Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The challenge with this is that many orgs have hundreds if not thousands of standards that must be adhered to in this situation. So if a engineer wishes to use a database, they can stand one up with the CDK no problem. But it's going to fail every audit unless they are aware of these requirements. And even if they are aware of these requirements, doing the integration for things like privileged access management, billing and security monitoring are a pain in the ass that provide no incremental value.

On the flipside, having a single platform team write the IaC components that do all of this grunt work tends to reduce the degrees of freedom that the engineer has to build the application architecture exactly how they want it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: