Welcome to curated list of handpicked free online resources related to IT, cloud, Big Data, programming languages, Devops. Fresh news and community maintained list of links updated daily. Like what you see? [ Join our newsletter ]

Building a secure SaaS application with Amazon API Gateway and Auth0 by Okta

Categories

Tags apis serverless infosec cloud app-development web-development microservices

Most applications require a form of identity service to manage, authenticate, and authorize users. In software-as-a-service (SaaS) applications, multi-tenancy adds specific challenges to this task that are important aspects to consider when designing a multi-tenant identity management service. By Humberto Somensi.

In this post, author will dive deep into the Auth0 identity platform by describing how to leverage Auth0 Organizations to enable multi-tenant identity in SaaS solutions, and how to integrate it with Amazon API Gateway, covering:

  • Auth0 essential building blocks
  • Auth0 Organizations: Your tenants in a nutshell
  • Multi-Tenant setup with Auth0 organizations
  • Onboarding new tenants
  • Login flow
  • Securing your application with Amazon API gateway
  • Using SaaS Identity to harden your tenant isolation posture
  • Exploring More Complex Use Cases

Identity is an important and complex subject in any context. When analyzed from a multi-tenant perspective, some new challenges are imposed. Like with anything we do at Amazon, start by understanding what your customers require. Then, select the appropriate identity provider and design your application to meet your customer needs. Very informative!

[Read More]

What is green computing?

Categories

Tags serverless cio miscellaneous app-development web-development cloud

Green computing, also called sustainable computing, aims to maximize energy efficiency and minimize environmental impact in the ways computer chips, systems and software are designed and used. By Rick Merritt.

Mobile users demand maximum performance and battery life. Businesses and governments increasingly require systems that are powerful yet environmentally friendly. And cloud services must respond to global demands without making the grid stutter.

The article makes a good job explaining:

  • Why is green computing important?
  • What are the elements of green computing?
  • What’s the history of green computing?
  • A pioneer in energy efficiency
  • A green computing benchmark
  • AI and networking get more efficient
  • What’s ahead in green computing?

… and more. Green computing hit the public spotlight in 1992, when the U.S. Environmental Protection Agency launched Energy Star, a program for identifying consumer electronics that met standards in energy efficiency. In an effort to accelerate climate science, NVIDIA announced plans to build Earth-2, an AI supercomputer dedicated to predicting the impacts of climate change. It will use NVIDIA Omniverse, a 3D design collaboration and simulation platform, to build a digital twin of Earth so scientists can model climates in ultra-high resolution. Nice one!

[Read More]

The future is serverless

Categories

Tags serverless ibm app-development web-development microservices

Why serverless computing is the future of all cloud computing. Since the introduction of cloud computing, the field experienced a series of back-and-forth evolutions, partly driven by cost factors that repeated themselves in various guises. However, in recent years, a new motivating factor might help cement the next evolution of cloud computing. By Michael Maximilien, David Hadas, Angelo Danducci II, Simon Moser.

Serverless computing was created to solve the problem of allocating cloud compute resources. Serverless was built to tackle this problem by adding automation that eliminates the need for users to predetermine the amount of compute resources necessary for their workload. As an open source example, Knative added scaling automation on top of Kubernetes-based cloud platforms. Knative makes the scaling decisions of workload services in line with actual service demand. As requests come in, Knative adjusts the compute resources to the demand. Knative scales the number of service pods infinitely (assuming Kubernetes has the resources) and when requests dry out, it scales down (to zero pods eventually).

In this blog post, we make the case and paint a vision that serverless computing is the future of cloud computing. The argument centers around the following premises:

  • Cloud computing is at the center of the modern interconnected world. Most modern applications use cloud compute applications for aggregating and processing data and for constructing information that edge devices need.
  • Cloud computing demand is expected to grow annually by 15%.
  • Cloud computing is projected to reach 50% of IT spending in key market segments
  • Cloud computing already consumes 1-1.5% of global energy and its growth represents an actual threat to the environment.

In this blog post, authors explained the motivations for serverless computing to be the future of all cloud computing workloads. We argued that this serverless-first future has various potential benefits for both cloud users and providers. Nice one!

[Read More]

The lean startup summary

Categories

Tags startups cio career miscellaneous learning management

Back in 2004, Eric Ries was working on a startup called IMVU and Steve Blank was an investor and advisor for them. Steve had a methodology he called “Customer Development.” This was later released in a book called The Four Steps to the Epiphany. Eric combined Steve’s framework, the manufacturing practices of Toyota from Japan and Agile software development in what became The Lean Startup. By Benjamin Arritt.

The process of creating a plan, setting milestones and delegating tasks to employees will not work with the start up because they don’t truly know what their customers want, which approaches are best and what will be sustainable.

Eric Ries

In this summary you will find outline for the book, including:

  • Vison
    • Start ups need to be managed differently from established companies
    • The purpose of a start up is to find a sustainable business model
    • Find your sustainable business model through validated learning
    • The leap of faith assumptions: test your value and growth hypothesis
  • Steer
    • Develop a Minimal Viable Product (MVP) to test your idea in the market
    • Build, measure and learn (BML) as fast and as often as possible
    • Use split-tests to optimize your product
    • Vanity metrics are often flattering but misleading and do not help you find a sustainable business model
    • To find the right business model for your company you usually have to pivot
    • Every startup should focus on one engine of growth
  • Accelerate
    • Batch
    • Grow
    • Adapt
    • Innovate

… and much more. Very useful summary for anybody trying to create their first startup!

[Read More]

Engineering in a hybrid world

Categories

Tags cio agile teams career

In 2020, the world shifted to remote work with most companies transitioning to hybrid or remote arrangements. At the time of this report (October 2022), over 50% of respondents had no definitive plan to return to the office. Like it or not, remote work is here to stay. By Vivian Guo.

Regardless of whether you are working in an office, it is almost guaranteed you will be interacting and working with remote workers. For engineering organizations with distributed teams, this presents a unique challenge of maintaining connection and collaboration across geographic barriers.

Distributed workforces have fundamentally changed how engineering teams collaborate with each other and the key processes and tools needed to enable successful software development. This year’s report explores how exactly the shift to remote work has impacted engineering organizations. Follow link to article and download this extensive pdf report. Good read!

[Read More]

Message routing and topics, thought shift

Categories

Tags cio app-development messaging devops event-driven

A lot has changed - Memory, Storage, and CPU are cheaper and available on demand. Cloud technologies have also disrupted this domain; we now have Infrastructure as a Service (IaaS) - Scaling, Load Balancing, and DR responsibilities have been delegated to the Cloud service providers. By Giri Venkatesan.

In an ideal world, a messaging broker would never need to open the payload - it can be simply passing messages between producers and consumers based on subscription. Not all consumers are equal; they may be built to handle subsets of messages even if they are of the same class. For example, a Tax Calculation service would need to process the message differently based on the country or region the message is originating from.

Fortunately, MQTT-based brokers adopted the hierarchical representation of topics from the get-go.

Message hierarchical taxonomy

Source: https://www.linkedin.com/pulse/message-routing-topics-thought-shift-giri-venkatesan/

The benefits of such a hierarchical scheme don’t stop there. Now we can use wild cards at any level to capture a broader range of message topics in a subscription:

  • Single-level wildcard: ‘*’
    • All credit card transactions from store 1049, with transaction number beginning ‘4’
    • quickpay/credit/*/4*/01049
  • Multi-level wildcard: ‘>’
    • All debit transaction to be cleared at bank 18
    • quickpay/debit/0018/>
    • Literals at each level are treated as Strings - hence wildcard usage on data types like latitude/longitude coordinates and other custom identifiers would also benefit
    • bustrak/gps_updt/*/*/45.3*/-75.7*

With support for versioning, topics can be altered dynamically without affecting the existing subscribers and overall architecture. Good read!

[Read More]

What to consider when modernizing APIs with GraphQL on AWS

Categories

Tags programming app-development cloud apis aws

In the next few years, companies will build over 500 million new applications, more than has been developed in the previous 40 years combined (see IDC article). API operations enable innovation. By Lewis Tang.

The main focus of this article:

  • How GraphQL works
  • Options for running GraphQL on AWS
    • Fully managed using AWS AppSync
    • Self-Managed GraphQL

Modernizing APIs with GraphQL gives your frontend application the ability to fetch just the data that’s needed from multiple data sources with an API call. You can build modern mobile and web applications faster, because GraphQL simplifies API management. You have flexibility to run an open-source GraphQL implementation most closely aligned with your needs on AWS Lambda, Amazon ECS, and Amazon EKS. With AWS AppSync, you can set up GraphQL quickly and increase your development velocity by reducing the amount of non-business API logic code. Easy!

[Read More]

How to improve your cloud cost forecasting

Categories

Tags programming app-development cloud software-architecture learning cio

Since technology usage is often an organization’s highest expenditure after personnel costs, effectively forecasting cloud spend is vital to planning, negotiating, and achieving sustainable economies of scale as you grow and mature your business on the cloud. So, what can you can do to more accurately predict future cloud costs? In particular, how can you forecast your AWS spend for the next month, quarter, or year? By John Klacynski.

The first blog in the series focuses on the best practices you can implement to improve financial predictability:

  • Increase cross-functional collaboration
  • Perform driver-based forecasting
  • Establish governance and accountability

Product teams are now empowered to create annual, quarterly, monthly, or even daily budgets depending on business needs. These reports give product teams the ability to spot anomalies early and take timely action to prevent cost or usage overage, or inefficient utilization or resource coverage of your Reserved Instances and Savings Plans. Thanks to tools like AWS Budgets, which lets you set custom budgets, alerts, and triggered actions related to exceeding or falling below desired thresholds, you can build a decentralized cloud spend forecast. Good read!

[Read More]

Why traditional logging and observability waste developer time

Categories

Tags programming app-development messaging devops

The ability to jump directly to a specific line of code that caused an error, without restarting, redeploying or adding more code, is where the magic happens in shift-left observability. By Shahar Fogel.

Because the truth is that while traditional APM and monitoring are critical, they are providing data that is often more interesting to Ops than to developers.

The last few years have seen their share of changes in DevOps. Those trends are highlighted by containers and microservices, security responsibility spreading to more teams and trying to automate as much as possible.

You could argue that the common denominator is making everything cloud native — containers epitomize emphasis on architects, more things are offered “as a service,” and scale is seemingly automated by moving everything to off-premises (on-demand) servers. But the big “philosophical” shift is to “shift left.” This means giving devs necessary access to real-time production data. That makes your entire operation more mobile and dynamic. Your dev teams gain the independence to move thromoja kancelariaugh production-level code without having to wait for Ops to grant them that access on a case-by-case basis. That’s why we elevate live debugging at Rookout to the same level of importance as remote debugging or the three pillars of observability.

The article further deals with:

  • Advancing on the leftward front
  • Example of developer-first observability in action
  • Cost-effective with money and time

Whatever production debugging solution you choose should integrate directly with monitoring and APM platforms. This will dramatically increase enterprise agility and velocity when it comes to diagnosing and pinpointing the root cause of performance issues. The ability to jump directly from a Datadog alert or anomaly to a specific line of code that caused an error, without restarting, redeploying, or adding more code, is where the magic happens in shift-left observability. Good read!

[Read More]

What is MQTT 5.0, and how does it work in IoT?

Categories

Tags iot event-driven web-development app-development messaging

MQTT serves as a tool to connect many types of IoT devices in deployments of all magnitudes. It originally started in 1999 for oil and gas pipelines to communicate over remote satellites. By MobiDev.

What you will learn:

  • Why Is MQTT used in IoT development?
  • An example of an MQTT 5.0 small system deployment
  • Which clients support MQTT 5.0 and Python?
  • Pros and cons of an MQTT v5.0 local network
  • Major practical differences between MQTT v3.1.1 and v5.0
  • MQTT 5 challenges

MQTT v5.0 is a suitable option for local IoT device communication if you have a central device that can host a message broker for communication between devices and/or the host. Despite its drawbacks (most of which were eliminated in MQTT v5.0), this protocol can be used for communication between small-to-medium sized networks of IoT devices. Interesting!

[Read More]