6 ms·
Introducing Heroku Private Spaces
- zrail 11y agoI'm really excited about this, and also really excited to see what the pricing is like.
- sudhirj 11y agoThe video looks like it's org-only - I think getting an org on Heroku starts at USD1000 a month.
- isaiahdw 11y agoHeroku Enterprise (required for Orgs, Private Spaces, etc) requires an annual agreement paid upfront ($18K/year minimum) for pre-allocated resources with a 20% premium for the included premium services (Org Account, Customer Solutions Architect and 24/7 Premium Support SLA).
- sudhirj 11y agoI can't make out if public facing apps can deployed inside a space, though - I just want to be able to use Heroku in the Singapore region :-/
- amerine 11y agoYes, the applications are publicly accessible by default, just like the Cedar-based ones.
- grandalf 11y agoThis is about three years overdue, but at least it's here. How close does it come to making PCI-DSS Level 1 attainable on Heroku? What about HIPAA?
- grandalf 11y agofollow-on questions: - is it now possible to write a script that generates network diagrams, etc., that are sufficient for PCI-DSS Level 1? - is the rest of Heroku's datacenter process documented so that it can be given to a QSA? - Would it now be possible for companies like Aptible to sell their core competency/service as a Heroku add-on? - Can add-ons be launched inside a private space? - Can access to Heroku, git deploys, etc., add-ons be 100% protected by multi factor authentication?
- njudah 11y agoPCI and HIPAA are on the roadmap for Private Spaces - stay tuned for updates.
- nzadrozny 11y ago> Can add-ons be launched inside a private space? Addon provider here: haven't heard anything official from Heroku on this, so this is my own personal speculation based on the current public Provider API. It seems that Heroku Postgres and Redis are available, and while they're _technically_ addons, they naturally have access to somewhat privileged APIs and architectural information that other addons do not have. Currently, when an addon is provisioned, we're given a region identifier for the US East and EU public regions. My uninformed guess is that Private Spaces amounts to "your dynos run on servers in a private VPC." IF the Postgres and Redis integrations were "quick 'n dirty," they could very well get provisioned within the same VPC. However, it also seems plausible that AWS VPC peering can be used for other addons to provide their own Private Spaces support. So it seems to me the question comes down to whether Heroku can (and/or _wants_ to) support VPC pairing with addons via their Provider API, so that other providers can provide their own private spaces.
- grandalf 11y ago> So it seems to me the question comes down to whether Heroku can (and/or _wants_ to) support VPC pairing with addons via their Provider API, so that other providers can provide their own private spaces. This would be a huge boon for add-on providers.
- pinum 11y agoSo... PPaaSaaS?
- cdnsteve 11y agoDoes Private Spaces (aka VPC) offer any type of SLA?
- guiporto 11y agoHeroku please launch new regions! I really hope you guys launch in Sao Paulo, Brazil.
- Paulods 11y agoYep. Wouldn't hurt to have Tokyo regions as well for Asia.
- njohansson 11y agoThey do in fact launch Tokyo as a region in combination with this announcement! (together with Frankfurt, Germany and two US regions) As all these places are AWS regions and this service most likely is built upon VPC I don't think it's a too wild guess that this service will eventually be available in all AWS regions (https://aws.amazon.com/about-aws/global-infrastructure/ https://aws.amazon.com/about-aws/global-infrastructure/)
- Paulods 11y agoYes i saw. I should have made clear i mean for standard Heroku instances.
- griffinheart 11y agoWe'll probably soon move out of Heroku exactly because of this, makes no sense to have our stuff in the States when our user base is in Tokyo.
- sudhirj 11y agoIs this enterprise-only?
- mrfusion 11y agoCan someone explain like I'm from 2005?
- gleenn 11y agoPrivate cloud app hosting which people like the government need
- l33thax0r 11y agoDon't companies, like distelli, already do something like this? I worked for the city and we used them.
- roymurdock 11y agoOr anyone creating apps for companies in industries where the data generated/stored by the app is regulated by the government. Healthcare is the main concern here with HIPAA but it should also apply to insurance, finance, and some industrial use cases.
- timlang 11y agoYou can sign up for the beta of Private Spaces here, as well as a technical webinar: https://www.heroku.com/form/enterprise-beta-programs https://www.heroku.com/form/enterprise-beta-programs
- austenallred 11y agoIs the technical webinar required to sign up for the beta?
- timlang 11y agoNo, but those attending the webinar will likely get precedence.
- anacleto 11y ago"This is about three years overdue." I couldn't agree more Recommended write-up: What is Heroku: getting started with PaaS development [0] http://cloudacademy.com/blog/what-is-heroku/ http://cloudacademy.com/blog/what-is-heroku/
- pbiggar 11y agoNo-one is ever happy.
- llama052 11y agoI guess I don't understand this market, if you need any sort of compliance, why don't you just host it direct in AWS? The tools are there and it's not hard? Using something like this is not cost effective imho.
- kgosser 11y agoSpeaking from a HIPAA point of view, the amount of complexity you must manage to build your own compliant environment on AWS is extremely high. HIPAA's controls account for block level encryption, managing your logs a certain way, and many many more things. Furthermore, compliance is more than just doing the right thing. It's proving that you are compliant. There is immeasurable value with selecting a vendor who is audited to be HIPAA Compliant or HITRUST Certified because then the risk is offloaded to someone with credibility in the marketplace via a Business Associate Agreement. If you wanted to build your own HIPAA compliant stack on AWS, and you want to be taken as credible when trying to sell to a CIO at a hospital, then you will need to go through the procedure of becoming HITRUST Certified as well. Otherwise you will just be nibbling at the edges and taking on all the risk while hampering your business model.
- llama052 11y agoAren't you still building your own compliant environment on the application side with a heroku like model? I'm pretty sure AWS has a package for HIPAA compliance that will checkmark most of the required fields outside of the application, and general settings fields. Most of the problems will come from the Application architecture. You can have a prebuilt envorionment for everything but if you're code is garbage then good luck. Not sure how hosting in AWS is any different from hosting on Heroku, considering you're ultimately still responsible for the Application side. Does Heroku manages your logs in someway that AWS cannot? Even with an agreement with a merchant, aren't you still responsible for your application code? Isn't that still subject to HIPAA requirements? Also AWS is HIPAA compliant and they will do a Business Associate Agreement, and has been HITRUST certified iirc.
- kgosser 11y ago
- dirkdk 11y agoIs this running in Salesforce datacenters? Not Amazon anymore, as it used to be?
- amerine 11y agoNo