5 ms·
I dread the companies that will mandate this, no local environment… (and I know, GCP and Azure had this for quite some time now)
by navaati 6y ago
I dread the companies that will mandate this, no local environment…
(and I know, GCP and Azure had this for quite some time now)
- acdha 6y agoThose companies are going to do it anyway, not without reason. If you have high security requirements something like this is important if you don’t want to have two laptops so your development work is isolated (think what keys someone could get with a bad npm/Python package install).
- mr_toad 6y agoYou can still do a bad install inside the cloud IDE and screw up your development environment. I’ve done this on Cloud 9. But it’s usually easier to trash a cloud IDE and create a fresh instance than it is to unknot a bad Python configuration on a local machine. (Although you can always use Docker or Vagrant)
- acdha 6y agoThe main advantage I was thinking was less “I broke my machine and I need to rebuild it” and more “we had everything setup on our jump server but it wasn't documented and now we can't figure out how to rebuild it” or “someone — totally not me — forgot to clear out the admin credentials after they were done and didn't think about it since everything worked”. Ephemeral servers are a great way to keep people honest about things like that.
- theamk 6y agoBut you don't need things to be web-based for this, do you? I have worked in places which say, "no code on laptops! You get a remote machine, all code must live here" Same security advantages, but you get way more customize-ability -- choose a terminal app, font, fullscreen or many windows, and so on.
- acdha 6y agoIt doesn't need to be web-based, of course. This isn't anything you couldn't do before — it's just much easier to setup and has fewer points to get wrong (ever see a jump server whose owner forgot to change the port 22 0.0.0.0/0 allow rule?). It's especially nice because it works for everyone in every context without needing anything setup so you can safely use it for examples, training, someone working with a loaner machine, etc. even if you normally work with a custom configuration.
- gravypod 6y agoFor big companies having a completely non-local dev environment actually works pretty amazingly. It's something that I've been trying to set up at home with Eclipse Che. The workflow is great. I can switch between laptops, desktops, etc with no changes. I can run really large jobs from my phone and come back to my desk an hour or two later to see if my code worked right. I can do all of this without installing anything on my local system.
- brightball 6y agoThe funny thing is that I remember doing exactly this with PHP in the early 2000’s on a small team. We didn’t even have version control on the project and just did all of the development in vim, relying on its lock files to ensure we didn’t edit the same files at the same time. Deployed changes with rsync. That project ran in an enterprise environment, customer facing for 10 years with almost no maintenance.
- damagednoob 6y ago> for 10 years with almost no maintenance. 10 years is a long time in security. Presumably that's what the maintenance was for?
- mrmonkeyman 6y ago"What a nice house! Big rooms, nice view. Very little maintenance." "Nah, the lock is 10 years old. Any thief worth his salt can break it nowadays. The entire house is worthless I say, worthless. Burn it! Burn it now! It is a danger to society if you let it stand." This is totally reasonable and normal.
- brightball 6y agoYep. It was also a project where we rolled our own...everything. This was an AJAX project before Prototype, jQuery or even JSON was popular so we had a lot of explicitly mapped paths and code that only didn’t exactly what was needed and verified every argument.
- swyx 6y agowhat are the benefits to mandating this?
- dspillett 6y agoFor the company: infrastructure management. You don't have a local PC (other than mainly a low cost thing acting as a fairly dumb terminal) that may have parts fail and will otherwise need upgrades every now and then, with local work that may need to be encrypted and backed up, ... You are working in "the cloud", your environment is running on a common set of VMs/containers, a fault in a node just means a new one spins up (or you get shunted onto the still running ones), hardware redundancy is handled at that level reducing single points of failer, local machines don't need to be monitored for data/apps/other they should not have, resource management (does anyone run their dev PC at full tilt 24/7? no? so CPU/IO/other resources can be shared), ... For the individual: similar concerns of hardware failures losing work go away a bit (there are still ways to lose everything, but less of them), easy moving between environments (desktop, laptop, phone), ... Though it depends how much is pushed to the "cloud". You may still need some meat on the local resource bones if not pushing any CPU crunching into the sky too. Essentially we are reinventing the thin client from the 90s/00s, which in turn reinvented many mainframe concepts, not that either ever completely went away, with an eye on much the same benefits.
- freehunter 6y agoIt's the "servers are pets, not cattle" but applied to local machines. That's sort of how IT has been run for a while now, but only half-hearted and in the worst way possible. Almost every organization I've worked with has the policy of "if you get malware, we wipe your whole machine and reinstall the gold image" which is quite disruptive because you then have to reconfigure your settings and reinstall all your software packages and regenerate SSH keys etc. It can be a whole day of downtime and then a week of slowly getting back up and running full speed. But if your hardware and local software are irrelevant, you can just swap your dumb terminal for another dumb terminal without skipping a beat. And with things like Chromebooks or iPads (actual real dumb terminals) the likelihood of getting to a "wipe it and start over" goes down a lot compared to machines running a full-fledged OS with a privileged user account. If you drop your Chromebook in a lake, you could run to Best Buy and get a new one for $300 and you've only lost an hour or so, and if all your data is stored in OneDrive and your IDE is Codespaces you haven't lost anything of real value.
- Kalium 6y agoWhat's there to be afraid of, so long as your workflows aren't made significantly more painful? A local development environment should still be possible in many cases. One shouldn't need to call AWS services.
- ShamelessC 6y ago...more painful workflows
- Kalium 6y agoAll the workflows my colleagues and I deal with that would be made more painful by this are ones that are on the list of things that should be migrated to machine management. Often because they involve humans touching production systems where no humans actually need to touch production systems. Can you help me understand what, precisely, this would do in your work that's so dreadful? Perhaps there's something I just don't know.
- ori_b 6y ago> What's there to be afraid of, so long as your workflows aren't made significantly more painful? It's more painful.
- oefrha 6y agoEventually we're just back to mainframes + dumb terminals, except the dumb terminals are web browsers.
- 0ldGrkh 6y agoThe environment problem does not really allow for the American dream of 1:1 ownership. I have little sympathy for a generation raised on such notions who see it all as theft. No such legal contract exists. It makes me wonder how the next generations would feel about a stable environment being taken. But we won’t be around and have our social orders so ...
- geogra4 6y agoHistory doesn't repeat, but it certainly rhymes
- pmontra 6y agoAnd swings back and forth. In 10 or 20 or 40 years there will be something about liberating computing from the cloud overlords. The last major swing in that direction: the home/personal computers of the 70/80s. An higher harmonic: owncloud and all the current self hosted services, but we're still swinging towards centralization.
- deleted 6y ago[deleted]
- qz2 6y agoI'm already arguing with our CSO about this on Slack!
- thspimpolds 6y agoAt least with Azure the new Windows Terminal App has Azure Cloud Shell in it. So you can use it like it was just a different session target and less fuss...
- dilyevsky 6y agoBig companies also usually mandate no external ips and at least in gcp case it doesn’t work without external interface on the vm
- dahfizz 6y agoDoes GCP not let you set up a VPN? All instances can have an interface on the VPN so that you log into the VPN and can hit your instance without it being external.
- dilyevsky 6y agoYes you can go on vpn or direct connect or bastion host to hit vms on private ip but their cloud shell thingy couldn’t do that last time i checked
- ohyeshedid 6y agoTheir cloud shell thingy is actually just a docker container, and you can create your own to load as a replacement.
- pjmlp 6y agoExactly something that I used to do about 25 years ago when working on UNIX, and keep doing regularly on Windows systems over Citrix or RDP.