Welcome to curated list of handpicked free online resources related to IT, cloud, Big Data, programming languages, Devops. Fresh news and community maintained list of links updated daily. Like what you see? [ Join our newsletter ]

The hybrid cloud balance: Knowing when to shift between public and private

Categories

Tags devops-and-ci-cd leadership-and-career cloud-and-infrastructure architecture-and-apis

In the last few years, industry analysts have been discussing the phenomenon of companies considering taking their workloads off the public cloud. In fact, a recent argument that market capitalizations of scale public software companies is weighed down by cloud costs, and by hundreds of billions of dollars, caught the interest of several enterprise leaders. By Ravi Kumar, @Infosys.

My own view is that the public cloud is indispensable to digital transformation. It remains one of the biggest opportunity areas for organizations and is practically the only proven way to scale a business quickly and reliably. And yet the approach to cloud that promises most value for enterprises is hybrid — both public and private — leveraged for the right reasons and at the opportune moment in a business’s lifecycle.

Data shows that only a modest number of companies – a 2019 survey by Gartner put that number at 4% — have actually repatriated (or need to repatriate) their public cloud workloads to a private cloud solution.

When the enterprise is significantly cloud-mature and may be looking at optimizing its workload for a number of reasons:

  • To lower cost: From an efficiency point of view, it takes the complete automation of operations built atop the cloud infrastructure layers of compute and storage to take advantage of cloud
  • Beating latency and improving availability: Public cloud service unavailabilities are rare but can create large-scale disruption when they do occur
  • Security comfort: Technology-wise, the public cloud is highly automated for security, which means less human intervention and fewer errors
  • Lack of skills: It takes deep skills in the areas of provisioning, cloud architecture, and performance reporting, to name a few, to manage workloads efficiently when running a private cloud

Clearly, repatriation is not a “mass” option, nor the default move at a defined stage of an enterprise’s cloud maturity. Very interesting!

[Read More]

Integrating Firebase with React Native

Categories

Tags product-and-design data-and-analytics frontend-and-mobile

Firebase is a Backend as a Service (BaaS) that provides an advantage to mobile developers who use React Native for developing mobile applications. As a React Native developer, by using Firebase you can start building an MVP (minimum viable product), keeping the costs low and prototyping the application pretty fast. By Aman Mittal.

In this tutorial, we will learn how to get started by integrating Firebase in a React Native application. We will also create a small application from scratch with the help of Firebase & React Native to see how they work together.

The tutorial covers:

  • Getting started
  • Configuring a Firebase project
  • Adding Firebase to a React Native project
  • Adding react-navigation
  • Navigating between the screens
  • Creating a Database with Firebase
  • Adding Data from the app to Firebase
  • Fetching Items from the Database

Firebase is a platform that got acquired by Google and has a healthy and active community. Most users in this community are web and mobile developers as Firebase can help with mobile analytics, push notification, crash reporting, and out-of-the-box it also provides email as well as social authentication. Code examples and screen grabs included. You can find the complete code inside this Github repo. Good read!

[Read More]

Testing implementation details

Categories

Tags frontend-and-mobile testing-and-quality product-and-design

Testing implementation details is a recipe for disaster. Why is that? And what does it even mean? By Kent C. Dodds.

There are two distinct reasons that it’s important to avoid testing implementation details. Tests which test implementation details:

  • Can break when you refactor application code. False negatives
  • May not fail when you break application code. False positives

Implementation details are things which users of your code will not typically use, see, or even know about.

So how do you avoid testing implementation details?

A surprising number of people find testing distasteful, especially UI testing. Why is this? There are various reasons for it, but one big reason I hear again and again is that people spend way too much time babysitting the tests. “Every time I make a change to the code, the tests break!” This is a real drag on productivity! The author will explain how described tests fall prey to this frustrating problem.

Follow the link to the full article to learn how do you avoid testing implementation details? Very good read!

[Read More]

Experimenting with Chaos Engineering and Blockchain

Categories

Tags devops-and-ci-cd business-and-emerging-tech leadership-and-career

In this article, we’ll show how you can use the open-source Chaos Toolkit (CTK) to better understand Blockchain, stable-states, and what immutability really means. By Sal Kimmich.

Typically in chaos engineering, your experiment automates the testing and reporting of your system’s strengths and weaknesses. You can use this to build more reliable systems. Let’s experiment with understanding the state of a blockchain transaction.

The content in more details:

  • Experiment: Understanding rollbacks, immutability and stable states
  • Actions vs probes
  • Running the transaction experiment
  • Some key takeaways

Diving into blockchain with experimentation is a great way to flex your mind around immutability and stable states. Chaos Toolkit is an open-source project hosted on Github. Nice read!

[Read More]

Modern least privilege and DevSecOps

Categories

Tags security-and-privacy leadership-and-career devops-and-ci-cd architecture-and-apis

James Watters, CTO for Modern Apps at VMware, gave a compelling talk at Cloud Native Security Day on what he called “modern least privilege.” The basic concept is to apply the principle of least privilege across the DevSecOps lifecycle to properly secure modern apps. By Kit Colbert @VMware, Cloud CTO.

Modern apps are more complicated than traditional apps – they have greater scale, change faster, are more distributed (i.e., no traditional security perimeter). While it may seem like this would make it more difficult to secure them, many of the innovations in the cloud native development space, when properly leveraged, can make many aspects of security easier by automating them and making them the default/easy option.

There are several principles of cloud native architecture that underpin the 3 Rs (Repair, Repave, Rotate):

  • Immutability
  • Ephemerality
  • Ephemeral identity
  • Event-driven vulnerability management
  • DevX as control (Shift left + DevX)

Delivering a great developer experience means allowing the developer to focus on their business logic. Developers should be thinking about security, but ideally the DevSecOps platform just handles most of it for them. I.e. the security controls, as much as possible, are just built in.

We have an exciting opportunity to dramatically improve security in our enterprise applications by embracing these principles of modern least privilege. Good read!

[Read More]

How to fix cybersecurity skills gap? Competitive pay

Categories

Tags leadership-and-career security-and-privacy miscellaneous

How to close the cybersecurity skills gap? Here’s a novel idea: pay security professionals better. By Jessica Lyons Hardcastle.

This simple fix could help address a decade-old problem, according to this year’s The Life and Times of Cybersecurity Professionals report, which found 38% of respondents believe that lack of competitive compensation is the No. 1 reason for the skills shortage.

Enterprise Strategy Group (ESG) and the Information Systems Security Association (ISSA) conducted research for their fifth annual report earlier this year. It’s based on data from a global survey of 489 cybersecurity professionals.

The report could be split into:

  • Companies aren’t investing in people
  • Cybersecurity training gap
  • Build relationships across the business
  • Advice for entry-level professionals

The top piece of advice (49%) was to get a basic cybersecurity certification, followed by join a professional industry organization (42%), and find a mentor (36%). Additionally, 29% recommend specializing in a particular cybersecurity area. Interesting read!

[Read More]

How to demonstrate ROI from your cyber security strategy

Categories

Tags leadership-and-career security-and-privacy cloud-and-infrastructure devops-and-ci-cd

The best outcome from a well-executed cyber security strategy should be that a business experiences no change or disruption to their operations or systems in the case of an external threat. By Martin Riley.

While avoidance of damage from cyber attacks should arguably be seen as justification for cyber security investment alone, if the outcome is invisible, the risk is that this investment comes under the spotlight and its validity called into question.

The article in terms of cyber security investment then describes:

  • Define your strategy
  • Demonstrate competitive advantage
  • Maximise your technology investment
  • Gaining confidence from the board

Maximising your cyber security investment is crucial to demonstrating ROI. There are tangible ways you can achieve this by driving greater efficiencies – and one area ripe for improvement is reducing the time it takes to cut through the noise created by outdated technologies, particularly when it comes to monitoring and response. Good read!

[Read More]

Building well-architected serverless applications: Regulating inbound request rates

Categories

Tags devops-and-ci-cd product-and-design leadership-and-career cloud-and-infrastructure architecture-and-apis

This series of blog posts uses the AWS Well-Architected Tool with the Serverless Lens to help customers build and operate applications using best practices. In each post, I address the serverless-specific questions identified by the Serverless Lens along with the recommended best practices. By Julian Wood.

API Gateway throttling

Source: https://aws.amazon.com/blogs/compute/building-well-architected-serverless-applications-regulating-inbound-request-rates-part-1/

The article pays attention to:

  • Throttle inbound request rates using steady-rate and burst rate requests
  • Identify steady-rate and burst rate requests that your workload can sustain at any point in time before performance degraded

Regulating inbound requests helps you adapt different scaling mechanisms based on customer demand. You can achieve better throughput for your workloads and make them more reliable by controlling requests to a rate that your workload can support. Nice one!

[Read More]

Safari isn't protecting the web, it's killing it

Categories

Tags miscellaneous cloud-and-infrastructure frontend-and-mobile security-and-privacy

I have seen some interesting rebuttals, most commonly: Safari is actually protecting the web, by resisting adding unnecessary and experimental features that create security/privacy/bloat problems. That is worth further discussion, because it’s widespread, and wrong. By Tim Perry.

The article makes plenty of good points summarised under:

  • Safari is killing the web by omitting easy safe features
  • Safari is killing the web through show-stopping bugs
  • Safari is killing the web by ignoring proposed new APIs

The health of the browser ecosystem affects everybody. There are two clear parallels with the past here:

  • The slow death of IE: by offering web developers fewer bugs, better tools and more features while IE stagnated, Firefox built enough developer goodwill to dramatically expand its marketshare against the odds, forcing IE (later Edge) to follow its lead.
  • WebExtensions: despite every browser previously offering their own add-on APIs, Chrome effectively dominated developer mindshare, provided more powerful & easier to use extension APIs that became far more popular, and both Firefox & Safari have eventually killed their own APIs and accepted Chrome’s, unintentionally allowing Google to unilaterally set the web extension standard.

For more follow the link to the full article. Well worth your time!

[Read More]

Combine functional and object oriented programming

Categories

Tags software-engineering frontend-and-mobile product-and-design

There are many languages that support both functional and object-oriented programming (OOP) such as Javascript, C#, Scala … In my case, learning functional programming (FP) from OOP experience creates some confusion on how to best use functional and OOP together. By Thang Le.

One of the main advantages of FP is providing a clean and concise way to represent business logic. Pure functions are easily tested and organized. Thus in the programming languages that support both FP and OOP, the main mean to tackle business puzzles should primarily be functions.

The article content is split into:

  • Functions for logic and objects for modularity
  • Separating domain models and business logic
  • Immutability in pure functions

Good code structure increases development velocity, reduces the amount of bugs and prevent application growth of complexity. Understanding all aspects of business domain is a prerequisite for well-organized codebase. Thus investing time to learn about the domain you are working on will certainly bring great benefits. Good read!

[Read More]