Hacker News new | ask | show | jobs
by slovenlyrobot 2477 days ago
This has been a /major/ sore point for Lambda use, amazing they fixed it, and always great to see they've documented the intense engineering requirements involved to make it happen.

AWS is a beautiful mix of business and technology, it's very rare to see such a large engineering-driven organization managing to balance customer friendliness. I'm an unashamed fanboy

1 comments

Major is a bit harsh.

As far as I know this was only an issue for legacy architectures.

No. Using an RDMS instead of DynamoDB is not a “legacy” architecture. You also shouldn’t expose your database publicly.
RDMS is not legacy, but perimeter security certainly is.
I’m one of the harshest critics of “lift and shifters” - old school net ops people who get one certificates by watching an ACloudGuru video, duplicate their on prem infrastructure and processes to the cloud and don’t go all in on the advantages of it and end up costing their clients more - but nowhere is it considered “legacy” to not use perimeter security.
Honest question: what, in you opinion, is the state-of-the-art approach? Something like BeyondCorp?
I think zero-trust goes into a good direction.

https://www.securityroundtable.org/zero-trust-approach-can-m...

There is an entire ecosystem of tooling that will shit itself and wake up half the company if you assign a public IP address in the wrong VPC

Stuff like this is pain in the ass, it was a major problem