4 ms·
I know the Kubernetes Assessment was the one to make all the news, but the teams actually audited a bunch of CNCF projects. Here is the one for the Vitess proje
by dkhenry 7y ago
I know the Kubernetes Assessment was the one to make all the news, but the teams actually audited a bunch of CNCF projects. Here is the one for the Vitess project
https://vitess.io/blog/2019-03-12-vitess-security-audit/ https://vitess.io/blog/2019-03-12-vitess-security-audit/
- jey 7y agoVitess is > A database clustering system for horizontal scaling of MySQL > Vitess combines many important MySQL features with the scalability of a NoSQL database. Its built-in sharding features let you grow your database without adding sharding logic to your application. What a quirky project. Is this for folks who started out with MySQL then find themselves needing to scale out in "NoSQL" style? > Vitess automatically rewrites queries that hurt database performance. That sounds scary.
- sciurus 7y agoVitess was created by Youtube. But they're hardly the only places scaling out MySQL. Facebook and Slack are two other prominent examples.
- halbritt 7y agoFacebook has taken MySQL scaling to extremes well beyond what Vitess offers. Not sure if that's a good thing.
- pas 7y agoAnd to understand scaling and extremes: FB basically uses RocksDB and/or MySQL as a low level storage layer for whatever thing they want to. (And on top they build the clustering stuff, with the particular CAP choices they think is best for that particular service/purpose.)
- dkhenry 7y agoSlack actually uses Vitess to scale out its databases.
- raesene9 7y agoIt's part of the CNCF graduation criteria now, that any project which is going to "graduated" status has to have a 3rd party security review, so you should be able to get one for any of the projects in that category.
- mfer 7y agoCure53 did the Vitess audit. I think they've done others for the CNCF, too. The Kubernetes audit was done by Trail of Bits. It was a different team that did the assessment.