5 ms·
Show HN: Hasura – A Postgres BaaS and Kubernetes PaaS on Your Own Infrastructure
- ecthiender 10y agoWe built Hasura over the last few years to help us build products fast. We didn't know what it would look like when we started, but we've ended up with something like a Parse + Heroku but on your own infra so that you can mess around with the internals when required. Key features: 1. Data APIs on a Postgres database 2. Deploy with git-push, or any docker image 3. Expose HTTP services on the API gateway over subdomains/paths 4. Automatic LetsEncrypt SSL cert generation for exposed http services 5. SSH service to get tunnelled access to TCP services on your cluster 6. Auth middleware built into the API gateway, so that upstream services don't have to resolve sessions 7. Out of the box auth APIs for password, email, recaptcha, social login. mobile-OTP stuff
- mej10 10y agoThis looks really cool, going to check it out this weekend. Thanks!
- bpicolo 10y agoI like that you took time to consider ACLs out of the box, that's something that most general-purpose tools leave too much to the developer, despite them being crucial for every app
- cuu508 10y agoInteresting, a couple quick questions: * for the host-your-own version are there any HA features for Postgres? * what language is it written in? GitHub link?
- ecthiender 10y ago> for the host-your-own version are there any HA features for Postgres? Not right now. This is definitely on our roadmap though. > what language is it written in? GitHub link? It's mostly in Haskell, with smatterings of Python. Planning to open source it soon!
- amalag 10y agoWhat is your monetisation strategy?
- ecthiender 10y agoWe do a lot of work with large enterprises.
- kreetx 10y agoHaskell -- cool!
- saganus 10y agoThis seems like working on a similar space as loopback.io, is this correct? if not, how would you compare the two? I ask because I'm currently using LB for a project and while I actually like it a lot I always like to be aware of alternatives and similar tools that I might need in the future.
- tango12 10y agoThe motivation is quite similar, especially with the out of the box APIs. The architecture/implementation is significantly different. Key value-prop differences are that out-of-box APIs are just one part of Hasura. The idea is to make it easy to integrate with community services (containerised) or deploy your own services in whatever language/stack. Some other specific differences: 1. Hasura Data API is a graphql like query language to Postgres. 2. Deployment is similar to Heroku. So you deploy code in any language/framework 3. Nginx based API gateway behaves like a session middleware, so that any upstrea service can re-use auth
- saganus 10y agogreat! seems like a nice tool to have in the toolbox :)
- deleted 10y ago[deleted]
- koolba 10y agoI like the cartoons too! Who drew them?
- ecthiender 10y agoWe have an in-house illustrator. This comment will make her very happy!
- icebraining 10y agoWell, you can tell her the illustrations alone would've made the visit to the site a great experience. I particularly love the ringmaster.
- pilatesfordogs 10y agoThanks! We've been lucky enough to have a couple of kickass graphic designers help us with our wackiest ideas! The logo is by https://twitter.com/shmunday https://twitter.com/shmunday Cartoons by http://www.sandhyaprabhat.com/ http://www.sandhyaprabhat.com/
- nsgf 10y agoFun fact: hasura in Greek stands for "loss/ lost".
- ecthiender 10y agoHahaha! The H in Hasura comes from Haskell, while Asura is the Sanskrit word for demon ('daemon').
- vladsanchez 10y agoIt also rhymes with "Basura" which means "Trash" in Spanish. ;-)
- armandososa 10y agoThen I guess it was fortunate that it it was written in Haskell and not in Basic
- brightball 10y agoOff the cuff it looks great. Going to have to set aside some time to try it out.
- splitrocket 10y agoIn the comparison page, it would be great to see how Hasura compares to other PAAS offerings, such as Deis, Flynn, Tsuru, etc. Agreed that built in ACLs and Baas is really fantastic.
- ecthiender 10y agoThanks! The BaaS components and the session middleware are precisely what differentiates Hasura from the above platforms.
- webmaven 10y agoYou should compare with Parse. And with Google App Engine / AppScale as well.
- deleted 10y ago[deleted]
- brightball 10y agoIf you can launch this with a tutorial on using it with Digital Ocean and build in VPC/VPN around your VM orchestration I imagine you'll see a pretty significant response.
- Kabootit 10y agoAside: ran through the demo and got a "bad gateway" at the very end trying to access the todomvc-jquery app. Guessing HNs'd. First impressions: very little magics/transparent, reasonable pieces, reasonable architecture, well packaged, nicely automated, descriptive UI, no glaring wtfs, all the bases are covered, looks easy enough to customize at any layer with skills I already have — all very sensible. Damn.
- ecthiender 10y agoThanks for the feedback! Can you elaborate what you mean by little magics/transparent?
- Kabootit 10y agoMagics: no new DSLs. The JSON to SQL thing seems more on the level of a convenience mapping than a DSL. And it can be skipped. Transparency: I felt like it wouldn't be hard to figure out what was going on behind each step. First guess easy vs black box not-so-fun. Overall easy to grok created app plus Hasura meta data associations and transformation points.
- webmaven 10y agoNice, and you've really polished that onboarding experience. Smooth and no head-scratching moments. One minor nit: It is quite nice that you provide links to jump to the right place for each step, but I would suggest adding images of the equivalent spot to click in the UI. So, what's the registration code?
- 0x777 10y ago> Nice, and you've really polished that onboarding experience. Thanks ! Alas, Tanmai (our CTO) will quote this at us for the foreseeable future, this being his idea. > So, what's the registration code? This is just something that is used with the startups and incubators we partner with. You can ignore this.
- manojlds 10y agoIt would be great if the events info have links to the events. I am based out off Chennai and use Kubernetes in production and would like to hear more about what you guys do at Hasura. Edit - realized that only the IIT talk wasn't a link. On mobile.
- kensai 10y agoΧασούρα! (so funny Hasura in Greek)
- dominotw 10y agoAsura's are indian vedic (vague) group who are primary opponents to gods. https://en.wikipedia.org/wiki/Asura https://en.wikipedia.org/wiki/Asura
- ecthiender 10y agoAsura is a demon (daemon - aka a background process). We love our puns.
- ojr 10y agoOne of the features, that I know how to do in MongoDB quickly but not in Postgres, is creating permissions not on the the role level (user, admin, etc) but on the id level like users with unique id blah234 and blah546 can access this table/row. I can figure it out in sql with time but it is not a tradeoff worth taking in my certain situation. I always look for this feature when I see a baas/paas tool show up on hacker news.
- amalag 10y agoIf you know the multiple id's, why not make a role for them?
- ojr 10y agoI don't know them
- ecthiender 10y agoThis is quite possible with the permission layer of the data service in Hasura. Why not add a new role that only 'blah234' and 'blah546' can be part of? All you have to do is to define permissions on this role. Also, creating permissions and roles are all exposed via API calls, in case you have a requirement where you need to create these dynamically.
- ojr 10y agoI looked into an api, I don't see how can leverage it in the way I want, yes these roles will have to be created dynamically, pretend a user makes a post and only wants certain users to see the post, a new dynamic role will have to be created every time a user creates a new post?
- tango12 10y agoYou could do that, but you don't need to. The ACL constraint can be any arbitrary SQLish expression that is a boolean. In this case, say select is allowed if: req_user_id is in article.viewers.user_id. This means, if the request's user_id is in the viewers list of the article. It depends on the fact, that you have a relationship called viewers which comes from a table that contains article_id, user_id. The idea is to allow any ACL rule that can be represented as a constraint in your data model.
- Just1689 10y agoI may be wrong but I think the username lookup on your login page is case sensitive.
- infinitebyte 10y agoCouldn't find docs for installing Hasura on own infrastructure?
- ecthiender 10y agoCurrently installation on cloud providers (that you own) happens through hasura.io. Register at https://beta.hasura.io https://beta.hasura.io and you can create a project. If you want to install on your own, we will be releasing docs over the next 2 weeks.
- infinitebyte 10y agoOkay. I am more interested in testing this on Openshift running on our infrastructure. Thanks!
- ecthiender 10y agoWe've never tried on OpenShift, but it works on vanilla Kubernetes cluster.
- Zaheer 10y agoThis is super useful. I'd wager 80% of API's are single data API's and Hasura would speed up development time by a significant factor while still allowing for more flexibility than just building on top of something like Parse. I think eventually most API's will use managed frameworks like this or go serverless so that a lot of the repetitive wiring code is abstracted out.
- tango12 10y ago:) Thanks. This is one of the key thoughts that inspired Hasura! We kept refining these data APIs on Postgres over the various products that we helped our clients build.
- weitzj 10y agoLooks great. How does it handle networking? E.g. if you are on AWS or Google you are fine with your VPC. But as far as I understood on Digital Ocean the private subnet is shared across all customers in this region. Do you employ an overlay network with encryption, e.g. Weave.net? Or do you deploy a VPN (tinc, peervpn) and Kubernetes on top?
- ecthiender 10y agoYou're right! On AWS and Google we use VPC. But on Digital Ocean we create single-node clusters only. We do not encourage multi-node clusters on Digital Ocean. Hopefully DO will address this soon!
- samblr 10y agoHow do I change some part of controller function of a DB table ? i.e can I change generated code (what language is the code?) or is it like hook functions available in cloud ?
- tango12 10y agoThe Data APIs are not actually generated. The Data API service exposes a JSON query language on any Postgres table. So if you want to customise the controller, the easiest thing to do is to write a custom API endpoint (which you can deploy to your server using a heroku style git-push or a docker image) which in turn can contact the data APIs or even the Postgres database directly.
- searchfaster 10y agoLooks great... may be just what I have been looking for. PS: The illustrations are awesome !
- guruparan18 10y agoIllustrations: They are indeed. These are the colorful demigods of Hinduism. More: https://www.google.com/search?q=mahishasura https://www.google.com/search?q=mahishasura
- HugoDaniel 10y agoIs it open source ?
- Arcsech 10y agoLooks kinda like Dokku + PostgREST + a fancy UI, is that mostly right? Not trying to disparage it, just trying to relate figure out what Hasura is, there's a lot going on. One thing that concerns me is the "Don't make changes to your Postgres schema outside of the UI, it'll mess things up" warning. If I already have a tool to manage database migrations, it sounds like using it with this would be a bad idea? Edit: Also, what accounts for the speed increase over a bare VM? I'm assuming something Hasura does for you, but it would be nice to know what that is.
- tango12 10y agoHasura engg. here. No offence taken! :) Hasura is indeed kind of what you described. The warning on the UI is mostly for non power-users who probably don't have a good db migration kind of practice. Underneath, the Hasura data API stores its minimal metadata within Postgres itself. That means that you can always use Postgres directly, and your migration tool works exactly the way it should. Whenever your schema migrations affect a data API, you need to ensure a metadata update for the Data API as well. We're going to be publishing examples of how DB migrations look using just a raw SQL setup, and an alembic setup! The speed increase for the Data APIs is because of a few reasons: 1) Efficient serialization/deserialization of the JSON queries and responses (https://hackage.haskell.org/package/aeson https://hackage.haskell.org/package/aeson) 2) Prepared statements 3) JSON aggregations done within Postgres (not generating the JSON) 4) Every client API call needs to be authenticated. The authentication is done by a efficient middleware written inside nginx with redis as the session store. The data API layer, then just does the authorization (this user-id can access this row).
- ruslan_talpa 10y agoActually Hasura is something that might be the only thing out there that is anything close to touching postgrest in this space (respect :)). The only thing that worries me a bit is that the client can generate any type of query, meaning it's easy to generate an unoptimized join that will kill the db (did i get it wrong? how do you protect against that?). The other thing i do not understand is why are you not relying on "reading" the schema and require to go through a gui to define the schema. Why did you not copy the queries from postgrest that introspect the database schema and the relations? If you guys want i can send you a single query that you run and get the structure of the database and all the relations and use that as your "metadata" :) (I'm from postgrest core team, probably competing with hasura in the future here https://graphqlapi.com https://graphqlapi.com)