# Dario Castañé — English writing — full context > English articles by Dario Castañé, a software engineer at Datadog and maintainer of Mergo and Zas, on Go, technology, politics and society. The following pages preserve the published Markdown. Resolve relative links against each page's canonical URL. --- ## Articles in English Language: en Source: https://dario.cat/en/posts/index.md Canonical: https://dario.cat/en/posts/

Articles in English

Articles in English. You can also browse the archive in all languages.

2026

2024

2022

2018

2013

2009

--- ## Monitoring a Synology NAS with Datadog Language: en Source: https://dario.cat/en/posts/monitoring-synology-nas-with-datadog/index.md Canonical: https://dario.cat/en/posts/monitoring-synology-nas-with-datadog/

Monitoring a Synology NAS with Datadog

There are two things worth watching on a NAS: the hardware (disks, RAID, temperature) and everything running on top of it. Datadog covers the first over SNMP and the second with its Agent, so I run both out of a single container on the NAS itself. Here's the whole setup, in the order I'd do it again. ## Step 1: Enable SNMP on DSM 1. Open DSM > Control Panel > Terminal & SNMP > SNMP. 2. Check "Enable SNMP service". 3. Enable SNMPv3 and create a user with SHA for authentication and AES for privacy. Synology's SNMP daemon only speaks SHA-1 and AES-128, so don't reach for SHA256 or AES256. 4. Write down your NAS's LAN IP. You need that one, not `127.0.0.1`, because the Agent runs in a bridged container. ## Step 2: Open the firewall for SNMP Under Control Panel > Security > Firewall, allow UDP port 161 from wherever the Agent lives. Here that's the NAS itself, but the traffic leaves through a Docker bridge network, so the allowed sources have to include the bridge subnet (usually `172.17.0.0/16`). Otherwise DSM's SNMP daemon never sees the packets. ## Step 3: Install Container Manager Open Package Center and install Container Manager, which is what Docker got renamed to in DSM 7.2. Launch it once so it initializes before you create anything. ## Step 4: Get a Datadog API key In Datadog, go to Organization Settings > API Keys and copy an existing key or create a new one. It goes straight into the compose file in the next step. ## Step 5: Create the SNMP config, then the compose project Order matters here. Create the SNMP config file before the container exists. If the path isn't there when Docker starts the container, Docker creates an empty directory in its place and your config gets silently ignored. 1. In File Station, create the project folder, for example `/docker/datadog-agent` inside the `docker` shared folder that Container Manager set up for you (on whichever volume it landed, usually `volume1`). Inside it, create a `conf.d` subfolder. 2. Inside `conf.d`, create `snmp.yaml` with your NAS IP and the SNMPv3 credentials from step 1: ``` init_config: loader: core use_device_id_as_hostname: true instances: - ip_address: '192.168.1.XXX' # your NAS LAN IP from step 1 snmp_version: 3 profile: synology-disk-station # pins Datadog's official Synology profile user: 'synology-monitor' authProtocol: 'SHA' authKey: 'your-authentication-key' privProtocol: 'AES' privKey: 'your-privacy-key' tags: - device_type:synology_nas - environment:prod ``` 3. Save it, then go to Project > Create in Container Manager. 4. Name the project, e.g. `datadog-agent`. 5. For Path, pick the folder from step 1 (`/volume1/docker/datadog-agent`, or wherever yours is). DSM keeps the compose file and project data there. 6. Under Source, choose "Create docker-compose.yml". 7. Paste this, with the `snmp.yaml` bind mount already in `volumes:`: ``` services: datadog-agent: image: datadog/agent:7 container_name: datadog-agent restart: unless-stopped network_mode: bridge # host mode collides with DSM nginx on 5001 cgroup: host # compose equivalent of `docker run --cgroupns host` environment: DD_API_KEY: "your-datadog-api-key" DD_SITE: "datadoghq.com" DD_ENV: "prod" DD_HOSTNAME: "synology-nas" DD_APM_ENABLED: "false" DD_PROCESS_AGENT_ENABLED: "true" DD_LOGS_ENABLED: "true" DD_LOGS_CONFIG_CONTAINER_COLLECT_ALL: "true" DD_CHECK_RUNNERS: "2" # lower to 1 on Atom/Celeron models # Leave DD_SYSTEM_PROBE_ENABLED alone. DSM's 4.4 kernel lacks the eBPF support it needs. volumes: - /var/run/docker.sock:/var/run/docker.sock:ro - /proc/:/host/proc/:ro - /sys/fs/cgroup/:/host/sys/fs/cgroup:ro # goes with cgroup: host above, for correct container and process metrics - /volume1/docker/datadog-agent/conf.d/snmp.yaml:/etc/datadog-agent/conf.d/snmp.d/conf.yaml:ro labels: com.datadoghq.ad.check_names: '["snmp"]' ``` Fix the path in that last volume line if you picked a different folder. 8. Click Next, look over the settings and deploy. Container Manager pulls `datadog/agent:7` and starts it with the SNMP config already mounted, so there's nothing left to edit afterwards. ## Step 6: Check that it came up Open a terminal from Container Manager, or SSH into DSM and run `docker exec -it datadog-agent bash`, then: ``` agent status ``` You want sections for `snmp`, `process` and `logs agent`, and no restart or crash loop. For the SNMP side specifically: ``` agent status | grep -A 10 snmp ``` The tag to look for is `vendor:synology`. If it's there, the mounted `snmp.yaml` was read and the `synology-disk-station` profile loaded, which means disks, RAID, SMART and temperatures all come for free. You never have to write an OID list by hand. Then open Infrastructure > Devices in Datadog. The NAS shows up there with its model, serial number and DSM version as metadata. ## Step 7: Confirm metrics are flowing In Metrics Explorer, search for: - `snmp.synology.diskTemperature` - `snmp.synology.diskStatus` - `snmp.synology.raidStatus` - `snmp.synology.system.temperature` - `system.cpu.*` and `system.mem.*`, which come from the host check rather than SNMP Give it about five minutes. If nothing turns up, skip to the troubleshooting list at the end. ## Step 8: Alerts Monitors > New Monitor > Metric, then set up these: - `snmp.synology.system.temperature` above 60°C, critical. - `snmp.synology.system.temperature` above 50°C, warning. - `snmp.synology.diskTemperature` above 50°C on any disk, warning. - `snmp.synology.diskStatus` anything other than 1 (normal), critical. - `snmp.synology.raidStatus` in degrade or crashed, critical. - Volume usage (`raidFreeSize`/`raidTotalSize`) above 90%, critical. - Volume usage above 80%, warning. The temperature numbers are a starting point. Check what your drives are actually rated for and move them. ## Step 9: A dashboard Dashboards > New Dashboard, then: - Color-coded query-value widgets for disk status, RAID status and current temperature. These are the ones you actually glance at. - Timeseries for CPU, memory, network throughput and storage I/O. - A table grouped by `synology_disk_id` or `synology_raid_name` for the per-disk and per-volume breakdown. I keep the NDM device page for the NAS pinned next to it, since that's where the topology and metadata live. ## Maintenance DSM updates have a habit of resetting SNMP settings, so after each one check that the service is still enabled, the credentials still match and the Docker bridge subnet is still in the allowed sources. After a Container Manager update, run `agent status` once to confirm the container came back cleanly, since network defaults sometimes shift. ## When something breaks The container restart-loops or throws certificate errors: that's host networking. Switch to `network_mode: bridge`. No SNMP data at all: check that `ip_address` is the LAN IP and not localhost, that the bridge subnet is allowed through the firewall on UDP 161, and that the version and credentials match what's on the SNMP page exactly. SHA and AES, not SHA256 and AES256. `snmp.yaml` mounted as a directory instead of a file: the file didn't exist yet when the container was first created. Delete the directory Docker made, create the real file in File Station, redeploy the project. The Agent eating CPU: drop `DD_CHECK_RUNNERS` to 1. No fan or power status: that one's expected. Those scalar OIDs ship disabled in Datadog's profile. Add them to the SNMP config by hand if you want them. --- ## A New Path Language: en Source: https://dario.cat/en/posts/a-new-path/index.md Canonical: https://dario.cat/en/posts/a-new-path/

A New Path

Today, coinciding with the anniversary of the November 28, 2010 elections and after fulfilling acquired commitments, I announce that a few weeks ago I left Pirates de Catalunya. This date is significant because these elections were the first in which Pirates participated, shortly after its official formation, and marked my first electoral experience. In fourteen years I've had the opportunity to build an alternative, influencing public life in a historic context: from the 15M movement to the rise of Catalan independentism, through the repression of the Spanish State and the growth of the far right, ending in the whirlwind of war and climate change in which the world is immersed. I've taken on multiple responsibilities that have made me grow more than I ever imagined on the day I filled out the Pirates membership form. I've led electoral lists, served as a councilor, and contributed to national and international projects, among many others. None of this would have been possible without you all, the hundreds of people with whom I've had the privilege of sharing this journey. I sincerely thank each and every one of you for the trust, dedication, and hours you've invested at every moment. Now, I close this chapter and begin a new one. I do so because I've decided to take on new personal and professional challenges. I will continue to engage in politics in a different way, mainly through my [personal](https://bsky.app/profile/dario.cat) [channels](https://mastodont.cat/@dario). Pirates, continue the good work and the fight for our [shared ideals](https://lektu.com/l/pirates-de-catalunya/guia-de-navegants-per-un-mon-millor/17120). I hope to meet you again on this new path I'm embarking on. Farewell! --- ## A portal between Ruby and Go (using FFI) Language: en Source: https://dario.cat/en/posts/portal-between-ruby-and-go/index.md Canonical: https://dario.cat/en/posts/portal-between-ruby-and-go/

A portal between Ruby and Go (using FFI)

Thinking about migrating some huge REST APIs from Ruby to Go, I researched how to replace the Ruby code progressively with Go code. I ended up with a possible FFI-based prototype. The solution is to have the Ruby code load a Go library and wrap the Go functions in Ruby classes and methods. ## The Ruby side The Ruby side is pretty straightforward. We must load the Go library and import the Go functions in Ruby classes and methods.
require 'ffi'

module Portal
  extend FFI::Library

  ffi_lib './libexample.so'

  class Example < FFI::Struct
    # This must be completely in sync with the C struct defined in Go code.
    layout :id, :int, :prefix, :pointer
  
    def initialize(prefix, id)
      self[:prefix] = FFI::MemoryPointer.from_string(prefix)
      self[:id] = id
    end

    # This feels convoluted, but it hides the fact that our function is loaded
    # outside of the "struct mirror" class.
    def greet
      Portal.greet(self)
    end
  end

  attach_function 'greet', [Example.by_value], :void
end

ex = Portal::Example.new('C', 137)
ex.greet
## The Go side The Go side is a bit more complex. We need to define a C-compatible struct and export the functions we want to use from Ruby. The cool thing is that we can define the functions with the struct as the receiver.
package main

/*
struct example {
	int ID;
	char *Prefix;
};
*/
import "C"
import "fmt"

// This declaration is just an alias to the C struct.
type Example C.struct_example

//export greet
func (e Example) greet() {
	fmt.Printf("Hello from %s-%d\n", C.GoString(e.Prefix), e.ID)
}

func main() {}
## The build The build is also straightforward. We need to: 1. Compile the Go code to a shared library. This command will generate the CGO bindings. 2. Run the Ruby code.
go build -buildmode=c-shared -o libexample.so example.go
ruby portal.rb
## The result If we run the code, we get the following output:
Hello from C-137
## The benefits The main benefit of this approach is that we can progressively migrate the Ruby code to Go. We can start by replacing part by part, until we are ready to switch to a pure Go service. It's not only possible to replace existing Ruby code. Now we can reuse RSpec/Minitest specs to test the new Go code. Instead of going for a full rewrite with no tests, we can start by testing the new code with the existing ones. ## The (possible) drawbacks Performance-wise this approach is not ideal. We are adding a layer of indirection. This probably adds some overhead to the calls. This is something we need to measure if applied to high-traffic services. Image generated with DALL-E and the prompt 'A digital illustration of a blue gopher staring to a wobbly shimmering Rick and Morty style portal. Eerie feeling, trending in artstation.' --- ## Delete Facebook #2 Language: en Source: https://dario.cat/en/posts/delete-facebook-2/index.md Canonical: https://dario.cat/en/posts/delete-facebook-2/

Delete Facebook #2

> **Progress made:** deletion of logins. The first easy step to end my dependence on Facebook is to delete all my websites and third-party applications logins. As I said in my previous post, I have 123 logins. And what have I found among those? For starters, reviewing [the list](https://www.facebook.com/settings?tab=applications), most of them are websites that I know and use, so I had to go one by one, checking if they have the option to identify myself without Facebook or any other social network. Or if I no longer use them or do not interest me anymore, to delete the accounts and applications. Before going through the different cases that I have found, in this post I want to highlight one in particular: Cosmopolitan-like tests websites. I imagine that many of us have fallen at some point in this, to laugh with someone on Facebook, like those of [QuizzStar](http://quizzstar.com/). To do so, you have to identify yourself with our Facebook account. What information do these websites usually collect? ![Permissions for QuizzStar](/images/quizzstar_permissions.png) I've looked at others, like [vonvon](https://vonvon.me/), and the permissions are identical or worse. This is a good example of the misuse we do (yes, us) of our own data, giving them away in exchange for a frivolous and funny result. Can anyone justify that the digital version of a teen magazine test needs all this? Most likely, the tests are a hook to obtain and sell personal data. Once we understand the seriousness of the matter, the question we immediately ask ourselves is “How can I get them to delete my data?”. The answer is not simple as to delete the entry from the list but [to contact each web and application manually](https://www.facebook.com/help/149151751822041) and ask them to be removed by giving a user identifier from the same permission screen. This is insane! *Interlude: while writing this post, Facebook has given me this reminder about the new European regulation on data protection. :facepalm:* ![Prepare for the General Data Protection Regulation](/images/facebook_gdpr.png) I want to give you an example. I have an application called [Instant Win](https://apps.facebook.com/instantlywin/?ref=br_rs). Following what is stated in the Facebook Help Center, I do: 1. I search for the application: [Instant Win](http://apps.facebook.com/instantlywin/?ref=br_rs). 2. On the page (blank) I look for a small link at the end of the right column that says “Report/Contact”. 3. I follow the wizard, indicating that I want to send a message to the developer (last option). 4. I follow the link on the next screen to send a message (sic). 5. It takes me to the [Woobox help center](http://help.woobox.com/), apparently the developer of the application. 6. I try to find a way to contact Woobox, but there is no form or address. 7. So I decide to go to the main website. 8. At the bottom of the page I find a contact address and send them the following email: > Hello, > > I recently found that I used your Facebook app Instant win at some point. I do not longer use it. Please delete any data related to user ID XXXXXXXXXXXXXXXX and confirm. > > Failure to comply with this request will be reported to the Spanish Data Protection Agency, as it would be against GDPR's article 17. > > This request is based on the procedure provided by Facebook in its Help Center. > > Thanks, > Dario Now I have to wait. I want to believe that I have found a bad example and with others it will be different. If not, this will show the little interest that Facebook (and some websites) have in the protection of our data. --- ## Delete Facebook #1 Language: en Source: https://dario.cat/en/posts/delete-facebook-1/index.md Canonical: https://dario.cat/en/posts/delete-facebook-1/

Delete Facebook #1

> **Progress made:** creation of my own page under my personal domain and review of active logins. As promised, [I'm writing down my progress](https://dario.cat/en/posts/delete-facebook/). In the last days I have recovered my personal domain, which I'll use as my main profile. Its advantages don't come without disadvantages. I'll control my identity, combined with [Keybase](https://keybase.io) (more about this tool in another post), and the authorship of my texts, available under the [CC BY-SA 4.0](https://creativecommons.org/licenses/by-sa/4.0/) license. There are more advantages, but I don't want to extend myself. Before I must admit that this isn't available to everybody without falling into another walled garden, much less at no cost. If you are curious, the web is generated with [Hugo](https://gohugo.io), using the theme [Minimo](https://themes.gohugo.io/theme/minimo/). [Repository available here](https://github.com/darccio/dario.cat) for techies. I have also reviewed what logins I have active. I have seen that there are 123. 123 external websites and mobile applications in which I log in using Facebook because it's easy. I also do it with Twitter. It's very easy but inconvenient. It's inconvenient for cases like the one we are dealing with, but the exercise serves to become aware of how easy it's to fall into the trap of utility instead of making decisions aimed at maintaining the personal sovereignty of your information. Finally, a brief comment. This is leading me to think about how to solve the problem generated. We like to share our lives, either in person or digitally. Therefore, there is a need that has not yet found an optimal decentralized solution. I'll write more about it but I can advance that, although there are proposals in the right direction, they are all wrong in some way: either of wanting to be very innovative or solving all the possible problems or being focused on a specific software, no matter how free (as in freedom). I sincerely believe that there are already existing solutions and architectures to build a social network protocol to achieve the necessary freedom and privacy. ![#DeleteFacebook](/images/delete-facebook-1.png) --- ## Delete Facebook #0 Language: en Source: https://dario.cat/en/posts/delete-facebook/index.md Canonical: https://dario.cat/en/posts/delete-facebook/

Delete Facebook #0

After the controversy of Cambridge Analytica, I have decided to stop feeding the beast, Facebook. I also decided that I'm going to document my process, since it is not simply stop using it or abruptly closing my account. Actually, I found it a rather complex process: I have many websites where I use Facebook as a login, there are people with whom I keep contact here exclusively, etc. So I'm not just gonna explain it so that others can do it, but I'll make you part of it. And you, are you going to leave Facebook? If yes, where are you going? If it's no, why and how would you rather to keep in contact with me? --- ## Introduction to liquid organizations Language: en Source: https://dario.cat/en/posts/introduction-liquid-organizations/index.md Canonical: https://dario.cat/en/posts/introduction-liquid-organizations/

Introduction to liquid organizations

Several years ago I decided to work after a big goal: to develop a participatory and organizational system for [Pirates de Catalunya](https://pirates.cat/en/). Its name, [Lýd](/lyd). I had a one year permanent on-line assembly experience, physical assemblies, two electoral campaigns, many tips and ideas from my colleagues. Also I had acquired and shared knowledge in conversation with people of around the world. I started the analysis, which lasted one year and a half, with two additional campaigns, hundred of work hours and more exchange of ideas with other collective’s colleagues. A time of compilation, writing and fine tuning of an idea to unleash the true power of any horizontal collective. Until today, July 1st 2013. After several versions, analyzing the outcomes and looking after the most clear and concise one, I release the [analysis](/lyd) as online documentation, available to any collective. I ask you to enhance and improve it. With this I set liquid organizations’ bases. But, what they are?
"Whose social graph is it?" by Jeremy Keith licensed under CC BY 2.0
## Liquid organizations They are horizontal organizations without fixed hierarchy, based on trust through delegation. All their members have equal weight and they organize themselves in workgroups or organic groups from shared traits (city, region, etc). It is based in three keystones: nexus (groups), flows and delegation. In this post I’m going to focus in two of them, leaving apart [nexus](/lyd/nexus). They are fully explained in the analysis. ## Delegation Without delegation, horizontal structures with crowded nexus don’t scale. They may work slow until stagnation. Delegation is key to allow a minimal structure without it getting petrified. Being it voluntary and revocable at any moment, we delegate because we trust. In Lýd is expected as free of terms or formalism. This allows to bring resilience to organizations as they are able to handle any unexpected situation. Lýd is targeted to decentralized organizations with actionable targets. It can be used in debate-oriented groups, because of flow concept, but its main objective is to allow a swift, auditable and locking-free decisionmaking. It is a full extent [liquid democracy](http://en.wikipedia.org/wiki/Delegative_democracy)'s application. E.g. when a group is created, in my opinion it should, as first action, hold a delegation “voting”, based on voluntary delegates’ merits. These delegations can change any time, even during a voting. First delegation “voting” eases member’s mutual acquaintance, as well as starting to work immediately. It doesn’t prevent new members becoming delegates, because there are no deadlines or restrictions. Before going to the next point, I want to point out while a member belongs to an organization, she trusts other groups where she doesn’t participate directly. This trusting is the ultimate implicit delegation and this already exists in current organizations. Lýd just make it explicit inside nexus. ## Flows In Lýd everything is a flow, from a conversation to a task or something bigger, a project. Everything revolves around dialogue and debate. These are required to get the best result from cocreation. But only this is not sufficient. We need also to get working together the appropriate group. Using nexus, flows are organized according to our needs and they allow opinion’s exchange in easy to handle and focused groups. Flows come with tools to manage usual situations like off-topics, low-content messages (e.g. +1 messages), etc. All these tools must be available to anyone except those that destroy content, to guarantee a truly horizontal and lock-free communication. ## Conclusion Lýd reaches a balance between different kind of members. It also allows organizations to self-regulate and to get maximum participation, directly or not, without restrictions or arbitrary rules. With this I close my first post about liquid organizations (also known as liqorgs). As different groups use it and others criticize and suggest improvements, I will improve the model. This will impact on the development of a tool to assist implementation and extension, about what I’ll keep you up to date too in next posts. --- ## What Internet told me: Geekvana, is it possible? Language: en Source: https://dario.cat/en/posts/geekvana/index.md Canonical: https://dario.cat/en/posts/geekvana/

What Internet told me: Geekvana, is it possible?

Time ago I wrote down a quick plain text file with the main "rules" about achieving the "geekvana", an inner peace state, which I learnt reading posts and posts through years. Now I am declutting my computer and I want to share my own steps: * simplicity * dump everything on * say no * sleep * declutter * use reminders * proactive * focus * don’t multitask (thinking about your next task or anything that worries you counts) * be aware of time * less time (restrict yourself) * allow interruptions (just handle them gently) * pile tasks * pick one at random (upon priorities) * automate everything (whenever possible) If you want a better explanation about, ask me, but I recommend you reading first [Leo Babauta's The Power of Less](https://zenhabits.net/leos-book-the-power-of-less-video-and-website/), an awesome book. --- ## Deciwave - Robot Rocking for Google Wave Language: en Source: https://dario.cat/en/posts/deciwave/index.md Canonical: https://dario.cat/en/posts/deciwave/

Deciwave - Robot Rocking for Google Wave

Last Sunday I built a little robot for [Google Wave](https://wave.google.com) which allows to embed music players from [GoEar](http://www.goear.com/), [Jamendo](https://www.jamendo.com/start) and [The Sixty One](http://thesixtyone.com): [Deciwave](https://deciwave.appspot.com/). It was really simple, once I got the Gadget API and its inners, to be able to replace a blip with the players. When I made one player I was so amazed that I integrated all my frequent music sites.
If you want to use it, just add deciwave@appspot.com to your wave, create a new [blip](http://google.about.com/od/b/g/google_wave_blip.htm) and paste a share URL on it.