trillian
almanack
trillian | almanack | |
---|---|---|
9 | 11 | |
3,464 | 21 | |
0.3% | - | |
9.6 | 9.0 | |
4 days ago | 3 days ago | |
Go | Go | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
trillian
- Is there a good example of an open source non-trivial (DB connection, authentication, authorization, data validation, tests, etc...) Go API?
- Google's Trillian – Verifiable Data Structures
-
Key transparency: A transparent and secure way to look up public keys
Archived. Not sure when. :( I'm not sure what if anything is a decent replacement/substitute.
In the README examples I see text about what I think is Certificate Transparency. That was definitely the first thing this made me think of. There's also a lot of talk in the project about CONIKS[1], & associate research papers are about 'bringing key transparency to end users'.
The scenarios[2] are interesting, but I'm not sure fully how this project helps. They explicitly call out Upspin for encrypted storage, which was linked recently[3].
It appears to make heavy use of the Trillian cryptographically verifiable data store[4].
[1] https://www.schneier.com/blog/archives/2016/04/coniks.html
[2] https://github.com/google/keytransparency/blob/master/docs/s...
[3] https://news.ycombinator.com/item?id=31520559
[4] https://github.com/google/trillian
- Don't trust your logs! Implementing a Merkle tree for an Immutable Verifiable Log (in Go)
- GnuPG used to ask for your support to help protect online privacy
-
There's a guy who the Space Force and Defense Department are paying $250k a year to go to MIT to study Bitcoin for them, to see how they could use its ledger in the same way they use GPS to store and track accurate immutable information. He just got permission to go public with his work.
Related is Google Trillian: https://github.com/google/trillian
-
Threat Actors Now Target Docker via Container Escape Features
https://stackoverflow.com/questions/37058322/how-can-i-verif...
CT (Certificate Transparency) is another approach to validating certs wherein x.509 cert logs are written to a consistent, available blockchain (or in e.g. google/trillian, a centralized db where one party has root and backup responsibilities also with Merkle hashes for verifying data integrity). https://certificate.transparency.dev/ https://github.com/google/trillian
Does docker ever make the docker socket available over the network, over an un-firewalled port by default?
-
Tamper-Evident Logs
Yeah, right on!
We're looking in more depth at other use cases, developing a better understanding of which types of problems this might be useful for, and ways to reason about the properties you want/get from using systems like this (e.g. https://github.com/google/trillian/tree/master/docs/claimant...)
[Disclaimer: I work on CT, Trillian, and some other related projects]
almanack
-
I think I'm going crazy refactoring my web app
You need to add the base template to the ParseFS call. The code here is more complicated than it needs to be. You don’t need to go through the FS yourself. The template parser can do that for you. Look at this example which doesn’t use a base template but could: https://github.com/spotlightpa/almanack/blob/master/layouts/layouts.go You would just change it to
-
Passing sql transactions when not needed
For me, GetBooks is a method on a query object and a query object has a DBTX interface struct field. So if I don’t need a transaction, I just use the normal DB as the DBTX but if I do, I call a method to open a TX first and use that. https://github.com/spotlightpa/almanack/blob/master/internal/db/db.go
- Is there a good example of an open source non-trivial (DB connection, authentication, authorization, data validation, tests, etc...) Go API?
-
ORM or no ORM (and which ones)?
Pagination is just an offset and a limit. There’s another package that handles the math for you: https://github.com/spotlightpa/almanack/blob/master/internal/paginate/paginate.go
- Help with lazy loading routes in Vue Router 3 with Vite
-
sqlc patterns in production
You can have methods on the SQLC structs. They just need to be in a separate file. See https://github.com/spotlightpa/almanack/blob/master/internal/db/page.go eg.
-
How are YOU using generics so far?
So far, just refactoring. I made a concurrency manager to simplify some stuff, and unified some pagination code. It’s like we said before generics: there are places you miss it, but not having it was never a total blocker. I think going working the x/slices x/maps packages will be the biggest time savers.
-
The HTML Data List Element
I ended up shipping this as a similar autocomplete field: https://github.com/spotlightpa/almanack/blob/master/src/comp...
It's a little different because I put the chosen selections on a row above the input row, but the principle is the same.
-
Testing a method which requires an API Key
https://github.com/spotlightpa/almanack/blob/master/internal/herokuapi/herokuapi_test.go#L14:L21
-
How to avoid duplicate code in gorilla/mux middleware
I’m using Chi not Gorilla, but you can see my JWT Auth middleware here: https://github.com/spotlightpa/almanack/blob/master/pkg/api/routes.go#L37
What are some alternatives?
Proofable - General purpose proving framework for certifying digital assets to public blockchains
bun - SQL-first Golang ORM
libgossamer - Public Key Infrastructure without Certificate Authorities, for WordPress and Packagist
tinykv - tiny in-memory single-app kv (cache) with explicit and sliding expiration
PGPy - Pretty Good Privacy for Python
Listmonk - High performance, self-hosted, newsletter and mailing list manager with a modern dashboard. Single binary app.
django-ca - Django app providing a Certificate Authority
Grafana - The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.
gatekeeper - 🐊 Gatekeeper - Policy Controller for Kubernetes
jet - Type safe SQL builder with code generation and automatic query result data mapping
tierney - Generic library for structured commands with explicit parallelism
myapp - 🚀 How to build a Dockerized RESTful API application using Go.