HNHacker News
TopNewBestAskShowJobs

abhishektwr

589 karma · joined December 30, 2010

/dev/null
submissionscomments
abhishektwr··on DevOps is a failure
And now 50% time software engineers are writing infrastructure. Don’t know what is solution but cloud-native landscape has increased cognitive overload.
abhishektwr··on Ask HN: In 2022 how do you develop a simple CRUD app if you have few time?
Thumbs up for Django.
abhishektwr··on Ask HN: What huge mistake did you make early in your career?
For senior roles CV/brand still weights. You need to be in initial shortlist then only leetcode and interview will be any help. I now work at a big brand high growth company and get pitched 2-3 new opportunities every week, although I have been in the current role less than 9 months. Previously I have to apply and rarely a recruiter approached me.
abhishektwr··on Ask HN: What huge mistake did you make early in your career?
Not starting with a big name tech corp or a high-growth VC-funded company. Big brand on CV makes big difference when recruiters are doing initial screening. A CS/MBA degree from top university helps. Do whatever you can to work with a big tech brand early in career, otherwise later you will regret.
abhishektwr··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
I will be happy to speak. My team specialise in identity and SSO implementations. In fact we also have our own identity product Axioms (https://axioms.io/).
abhishektwr··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
Congratulations on launch and good luck in a very crowded market. We are building something similar with focus on SaaS companies (https://axioms.io/). I really like your multi-tenancy approach - interesting take could be very useful for B2B SaaS companies. We achieve similar outcome using organizations.
abhishektwr··on BBC Online Moves to AWS, Serverless
I am unable to suggest anything as I am out of touch these days. 5 years back every media CIO/CTO wanted to have Adobe AEM paired with Wordpress. Then they realised Adobe AEM is way too costly so decided to build authoring experience in-house but still using Wordpress and like for rendering and delivery. Recent trend use JAMStack/SSR for rendering. Don’t get me wrong it’s all great but doesn’t solve real problem media businesses face these days.
abhishektwr··on BBC Online Moves to AWS, Serverless
I never understood why media companies continue to reinvent the wheel. What’s commercial benefits if at all any? I guess, good for everyone’s CV. Build better media products, but no let’s build another publishing system.
abhishektwr··on Launch HN: Epihub (YC S20) – Shopify for teaching online
Very timely. Just signed up.
abhishektwr··on Show HN: Create beautiful mockups and graphics for your app in a few clicks
Pricing is quite tricky. Gave a try without knowing that with free plan you can download only 3 times. Otherwise output looks great.
abhishektwr··on JWT (JSON Web Token) debugger
JWT Debugger App is a good alternative. It’s cross-platform so you can install on you local desktop or just use web version whatever works for you.

https://jwtdebugger.app/

abhishektwr··on Show HN: A cross-platform JWT Debugger
Hi HN, We have created a cross-platform interactive JWT Debugger App with JWT token validation support using JWKS Endpoint and PEM/Secret Keys. Use the web version as a progressive web app or install desktop apps for Mac, Window, and Linux.

Love to hear your feedback. App itself is open-source and if you find any issues or like to add a feature just open a Github request (https://github.com/axioms-io/axioms-jwt-debugger). We will love to help.

The app is built on top Quasar Framework which is why it is cross-platform. It took about a day to pull this off. So current codebase is probably not completely clean yet but the app itself is fully functional.

abhishektwr··on Supabase (YC S20) – An open source Firebase alternative
Looks great. Gone give a try.
abhishektwr··on Ask HN: Has anybody shipped a web app at scale with 1 DB per account?
Thank you. Saved me.
abhishektwr··on Ask HN: Has anybody shipped a web app at scale with 1 DB per account?
Firebase has this interesting feature called "namespace". If you are building the multi-tenant app using namespace it will give you probably desired results. So I guess you can call each user's environment a database if you are using namespace.
abhishektwr··on Ask HN: Has anybody shipped a web app at scale with 1 DB per account?
For Postgress you can use and scale one schema per customer (B2B). Even then, depending on the instance size you will be able to accommodate 2000-5000 customers at max on a Postgres database instance. We have scaled one schema per customer model quite well so far (https://axioms.io/product/multi-tenant/).

That said, there are some interesting challenges with this model like schema migration and DB backups etc. some of which can be easily overcome by smartly using workers and queuing. We run migration per schema using a queue to track progress and handle failures. We also avoid migrations by using Postgres JSON fields as much as possible. For instance, creating two placeholder fields in every table like metadata and data. To validate data in JSON fields we use JSONSchema extensively and it works really well.

Probably you also need to consider application caching scenarios. Even you managed to do one database per customer running Redis instance per customer will be a challenge. Probably you can run Redis as a docker container for each customer.

abhishektwr··on Ask HN: Looking for side project ideas
On side, does newscaptureapi provide author information i.e. name of author bare minimum, email will be great. And also how you tackle copyright issues?
abhishektwr··on Loginsrv: JWT login microservice with back ends like OAuth2, Google, GitHub
Assuming you are using traditional web app and not SPA, I think it’s absolutely possible to generate restricted access tokens for anonymous users either using Machine to machine (M2M) client authentication or service account (SA) client authentication basically without any user context. Many Identity as a service providers supports M2M, and platform I am in involved supports both M2M/SA (disclaimer in profile). You can effectively attach an anonymous role to your OAuth client of type M2M/SA and start issuing access tokens. For SPA it could be complicated.
abhishektwr··on Loginsrv: JWT login microservice with back ends like OAuth2, Google, GitHub
Can you explain bit more about your use case? You meant to say a just access token but no id token or session?
abhishektwr··on JWT scope claim compression using a bitmap
You still have to make network calls to obtain public key (JWKS) to validate token signature. Unless you are using shared private keys. With userinfo you will know if token is invalidated or not.

I guess it also depends on use case. If you are in domains such as banking with elevated security requirements, then probably you want to hit userinfo endpoint else you can continue with token validation with cached or stored keys.

abhishektwr··on JWT scope claim compression using a bitmap
I am curious, why will you not use OAuth 2 userinfo endpoint which can serve a lot more detail and keep claims in JWT simpler and lightweight.
abhishektwr··on Ask HN: What are your favorite developer-efficiency tips?
Use Makefile, Readme and .env files more effectively (mainly to avoid WTF moments when you don’t remember why you did something when you did it).

I am not good at remembering commands particularly when you have to deal 10 different technologies (Kubernetes, Docker, Framework specific stuff) so create some standard wrapper functions as make shortcuts and document them in Readme.

abhishektwr··on OAuth 2.0 Security Best Current Practice
Thanks for the pointer. I am not sure if OAuth 2.1 is part of working group yet. Nonetheless, a good consolidated read compared to reading 20 different RFC specs.
abhishektwr··on OAuth 2.0 Security Best Current Practice
I need to read this draft RFC a few times before I can grasp it completely. There is an existing RFC drafted in 2013 with a focus on OAuth 2.0 threat model and security considerations [1], and it looks like this new RFC is making more specific recommendations on top of it. May be read them together.

To be honest, I was wishing for OAuth 2.5 if not OAuth 3.0 to consolidate already fragmented OAuth 2.0 spec and landscape [2]. At this stage, there are too many draft proposals and a majority of them led by vendors with some interest in standardizing their implementations.

For example, this RFC suggests restricting issued access token to one resource at a time (using audience parameter). Well with Microservices landscape this gets really challenging. Your client application may be interacting with multiple resources. Neither OpenID Connect nor OAuth 2.0 offer solutions to issue multiple access tokens (not yet). An API Gateway may be a solution but still so much ambiguity.

I think OpenID Community has done a better job to organize their specifications and working groups [3]. If you go on their specification page it tabulates really well what spec is final, currently under implementation, draft, or obsolete. Still, big vendors influence agenda and direction.

(Disclaimer: I am the founder of https://axioms.io/ which OAuth 2/OpenID Connect compliant identity management platform)

[1]: https://tools.ietf.org/html/rfc6819

[2]: RFC 6749, RFC 6750, RFC 6819, RFC 7662, RFC 7009, RFC 7519, RFC 8414, RFC 7591, RFC 7592, and 20 more.

[3]: https://openid.net/developers/specs/

abhishektwr··on Ask HN: How come there is no example code for B2B-SaaS apps?
Just to add details on this topic, Multi-tenancy is quite complicated subject and there are many ways to implement it.

(1) One database per tenant. Each tenant gets their own set of tables. Dedicated virtual infrastructure with strong data isolation. (2) One database but one schema per tenant using Postgres. Each tenant gets their own set of tables. Shared virtual infrastructure with strong data isolation. (3) One database one schema one set of tables but tenant data is segmented using tenant key in the tables. Shared virtual infrastructure logical data isolation. On top you can create tenant specific views.

Before you choose one, you need to analyse best possible approach according to your needs factoring performance, cost, maintenance and scalability. You can also mix some of these approaches in you solution. So for instance we use all 3 on top of single codebase.

Happy to respond any specific questions anyone may have.

abhishektwr··on Ask HN: How come there is no example code for B2B-SaaS apps?
Will you consider a SaaS option? We are finishing up a identity management platform which does exactly that (at least access management part with 3-tiers of multi-tenancy). Our dedicated option allows you to host up to 1000-5000 tenants in a completely isolated infrastructure. Happy to have a chat.
abhishektwr··on Show HN: Explore Wikipedia edits made by institutions, companies and governments
Looks great. This could be interesting feature for media monitoring companies.
abhishektwr··on Rules for Data Modeling with DynamoDB
Having spent a few years working with DynamoDB to build multi-region, multi-tenancy platforms, I must say that DynamoDB is a good fit as a supplement datastore i.e. you should only store a sub-set of information managed by your serverless microservice. DynamoDB multi-region replication is just amazing. Unfortunately, we had a few massive billing spikes with DynamoDB, and we end-up adding pricing measurement and tests to track read/write units in all our functions.

I generally don't recommend DynamoDB as primary data store irrespective of your use case. It takes too much time to model the data. With every new requirement, you have to redo a lot of modelling exercise. Choices you made in beginning start looking bad and you will not remember why you created that particular combination of the composite key or local secondary index which offers no benefit due to incremental changes. Transaction support is painful, existing SDKs just don't cut.

I often wish some of the GCP Firebase features are available in DynamoDB like namespace, control on daily throughput to avoid billing spikes and transaction support.

abhishektwr··on Ask HN: What projects are you working on now?
I am working full-time on a new end-to-end identity platform Axioms. Authentication, Authorisation and Assurance - all in one platform . Ready for beta in a week. Unfortunately, I have been slow to get this out early due to health issues but I am glad I prioritised my well-being.

https://axioms.io/

abhishektwr··on Leadership Bits – short podcasts for tech execs
I may not have an absolute answer but I think it’s not impossible to measure the leadership styles. There is a lot of survivorship bias in leadership stories and acknowledging that is a very first step to measure it. To me a good leadership style inspires and help others to become a leader particularly those who at first glance don’t seem like a leadership material. We can simply count the number of people one personally guided to either become a leader or grow as leader. We can also measure the impact they created in their own functional area as well as in whole business unit.
Page 1 of 2Next →