Oracle Java & Node.JS Cloud Blogs Coming

Tags

, , ,

Over the coming months I’m planning on running a series of blogs on getting setup and using Oracle’s Java Cloud and the upcoming Oracle Node.JS Cloud when we can get access to it.

In both cases we’re aiming to demo the capabilities, setup eyc around the classic Hello World – but with a bit of a twist. Rather than simply sending to the console we’re going to use a mobile push notification – without resorting to having to build a mobile app.

By taking this approach to hello world aside from keeping it simple we can see how to bring 3rd party APIs into the mix.  The first couple of posts wont need to much on the Oracle front – as we’ll walk through getting things setup and running a proof without the cloud stuff. As they say keep it simple stupid.

So that you can see the blog entries for each of this two stories, I specifically setup in my blog two entry categories:

A few posts will obviously be common to both.

Free Network Security eBook

Tags

, , , , , ,

I came across the following promotion via LinkedIn. The book isn’t that new, but looking at Amazon reviews suggests that there maybe some value still:

Network Security For Dummies — eBook (usually $22.99) FREE until January 1st!

Get quick, easy, low-cost solutions to all your network security concerns.

CNN is reporting that a vicious new virus is wreaking havoc on the world’s computer networks. Somebody’s hacked one of your favorite Web sites and stolen thousands of credit card numbers. The FBI just released a new report on computer crime that’s got you shaking in your boots. The experts will tell you that keeping your network safe from the cyber-wolves howling after your assets is complicated, expensive, and best left to them. But the truth is, anybody with a working knowledge of networks and computers can do just about everything necessary to defend their network against most security threats.

Whether your network consists of one computer with a high-speed Internet connection or hundreds of workstations distributed across dozens of locations, you’ll find what you need to confidently:

  • Identify your network’s security weaknesses
  • Install an intrusion detection system
  • Use simple, economical techniques to secure your data
  • Defend against viruses
  • Keep hackers at bay
  • Plug security holes in individual applications
  • Build a secure network from scratch

– Download from: http://opensourceuniverse.tradepub.com/free/w_wile145/?p=w_wile145#sthash.i4fHNQgA.dpuf

Oracle Press Celebrates 20 Years of Support for the Global Oracle Workforce – – Originally @UKOCN

Tags

, , ,

Oracle Press Celebrates 20 Years of Support for the Global Oracle Workforce  

Happy 20th Birthday, Oracle Press! Since 1994, McGraw-Hill Education has partnered with Oracle Corporation to help Oracle professionals develop the skills they need to be successful with Oracle’s products and technologies.

What started out as one book on Oracle’s groundbreaking database, Oracle: The Complete Reference, has grown to 120 titles covering the entire Oracle ecosystem-databases, middleware, applications, servers, and certification. Oracle Press titles have sold more than 3 million books in print around the world, with thousands of eBooks accessed via devices and platforms, including Safari, Books 24X7, and McGraw-Hill Education’s own McGraw-Hill Education eBookLibrary.

Working closely with Oracle’s internal product development teams, Oracle Press has developed rigorous best practices for producing the highest quality content on the topics most critical to our readers.

More than half of Oracle Press’s authors are Oracle employees–the technologists driving Oracle’s products forward. And we’re always looking for new book ideas, authors and technical advisors.

  • To get an amazing 20% off all Oracle Press titles from McGraw-Hill please Click here

Enterprise Architect Cloud

Tags

, , , , , , ,

With version 11 of Sparx‘ Enterprise Architect tool a new cloud feature was introduced to support team working, which previously had been achieved using a shared Database.

When we heard about EA Cloud, both myself and my colleagues got rather excited, thinking that this would be the opportunity to offload the effort of looking after a central DB (making sure backups happened, fine tuning the DB settings and so on) plus maintaining the platform’s patching for security etc. Not only that through the cloud capability we could host the repository that made it very easy for the team to access the repository on the move without needing to have another whole in our corporate firewall etc.

Unfortunately, EA Cloud provides all the software to establish a cloud based repository – which can be used through firewalls etc – HTTPS traffic rather than DB connectors on unusual ports but not the hosting.  This seems to a bit of a missed opportunity for Sparx who already have to deal with all of these points to host 3 demo cloud servers.  So the next step of instantiating a server for a regular on going fee doesn’t seem too challenging, not to mention promotes customer tie in, plus the ability to capture some potentially interesting metrics about its users (e.g. which modelling techniques are most popular etc).  Having looked at Sparx partners they don’t offer the capability either which is a shame.

More Packt news – Christmas $5 offer

Tags

, , , ,

So you may have guessed Packt are running the Christmas promotion again – ebooks for $5 (or £3.60 to us Brits). The promotion runs until Jan 6th.5-dollar-promo

As you can see through my blog, Packt have some great books – https://mp3muncher.wordpress.com/tag/packt/ some of which I have helped with during their development (a little shameless self promotion).

So head over to http://bit.ly/1C4FAaQ

Packt has sent another Camel along

Tags

, , , , , ,

 Having been a little inactive on the book reviewing front with Packt in the last couple of months.  They have been working on a new Camel book – in addition to the excellent Apache Camel Developer’s Cookbook and several smaller Instant books (Instant Apache Camel Message RoutingInstant Apache Camel Messaging System) and asked me to again prepublication review.

Does Packt need another Camel book?  Maybe, this new volume from what I have reviewed so far is focusing on custom development and certainly starts with the real Camel development basics.  So feels like it is more targeted to a complete newbie to Camel. Several chapters in and the book hasn’t faced into how Camel supports Enterprise Integration Patterns in a deep manner – although that may yet come.  Watch this space as I’ll  post on how the book is likely to shape up.

Mitigating Risks of Cloud Services

Tags

, , , , , , , ,

As previously blogged there are risks with using cloud that differ from self hosting solutions. SaaS, PaaS and all the other XaaS offerings aren’t a panacea. Hopefully you won’t become the next Sony as the provider keeps you patched etc. But if you’re using a SaaS provider that goes bust or you get into litigation with your provider, as result losing access to your data. It could be potentially be months whilst the lawyers sort things out. A horrible situation that no one wants to find themselves in. But how to mitigate such risks?

Any half decent SaaS provider should give directly the means to get a view of all your data through a generic or custom report (s), or will should make available the means for providing an export of your data. The later approach may well come with a cost. If your SaaS solution has a lot of data in place – for example a multinational’s HR solution you may want to just target the extract of deltas. This means extra donkey work and someone to ensure it is happening. How frequently that should depend upon your business needs through an agreed Recovery Point Objective and the tolerance to potential data loss as you can assume you’ll lose everything from the last snapshot. If you have middleware in front of your SaaS service you can have a wiretap to reduce the risk here.

Your net position is in the event of a loss or possibly a prolonged service outage (remember even Amazon have had multi-day failures & not all SaaS solutions follow good cloud practise of being able to fail to secondary centres) is that you have your data and can atleast cobble something together to bridge the gap. Unless you SaaS vendor is offering you something very unique then they’re probably going to have competitors that are more than likely to be glade to help you import the data into their solution for you.

All this for a case of paranoia? Well actually you can have harvest a raft of other benefits from taking full data extracts – for example reconciliation with a view to managing data quality – statistics from Experian show the value of resolving discrepancies. This is to say – that you might find data errors between systems as a result things like edge scenarios such as handling errors in the integration layer. To illustrate the point, let’s assume that your web sales channel is via a SaaS provider and you’re receiving the sales into your on premise ERP for fulfilment and accounting. By taking every week all transactions in the SaaS solution you can identify and discrepancies and reconcile any issues between the sales solution, your finance and fulfilment capabilities to ensure what you have sold is what you have accounted for.  If we’re talking about solutions that impact your financial accounting, then for atleast US declarations it maybe necessary to perform such reconciliation in support of Sarbanes Oxley (SOX) requirements.

Add to this a richer data set can be added to your Big Data or Data Warehouse environments allowing you to gain potentially further insights into your activities.

When you are running a hybrid of on premise and cloud solutions or event just cloud but a mix of vendors don’t just think about you application data, but consider whether audit and web traffic information can be retrieved from the vendor – there maybe value in feeding that data into a solution such as Splunk which may then find a pattern of misuse or attack that may not show up with just the monitoring data from your on premise solutions.

The final point I should make, is don’t assume your service provider will let you at the data as described – look at your contracts before any payment or act of agreement. Ideally such checks should be part of your service due diligence activities (along with ESCROW) etc. There are SaaS providers who will consider the data as their property not yours even when the data might be about your employees.

Learning Lessons from Oracle Apps User Group submission

Tags

, , , , , , , , , , , ,

As the build up to the Oracle Applications User Group conference (Collaborate) progresses the presenters have been informed of whether there submissions have been accepted.  Among many I made several submissions.

Before I share what I think I should have learnt from making submissions let me give some background to how we got to where we are. So my boss is keen that we have a member of the Enterprise Architecture team who has a strong Oracle recognition. As we are a customer rather than partner the only opportunity really is through the Ace programme as an Associate. Well I have been as active as the demands of the day job allows With the UK Oracle User Group (UKOUG). We agreed presenting at something as big as OAUG’s annual conference Collaborate would be the next step to making a case.

So whilst at Oracle  Open World we finally agreed that step and joined OAUG and found we only had a couple of weeks to get our submissions together – during which time I had to get internal sign off for my submissions plus deal with a family emergency.

So with the scene set, perhaps lesson one, don’t work in haste. OAUG run webinars about how to create submissions – a worthwhile exercise to attend although it does focus on what OAUG provides in the form of submission information (any themes for the conference identified and the amount of information needed) and the process & mechanics of selection. The important message is to temper your expectations as selection success rate is about 1 in 6 submissions. I looked at their themes and identified what I had in mind more or less fitted (big tick for me).

All of this meant I could assemble my submissions including details for my employer of what internal work and sources likely to be drawn from. Mistake here is perhaps I should have done this as soon as we had agreed to try as it would have meant I could give focus on getting my submission together sooner.

Perhaps the biggest missed opportunity, was having joined OAUG was to immediately look through previous conference papers and presentations, and most critically the ‘abstracts’ with these to get a feel of the messages, language and themes of presentations that had been accepted.  Understanding how the presentation submission might resonate with those voting on which presentations to accept could have made a big difference.  In hindsight I suspect my submission wording was a little to academic rather than informed by battle worn insights and how we’ve beaten some challenges.

All of this would help by having actually attended a previous Collaborate conference and got a feel for the ‘character’ of the conference and the people attending. I do know from Oracle Open World and Oracle’s one day sessions have some commonality in character and attendance but feel different and have some slight differences in attendance (Oracle sessions are slightly more abstract except customer presentations) and attendance can be a bit more decision maker in attendance. Where as UKOUG attendance is more orientated to those who execute delivery or drive the delivery aspects.  Then open source events differ a bit again.

To help inform thinking and learning how to progress I have been reading the excellent book Confessions of a Public Speaker by Scott Berkun (amusing and insightful book on public speaking and full of useful practical simple advise). Some may say a little masochistic given my submissions weren’t selected. But, certainly helped thinking about the approach for example really focusing down on the key message, and then how to prepare if a submission is selected.

To conclude, what now?  Well we will be applying these observations going forward, and will have done the reading of previous submissions and got together my submission ideas by the time submission opportunities open for next year – so no haste.  With a little luck will have attended Collaborate as just a delegate.  Then of course there is perhaps Open World as an opportunity.

Single Vendor Cloud

Tags

, , , , , , , , , ,

The recent outage of Microsoft Azure, raises some interesting questions. This isn’t the first big vendor cloud service outage, Amazon AWS and others have had their moments. Of course this had lead to the recommendation that to ensure your service has continuity that a DR arrangement with a different provider be in place. This works with Platform as a Service. But what we have been seeing is move from PaaS up the value stack to vendors offering their own rich ecosystem to build on – from Amazon SQS to Oracle’s latest announcement Oracle Internet of Things platform.

These solutions, can be built with open standards etc but ultimately when used create vendor lock-in as no one else will have an equivalent capability with the same APIs. So how do you mitigate these outages, or even the risk of such an outage? Well Oracle do claim you can actually run all their cloud capabilities on premise. But is that practical? As cloud is adopted organisations are going to wind back their hardware capital outlay, after all that is one of the value points of cloud.

So where does that leave us? Accepting the risk and trying to mitigate the risks in our own commercial agreements? What about the fact in an IoT solution where you’re event stream processing and using period on period comparisons to set thresholds which means the likely data loss from an outage will have both ‘echos’ as you period analysis has holes in data plus false thresholds as the data hole will skew the data when that period is being used for period comparison.

Difficult questions with no obvious answers, other than you mitigate you things commercially and push Microsoft and others to make things more robust – time for Netflix Chaos monkey?

Next Generation SOA book

Tags

, , ,

My copy of the Next Generation SOA on the Service Tech Press /Prentice Hall arrived today. This is first Prentice Hall book I have contributed to as a pre publication reviewer. It is always nice to see a recognition in the book, particularly when the draft of the book is of such a high standing your feedback is more helping finesse things.

Acknowledgements

Next Generation SOA

I have previously blogged that this is a book I would highly recommend, it isn’t a vast heavyweight text, but provides a great broad view of SOA in the current IT landscape.  If you’re not adverse to eBooks you might consider getting the ebook version as the diagrams look far better in colour than in the grayscale of the print edition.

Next Generation SOA