Biggest take aways from the AWS SaaS Factory live ...
# general
g
Biggest take aways from the AWS SaaS Factory live stream: • Multi-tenancy is very much a security and access control game. • Multi-tenancy and security are much easier to get right when you are starting than after you have a mess and an incident on your hands. • A lot of decisions around security, compliance and tenant isolation are business requirements (sometimes a bit obscured behind pricing, costs, tiering and capabilities) • In startups, you know from day 1 that your business will experiment with things - tiers, pricing, tenant customization. There are a lot of known design patterns that give you flexibility, start with those. • Israel should be renamed "SaaS Nation"
👍 5
gratitude thank you 1
b
• If you invite Gwen to a show, she brings a great following and conversation with her. • If you are actually in Israel, the show is 4pm rather than 6am 🥱
💜 3
l
Nice points. Regarding multi-tenancy - Have anyone used SQL proxy in prod? Basically we are creating separate DB for each tenant but this bring another complexity to manage connections at service end. Also DB host have limit on max connections as well. Hence instead of writing our own logic we could use connection management in SQL proxy (with long live connection pool) to route request to proper tenant DB. Please share any critical feedback in this arch.
g
I haven't looked at SQL proxy specifically, but I used another connection pool manager (ages ago and Oracle specific) and the key memory I have is that you need to be careful about handling cases where the pool is exhausted. We had cases where we deadlocked because the pool was exhausted, but the threads that were waiting for connections were also the one holding connections (for another task). Be careful not to create an async mess and shoot yourself in the foot. (On the plus side, I got my early start at giving conference talks by discussing connection management and concurrency issues).
l
Wow let me have a look into pgbouncer. I was checking this https://proxysql.com/
b
@Lalit Pagaria - Assuming you are building on AWS, are you using self managed DB, or RDS? Not to muddy the waters with yet another option, there is an AWS service called RDS Proxy which works with Aurora and RDS and many SQL engines. It comes with some distinct advantages - fully managed, more integrated security story with IAM and Secrets Manager...
👍 1
🔥 1
l
@Bill Tarr yeah that is an option but it is pricey and not covered in their free tier plan. T3 small instance will cost $23 but on-demand of the same size will cost $15. Also one instance we may be able to connect RDS of different AZ. In fact we are not using EKS because they charge $70 instead we are using ECS which is free. We are a bootstrap startup with wafer thin margins so staying positive since the beginning is what we like, at least we hope 😅
g
Joining the complaint about EKS costs. I span one up for testing, thought I deleted it, turned out that I didn't. 50% of our cloud costs for the month was from this one test cluster. I'm testing with
kind
now 😅
And we are also on ECS now
👍 1
b
I'll share those comments with the containers team channel for sure
l
g
I saw this earlier today. Seems insane with a small team.
l
Yeah but cloud cost is going crazy. One of my known people told me that they were able to source GPU at $1 per hour which cost approx 4-5$ per hour on public cloud. And now they are launching an ML training startup.
g
Charity Majors once said that most startups end up selling arbitrage on cloud costs. Not 100% true, but many are.
👍 1
For me the risk of trying to run all this myself seems far higher than cloud costs. So I try to save money, but when cloud vendors can give me peace of mind at low effort, it is worth it.
👍 2
l
Two major make and break stages for many SaaS startups 😅 • When free tier ends • When they run out of cloud credits
😞 1
g
LOL. It is a game of getting to enough revenue and economy of scale before you run out of free.
🙂 1
b
the article is an interesting argument, but pretty myopic to their use case. I probably shouldn't get into the business of defending the public cloud, since I have a vested interest 🙂 but I don't just think of the public cloud as renting computers, especially for SaaS. Compliance, multi-region, serverless, public marketplaces, security backbone... just a lot of things that would be a challenging at best to build out. Just my two cents...
l
Yeah agree Bill. Having worked in the data centre building industry I would not like to take that pain for my own startup until absolutely necessary for some regulatory reason.
👍 1
💯 1
b
agreed. Worked in PCI-DSS data centers for a few years... Happy to not be doing that anymore 🙂
😂 1
g
This is weird:
Let's take HEY as an example. We're paying over half a million dollars per year for database (RDS) and search (ES) services from Amazon. Yes, when you're processing email for many tens of thousands of customers, there's a lot of data to analyze and store, but this still strikes me as rather absurd.
They are storing emails in RDS? It doesn't sound right.
l
Might be storing email meta in RDS, text in ES and attachments in S3. I guess they might have a heavy rule-based engine.
g
oh, makes sense
Thinking back to my time at Ning - Spam filtering alone takes quite a lot of resources.
I've used Superhuman, their rules are extremely simple. Maybe thats a good way to keep costs down. KISS 🙂
👍 1
l
I have heard a lot about superhuman. Let me check it out.
g
Not sure it’s worth the cost, personally. But I’m curious if it does for you.
👍 1
y
@Gwen Shapira @Bill Tarr its unfortunate i had to deal with fires in house to extinguish. My rant/question was on getting working code towards a saas. As in here is a mom and pop shop running as running a saas using these x/y/z technologies. There are tons of technologies to chose from but just having a PDF talking about well architected design (something AWS does nowadays) is maybe not enough
I would rather have something oriented towards a saas problem (lets say authentication as an example) but with working code.
b
@Yassin Mohamed are you building with Serverless or EKS perhaps?
y
good question its a mix of serverless and EKS
b
we do have reference architectures for both of those... I think you said ECS, strictly speaking, we don't have an ECS reference, but we do have a project called SaaS Boost that is based on ECS...
y
we want to farm out to serverless from time to time to handle the load
we are actually building a platform so customers could be using the serverless part to offload ingestion
b
I'd like to speak with you more about what you are building, but in the mean time - https://github.com/aws-samples/aws-saas-factory-ref-solution-serverless-saas
gratitude thank you 1
take a glance at that...
y
This is actually good timing 🙂 i will ping you on a DM if that is ok ?
b
sure
feel free to include @Gwen Shapira as well if you like
👍 1
y
@Bill Tarr btw that repo seems like it could answer what i want from my cursory look. I will go and make sure i understand what it is solving and how before ask more questions to both of you ... 🙂 sheers and have a great weekend
b
if you want a jumpstart,

https://www.youtube.com/watch?v=CVMXYcqJI40&list=PLoqD0z_296PbD-X7HLDq81RYCo4Wx1WNG&index=2&t=9s▾

😍 1
the authors of the ref arch discussing it in detail 🙂
s
Note AWS has a nice PDF somewhere about SaaS multi-tenancy options & standards, mostly settling on basic single DB, include account-in-every-row, sorta system as a baseline, but has to be built from scratch that way, so the core code/framework does the work. Auth across the accounts gets messy, as do any multi-account views, though.
b
hi @Steve Mushero - Let me know if you find that, I'd be curious about the context there. Our team does have a whitepaper that outlines "*SaaS Architecture Fundamentals*" we just published recently, but I'm not sure that's what you are referring too... We have a lot of publications 🙂
s
SaaS Tenant Isolation Strategies (AWS), from 2020 (an update of the earlier paper I saw): https://d1.awsstatic.com/whitepapers/saas-tenant-isolation-strategies.pdf
b
yup, that's from our team as well. A good resource, bit more specific than the one I references, but a really good deep dive on isolaiton.
s
🙂 I thought folks were asking how to separate customers, even separate DBs, etc. so though this appropriate, though perhaps I missed the larger picture. Good basics, though.
b
Oh not at all, you are spot on for sharing it!