5 ms·
> We believe that developers do not and should not care about things like VPCs, security groups, etc. I very strongly and fundamentally disagree with this sent
by web007 4y ago
> We believe that developers do not and should not care about things like VPCs, security groups, etc.
I very strongly and fundamentally disagree with this sentiment. I know they don't, but they should!
Developers should understand how and where and why/why not their code is deployed. They should understand what their security model is AND HOW IT WORKS, because if they don't they will 100% without fail open their SG to 0.0.0.0/0 and embed hard coded passwords (usually "password", or "p@ssw0rd" at best). They should know what a VPC is, but maybe they don't need to know anything beyond "private network" and probably "NAT is involved".
Hiding these concepts is a double-edged sword. You get the simplicity of "make me a database" but don't understand why or how it works. You don't have to fiddle with security groups, until you do and then because you don't understand them you go with 0/0. You don't have to think about VPCs until you rack up a $10k bill because you never considered how you could route between instances vs round-tripping out of the VPC and back in through a LB - twice.
- igorzij 4y agoI see your point clearly, and it's a good one. However, consider the following counterargument: the exact same thing could be said (and was said) extensively about low-level programming concepts such as registers, later pointers, memory allocation, etc. It was essential for every software engineer to master... until it wasn't. Same with lower-level OS fundamentals. Same thing earlier with pre-PC hardware. We've come full circle with the present-day cloud providers like AWS. 15 years ago they started as simplification, but today they are boxes of 200+ specialised building blocks that are anything but trivial to put together. A human specialist has to be involved. But why? This complexity is completely artificial, its sole purpose is to keep their customers locked in. This must and will be solved with better tooling. That's what we are trying to make.
- skyzyx 4y agoI disagree that it’s complex for the sake of vendor lock-in. Having spent four years working at AWS I can tell you that it’s complex for two reasons: 1. Some of the stuff is genuinely complex. 2. The software engineers and development managers regularly ignore the user experience teams and their feedback.