DevKini
265 subscribers
40 photos
5 files
559 links
Info and Updates on software development and general computing.

Info dan maklumat terkini berkaitan pembangunan perisian, programming serta IT/Komputer secara umum.

Untuk sebarang maklum balas, boleh hubungi @devkiniadmin.
Download Telegram
Terraform is an infrastructure as code software by HashiCorp. It allow you to define your whole AWS or Google Cloud platform in a code that will then be executed to build your infrastructure like running up virtual machines instance, defining private network, load balancer, database etc. It can be compared to AWS Cloud Formation.
Infrastructure as Code evolved to solve the problem of environment drift in the release pipeline. Without IaC, teams must maintain the settings of individual deployment environments. Over time, each environment becomes a snowflake, that is, a unique configuration that cannot be reproduced automatically. Inconsistency among environments leads to issues during deployments. With snowflakes, administration and maintenance of infrastructure involves manual processes which were hard to track and contributed to errors.

https://www.visualstudio.com/learn/what-is-infrastructure-as-code/
As in most organizations today, we see that developers are becoming increasingly DevOps-oriented, with constant focus on continuous delivery. We also see developers playing a central role not only with software-related issues, but with operations and production environment issues and requirements as well.
...
Here are seven things that every developer should know about production infrastructure.

https://techbeacon.com/7-things-developers-should-know-about-production-infrastructure
Here a very nice list of different ways docker being used in application development. It's a slide from a talk but unfortunately there's no recording found for the talk. //@devkini

https://l0rd.github.io/containerspatterns/
https://snowcamp2018.sched.com/event/D2ny/containers-patterns
Martin Fowler - Software developer can make the profession more respected other than just being a code monkey by mastering knowledge in the domain they're working on and having a sense of responsibility that the things they build will have impact to the world. Speak up and say NO if you're being asked to build something that can harm user.

https://www.youtube.com/watch?v=4E3xfR6IBII
... In short, all three solve problems using code. Programmer is the umbrella term which means problem solver, a Hacker is the creator/tinkerer, and a Developer is a formally trained programmer who doesn’t just solve problems but does so in a structured and disciplined way likely learned as part of a formal education.

https://danielmiessler.com/study/programmer_hacker_developer/
Conteng-conteng ...

Rough.js is a light weight (~8k), Canvas based library that lets you draw in a sketchy, hand-drawn-like, style.

http://roughjs.com/
Apa yang unik tentang Flutter ?

Ia tidak menggunakan webview dan juga tidak menggunakan native widget. Sebaliknya ia menggunakan rendering engine sendiri untuk menghasilkan UI.

Bagaimana dgn saiz app ?

Oleh kerana ia didatangkan dengan UI engine sendiri, saiznya menjadi sedikit lebih besar daripada native app. Secara asasnya, saiz apk utk app skeleton sekitar 7MB.

Apa beza flutter dengan reactnative ?

ReactNative menggunakan native widget di mana kod user dalam JavaScript berkomunikasi dengan native widget melalui JavaScript bridge. Manakala dalam flutter, kod utk core engine dalam C/C++ dikompil ke native code melalui NDK (android) dan kod user dalam Dart melalui Ahead of Time (AOT) compilation ke native code. Dalam IOS, kod C/C++ dikompil ke native code menggunakan LLVM. //@devkini

https://flutter.io/faq/#what-makes-flutter-unique
So two of our fellows take a look into Dartlang and here are their comments:-

* Dang. Futures and streams are literally everywhere in dartlang.
* What I like about Dart core libraries is that async/await is built into the libs from the start. So all the API seems very natural.
* In .NET, when async/await was introduce, there would be 2 version of methods, like ToList() and ToListAsync(). It was just so not pretty. And some library do not play well with async/await, then we need to wrap some async code as sync etc.
* I'm looking at dart:HTML, dart:io, the builder code, etc. Everything has async/wait, futures.
* And asynch behaviour is very consistent. I got tripped a bit when I found out dartlang has two event queues.
* The wrapping seems to be very straightforward (referring to wrapping async code as sync above).

FYI, Dart also the primary language being used in Google Flutter mobile framework.

Join this channel @devkini for more insight on programming and software development tools by our experienced fellows.

https://www.dartlang.org/
Tech meetup this week:-

* Golang Malaysia - 27/03 (Tuesday) - Tuxuri's office, Unit 09, Level 12, Tower 3, UOA Business Park (https://web.facebook.com/events/951134985051141/).

* FreeBSD Meetup - 29/03 (Thursday) - Level 26-27, Menara 3 Petronas, Persiaran KLCC (https://wwcodekl-freebsd.peatix.com/)

* Startup/Developer Meetup - 31/03 - Bitspace, Cyber Jaya (https://www.startupdeveloper.my/).

//@devkini
How docker is useful to me ? I'm not doing any serious work in PHP anymore but now and then, we have customers or friends asking about problem in their PHP app. Since I don't have proper PHP environment setup anymore, having docker is super useful to quickly test issue with these PHP code. //@devkini

http://metak4ml.blogspot.my/2018/03/php-with-docker.html
One good lesson here. Never serve user generated content at the same domain of your main website. This is very common practice actually.

Let your website is www.easyphone.com, and you allow user to upload a profile picture, probably you'll serve the profile picture from something like www.easyphone.com/images/user/xyz/profile.jpg. That's wrong.

If users can upload HTML documents and have them hosted on your application’s primary domain, that’s an excellent way to setup phisihing opportunities for attackers. Serving user content from your domain can also fool users into thinking malicious content is actually legitimate content from your company, as the FCC found out last fall.

Users could upload malicious javascript that would be run by the browser with the same trust level as your application’s javsacript code, allowing it to tamper with your site’s cookies and potentially steal user’s credentials, sessions or other data.


Always serve the uploaded files from different domain like www.ep-content.com/images/user/xyz/profile.jpg. //@devkini

https://blog.hartleybrody.com/startup-security/