Rendered at 12:44:04 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
dbarlett 21 hours ago [-]
Speaking as a former Blog Bar Raiser, cperciva has internalized the AWS blog style guide better than most Amazonians. This is spot-on.
cperciva 21 hours ago [-]
Wait, there's an official style guide?
(In all seriousness, I've been reading AWS launch posts for 20 years; this one was mainly imitating the S3 Files launch post but I diverged by adding the customer quote and the FAQ -- because of course I started this process with a PRFAQ, and some of the questions in the FAQ are legitimately important.)
dbarlett 20 hours ago [-]
I left 18 months ago, so my memory is a bit fuzzy, but there was at least an overall style guide, one for each post type (e.g. a launch announcement), and the style for procedures (inherited from AWS Docs).
cperciva 20 hours ago [-]
Oh, I was being facetious. I'm pretty sure Jeff mentioned needing to spend time writing a style guide when he started having other Amazonians write posts for "his" blog.
Oh, I assumed that "style guide" meant things like starting launch posts with "I'm excited to announce", providing a simple demonstration of how to use the service, including screenshots, including a customer quote if available, and ensuring that pricing and availability were clearly laid out.
donavanm 11 hours ago [-]
There are, internally, and theyre pretty good. I always tried to use the AWS Docs style guide when writing internally, for example. Theyre specific on how to refer to products vs services vs features, which nouns to use, tone, grammar, etc.
PS: you might get tripped up on 0x00, 0x2F, or similar control characters? As i recall any valid octet can be included in a label. We definitely saw literal ‘*’ and ‘.’ inside labels. And I wouldnt be surprised to find a bell in there either.
cperciva 11 hours ago [-]
[dead]
21 hours ago [-]
georgemcbay 18 hours ago [-]
> cperciva has internalized the AWS blog style guide better than most Amazonians
A little bit of Canadian/non-American English slipped in (eg. enrol, behaviour), which AFAIK would have been flagged for a real Amazon post because as Americans we were brave enough to get rid of the 'U' in a lot of British words, like 'colour' and 'armour'.
But by God, we kept the British 'U' in the word 'glamour'.
cperciva 17 hours ago [-]
Yeah, I was aware of those... but I just couldn't bring myself to write American, especially in the current political climate. You can consider those a non-tariff trade barrier.
QuinnyPig 14 hours ago [-]
It was my first feedback for you. I’m still incensed.
georgemcbay 17 hours ago [-]
That's entirely fair.
As a heavily disaffected American (who still can't wrap his head around the fact that we let this happen twice) I support any form of protest against us.
mlhpdx 21 hours ago [-]
At first I thought this was a general purpose file system over R53, ala Corey Quinn. But my, what a gorgeously terrible idea. Well done.
QuinnyPig 18 hours ago [-]
You might note who the customer quote is from.
colechristensen 21 hours ago [-]
to be fair, it's also that just with some severe restrictions on filenames
threecheese 20 hours ago [-]
A “schema that reads like XML that learned JSON in prison” IM DEAD
Stealing this. Gold lies at the intersection of cperciva and quinnypig.
donavanm 11 hours ago [-]
This is just the era of AWS (and amazon APIs). A lot of them look like SOAPy xml rpc because thats how they started, based on internal service frameworks. Check out SQS or S3 for similar examples.
Around 2010-11 there was a shift towards RESTish structures and json for serialization. A lot of methods and payloads still feel SOAPy, but look like json. I think it was DynamoDB which had the most unfortunate API with a literal xml-json transform live in the API service.
And then somewhere around 2015 you started seeing more well defined RESTish APIs with better tooling and adoption for smithy (and some openapi, iirc).
cherioo 4 hours ago [-]
> If the same record is changed in the file system and in Route 53 at the same time, we aim for last-write-wins. This is not strictly possible, since Route 53 does not expose modification timestamps on records
Except route 53 provides a fully ACID transactional API you can build your own locks with!
21 hours ago [-]
dougcalobrisi 20 hours ago [-]
Route53 makes a great, simple, HA key-value store for some use cases. I've used it in GitHub Actions when nothing else was easily available to store values and put a little post together explaining how a while back. For many things, there isn't a reason for more complexity.
And artifactory makes a good message board for your slightly-more-rambunctious-than-intended AI agents to collaborate and commiserate.
UltraSane 18 hours ago [-]
And route53 makes DNSSEC very easy to enable so all the DNS data is cryptographic signed. This makes putting public keys and certificates in DNS much more sensible.
cbm-vic-20 18 hours ago [-]
I dug into the DNSSEC rabbit hole a few weeks ago and got drawn into the fascinating root key signing ceremony.
I knew of GPG key signing parties, but never anything at this scale or impact. Might try booting the "Signing Computer Operating System Image Release coen-2.0.1" ISO in a VM and checking it out.
UltraSane 16 hours ago [-]
It really is something to behold. When you start storing FIPS 140-2 Level 4 HSMs offline inside safes you know things are serious.
fr2029 18 hours ago [-]
neat, thanks
ahachete 14 hours ago [-]
Good job, Colin.
I see you are following the Dyna53 [1] steps ;) What a school of thought you have sparked, Corey!
cryptoshreddable via a KMS-wrapped DEK in the additional section, job done
ChiperSoft 21 hours ago [-]
Are there that many people managing their dns by hand that they need this? Outside of various txt records, most of my domains are mapped to specific resources via automation.
cperciva 21 hours ago [-]
There are apparently many people managing their S3 Objects by hand but long to have them in a file system, yes.
regularfry 21 hours ago [-]
I don't think this is there to satisfy "need".
But "automation" with this could legitimately (well, mostly) be based on a git repo with an s3files mount inside it. And a cron job, if you really want to get fancy.
cperciva 21 hours ago [-]
Files which aren't DNS keys get ignored by Route 53 Files. So you could absolutely have a git checkout and update your DNS with 'git pull'.
stackskipton 21 hours ago [-]
Last job, we did for various control/audit reasons BUT it was all IaC and tickets.
colechristensen 21 hours ago [-]
This is... well it's mostly a joke. It's funny but you can indeed use and interact with DNS as a file store or have a file system based control over records.
Both DNS and S3 or any filesystem really... they're just key/value stores.
DNS also has considerably higher reliability and compatibility than almost anything else
esseph 21 hours ago [-]
> Are there that many people managing their dns by hand that they need this?
How many thousands or millions of employees does your org have? And how many projects deployed over the decades?
Am I the only one who thinks that read() and write () (block based api) would be a poorer experience for managing key/value dns records?
YesThatTom2 20 hours ago [-]
This is FANTASTIC! I laughed so hard I nearly fell out of my chair.
Have you seen DNSControl?
If you want a serious alternative to the Route53 API, there's an open source project called https://dnscontrol.org/ DNSControl. It's like Terraform for DNS but it doesn't suck like Terraform.
Version v5.0 just shipped. It's a major rewrite that makes it much more extensible.
I'll recommend dnscontrol as well, although the post is an unseasonal April fools joke, so helpful suggestions may be out of place.
The is-a.dev project uses dnscontrol to manage a subdomain registration service in GitHub, which is really clever. See https://github.com/is-a-dev/register
cperciva 11 hours ago [-]
unseasonal April fools joke
Not at all. Route 53 Files is a completely real service.
(In all seriousness, I've been reading AWS launch posts for 20 years; this one was mainly imitating the S3 Files launch post but I diverged by adding the customer quote and the FAQ -- because of course I started this process with a PRFAQ, and some of the questions in the FAQ are legitimately important.)
As a non-Amazonian I've never seen it, of course.
PS: you might get tripped up on 0x00, 0x2F, or similar control characters? As i recall any valid octet can be included in a label. We definitely saw literal ‘*’ and ‘.’ inside labels. And I wouldnt be surprised to find a bell in there either.
A little bit of Canadian/non-American English slipped in (eg. enrol, behaviour), which AFAIK would have been flagged for a real Amazon post because as Americans we were brave enough to get rid of the 'U' in a lot of British words, like 'colour' and 'armour'.
But by God, we kept the British 'U' in the word 'glamour'.
As a heavily disaffected American (who still can't wrap his head around the fact that we let this happen twice) I support any form of protest against us.
Stealing this. Gold lies at the intersection of cperciva and quinnypig.
Around 2010-11 there was a shift towards RESTish structures and json for serialization. A lot of methods and payloads still feel SOAPy, but look like json. I think it was DynamoDB which had the most unfortunate API with a literal xml-json transform live in the API service.
And then somewhere around 2015 you started seeing more well defined RESTish APIs with better tooling and adoption for smithy (and some openapi, iirc).
Except route 53 provides a fully ACID transactional API you can build your own locks with!
https://doug.sh/posts/route53-as-a-key-value-store-2026-edit...
https://www.iana.org/dnssec/ceremonies/62
I see you are following the Dyna53 [1] steps ;) What a school of thought you have sparked, Corey!
[1]: https://dyna53.io/
[0]https://banner.triweb.dev [1]https://news.ycombinator.com/item?id=39502097
But "automation" with this could legitimately (well, mostly) be based on a git repo with an s3files mount inside it. And a cron job, if you really want to get fancy.
Both DNS and S3 or any filesystem really... they're just key/value stores.
DNS also has considerably higher reliability and compatibility than almost anything else
How many thousands or millions of employees does your org have? And how many projects deployed over the decades?
Have you seen DNSControl?
If you want a serious alternative to the Route53 API, there's an open source project called https://dnscontrol.org/ DNSControl. It's like Terraform for DNS but it doesn't suck like Terraform.
Version v5.0 just shipped. It's a major rewrite that makes it much more extensible.
https://github.com/DNSControl/dnscontrol/releases/tag/v5.0.0
The is-a.dev project uses dnscontrol to manage a subdomain registration service in GitHub, which is really clever. See https://github.com/is-a-dev/register
Not at all. Route 53 Files is a completely real service.