Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cainlevy
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
cainlevy
9y ago
Seems like an oversight, doesn't it? I've created an issue to track here: https://github.com/keratin/authn-server/issues/15
2.
▲
by
cainlevy
9y ago
Yeah. I think Travis provides a warmed server.
3.
▲
by
cainlevy
9y ago
Thanks for the report! I believe I've tracked this down to an initialization routine that MySQL goes through on the first boot. It happens after docker-compose unblocks. Likely a wontfix. :/
4.
▲
by
cainlevy
9y ago
My intention for the user-facing endpoints is that the host app will never need to see or accidentally log a user's password. It's a pattern inspired by credit card vaults. Could you still achieve your deployment goals with a Gate
5.
▲
by
cainlevy
9y ago
Fixed, thanks!
6.
▲
by
cainlevy
9y ago
That all sounds like a direction I'd happily consider: * Google Cloud Storage implementations for data interfaces * Metrics interface with a Prometheus implementation (STATSD to follow) * Redis-backed HLL metrics are optional Feel free
7.
▲
by
cainlevy
9y ago
Thanks! Have you seen the /stats endpoint? It exposes the metrics as JSON, which may be a good match for your suggestion. I'd also like to export the key events to a STATSD-compatible sink so a sophisticated user can manage metric
8.
▲
by
cainlevy
9y ago
Yep, it's very broad. Let's say it depends how "majestic" a person's monolith is? :D One point of context I'd like to inject here is that chatter between AuthN and a host app is pretty minimal. Aside from execu
9.
▲
by
cainlevy
9y ago
It's on my roadmap. Prioritizing is hard. :/
10.
▲
by
cainlevy
9y ago
Keycloak does some really great things. It does require managing a Java runtime though, and is missing the streamlining that allows AuthN to run as an invisible API. Keycloak (and similar) hosts and renders your login page. You customize th
11.
▲
by
cainlevy
9y ago
Yeah, I don't expect this JWT scheme to become an adopted standard. It's been streamlined from OIC for the narrow use case of working tightly with a trusted app. Adding support for inbound federation is on the roadmap. Support for
12.
▲
by
cainlevy
9y ago
Yeah, name/pass sounds pretty simple, doesn't it? But doing it correctly, securely, with a service architecture? That gets interesting. > It would be much more interesting to me if it also did Oauth2 login with Google/Face
13.
▲
by
cainlevy
9y ago
Tests are colocated inside packages (folders) using a `_test.go` convention. Service tests[1] are the main unit tests, and use mock implementations of the data store interfaces. Data (DAO) tests[2] are generally run across every implementat
14.
▲
by
cainlevy
9y ago
Strong choice! My dream is for AuthN to provide authentication and account functionality for folks who have not yet invested in an API gateway, and then seamlessly plug in when their architecture matures later. Extracting user accounts can
15.
▲
by
cainlevy
9y ago
I would dearly love that! The answer is not yet. Can you recommend any testers that are OSS-friendly? My current plan is to set up a HackerOne page. I know that bug bounties don't replace good penetration testing, but it's a start
16.
▲
by
cainlevy
9y ago
> Dex is NOT a user-management system, but acts as a portal to other identity providers through "connectors." > ORY Hydra is not an identity provider (user sign up, user log in, password reset flow), but connects to your exi
17.
▲
by
cainlevy
9y ago
Auth0 is top-notch SaaS. I have only good things to say about their product. Aside from being OSS, one major difference is that Keratin AuthN is purely an API. It's optimized for customization so that it will fit with any bespoke (secu
18.
▲
by
cainlevy
9y ago
I'm currently investing in JWT and have not done enough research on SAML to make it part of my plans. Happy to learn more.
19.
▲
by
cainlevy
9y ago
I'd love to fill that in! If anyone would like a comparison, please add links in this thread and I'll reply. Later, I can collect it into a published page.
20.
▲
Show HN: Keratin AuthN – Accounts and Auth Microservice in Go
(keratin.tech)
104 points
by
cainlevy
9y ago
|
54 comments
21.
▲
by
cainlevy
9y ago
Oh? Seems like you still want to support old client versions, which means retaining the fragments that they reference. The question then is what implications that has on a server -- do old fragments need to be eventually garbage collected?
22.
▲
by
cainlevy
9y ago
I'd be interested to read an analysis of how this compares to the backends-for-frontends pattern. Also, it seems like Relay Modern reintroduces API versioning, but automates it behind a compiler step. Is that a fair characterization? D
23.
▲
by
cainlevy
10y ago
> using HMAC SHA-256 HMAC is great for monolithic architecture, but I've quite enjoyed using asymmetric RS256. I don't think that's something AS::ME offers.
24.
▲
by
cainlevy
10y ago
1. The reason AS::ME can be that nice is because it assumes a monolithic architecture and a single framework. For example, AS::ME relies on shared secrets, which I think makes it unfit for distributed systems. Implementing JWK with asymmetr