My favorites are a bit later – Lanquidity (1978) and Sleeping Beauty (1979).
A good start might be the lone release on Savoy, The Futuristic Sounds of Sun Ra (1962) – China Gates is such a hypnotic jam.
135 karma · joined April 22, 2014
My favorites are a bit later – Lanquidity (1978) and Sleeping Beauty (1979).
A good start might be the lone release on Savoy, The Futuristic Sounds of Sun Ra (1962) – China Gates is such a hypnotic jam.
This is a good read on Saturn: https://londonjazzcollector.wordpress.com/2021/07/09/beginne...
Top 10s are always tough, but I'll give it a shot. I have a penchant for the obscure, but if I were to consider total output, my list would be (I know I'm leaving some out)...
- Arthur Verocai (anything he arranged) - Joyce Moreno - Jorge Ben - Milton Nascimento - Edu Lobo - Nara Leao - Elis Regina - Marcos Valle - Gal Costa - Joao Donato
And a bonus top 5 groups
- Tamba Trio - Novos Baianos - Azymuth - Quarteto Em Cy - Dom Salvador's groups (Rio 65, Salvador Trio, etc.)
For a deep dive into the obscure stuff, I used to do a podcast from my collection. Lots here to keep anyone busy.
https://www.independent.co.uk/arts-entertainment/music/featu...
There’s a recent book compiling much of the original cover art. Recommended.
Sun Ra: Art on Saturn: The Album Cover Art of Sun Ra's Saturn Label https://a.co/d/7h3J9II
Exactly right... BeyondCorp is more of a reference architecture than a product. Google's own internal implementation is what the research papers focus on, but we're seeing more companies adopt similar models by shifting access controls to the application layer, where a request can be independently authenticated (corporate IdP) and authorized (RBAC, policies) against more dynamic conditions - such as the security posture of the user's device.
The Identity piece is a critical component to the system as the user system of record, but really just one of the inputs in a BeyondCorp-like environment.
https://www.scaleft.com/blog/how-to-deploy-a-beyondcorp-styl...
I agree with many commenters that it appears transformative, but that's only through the lens of Google. Centralized access controls at Layer 7 through a proxy service that can authenticate and authorize requests, while brokering encrypted sessions isn't that out of reach. Our goal at ScaleFT is to offer as much as a service as we can.
Where things do get tricky, though, is with the access policies and device attestation in a BYOD environment. Admittedly, we have work to do in this regard, but it may not require a full MDM layer. Really, you only need to query device state at a given time to make an authZ decision.
Love to see BeyondCorp get more coverage, and I hope to see further adoption outside of Google.
Similarly, apps are placed behind a reverse proxy, which performs authN via your company's IDP, then authZ against the policies associated with the resource. These can be basic RBAC or more device oriented decisions such as whether the client disk is encrypted.
We also believe a SaaS model is the way to make BeyondCorp a reality for companies who aren't Google, but there's more to it than a proxy service. We've found the more challenging aspects of a complete system to be the policy engine and device bindings, and have spent the past couple years working to offer with our product.
Glad to see CloudFlare talking about BeyondCorp, the more who are providing solutions in this space, the easier it will be for companies who are not Google to get there.
My eventual life goal is to do something similar with my Brazilian record collection... have the skeleton of such catalog at: https://www.novedos.com/collection.
This. I've been a record collector for 20 years, mostly focused on rare Brazilian music - https://www.novedos.com.
I don't DJ anymore so it's primarily a collector thing for me. Aside from the master tapes, an original vinyl copy is as close as you can get to the original recording, which is special. I'm far from an audiophile, so it's not about the sound, it's about the feels.
Our first priority in developing our bastion product was to guarantee end-to-end privacy and verifiability, so the cleartext is not available on any bastion. We do have a roadmap item to support customers' desire for visibility into team activity, but we engineered for privacy first. Our current auditing is event-based - device enrolled, credential issued, ssh/rdp login, etc.
Happy to discuss our roadmap further - ivan.dwyer@scaleft.com
The first couple BeyondCorp papers talk a lot about how Google deployed this architecture side-by-side their traditional LAN, and slowly migrated applications over, only after closely inspecting and understanding the traffic.
But the real point they make is that Internet != safe = very much worry about security.
The most common feedback I get is that it seems like too much of a stretch for companies that don’t operate at Google scale. That may be true if looking at the system as a whole, but the principles behind the architecture should attract anyone’s attention - remove trust from the network by authenticating and authorizing every request based on what’s known about the user and connecting device at the time of the request.
Disclaimer: I work for ScaleFT, a provider of Zero Trust access management solutions.
Edit: If folks are interested in hearing more about how other companies can achieve something similar, here's video of a talk I gave at Heavybit a few months ago on the subject: https://www.heavybit.com/library/blog/beyondcorp-meetup-goog...
Very true that a key benefit of AWS Lambda is the ability to hook into the internals, but to the article's point, that's a pretty significant level of lock-in. We recommend to our customers who want a similar level of functionality hook up the internal events to SNS, at which point a job can be triggered on our end.
We operate across any cloud, standardizing through Docker images as the unit of code. It's "serverless" to the developer in that the only configuration is setting the event triggers. Of course there's compute involved, but it's outside of the development lifecycle.
If you're open to a hosted solution, check out IronWorker: http://www.iron.io/worker
It's an async task processing service with a built-in job scheduler. You can upload your python scripts to Iron.io, then set schedules and other triggers to execute on-demand. We have a dashboard to manage tasks and schedules, see what ran and what failed, and you can visualize the characteristics you're looking for. We do distribute the workloads for you, but sounds like it could be a good fit.