7 ms·
Wondering why does any developer need update/delete/drop access to a prod database? Or why would ad hoc scripts have this ability?
by badmadrad 9y ago
Wondering why does any developer need update/delete/drop access to a prod database? Or why would ad hoc scripts have this ability?
- gremlinsinc 9y agoonly devops should have this info and they should be guarding it fiercly and only use when they know why/when... it would be easy enough to mirror all production data to a 2nd db w/ full read/write that's updated daily or weekly from source. That should give plenty of data for devs to work with.
- beardbandit 9y agoNow convince a place that isn't doing this to spend time and resources to put this into place. 'Ship fast and break things' is one of the best and worst cultures in the tech industry.
- gremlinsinc 9y agoYou'd think a product geared towards development and dev best practices...would maybe use some themselves?
- deleted 9y ago[deleted]
- jlgaddis 9y agoBest practices are always for everybody else, we can skirt around them because ...
- idunno246 9y agoisnt the idea of guarding access fiercely from developers the antithesis of devops? That just makes 'devops' people 'ops'
- notatoad 9y agoThe idea that developers should actually be involved in ops doesn't seem to be DevOps anymore. Apparently that's called "NoOps" now, and DevOps is just ops people scripting things.
- balls187 9y agoLeast privileged access isn't necessarily the antithesis of devops. You could argue that dev-ops model include automation for operations on production systems, with direct access to production systems limited to a reduced set of staff. Developers can create the change-sets to modify infrastructure, but those change sets are reviewed, validated, tested, and then executed on production via CI/CD Automation. Infrastructure as Code, and Immutable Infrastructure lends itself well to that approach.
- joelcornett 9y agoTL;DR don't rely on humans to "do the right thing", even if they're supposed to know what they're doing (i.e. ops people). As part of a team (and an organization) that practices "devops" heavily, all of our devs do ops. We maintain the separation using an oncall/ops rotation and only touching prod from designated "ops" hosts. We also follow a "2 person" rule when touching production. We use a secrets management system to deliver credentials to hosts and alarming setup when the "wrong" hosts (e.g. dev hosts with access to prod creds) have access to certain creds.
- evfanknitram 9y agoMaybe because developers do operations for the production system?
- balls187 9y ago> Maybe because developers do operations for the production system? Which is probably why they dropped the prod db.
- evfanknitram 9y agoYeps. Pure operations people don't make mistakes.
- zaidf 9y agoThat’s a strawman. The argument is “would a devops person focused primarily on deployment be significantly less likely to make errors of this nature?”
- evfanknitram 9y agoWhen I look at our development, devops and operations people, the likely hood of making stupid mistakes seems to be correlated to skill-level rather than what title the person has. The developers who work part time with operations seems to cause less problems than pure operations-people, maybe because they only do it part time and therefore are a bit more careful. But I'm sure you can enlighten me with some actual research-based facts?
- bigtones 9y agoI thought the same thing. The production database should not even be on the same LAN segment as the development stuff, you should have to VPN or tunnel into it specifically to query it.
- iampims 9y agoI believe they run on Heroku, and there is no such separation possible.