10. Security in the Cloud

“Security is always excessive until it’s not enough.”

Robbie Sinclair, Head of Security, Country Energy, NSW Australia

Security is hard. It’s messy, it’s ugly, it’s time consuming, and it’s far less interesting to write code for than the rest of our application. As a result, most security-related coding tasks are often left until the last minute. When the last minute has arrived, people are usually scrambling to get the release out the door, and they need to make tradeoffs. Should we fix bugs or add new features? Since the security stuff hasn’t even been started yet, it gets qualified as new features, and, in Hollywood jargon, gets left on the cutting-room floor.

It doesn’t have to be this way. More importantly, it ...

Get Cloud Native Go: Building Web Applications and Microservices for the Cloud with Go and React now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.