• 2 Posts
  • 80 Comments
Joined 3 years ago
cake
Cake day: July 2nd, 2023

help-circle












  • Modelling how you want to handle trust in your architecture doesn’t have a best answer really. Many ways to pet a cat, and all that jazz. Some prefer to trust only end to end, meaning not just establishing trust at the API entry, but all the way to the backend. There are arguments to be made for doing it either way. As long as your services behind the API gateway are in a private network, it is maybe okay to establish complete trust here and you could even terminate TLS and use clear communications. Another more secure pattern is to authenticate the call to the API, authorize which backends can be called, then verify the source caller in the backend as well.


  • There are many public sector organizations that need programming done. There are also organizations that back FOSS work. However, if it can’t involve devops, cloud, or containers, I don’t know how much will be left for you to do. There are tasks that don’t involve those, but they’re few and far between. And anybody who said those aren’t part of “REAL programming” wouldn’t get a second listen from me in a hiring scenario.




  • I think most communication errors are on behalf of the speaker, so that’s on me. Rereading, I can see how it would come off that way, but it wasn’t intended.

    There are only a few communities where the sum total of several instances of saving a few keystrokes would be appreciated candidly. A bunch of nerds talking about code sharing are the vim golfers of the world.