I'm going to look that up from the reverse proxy,

cache it. And then if the Postgres things changes, it sends a

notification to the reverse proxies, they update their cache. Right.

So, you know, ideally, there would be no database, and it

would all be consensus-based, but I

don't, I don't wanna go that far. So, well, we'll have to see how this

works for you because, I mean, this is not

a small task, but I'm sure you're gonna learn a lot along

the way. So, yeah, I will. I do.

But in the end, yeah, the idea is simple-ish.

You know, you, you receive a request and then, yeah, you have a, a pair

process that connects to the server and just But

yeah, the devil lies in the details there, definitely.

Definitely does. All right, so that was number 2. You had one more thing before

general availability? So number 1 is the reverse proxy. That's what

I'm working on right now, next to fixing UI issues. Oh, that was number 1,

right. Number 2 is adding actions,

so CI runners. I already support self-hosted

CI runners, so you can run your Gittee or Forge Runner

on your own device or on a server, and then connected,

registered with Pushin. But it's working, but the UI,

it's not that great yet. It's still, the support isn't that great yet. So I'm

working first on getting the UI ready, getting the lifecycle

correct and polished so that if you have a job that fails,

it notifies you, and the

jobs are enqueued properly. And if you, for example, schedule a

job because you push to a branch, and then you create another,

you push another commit to the same branch, branch, like the new job should supersede

the old job, that kind of stuff. I'm just kind of like polishing

that whole experience. And once that's done,

I want to start offering you a managed CI service

as well. And whoever, like, if you ever thought about

doing managed CI, it's a freaking nightmare security-wise.

It's just, you literally execute other people's code on your hard It's

the worst possible thing. Yeah. So that

will take a lot of time. And ideally, and I think,

like, if I can, and I think I can, I'm gonna use other

people's infrastructure. Like, there's something in

the UK, and there's, like, CoYep or so in

France. Mm-hmm. Like, there are very few that basically

just hand you Firecracker VM one-off instances that you can run your

stuff on, and that you can also spin other Docker images on. Like, that is

actually the biggest Right. Because they allow you to use

a Firecracker VM to run your code, but they don't allow you to start another

Docker image inside that. Maybe it's not a Docker image, but, you know, start a

Docker inside that VM, which you need

for proper CI. Right. So these are all the issues,

but that is something I'm going to figure out in the next 3, 4 months.

And I also need it. So, you know, I'm going to make

it good for everyone. So that's number 2, managed CI. And third one is adding

subscriptions. That's a pretty straightforward one.

But in order to be open for business, I need

to take money. Otherwise,

it's not a business. Your multiple 20-core

servers are not free. Is that what you're saying?

Unfortunately not, but they're surprisingly cheap. So the one I'm running

now is like €35 a month. It's a

good deal. It's so cheap. Yeah. It pays

to run it bare metal. It does. I mean, 20 cores,

64 gigabytes of RAM, a 1 terabyte

NVMe disk, 2 actually, you know, for RAID,

I think. Yeah, 2. Yeah.

But yeah, so these 3 things and then beginning of '27,

generally available. Yeah. I also,

in October, I'm going to be more or less full-time on Pushin. So,

like, I'm kind of winding down my other contracting work,

except for the EEF, that's going to continue. And then I'm going to be full-time

on Pushin, plus the 2 days

a week I get from the EEF. Wow. Very nice.

So you'll be able to really be able to

push it forward. I'm gonna push it. Yeah. I'm gonna push

it. It didn't quite work as I thought it would in my head, but— It's

fine. We can do a follow-up next session, in the next episode.

There we go. Very nice. Well, we're excited to see

where this is going because it's a very cool project, Peter.

Thank you. Thank you. All right. Let's wrap it up.

It's been an hour. I thought we would be much shorter. Still, we just

kept rambling on, and here we are.

That's the way it is. It is what it is.

All right, everyone. Thank you for listening yet again to another rambling

episode of Macro Mayhem with myself,

Gus Workman, and my good friend, Peter Ullrich, on the other end.

We will be coming back in 2 weeks, which is gonna be Goatmire

time, but I I'm available to record something from

the Goatmire camp. We might do something from Goatmire.

Yes. So, keep your eyes open,

not eyes, ears open. Look at your phone at all times for the notification

of the next Macro Mayhem episode, which will come to you just

before Goatmire. Yeah? And if you're around at Goatmire,

come find us. Come chat. Yes, please. We'll be there.

And I'm gonna wear my ugly sweater, maybe.

All right, everyone. All right. Have a good one.

Thank you for listening. See you next time on Macro Mayhem.

005 - OTP Security Releases, ElixirConf US, and Goatmire Badges
Broadcast by