Skip to main content

Posts

First Look at Cerbos: A Solution for Dynamic Role & Permission Management

Introduce My next post is about tools for managing roles and dynamically controlling access to resources. Some business requirements demand extreme flexibility, often requiring a combination of RBAC + ABAC at the same time. From my experience, I’ve seen a lot of solutions, but most don’t cover all the key points. There are three circles that are really hard to combine: Performance, Security, and Flexibility . And when someone tries to implement all three—oh, it’s painful. But I found a technology that (almost) solves this challenge: Cerbos —a scalable, open-source authorization layer for handling roles and permissions. ( Cerbos site ) Why is it good? ✅ Centralized configuration – Everything is managed in one place. ✅ Easy integration – SDKs are available for all popular languages:     🔹 .NET, Go, Java, JS, PHP, Python, Ruby, Rust ✅ Great documentation – Clear examples and guidance. ✅ Playground for testing – No need to run an app or set up tools. Just te...

RavenDB - overview, thought, and what next...

  Exploring RavenDB: First Impressions and Key Features 🚀 At the recent conference ( https://devworldconference.com ), I was impressed by the possibilities and feature set of RavenDB. It’s not just another NoSQL database—it delivers on its promises with ease of use, powerful features, and high performance. In this post, I’ll share my first-hand experience with RavenDB, highlighting its key features, what makes it stand out, and my thoughts after testing it in a real-world pet project. Let’s dive in! 👇 List of features: Database Management Studio & Open-Source NoSQL Document Database – Ease of Use It's not just a slogan—it’s true. It took me around 5 minutes to run RavenDB and its Database Management Studio on my laptop. You can start experimenting with this DB locally in just a few minutes, without digging through tons of tutorials or manuals. No need to install dozens of tools and subsystems—just a few minutes, and you have a full sandbox for exploring and learning everyt...

"Dushnylo" Series: Introduction and the first episode.

Lately, I've noticed a recurring and perplexing theme in numerous posts and articles. Certain tech authorities assert that some established patterns are superfluous. For instance: "The repository pattern is unnecessary; simply use the ORM directly within your business logic—no need for abstractions." Therefore, I've chosen to initiate a new series titled “Dushnylo” (Definition: An individual who is excessively critical, focuses on minute details, and overwhelms others with arguments about why something is incorrect or flawed.) The inaugural topic in the “Dushnylo” series: "Reduced Abstraction, Increased Direct ORM Usage in Business Logic" Why circumventing abstractions breeds disorder: Strong Coupling and Reduced Testability By directly integrating an ORM into your business logic, you create a strong dependency between your business layer and the database implementation. This strategy: Makes migrating to a different ORM or database significantly more chal...
Last week, we saw plenty of posts about integrating DeepSeek into applications, running it locally, and similar topics. What surprised me, though, is that while I expected issues to surface, I didn't anticipate such a massive security problem with DeepSeek AI chats. Big thanks to Gal Nagli for this research: https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak . We've seen countless discussions on how companies achieved this cheaply—but also so insecurely. This reflects the current state of the industry, where everyone is racing to outdo competitors in budget, speed, and features while completely neglecting security and stability. Take Garmin as another example: https://www.dcrainmaker.com/2025/01/garmin-watches-are-crashing-when-trying-to-start-gps.html . Or this persistent Windows Update issue: https://www.youtube.com/watch?v=h8ppow5te20 And perhaps the biggest failure yet—the CrowdStrike incident: https://en.wikipedia.org/wiki/2024_CrowdStrike-related...

Error handling in GO, my thoughts.

Go's error handling emphasizes simplicity and explicitness.  This post explores its unique approach and compares it to other languages. Agenda   Why is it an interesting topic in GO? What do we have in different languages? It is why you can trust. Why is it an interesting topic in GO? I like having control over the processing of the source code; that code has a clear and structured flow, and it helps to read and understand the code and what's going on here. GO has it. And that's all that GO has. You are limited to processing it ONLY in this way. GO developers are discussing that it is a problem that you need to write each time mechanism to validate the error state and handle it on each layer of the process flow. And YES, it is noisy, I totally agree here. But when I saw this discussion, only one thing in my head. Did you try to debug the bug when you can't see where and who throws this exception? Yeah, it is the wrong implementation, but in my experience, I saw it very ...

Hints and Hacks: Mastering Go Project Structure and Generic Repositories with GORM

  Mastering Go Project Structure and Generic Repositories with GORM Establishing a robust project structure is paramount when building scalable and maintainable Go applications. Coupled with the flexibility of a generic repository, this approach ensures clean, reusable, and extendable code. In this article, we'll explore how to set up a well-structured Go project and implement a generic repository pattern with GORM, focusing on practical examples and best practices. Why Project Structure Matters A well-organized project structure is critical for: Scalability : Adding new features or components becomes seamless. Readability : Developers can easily navigate the codebase. Maintainability : Issues can be identified and resolved efficiently. Adhering to a modular structure, your application remains clean and manageable as it grows. Recommended Go Project Structure Here is a typical project layout for a Go application leveraging GORM and a generic repository: app_db_generic...

Taming the Shadow: Turning Tech Debt into a Strategic Advantage

Tech debt is one of those topics that can make or break a project.  It's like this ever-present shadow lurking around our cool, innovative ideas. It's necessary sometimes, but when it grows too much, it can weigh everything down like an anchor. 🚀 Here's my spin on how to manage tech debt effectively: - 𝗨𝗻𝗱𝗲𝗿𝘀𝘁𝗮𝗻𝗱𝗶𝗻𝗴 𝗧𝗲𝗰𝗵 𝗗𝗲𝗯𝘁: See it as a necessary compromise to get things moving but don’t let it turn into a never-ending burden. - 𝗙𝗼𝗰𝘂𝘀 𝗼𝗻 𝗪𝗵𝗮𝘁 𝗖𝗼𝘂𝗻𝘁𝘀: Align tech debt management with the business's core priorities. Score quick wins but keep an eye on securing long-term success. - 𝗖𝗼𝗺𝗺𝘂𝗻𝗶𝗰𝗮𝘁𝗶𝗼𝗻: Keep the lines open between dev teams and business folks. Everyone should be transparent about tech debt implications and the choices being made. - 𝗔𝗹𝘄𝗮𝘆𝘀 𝗚𝗿𝗼𝘄𝗶𝗻𝗴: Keep things fresh with frequent updates and changes. Be open to the latest tech trends and business shifts. Investing in education is something I hold in...