4 ms·
Closest thing to true “serverless”: entire MVC app (Django/Rails/Laravel) in the browser with WASM and data persistence by SQLite over CDN. All the server has
by _1tem 1y ago
Closest thing to true “serverless”: entire MVC app (Django/Rails/Laravel) in the browser with WASM and data persistence by SQLite over CDN.
All the server has to do then is serve binaries, all the business logic is in the client.
- gjsman-1000 1y agoBrilliant… but now you need to validate that the client did all their business logic correctly without tampering. That alone can be so complex it defeats the point.
- justinrubek 1y agoNo... you don't need that. Not for the overwhelmingly vast majority of cases. Let people use their own software. Tampering? Not my problem. Let people do it if they want.
- gjsman-1000 1y agoAnything that runs as a SaaS, or B2B, has that issue… which is the overwhelming majority of software. Anything that requires sharing information with other users is also a pain in the neck, as you basically need to treat your internal logic like a proprietary, potentially hostile, file format.
- Fire-Dragon-DoL 1y agoThere is a lot of SaaS that is essentially "for the buyer to the buyer", what I mean is that the software doesn't provide content to somebody else, or there is no incentive to serve malicious content (e. g. B2B). Why would tampering be relevant in those cases? There are situations where it's relevant, but I don't think it's as many as you say
- kevmo314 1y agoAnything that involves sharing data with other people will run into issues around updating. If your API surface is a shipped sqlite db instead of an API call it's liable to be abused in so many ways.
- a_wild_dandan 1y agoLocal-first doesn't mean local-only though, yeah? Isolate cloud usage to those collaborative features. If that's a huge ask, then your thingy probably isn't the kind of tool we're talking about localizing here!
- Terr_ 1y agoThe "overwhelmingly cast majority of cases" will be an employee of a larger company, a person/computer that cannot be trusted with arbitrary access to data and exceptions to business rules in code.
- drdaeman 1y agoIf it's a single-user app, you can only load data the user actually needs and is cleared to access. And/or lock down the device. Multi-user app (and if we're talking about companies, it's multiple users by the very definition) where users are not trusted almost always needs either a central service with all the access controls, or a distributed equivalent of it (which is, indeed, very hard to implement). “Local-first” in those cases becomes less relevant, it’s more of a “on-premises/self-host” in this case. But I think while end-user non-business software can be small compared to enterprise stuff, it is still a fairly big market with lots of opportunities.
- bcoates 1y agoWhat's WASM adding here? Without that you're just describing an ordinary SPA+CDN
- _1tem 1y agoThe ability to port existing apps to serverless. See for example Wordpress in WASM.
- williamstein 1y agoWASM adds the ability to run a local copy of SQLite (or even PostgreSQL) entirely in the browser.