61 karma · joined October 13, 2014
Maybe someone from HN could help fix the title + desc if possible :))
We will probably write a blog post or two about how we've designed the API + infra around it as there are some interesting topics to be covered.
One of the goals was to also have fun and experiment with a few approaches we've been wanting to use but could not on our daily jobs.
For reference, everything is on AWS and we are using AWS CDK (TypeScript), having moved away from serverless.com recently.
We are ONLY using managed services/resources which are "fully serverless" (API GW, WAF, Dynamo + Dynamo Streams, Lambda, EventBridge, ...) - to save cost, to minimise waste, to reduce ops, etc.
Hope this helps, happy to provide more details.
We faced this ourselves countless times, and it is exactly why we created both OTS and Snip (https://github.com/sniptt-official/snip - like OTS but with the ability to persist secrets and also create shared vaults etc.).
Pleased to say that self-hosted options for both OTS and Snip are currently top of our roadmap.
Keep an eye on the repos for updates! :)
For example, some sort of "self-serve" UI where you could get an API key which would allow users/teams have dedicated rate-limits and not use the default/public limits? Or a self-hosted option where the API could be deployed to the company's cloud of choice?
Or.. leave as is?
Please let us know! :)
As for "grace period", are you asking about URL/link previews and whether those have any effect on reading the secret? If so, the answer is no - the secret will only be read once the client-side JavaScript code is loaded and executed, only certain layout components are rendered server-side.
But I may have misunderstood your question, in which case please do not hesitate to ask again :)
Having read the Show HN "guidelines" at https://news.ycombinator.com/showhn.html, I don't see anything wrong with posting a link to the tool's GH repo. There is a (yes, very simple) README which contains everything a user needs to try the tool out and provide constructive feedback.