Practices of reliable software design (News)

19 Aug 2024 · 9 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The Changelog: Episode Notes

Title

Practices of Reliable Software Design (News)

Episode Overview In this episode, the hosts discuss various topics related to software design practices, the npm community's issues with micro-libraries, metaphors for problem-solving, a significant data breach, and a versatile data tool called Dasel.

---

Key Discussions

  1. Practices of Reliable Software Design
  2. Speaker: Chris Stjernlöf
  3. Concept:
  4. Chris shares insights he gained while answering a friend's query about building an in-memory cache.
  5. He lists eight reliable software design practices based on his experience:
  6. Use Off the Shelf: Utilize existing solutions instead of building from scratch.
  7. Cost and Reliability Over Features: Prioritize dependable solutions over having many features.
  8. Idea to Production Quickly: Aim for swift implementation to get ideas into production.
  9. Simple Data Structures: Keep data structures uncomplicated for ease of use.
  10. Reserve Resources Early: Plan resource allocation ahead of time.
  11. Set Maximums: Define limits on resources to avoid overruns.
  12. Make Testing Easy: Ensure that testing is straightforward to encourage thorough testing practices.
  13. Embed Performance Counters: Integrate counters to monitor performance effectively.
  • Takeaway: These practices reflect accumulated wisdom that can significantly ease the software engineering process.
  1. The Issue with Micro Libraries
  2. Speaker: Ben Visness
  3. Thesis:
  4. Argues against the excessive use of micro libraries in the npm community.
  5. Proposes that micro libraries should either be integrated directly into the codebase or avoided entirely.
  • Key Points:
  • Dependency Costs: Discusses the costs and benefits of dependencies without quantifying them, emphasizing that micro libraries often present more downsides.
  • Quote: "A little copying is better than a little dependency," attributed to Rob Pike.
  1. Metaphors for Problem Solving
  2. Concept:
  3. Introduces three metaphors to categorize problem-solving strategies:
  4. Harvesting: Straightforward issues requiring perseverance.
  5. Fishing: Problems with uncertain solutions that may yield quick results with skill and luck.
  6. Panning for Gold: Searching for rare opportunities that could lead to significant success.
  • Application: By categorizing problems, teams can determine clearer strategies for tackling them.
  1. National Public Data Breach
  2. Speaker: Troy Hunt (Have I Been Pwned)
  3. Summary:
  4. Discusses the complexities of a national data breach where data aggregators were involved.
  5. Key takeaway: No evidence suggests that social security numbers were leaked, and affected individuals should view the information as merely informational.
  1. Dasel: A Versatile Data Tool
  2. Description:
  3. Dasel allows querying and modifying various data formats (JSON, YAML, TOML, XML, CSV) using a standard selector syntax.
  4. Advantages: Reduces the need to learn multiple tools for different data formats, making it a user-friendly solution.

---

Sponsored News

  • Supabase Launch Week 12 Recap: Highlights from recent releases including new features for Postgres, real-time channel authorization, multi-factor authentication, and more.

---

Closing Notes

  • Stay updated through the Changelog newsletter for more insights, cheat sheets, and features.
  • New Changelog++ members can build custom feeds, with positive feedback reported.

---

Call to Action

  • Encourage listeners to leave a five-star review if they enjoy the content and to stay tuned for the next episode.

---

This markdown file encapsulates the main points, discussions, and insights from the podcast episode, structured for clear and easy navigation.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:28What up nerds? and the repo in your chapter data and the newsletter. And remember, be kind, rewind. Okay, let's get into this week's news. Practices of reliable software design. Chris Stiernyov got nerd sniped. Out of the blue, a friend asked him how he would build an in-memory cache laying out a few design constraints, and he couldn't not take the bait. Quote, in the process of answering the question and writing the code, I discovered a lot of things happened in my thought processes that have come with experience. These are things that make software engineering easier, but that I know I wouldn't have considered when I was less experienced.

1:10End quote. Chris jotted down eight practices that he's adopted with experience and used while writing this fast, small, in-memory cache. They are, one, use off the shelf. Two, cost and reliability over features. Three, idea to production quickly. 4. Simple data structures. 5. Reserve resources early. 6. Set maximums. 7. Make testing easy. And 8. Embed performance counters. A few of these I live by, a few of these I hadn't even really considered. I imagine every experienced dev has a similar list floating around in their head. Now that would be an aggregation project worthy of some effort. micro libraries need to die already ben visness has had enough with the npm community's propensity to pull in micro libraries to suit every need quote here is my thesis micro libraries should never be used they should either be copy pasted into your code base or not used at all however my actual goal with this article is to break down the way i think about the costs and benefits of dependencies.

2:21I won't be quantifying these costs and benefits, but I hope that by explaining the way I think about dependencies, it will be clear why I think micro libraries are all downside and no upside. End quote. Micro is a subjective measure, but Ben is talking about single function kind of libraries. The case study he uses is, is number, which certainly qualifies as micro by any measure. I wholeheartedly agree with him. A saying I learned from years of producing GoTime, I believe it was Rob Pike who said, a little copying is better than a little dependency. Harvesting, fishing, panning for gold. I like this set of metaphors for how to think about bucketing challenges into different categories.

3:06Some problems are like harvesting. Quote, harvesting problems have straightforward solutions and no shortcuts. You just get a big basket and pick every strawberry in the field. You solve these problems with pure perseverance, slogging away for weeks, months, or years until they are done. Some problems are like fishing. You know that there are fish out there in the ocean, but you don't know exactly where. If a great fisherman knows where the hungriest fish are and how to set their lines just right, they might catch everything that they need in a few hours. Fishing problems can sometimes be solved shockingly fast by motivated teams with a bit of luck.

3:44Some problems are like panning for gold, going out to a river or stream where there might be gold, getting your pan out, and seeing if you can find traces of the stuff in the sediment. If you find gold, you can become generationally successful. Think of the massive moats created by Google search or the Airbnb network. End quote. If you can categorize the problem you're trying to solve into one of these buckets, applicable strategies become much more clear. It's now time for sponsored news. Supabase launch week 12 recap. Last week was launch week 12 for Supabase. Here's a recap of what they shipped.

4:25Monday, they launched Postgres.new, an in-browser Postgres with an AI interface. Tuesday, authorization for real-time's broadcast and presence went to public beta. You can now convert a real-time channel into an authorized channel using RLS policies in two steps. Wednesday, they shared three new announcements for Supabase Auth, support for third-party auth providers, phone-based multi-factor authentication, and new auth hooks for SMS and email. Thursday, they released log drains so you can export logs generated by Supabase to external destinations like Datadog. or custom HTTP endpoints. And Friday, they released support for WebAssembly Foreign Data Wrapper.

5:13Now anyone can create a foreign data wrapper to allow Postgres to interact with externally hosted data and share it with the Supabase community. That is a lot. Learn more all about Supabase's launch week announcements by following the link in the chapter data and the newsletter. And thank you to Supabase for launching with Changelog News. Inside the 3 billion people national public data breach. Here's Troy Hunt from Have I Been Pwned. Quote, usually it's easy to articulate a data breach. A service people provide their information to had someone snag it through an act of unauthorized access and publish a discrete corpus of information that can be attributed back to that source.

5:56But in the case of national public data, we're talking about a data aggregator most people have never heard of, where a threat actor has published various partial sets of data with no clear way to attribute it back to the source. I've been collating information related to this incident over the last couple of months, so let me talk about what's known about the incident, what data is circulating, and what remains a bit of a mystery. End quote. When Troy says he's been collecting info for a couple of months, he's not kidding. This one goes deep, and it's a very long post, my summary of his summary, it's a giant mess.

6:31But here's one important takeaway. Quote, there were no email addresses in the social security number files. If you find yourself in this data breach via have I been pwned, there's no evidence your social security number was leaked. And if you're in the same boat as me, me being Troy, the data next to your record may not even be correct. So treat this as informational only, an intriguing story that doesn't require any further action. Daycell, one data tool to rule them all. I like this pitch. Here it is. Say goodbye to learning new tools just to work with a different data format. Daycell uses a standard selector syntax no matter the data format.

7:13This means that once you learn how to use Daycell, you immediately have the ability to query and modify any of the supported data types without any additional tools or effort. End quote. This is a lot like JQ, but it supports JSON, YAML, TOML, XML, and CSV with zero runtime dependencies. The only thing I can imagine that would be better would be to use SQL instead, because that'd be even one less syntax for most of us to learn. But still, very cool. Check it out. That is the news for now. But also scan the changelog newsletter for more goodies, including Visual Data Structures Cheat Sheets, Go Is My Hammer, and Everything Is A Nail, Steve Kalabnik Taking a Stand Against Names, and Data Is Just An Added Sense.

8:02Oh, and did you know that Changelog++ members can now build their own custom feeds? What, what, what? Feedback for this brand new feature has been overwhelmingly positive, and people have created 124 feeds already, so that's pretty cool. Try it for yourself at changeblog.com slash plus plus. Have a great week. Leave us a five-star review if you dig our work. And I'll talk to you again real soon.

From the publisher

Chris Stjernlöf got nerd-sniped and ended up writing down his practices of reliable software design, Ben Visness has had enough with the npm community's propensity to pull in micro-libraries to suit every need, "Stay SaaSy" makes three metaphors for problem solving categories, Troy Hunt takes us inside the "3 billion people" National Public Data breach & Dasel is one data tool to rule them all.

More from The Changelog: Software Development, Open Source

All 232 episodes
Practices of reliable software design (News)The Changelog: Software Development, Open Source · 9 min
Listen in VO