Live data from Hacker News

Cloud.gov

cloud.gov

51–59 of 59 posts

Re: Cloud.gov

#51
post #39

Cloud.gov was really promising when it was announced years ago, but in practice there ended up being so many differing security requirements and security boundary tensions between them and purported customers of them that they didn’t end up having any real impact because while some could use them, many could not, and those who could often found it easier to just not use them. There were also issues getting needed per…

The issue is the business processes the government uses to contract, and purchase products and services as well as the processes for moving money between different agencies and departments are horrendous and involve a lot of people. This is true wether the value involved is $1 or $1 million. If any of the people involved is incompetent or decides they aren’t going to do their part in a timely fashion you are screwed.…

that seems to be the problem the post purports to solve?

if they don't handle the compliance hassle of FARS (and maybe DFARS), what is their value proposition?

Re: Cloud.gov

#52
post #11

As someone who runs 20+ cloud based government applications it is unclear to me how this is easier to secure, more performant, or cheaper than AWS. My first impression is this adds a lot of risks and unknowns in a critical area where there are existing and well-known best practices.

I am curious, do you own a business that bids on govt contracts? This is something i am interested in learning but i am not sure if this is feasible for an individual

Re: Cloud.gov

#53

https://cloud.gov/docs/deployment/frameworks/ Not supported cloud.gov cannot run applications that use .NET Framework, or application binaries that require access to Microsoft Windows kernel or system APIs. Interesting that most container/cloud environments don't support .Net framework

Just use VM for legacy application.

Re: Cloud.gov

#54
post #39

Earlier quoted context omitted.

The issue is the business processes the government uses to contract, and purchase products and services as well as the processes for moving money between different agencies and departments are horrendous and involve a lot of people. This is true wether the value involved is $1 or $1 million. If any of the people involved is incompetent or decides they aren’t going to do their part in a timely fashion you are screwed.…

that seems to be the problem the post purports to solve? if they don't handle the compliance hassle of FARS (and maybe DFARS), what is their value proposition?

Transferring funds between agencies or departments is onerous it isn’t substantially easier to do that than just going direct.

Re: Cloud.gov

#55
post #45
post #24

Earlier quoted context omitted.

I'll have to look closer, if there is cost savings I would consider it. We put a lot of effort into achieving AWS "Well Architected" so I'd hate to end up in a lesser position by going in a potentially lesser known, lesser tested, lesser supported approach.

It seems like someone with an application up and running on AWS isn't really the target audience. (Although I'm still trying to figure out who _is_ the target audience, here.)

You need a low/moderate impact web app, you only need bread and butter infrastructure, django/ruby/node app, postgres, redis, basic autoscaling. You (your agency) does not have experience doing this (for example, you’ve never built something on remote-hosted infrastructure before, you’ve never built anything that wasn’t locked to windows before, you’ve never done anything that wasnt hardcore waterfall before, etc). You wouldn’t know where to start if someone asked you to build a web app that would be easy to find technical talent to support going forward (you just assume this means a building into a Microsoft product). You don’t know why open source software makes your life easier when maintaining a software system. More charitably, you want try this “agile development” thing that everyone is talking about, and you need air cover to keep your IT dept from demanding that you give a contractor 500k-1.5m to put up a “secure” boilerplate, ‘hello world’ modern web app deployment that will kick off your agile dev process, which ought to take one person a week to deploy and another person a week to lock down.

There are a surprising number of agencies and departments that meet the above description, but either they don’t know what cloud.gov is, or equally likely, their IT department would rather spend a lot more money on a contractor and feel like they have more control. There is zero incentive to take a chance, even if you can be reasonably sure you’ll get as good or better infrastructure for 1/5 or 1/10th the cost. No one will be impressed that you saved the money and you’ll live in fear for years that something will go wrong and you won’t get promoted because you chose a scary new thing and it backfired.

They’re (IT) also likely to understand a “web app” as something tightly coupled to their existing systems (meaning they cannot imagine their existing systems securely communicating with an external, independent API, even they themselves built it) which pretty much excludes all modern software practice and excludes using cloud.gov to build additional capability.

If a potential client already knows how to build, deploy, secure and get their IT dept to authorize an aws-hosted modern web server, they’re not (at least right now) a target audience for cloud.gov, but I don’t think that describes most agencies or departments

Re: Cloud.gov

#57
post #18

Earlier quoted context omitted.

M̶o̶r̶e̶ ̶i̶m̶p̶r̶e̶s̶s̶i̶v̶e̶ ̶i̶s̶ ̶t̶h̶e̶ ̶l̶a̶c̶k̶ ̶o̶f̶ ̶g̶o̶o̶g̶l̶e̶ ̶a̶n̶a̶l̶y̶t̶i̶c̶s̶.̶ I was wrong. They are are using GA.

"The Google Analytics account that powers analytics.usa.gov is experiencing issues with realtime reporting. Realtime data may be inaccurate."

https://issuetracker.google.com/issues/228201905?pli=1

Re: Cloud.gov

#58
post #23
post #12

The UK equivalent has just announced it’s closing down for many of the reasons people comment here - https://gds.blog.gov.uk/2022/07/12/why-weve-decided-to-decom...

It seems like this product could be better (less risky) as a set of shared config files or something.

I don't think it ever quite works in practice. Letting teams come pick up the config module off the shelf in January is all well and good, but when the maintainers of the module issue a security fix in October how can you ensure the consumers apply it?

On top of that, how can the maintainers know if a change they make will be safe in the environments of the consumers?

IMO you either offer the whole service (i.e. a PaaS), or you form technical groups within the organisation which regularly share their learnings and experiences. Sharing code (aside from the smallest modules) when you don't have control or influence over the consuming team just doesn't work in the long run.

Re: Cloud.gov

#59

Earlier quoted context omitted.

So we need BaaS? Bureaucracy as a service?

I’m sure AI in charge of organizing a process can build forms and reach BAAS naturally. What I wonder is, to output a mess process, would it be faster than actual government services, or do govt services effectively act as brownian agents?

if that were true it would have already happened in healthcare, so they can extract more from sick people in the States; these existing systems optimize around different problems, goals and bounds
Post reply on HN