‹ BackHN Continuity

Thread

Fakecloud: Local AWS cloud emulator for integration tests

154 points · 78 comments · theanonymousone

  1. otterley · · focus · HN ↗
    There’s also MiniStack, which forked from LocalStack after they started breaking developer workflows: <a href="https:&#x2F;&#x2F;ministack.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ministack.org&#x2F;

    Both fakecloud and its website look sloppily vibe-coded, and its “authors” are anonymous. It’s going to take a while for it to earn trust. I’d treat it with suspicion. (Curl-to-shell pipe to install? Ugh.)

    1. straygarr · · focus · HN ↗
      Agreed with everything up to:

      &quot;curl-to-shell pipe to install&quot; - what&#x27;s the problem here? that&#x27;s pretty common on linux systems and something the AWS CLI uses.

      Or is the problem the fact that this dev is untrusted and is executing a possibly malicious script on your machine?

      1. MisterMunchkin · · focus · HN ↗
        Running arbitrary code directly in your terminal is very dangerous
        1. luma · · focus · HN ↗
          Any code I didn&#x27;t write is arbitrary code. At some point I&#x27;m left to trust someone or run no software at all.
          1. mulmen · · focus · HN ↗
            It’s a shell script. You can download and read it before you run it. Piping it directly to the shell is reckless.

            I’m not sure how your machine is configured but mine has permission boundaries and security policies that make sure programs are behaving properly. I don’t run everything with my personal user context.

            1. mynameisvlad · · focus · HN ↗
              So then... Just do that and it&#x27;s no longer reckless.

              If someone wants to be reckless they can be. If someone doesn&#x27;t, they also have that ability.

            2. bornfreddy · · focus · HN ↗
              Actually... Server can detect if you are piping or not and serve a modified version for inspection.

              But really, there is no reason not to use prebuilt packages for distribution. Curlpiping needs to die.

              1. [deleted] · · focus · HN ↗

                [deleted]

              2. otterley · · focus · HN ↗
                At first I thought “this sounds like bullshit” but then found <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20230408195648&#x2F;https:&#x2F;&#x2F;www.idontplaydarts.com&#x2F;2016&#x2F;04&#x2F;detecting-curl-pipe-bash-server-side" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20230408195648&#x2F;https:&#x2F;&#x2F;www.idont...
              3. [deleted] · · focus · HN ↗

                [deleted]

              4. mulmen · · focus · HN ↗
                Package distribution is the best solution but why would you download the install script a second time?
        2. john01dav · · focus · HN ↗
          If you&#x27;re about to install an upstream binary with this and you&#x27;re not reviewing this then it&#x27;s purely (irrational) vibes to be concerned with the also unreviewed shell script from the same source.
          1. NewJazz · · focus · HN ↗
            Yeah but at least with a binary you can verify the checksum of a recent official immutable github release rathrr than just trust a script hosted on the website.
            1. darkwater · · focus · HN ↗
              If you don&#x27;t really trust the author, what&#x27;s a checksum going to provide you? That the maybe malicious code released on GH has not been tampered with? Not so helpful.
              1. NewJazz · · focus · HN ↗
                In the case I described you are trusting the developer at least a bit. But you aren&#x27;t trusting them to keep their website secure.

                Furthermore, you can be sure that theversion that you download is the same version it has always been and it is the same version everyone else sees. Curl|bash can mean getting a version of the code that is different from everybody else.

      2. sdcfgy · · focus · HN ↗
        I&#x27;m worried that this behaviour has to be defended.
      3. jasongi · · focus · HN ↗
        For a mock server? Surely a versioned, standalone executable, library&#x2F;package or docker image makes more sense. Integration tests generally need to be portable and running on CI, you don&#x27;t wanna be shell-piping whatever exists in the moment.
      4. x3n0ph3n3 · · focus · HN ↗
        curl-to-shell is a terrible installation mechanism because it&#x27;s not easily reversible and I can&#x27;t tell if any of the assets are signed, or integrity checked, or not.
      5. ssl-3 · · focus · HN ↗
        The problem, for me, is that self-running installers can create a mess that&#x27;s hard to keep track of.

        I&#x27;ve run Linux without meaningful package management, as that was kind of the style of the time 30 years ago with Slackware. It can quickly become untenable.

        There&#x27;s no real difference between an uninspected script that gets piped straight from the URL into the shell, or a similarly-uninspected make&amp;&amp;sudo make install routine from a tarball. They can both execute code that does bad things (whether unintentionally or deliberately), and they can both leave a mess that is hard to cleaned up.

        I&#x27;ve found that it is better to just avoid going down that road to begin with. Whether distro-specific packages, Docker containers, flatpaks, or whatever: All of these make housekeeping easier.

        1. giantrobot · · focus · HN ↗
          &gt; The problem, for me, is that self-running installers can create a mess that&#x27;s hard to keep track of.

          For reasons my machine with a beefy GPU is stuck on an older set of Nvidia drivers. I&#x27;ve got them pinned with apt. The ollama installer fucked everything up by updating stuff that apparently wasn&#x27;t pinned. After I had fun cleaning up that fucking mess I found it overwrote my custom systemd service file so I had to go in and fix that.

          Curl-to-shell is a bullshit antipattern. I have no interest in going back to the dark days of expanding tarballs to &#x2F; and hoping for the best.

          1. ssl-3 · · focus · HN ↗
            Right. I&#x27;ve done the same.

            And when the new distro-provided nVidia driver does something garish like, say, break XFCE, then it&#x27;s easy(ish) to roll it back using distro tools and pin it there. After that, just wait until some other more-functional combination of shakes loose in the distro channel.

            When a new nVidia driver shows up that promises a fix but the distro hasn&#x27;t packaged it yet, then the temptation to just download and run the installer that&#x27;s on nVidia&#x27;s website. But using nVidia&#x27;s special-sauce installer taints the system in ways that distro tools deliberately seek to avoid.

            And: Oh, man. I&#x27;d almost forgotten about the binary tarballs that were intended to be simply dumped into &#x2F;, where they&#x27;d just tromp on whatever. Sure, it was fast. And for some people, some times, it even worked. Sometimes, it didn&#x27;t work. Other times, it broke other things that had been working. And it left a mess behind every single time.

            A little bit of a mess isn&#x27;t necessarily devastating on a personal system. But the mess accumulates every time such an unmanaged installation process happens until it eventually overwhelms to the point that even the most functionally-disorganized of people become dysfunctional.

    2. tingletech · · focus · HN ↗
      &gt; and its “authors” are anonymous.

      The blog posts are all attributed to &quot;Lucas Vieira&quot; and the dev group <a href="https:&#x2F;&#x2F;faisca.dev" rel="nofollow">https:&#x2F;&#x2F;faisca.dev that is attributed as the author has 2 other projects. Lucas comes up in LinkedIn and looks like an actual person working in San Francisco.

      Re: curl; this seems to work:

        cargo install fakecloud
      1. losteric · · focus · HN ↗
        faisca.dev is also vibed - perhaps it&#x27;s a real human using AI to build an online fascade
        1. SomeUserName432 · · focus · HN ↗
          I don&#x27;t think it&#x27;s being questioned that at some point there is human behind this. Though it could always be that spider.
        2. _zoltan_ · · focus · HN ↗
          why does it matter that it&#x27;s a vibe coded website?
          1. otterley · · focus · HN ↗
            Because taste, creativity, and differentiation matter to a human audience. Perhaps not you personally, but to most people. Ask any experienced marketer.
            1. fragmede · · focus · HN ↗
              I don&#x27;t know about your experienced marketers, but mine are all using AI in some way shape or form!
              1. otterley · · focus · HN ↗
                It’s not really a question of whether they’re using it or not (most of them are); it’s a question of whether they’re using it to generate work product intended to be consumed by their customers. Most know better than that. Some might use it for that, too; but you know what they say about half of the population being below average.
    3. iLoveOncall · · focus · HN ↗
      &gt; Both fakecloud and its website look sloppily vibe-coded

      As if the MiniStack website wasn&#x27;t also obviously vibe-coded lol.

      1. otterley · · focus · HN ↗
        It probably is, and that’s not great, either.
      2. nnucera · · focus · HN ↗
        Yes, the prompt was: &quot;Make a Ministack website. Make no mistakes&quot; Does that make it less useful?

        You can check who’s using Ministack on public GitHub repos, NVIDIA, Block, NASA, the U.S. gov, the UK gov, and many others. There are plenty of examples demonstrating that we’re doing something good

        If you still want to use COBOL because it makes you feel better or smarter, good for you. That doesn’t mean Ministack lacks quality

        1. otterley · · focus · HN ↗
          Your software can be great and your website can be mid at the same time. Perhaps the latter isn’t the highest priority for you, but criticism of it isn’t invalid.
    4. upg1979 · · focus · HN ↗
      Happy living with Moto <a href="https:&#x2F;&#x2F;docs.getmoto.org&#x2F;en&#x2F;latest&#x2F;index.html" rel="nofollow">https:&#x2F;&#x2F;docs.getmoto.org&#x2F;en&#x2F;latest&#x2F;index.html
    5. [deleted] · · focus · HN ↗

      [deleted]

    6. lucas_vieira · · focus · HN ↗

      [dead]

    7. dmacvicar · · focus · HN ↗
      MiniStack is not (as I remember), a fork of LocalStack.

      Disclaimer: I work for LocalStack

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.