HNHacker News
TopNewBestAskShowJobs

andreacavagna

45 karma · joined September 8, 2020

AWS Community builder and Open-source lover

I'm passionate about making my open-source project sustainable. I'm a co-founder of Noovolari (www.noovolari.com)

Feel free to email me at a.cava94@gmail.com

submissionscomments
andreacavagna··on Open-source alternatives to popular B2B tools
making it open-source and submit pull-requests will be awesome, and sort of making sense with the purpose of the website
andreacavagna··on Next Billion-Dollar Enterprise Software Companies Will Be Born Outside the US
As always a great point of view by Glenn Solomon, I really like this part:

"The market fundamentals that underpin this trillion-dollar software sector are clear: as every company transforms into a software company—a transformation only accelerated by the pandemic—developers are in the driver’s seat.

They want to choose their own tools, technologies and platforms, not products foisted on them by their employers. Thus, enterprise software companies that understand and cater to developer needs stand to generate hundreds of millions of dollars in revenue in the years to come. "

The idea that, in the next years to come, an important seat in the business technology world will be occupied by developers can bring back force to the community itself.

andreacavagna··on Show HN: Leapp – Multi-cloud credentials tool for developers
We are going to implement a custom credentials process for AWS too with the Leapp Daemon, it's in the roadmap of the project.

Thanks for pointing it out.

The main difference is that Leapp also disable the profiles whenever they are not needed, so attackers can't find even the credential process attached to a not in use profile.

The main idea is to bring only the least credentials needed in order to make developers work.

check specification for an in-depth explaination: https://github.com/Noovolari/leapp/wiki/specs

andreacavagna··on Show HN: Leapp – Multi-cloud credentials tool for developers
Chamber is a wrapper around AWS Session Manager Parameter store.

To make Chamber work, you need a set of AWS Credentials. Leapp, by now, manages those AWS credentials and ensure that only short-lived credentials will be stored in the ~/.aws files.

Chamber can be a sort of Action of Leapp, like what happens with AWS SSM in Leapp, so for each Leapp Session you can, in the app, access to an EC2 instance directlly from Leapp, without any pem key, via AWS Session Manager System Manager.

So the goals of the 2 tools are a bit different, we work to secure and provide access to the Cloud, Leapp is an enabler to work in cloud for developers.

If you want to better know what are the goals of the app, refer to the Specification

https://github.com/Noovolari/leapp/wiki/specs

andreacavagna··on Show HN: Leapp – Multi-cloud credentials tool for developers
We are almost close to support GCP with the new core business logic of the Leapp Daemon:

https://github.com/Noovolari/leapp-daemon

in the next releases we will move the business logic from electron to here.

The Electron App and a CLI will communicate with the Leapp Daemon.

Btw, the daemon is close to manage GCP and Alibaba Cloud Sessions!

andreacavagna··on Move fast, but understand the problem first
I just lived this on my skin.

My team and I, 4 engineers, we focused for about 2 years only on moving fast, and moving on doing a feature battle with the competitors.

After all this this we stopped and restarted a new journey focusing on things that really matter: - Why - How - What Are we doing it, and it changed everything for us.

My teammate has posted the story of the last 7 years of my team today, i give you the link if you are interested in knowing more:

https://medium.com/leapp-cloud/road-to-noovolari-89df7704e31...

andreacavagna··on Show HN: Leapp – Multi-cloud credentials tool for developers
Less than a year ago, my team and I decided to develop an essential tool that securely manages programmatic (CLI/SDK) access to AWS resources distributed among several Cloud accounts.

Temporary credentials access was a constraint for accessing the Cloud in our company, so we decided to build an open-source (https://github.com/Noovolari/leapp) tool for every access method on your behalf.

Leapp manages different access methods: IAM Users, IAM Roles federated with multiple Identity Providers (G Suite, Okta, and OneLogin at the time), IAM Role Chained to another AWS entity (the cross-account Role access thing), AWS Single Sign-On Roles, and Azure Subscriptions by now.

Leapp store securely information of the developers (like AWS Access Key and Secret Keys) and generate short-lived credentials accessible to any CLI, SKD, and external library.

The idea of the App is to provide the Cloud credentials I need only when required. Otherwise, the Cloud Credentials file is cleaned and not accessible to any attackers.

We integrate the project with specific services like AWS Single Sign-On, the automatic provisioning of the account available to access, and AWS System Manager Session Manager to access EC2 instances directly from the App.

I'm also finalizing the Access to other Cloud providers (Google Cloud Platform and Alibaba Cloud) in the following months.

Hundreds of developers are downloading it, and the most common reaction is: "It's addictive. I don't want to go back to anything else."

After all those requests, from today, we will help the company-wide adoption of the project with enterprise support of the open-source project.

https://www.leapp.cloud/support

andreacavagna··on Ask HN: Landing page vs. GitHub repo, where to link in Y Combinator Show?
I think I will do this strategy
andreacavagna··on Ask HN: Which browser do you use and why?
i'm the only one that is using Brave? Privacy and getting paid for all the ads you want to see in crypto, to me haas been a game-changer. https://brave.com/
andreacavagna··on Ask HN: What open-source projects you built yourself? How you maintain it?
Thanks for your words! Did you started with the Saas business model or you served some support services before.

I'm having some asking from my community to open an enterprise support to my project and then we will see at the opportunities for other project, like a saas solution

andreacavagna··on Ask HN: What open-source projects you built yourself? How you maintain it?
I completely agree with you, also I can suggest a model to measure the gravity of your community in an open-source project, take a look at Orbit: https://orbit.love/
andreacavagna··on Ask HN: What open-source projects you built yourself? How you maintain it?
Awesome template, my project is an electron based cross-platform app tjat encapsulate an angular project.

Securing our template has been an hard challenge:

https://github.com/Noovolari/leapp

andreacavagna··on Ask HN: What open-source projects you built yourself? How you maintain it?
so you decided to open the company and the open-source project at the same time right?

Why Saas is the choice for the first commercialization model?

I can suggest this community, it's helping me a lot on lot of choices to be made in the COSS community:

https://www.coss.community/

andreacavagna··on Ask HN: What open-source projects you built yourself? How you maintain it?
When have you started thinking about making it a profitable project? Did it start from a community need, or the project started as a commercial open-source solution?
andreacavagna··on Ask HN: What open-source projects you built yourself? How you maintain it?
nice project! have any idea on how to comunicate the project properly?

I've seen so far that is truly important create a community behind a project, and that's the true power of open-source, because if there is an audience and a community interested in solving a common problem, it will be also something available to pay for a solution tha solve a common problem

andreacavagna··on Ask HN: What open-source projects you built yourself? How you maintain it?
https://github.com/Noovolari/leapp
andreacavagna··on Ask HN: What open-source projects you built yourself? How you maintain it?
I'll start. I'm working on an open-source, cross-platform app to manage Cloud Providers credentials for developers.

The project started from a work need; as a consultant, it was a daily task to switch from a cloud account to another, and I was looking for a secure and easy way.

The project grows rapidly, and I'm looking to add support to the solution for the enterprise that is adopting the solution at the company level.

In the community, I've had some requests for troubleshooting and bug prioritization and granting a certain level of continuity. I think that a support option for the enterprise is the best option.

andreacavagna··on Open Source is eating Europe [pdf]
one of the most clear view on the OSS community and growth in Europe.

For the commercialization of an open-source project I will suggest this article from a post of Peter Levine:

https://a16z.com/2019/10/04/commercializing-open-source/

I started from this article in finding the way to commercialize my open-source project here in Italy

andreacavagna··on Open-source tool for Cloud credentials management now support AWS Single Sign-on
Yeah, definitely, because Leapp only generates plain short-lived credentials with access key and secret key, and the corresponding session token from AWS Single Sign-on. So it's fully compatible with all the open-source solutions, including CDK
andreacavagna··on Open-sourcing Cloud-access management
I'm planning to add more and more integration to this DevTool Application with the goal to help as many developers as possible, with Short-live credentials for CLI and SDK.
andreacavagna··on Chef cofounder on CentOS: It’s time to open source everything
> One way that open source companies are doing this model to fantastic effect is by open sourcing their upstream and creating a cloud distribution (read: managed service). A variety of companies have embraced this model to greater or lesser extents.

COSS is the emerging Business model, and helps entrepreneur take the best from Open-source and Cloud

← PreviousPage 2 of 2