Lack of API visibility is a top security concern at many enterprises today. APIs that operate in disconnected silos produce inconsistent analytics and decentralized security. API traffic metadata mining is the new gold rush. Learn how mining and analysing this untapped resource leads to richer API insights and stronger threat detection and blocking.
API transactions are subjected to many authorization decisions at many different layers. User identities, application scopes, attributes, roles, data privacy, user consent, contracts… Tidy up your decision-making responsibilities across your stack. This presentation will discuss the benefits and tradeoffs of decoupling authorization from service implementation.
This document discusses the importance of API security testing. It notes that 56% of webinar attendees felt API security was very important to their organization, but only 12% were doing extensive security testing. It highlights some examples of security breaches caused by insecure APIs and recommends implementing API management solutions to protect against threats like unauthorized access, data exposure, and denial of service attacks. The document demonstrates how an API gateway can detect and block a SQL injection attack on a banking API. It emphasizes the importance of putting security protections in place for APIs and including testing in the development process.
apidays LIVE Paris - Driving innovation through External APIs without putting...apidays
External APIs are driving unprecedented innovation across industries like e-commerce and fintech by automating processes, improving customer experiences, and enabling new business models. However, using third-party APIs also carries risks around security, compliance, and business continuity if not properly governed. The concept of "shadow APIs" - APIs used without an organization's knowledge - exacerbates these risks. To mitigate risks, organizations should detect all API dependencies, build an API knowledge base, integrate governance into development processes, and map all API data flows. Proper API governance is crucial, especially for external APIs over which organizations have less control.
Managing Sensitive Information in an API and Microservices WorldApigee | Google Cloud
Managing Sensitive Information in an API and Microservices World. A presentation by Peter Miron (Apcera) and Joshua Norrid (Apigee) at Apigee's Adapt or Die, San Francisco 2016. See events.apigee.com
Google has invested $27 billion in data centers worldwide since 2014 to build the world's fastest and most powerful cloud infrastructure. In 2016, Google Cloud Platform experienced 36% year-over-year growth in bookings, a 50% increase in net customer count, and over 90 new features shipped. Google processes over 1 billion API calls per day and saw 58% year-over-year growth in Black Friday traffic.
API Management Workshop (at Startupbootcamp Berlin)3scale
These are the slides from the API Management Workshop, held at the Startupbootcamp Berlin on October 17.
We covered benefits of APIs for an organisation (regardless of size, sector, stage or purpose) and gave examples of successful deployment of APIs.
We then described the typical API lifecycle:
plan/design > build/integrate > operate/manage > share/engage.
We covered many best practices and tools for each stage and gave practical demos about how to secure and manage APIs.
The document discusses securing APIs and presents examples of security issues with Snapchat, Nissan Leaf, and other APIs. It outlines approaches to API security used by large enterprises, distinguishing between internal and external APIs. The presentation emphasizes establishing security at multiple layers, with a focus on the API management layer. It provides examples of security measures like mutual TLS, rate limiting, input validation, OAuth 2.0, and monitoring for anomalies. Governance techniques like flow hooks are also presented. Live demos illustrate bot detection, proof of work, and extending OAuth with techniques like token binding and proof of key for JWTs.
apidays LIVE Hong Kong 2021 - Event-driven APIs & Schema governance for Apach...apidays
apidays LIVE Hong Kong 2021 - API Ecosystem & Data Interchange
August 25 & 26, 2021
Event-driven APIs & Schema governance for Apache Kafka
Hugo Guerrero, APIs & Messaging Developer Advocate at Red Hat
------
Check out our conferences at https://www.apidays.global/
Do you want to sponsor or talk at one of our conferences?
https://apidays.typeform.com/to/ILJeAaV8
Learn more on APIscene, the global media made by the community for the community:
https://www.apiscene.io
Explore the API ecosystem with the API Landscape:
https://apilandscape.apiscene.io/
Open API and API Management - Introduction and Comparison of Products: TIBCO ...Kai Wähner
In October 2014, I had a talk at Jazoon in Zurich, Switzerland: "A New Front for SOA: Open API and API Management as Game Changer"
Open API represent the leading edge of a new business model, providing innovative ways for companies to expand brand value and routes to market, and create new value chains for intellectual property. In the past, SOA strategies mostly targeted internal users. Open APIs target mostly external partners.
This session introduces the concepts of Open API, its challenges and opportunities. API Management will become important in many areas, no matter if business-to-business (B2B) or business-to-customer (B2C) communication. Several real world use cases will discuss how to gain leverage due to API Management. The end of the session shows and compares API management products from different vendors such as TIBCO API Exchange, IBM, Apigee, 3scale, WSO2, MuleSoft, Mashery, Layer 7, Vordel
Apigee and Accenture Webcast - Accenture Technology Vision 2013 - An API Cent...Apigee | Google Cloud
The document summarizes Accenture's Technology Vision for 2013, which identifies eight technology trends and discusses each trend from an API-centric perspective. The eight trends are relationships at scale, design for analytics, data velocity, seamless collaboration, software-defined networking, active defense, and beyond the cloud. For each trend, the document outlines the role and importance of APIs, such as how APIs power the app economy and unlock agility in virtualization. The vision is that every business will become a digital business where the API is the central product.
Pitney Bowes uses API management to deliver a broad set of cloud-based digital ecommerce capabilities, enable extensive partnerships, and optimize its own operations.
apidays LIVE New York 2021 - API design is where culture and tech meet each o...apidays
apidays LIVE New York 2021 - API-driven Regulations for Finance, Insurance, and Healthcare
July 28 & 29, 2021
API design is where culture and tech meet each other
Aleksei Akimov, Head of API at Adyen
apidays LIVE Paris - Drawing the right lines: DDD, APIs and Microservices by ...apidays
apidays LIVE Paris - Responding to the New Normal with APIs for Business, People and Society
December 8, 9 & 10, 2020
Drawing the right lines: DDD, APIs and Microservices
Ronnie Mitra, Director of Technology at Publicis Sapient
Learn about how to protect your digital assets from known external threats at the API layer. Secure your assets against threats like SQL injection, JSON threat protection and application DoS. Protect your apps from cyber threats and bad bots with data-driven enterprise grade API security and Adaptive Threat Protection.
apidays LIVE Paris - The State of SaaS Integration by Gertjan De Wildeapidays
The document discusses trends in SaaS integration and API standardization. It notes that the number of SaaS apps used by companies is growing significantly each year, driving demand for easier integration. API standards like OpenAPI are gaining adoption and helping improve integration. It recommends companies adopt a hybrid integration strategy using both native and third-party integrations. Focusing on the developer experience through SDKs, documentation, and events can help attract more developers to an API. The document predicts continued growth in areas like no-code/low-code platforms, embedded workflows, and compliance-focused APIs.
Managing Sensitive Information in an API and Microservices WorldApigee | Google Cloud
As enterprises begin to share their sensitive data through APIs the ability to enforce authorization and non-repudiation of data with full visibility and traceability is critical for corporate compliance and viability. Join Apigee and Apcera on how to best manage data sovereignty through an end to end chain of custody through workloads, APIs and end users.
John Phenix proposes automating API governance at HSBC to improve the developer experience and ensure consistency. He outlines five tips: 1) Govern only real risks, not preferences; 2) Ensure governance scales with development; 3) Shift governance left to catch issues earlier; 4) Transition from reviewing correctness to reviewing appropriateness; 5) Automate as much as possible while still involving people. Phenix advocates a hybrid centralized-federated model and using tools to automate reviews, integrate with CI/CD, and provide dashboards. Example rules cover security, operations, and style standards.
apidays LIVE Australia 2021 - Leveraging Async APIs to deliver Cross Domain A...apidays
apidays LIVE Australia 2021 - Accelerating Digital
September 15 & 16, 2021
Leveraging Async APIs to deliver Cross Domain Agile Collaboration
Nuwan Dias, VP API Management & Integration at WSO2
[WSO2 API Day Toronto 2019] Extending Service Mesh with API ManagementWSO2
In this deck, we discuss how to augment service mesh functionality with API management capabilities, so you can create an end-to-end solution for your entire business functionality — from microservices to APIs, to end-user applications.
Is Your API Being Abused – And Would You Even Notice If It Was?Nordic APIs
APIs are a wonderful thing and bring many benefits, but by their very nature they are also a window into how your business operates. If someone can exploit your system for gain, they will.
This presentation will give multiple real examples of API abuse in the wild, via methods such as data scraping, service misuse/cheating, unauthorized aggregation and fake account creation. How is it done, how are existing API controls bypassed, and what are the business implications?
The audience will learn that API abusers are inventive and they use smart tools. The audience will also learn who some of these API abusers are, and may be surprised by the result. (Spoiler: they can be your customers!)
Finally, some guidance will be given around what additional access controls can be put in place to ensure API based businesses continue to prosper.
apidays LIVE Australia 2021 - How to Achieve Zero-Trust Security With Kuma Se...apidays
apidays LIVE Australia 2021 - Accelerating Digital
September 15 & 16, 2021
How to Achieve Zero-Trust Security With Kuma Service Mesh
Marco Palladino, CTO & Co-Founder at Kong
Extend your legacy SOA/ESB infrastructure to Mobile & IoT
This webinar recording provides a use-case driven discussion around appropriate use of existing middleware infrastructure as well as its shortcomings. It dives deep into how APIs can not only complement an ESB or SOA infrastructure but also fill existing gaps.
Watch this webinar recording to learn about:
- Strengths and weaknesses of your existing ESB/SOA infrastructure
- Architecture strategy: extend and add value to legacy middleware with APIs
- Integration / API use cases in Retail, Manufacturing and Telecom
- The API360 approach to digital strategy
We'll explore how 4 forces will impact the API market over the next two to four years, and how hybrid- and multi-cloud, open source, developer-led adoption, and cloud-native application architecture are driving profound changes in the API market.
Gartner AADI Learning Lab - Microservices and API ManagementColin McGovern
This set of slides was used during a demo that showed a service being built, deployed on a service mesh, and exposed as a proxy at the edge of the mesh, all in under 10 minutes.
This document discusses how AWS blockchain services can help retail companies. It provides examples of Nestle tracking coffee supply chains and CJ OliveNetworks building a digital content copyright management system using Amazon Managed Blockchain. It also outlines how the Singapore Exchange is working with AWS to enhance collaboration for local and cross-border trade settlements.
The document discusses securing APIs and presents examples of security issues with Snapchat, Nissan Leaf, and other APIs. It outlines approaches to API security used by large enterprises, distinguishing between internal and external APIs. The presentation emphasizes establishing security at multiple layers, with a focus on the API management layer. It provides examples of security measures like mutual TLS, rate limiting, input validation, OAuth 2.0, and monitoring for anomalies. Governance techniques like flow hooks are also presented. Live demos illustrate bot detection, proof of work, and extending OAuth with techniques like token binding and proof of key for JWTs.
apidays LIVE Hong Kong 2021 - Event-driven APIs & Schema governance for Apach...apidays
apidays LIVE Hong Kong 2021 - API Ecosystem & Data Interchange
August 25 & 26, 2021
Event-driven APIs & Schema governance for Apache Kafka
Hugo Guerrero, APIs & Messaging Developer Advocate at Red Hat
------
Check out our conferences at https://www.apidays.global/
Do you want to sponsor or talk at one of our conferences?
https://apidays.typeform.com/to/ILJeAaV8
Learn more on APIscene, the global media made by the community for the community:
https://www.apiscene.io
Explore the API ecosystem with the API Landscape:
https://apilandscape.apiscene.io/
Open API and API Management - Introduction and Comparison of Products: TIBCO ...Kai Wähner
In October 2014, I had a talk at Jazoon in Zurich, Switzerland: "A New Front for SOA: Open API and API Management as Game Changer"
Open API represent the leading edge of a new business model, providing innovative ways for companies to expand brand value and routes to market, and create new value chains for intellectual property. In the past, SOA strategies mostly targeted internal users. Open APIs target mostly external partners.
This session introduces the concepts of Open API, its challenges and opportunities. API Management will become important in many areas, no matter if business-to-business (B2B) or business-to-customer (B2C) communication. Several real world use cases will discuss how to gain leverage due to API Management. The end of the session shows and compares API management products from different vendors such as TIBCO API Exchange, IBM, Apigee, 3scale, WSO2, MuleSoft, Mashery, Layer 7, Vordel
Apigee and Accenture Webcast - Accenture Technology Vision 2013 - An API Cent...Apigee | Google Cloud
The document summarizes Accenture's Technology Vision for 2013, which identifies eight technology trends and discusses each trend from an API-centric perspective. The eight trends are relationships at scale, design for analytics, data velocity, seamless collaboration, software-defined networking, active defense, and beyond the cloud. For each trend, the document outlines the role and importance of APIs, such as how APIs power the app economy and unlock agility in virtualization. The vision is that every business will become a digital business where the API is the central product.
Pitney Bowes uses API management to deliver a broad set of cloud-based digital ecommerce capabilities, enable extensive partnerships, and optimize its own operations.
apidays LIVE New York 2021 - API design is where culture and tech meet each o...apidays
apidays LIVE New York 2021 - API-driven Regulations for Finance, Insurance, and Healthcare
July 28 & 29, 2021
API design is where culture and tech meet each other
Aleksei Akimov, Head of API at Adyen
apidays LIVE Paris - Drawing the right lines: DDD, APIs and Microservices by ...apidays
apidays LIVE Paris - Responding to the New Normal with APIs for Business, People and Society
December 8, 9 & 10, 2020
Drawing the right lines: DDD, APIs and Microservices
Ronnie Mitra, Director of Technology at Publicis Sapient
Learn about how to protect your digital assets from known external threats at the API layer. Secure your assets against threats like SQL injection, JSON threat protection and application DoS. Protect your apps from cyber threats and bad bots with data-driven enterprise grade API security and Adaptive Threat Protection.
apidays LIVE Paris - The State of SaaS Integration by Gertjan De Wildeapidays
The document discusses trends in SaaS integration and API standardization. It notes that the number of SaaS apps used by companies is growing significantly each year, driving demand for easier integration. API standards like OpenAPI are gaining adoption and helping improve integration. It recommends companies adopt a hybrid integration strategy using both native and third-party integrations. Focusing on the developer experience through SDKs, documentation, and events can help attract more developers to an API. The document predicts continued growth in areas like no-code/low-code platforms, embedded workflows, and compliance-focused APIs.
Managing Sensitive Information in an API and Microservices WorldApigee | Google Cloud
As enterprises begin to share their sensitive data through APIs the ability to enforce authorization and non-repudiation of data with full visibility and traceability is critical for corporate compliance and viability. Join Apigee and Apcera on how to best manage data sovereignty through an end to end chain of custody through workloads, APIs and end users.
John Phenix proposes automating API governance at HSBC to improve the developer experience and ensure consistency. He outlines five tips: 1) Govern only real risks, not preferences; 2) Ensure governance scales with development; 3) Shift governance left to catch issues earlier; 4) Transition from reviewing correctness to reviewing appropriateness; 5) Automate as much as possible while still involving people. Phenix advocates a hybrid centralized-federated model and using tools to automate reviews, integrate with CI/CD, and provide dashboards. Example rules cover security, operations, and style standards.
apidays LIVE Australia 2021 - Leveraging Async APIs to deliver Cross Domain A...apidays
apidays LIVE Australia 2021 - Accelerating Digital
September 15 & 16, 2021
Leveraging Async APIs to deliver Cross Domain Agile Collaboration
Nuwan Dias, VP API Management & Integration at WSO2
[WSO2 API Day Toronto 2019] Extending Service Mesh with API ManagementWSO2
In this deck, we discuss how to augment service mesh functionality with API management capabilities, so you can create an end-to-end solution for your entire business functionality — from microservices to APIs, to end-user applications.
Is Your API Being Abused – And Would You Even Notice If It Was?Nordic APIs
APIs are a wonderful thing and bring many benefits, but by their very nature they are also a window into how your business operates. If someone can exploit your system for gain, they will.
This presentation will give multiple real examples of API abuse in the wild, via methods such as data scraping, service misuse/cheating, unauthorized aggregation and fake account creation. How is it done, how are existing API controls bypassed, and what are the business implications?
The audience will learn that API abusers are inventive and they use smart tools. The audience will also learn who some of these API abusers are, and may be surprised by the result. (Spoiler: they can be your customers!)
Finally, some guidance will be given around what additional access controls can be put in place to ensure API based businesses continue to prosper.
apidays LIVE Australia 2021 - How to Achieve Zero-Trust Security With Kuma Se...apidays
apidays LIVE Australia 2021 - Accelerating Digital
September 15 & 16, 2021
How to Achieve Zero-Trust Security With Kuma Service Mesh
Marco Palladino, CTO & Co-Founder at Kong
Extend your legacy SOA/ESB infrastructure to Mobile & IoT
This webinar recording provides a use-case driven discussion around appropriate use of existing middleware infrastructure as well as its shortcomings. It dives deep into how APIs can not only complement an ESB or SOA infrastructure but also fill existing gaps.
Watch this webinar recording to learn about:
- Strengths and weaknesses of your existing ESB/SOA infrastructure
- Architecture strategy: extend and add value to legacy middleware with APIs
- Integration / API use cases in Retail, Manufacturing and Telecom
- The API360 approach to digital strategy
We'll explore how 4 forces will impact the API market over the next two to four years, and how hybrid- and multi-cloud, open source, developer-led adoption, and cloud-native application architecture are driving profound changes in the API market.
Gartner AADI Learning Lab - Microservices and API ManagementColin McGovern
This set of slides was used during a demo that showed a service being built, deployed on a service mesh, and exposed as a proxy at the edge of the mesh, all in under 10 minutes.
This document discusses how AWS blockchain services can help retail companies. It provides examples of Nestle tracking coffee supply chains and CJ OliveNetworks building a digital content copyright management system using Amazon Managed Blockchain. It also outlines how the Singapore Exchange is working with AWS to enhance collaboration for local and cross-border trade settlements.
Microservices architecture advocates breaking monolithic applications into independent, isolated services that each have a single well-defined purpose. This allows each service to be developed, deployed and scaled independently. Key aspects of microservices include logical decomposition of functions, physical isolation of services using containers, independent data stores for each service, and asynchronous communication between services using a messaging platform. Monitoring and service discovery layers are also important to ensure high availability of the application and routing of requests to available services. While microservices improve scalability and flexibility, enterprise service buses are still needed for integration across applications.
Both API Gateways and Service Meshes offer similar features and capabilities but are each implemented on a different axis in your application’s data plane. Draw those capabilities in a Venn diagram, you’ll see a lot of overlap between the API Gateways and Service Meshes. This is NOT a talk about the overlap. This is a talk about the things outside the overlap and why they matter (#HereBeDragons). The talk focuses on three questions around North/South & East/West Traffic. This talk is for a senior developer/architect on where to best inject cross-cutting concerns around security, observability and resiliency enabled by API Gateways and Service Meshes.
Centralization and automation of containerized service (microservices) management with the ability to control policies consistently across several service meshes increases visibility and control over all API traffic while enabling enterprises to independently and rapidly deliver on innovation without the bottlenecks. Check out our demo to see how Axway and AMPLIFY Central provide packaged maturity for service mesh management along with centralized policy management of APIs and Microservices that run in the cloud and/or on-premises infrastructure.
AWS Summit Singapore 2019 | Next Generation Audit & Compliance - Learn how RH...AWS Summits
Speaker: Alejandra Artiguez, FSI Compliance Program Manager, APAC, AWS Customer Speaker: Clara Lee Hui Theng, Head Technology & Operations, RHB Bank Berhad (Singapore)
Security and Compliance is a shared responsibility between AWS and the customer. In this session we will examine the AWS Shared responsibility model, and AWS compliance programs customers can use to gain assurance of security controls in the cloud. We will dive-deep into a number of cloud native security services that customers can use to protect their critical systems when migrating to AWS. Finally we will review a next-generation approach to audit and continuous compliance leveraging automation to identify mis-configurations and perform automatic remediatation to protect your AWS workloads.
Agile integration architecture in relation to APIs and messagingKim Clark
This document discusses agile integration architecture from three perspectives: application integration, APIs, and messaging. It outlines how traditional centralized integration approaches are moving to more decentralized models with fine-grained deployments, application autonomy, and cloud-native implementations. APIs are shifting from system-centric to consumer-centric exposure, while messaging is evolving from self-managed to platform-managed infrastructure. Microservices require both asynchronous communications via events and synchronous APIs to fully decouple components. Agile integration architecture enables independent, scalable, and resilient digital applications and services.
Speaker: Olivier Klein, Head of Emerging Technologies, AWS
Building applications is changing rapidly and data is now key to success. The code that powers your distributed applications needs to be portable and embrace open-source frameworks to fast-track dev efforts and abstract away difficult concepts. A rapid expansion of ecosystems and cloud computing are driving an incredibly fast pace of innovation with rapid growth in cloud-connected systems and edge devices, whilst advances in machine learning create increasingly intelligent systems. So, in this fast-paced, complex world, what are the strategies and techniques that builders can use to create successful, data-driven platforms of the future? How can they embrace distributed computing models in a highly-available and scalable manner and derive business value through data-centric deployments? Join us for our Techfest keynote to hear about new concepts, services, open-source frameworks, and methodologies in conjunction with AWS to help builders innovate faster in a lean fashion.
WSO2 Integration Platform - The most comprehensive integration platform for y...WSO2
The document discusses the evolution of integration from traditional SOA to a new hybrid integration ecosystem. It describes how WSO2 products like the ESB and API Manager address integration challenges and enable both on-premise and cloud-based hybrid integration. It also outlines how future integration will involve technologies like API management, Internet of Things (IoT), and protocols for low-powered devices.
The document discusses AWS migration tools and strategies. It provides an overview of AWS services like Application Discovery Service and Migration Hub that help with discovery, planning, and tracking migrations. It also summarizes common migration patterns and challenges, and highlights how tools like ADS can help with discovery of on-premises assets and costs to better plan a migration. Example customer migrations are provided that leveraged AWS to reduce costs while improving agility.
The document describes how to build multi-tier architectures using Amazon API Gateway and AWS Lambda as the serverless logic tier. Some key points:
1. API Gateway acts as the front door for the logic tier and integrates AWS Lambda functions, allowing them to be triggered by HTTPS requests.
2. Lambda allows arbitrary code to run in response to events, including API Gateway requests. This enables running business logic behind APIs.
3. The combination of API Gateway and Lambda handles scaling, availability, security, and management of the logic tier infrastructure. Developers can focus on application code.
4. Lambda functions can access data tier resources both within a VPC for private resources, as well as services like S3
DevConZM - Modern Applications Development in the CloudCobus Bernard
The document discusses developing modern applications in the cloud. It covers topics like building applications with serverless technologies, modeling infrastructure with code, structuring apps as microservices, containerization, continuous integration/delivery (CI/CD), and service meshes. The overall message is that cloud-native design approaches like these can help businesses rapidly innovate and gain a competitive advantage.
엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...Amazon Web Services Korea
This document discusses strategies for effective cloud adoption in enterprises. It highlights the challenges of enterprise IT such as needing fast time to market and constant innovation. The business value of cloud adoption is also presented, including potential cost savings, staff productivity gains, and improved business agility. Common challenges for enterprise cloud adoption are discussed. The document provides recommendations for building an internal cloud team and establishing a cloud landing zone to help with adoption. It also emphasizes the importance of modernizing databases as part of the cloud migration process.
Serverless Logic Tier The logic tier of the three-tier architecture represents the brains of the application. This is why integrating Amazon API Gateway and AWS Lambda to
form your logic tier can be so revolutionary.
What You Need to Know About Operationalizing Your AWS Transit HubKhash Nakhostin
You’ll see a demonstration of the best practices we’ve gleaned from working with operations teams, who all require:
Visibility. Do you have a way to centrally view your network, see performance bottlenecks, control security policies, and set other configuration details?
Deep Analytics. Can you easily gather performance and audit data and export it to Splunk, DataDog, or other advanced reporting tools?
Monitoring and Troubleshooting. Do you have a real-time view of network health, and how easily can you access the data needed to locate and fix issues?
Alert Management. When issues do occur, what real-time alerting is available?
This document provides an overview of security best practices for Amazon API Gateway. It discusses API Gateway's security features such as encryption of data in transit and at rest. It also covers identity and access management using IAM. API Gateway supports authentication using standards like OAuth 2.0 and OpenID Connect. The document outlines design principles like implementing least privilege access and minimizing attack surfaces. It also discusses how to enable auditing, automate security practices, and apply defense in depth across layers.
apidays LIVE JAKARTA - Take control of your microservices with App Mesh by Ak...apidays
apidays LIVE JAKARTA - Connecting the Digital Stack
Take control of your microservices with App Mesh
Akhmad Makki, Enterprise Solution Strategist at Software AG
CodeBuild CodePipeline CodeDeploy CodeCommit in AWS | EdurekaEdureka!
This document provides an overview of AWS, DevOps, continuous integration and delivery, CodePipeline, CodeDeploy, CodeBuild, and CodeCommit. It discusses that AWS is a cloud platform offering computing and storage, DevOps aims to reduce change deployment time while ensuring quality, continuous integration and delivery automate software releases, and CodePipeline automates and visualizes app release processes through various stages like source, build, test and deploy handled by services like CodeBuild, CodeDeploy, and CodeCommit.
Service Virtualization + API Management togetherPablo Gutierrez
The document discusses how CA API Management and CA Service Virtualization can help accelerate application development at lower costs and better quality. It describes how these solutions address challenges of API management by providing a policy framework and gateway to securely expose APIs. It also explains how service virtualization eliminates constraints in development and testing by providing virtual services that stand-in for unavailable or costly dependencies. The combination of API management and service virtualization can improve application delivery speed and quality.
How to Choose the Right API Platform - We Have the Tool You Need! - Mikkel Iv...Nordic APIs
A presentation given by Mikkel Iversen, Business Development Director at Redpill Linpro, at our 2024 Platform Summit, October 8-9.
In this session we will demo a tool developed by Redpill Linpro to help you choose the right platform to support your API initiative. The evaluation model combines AI and our vast experience from the API and integration space to help you choose the platform that best suits your requirements.
Bulletproof Backend Architecture: Building Adaptive Services with Self-Descri...Nordic APIs
A presentation given by Sean Travis Taylor, Head of Platform at Redeem, at our 2024 Platform Summit, October 8-9.
The ability for web services to adapt to changes is crucial for maintaining seamless integration and operational efficiency throughout the many services that stitch together commerce, work and play across the vastness of the Internet.Illustrated with a fictional case study from the ecommerce sector, this talk introduces an approach to achieving such adaptability through the use of self-describing messages: a method where each message carries all the required data and metadata necessary for processing, without relying on any external data handling or centralized knowledge.Our case study involves an ecommerce storefront that relies on data from a third-party vendor with a highly volatile API. Despite the vendor’s frequent API changes, our approach using self-describing messages ensures that the storefront maintains uninterrupted service, safeguarding both sales and customer experience. This example not only underscores the robustness of self-describing messages in handling API volatility but also highlights their role in preventing business disruptions and reducing the need for frequent developer interventions and cross-functional meetings.The session will also discuss major advantages of systems that incorporate self-describing messages like improved scalability and easier updates and upgrades without centralized data handling. By the conclusion of this talk, attendees will appreciate the strategic value of implementing self-describing messages to enhance service adaptability and maintain business operations in the face of constant change.
Implementing Zero Trust Security in API Gateway with Cilium - Pubudu Gunatila...Nordic APIs
A presentation given by Pubudu Gunatilaka, Senior Technical Lead at WSO2, at our 2024 Platform Summit, October 8-9.
Cilium, an open-source, cloud-native solution using eBPF, can integrate with the Kubernetes Gateway API to significantly enhance API management with advanced networking, security, and observability features. It offers high-performance, programmable networking for modern cloud-native environments. This session will overview Cilium and the Kubernetes Gateway API, looking at current capabilities and how to use these technologies to enhance both north-south and east-west-style API management. Attendees will walk away with actionable advice for using state-of-the-art cloud-native tools to improve API management and a zero-trust security posture.
Event-Driven Architecture the Cloud-Native Way - Manuel Ottlik, HDI Global SENordic APIs
A presentation given by Manuel Ottlik, Product Owner for Global Integration Platform at HDI Global SE, at our 2024 Platform Summit, October 8-9.
When it comes to integrating software, you can choose between synchronous integration, most often done through REST APIs, or asynchronous communication, often referred to as event-driven architectures. While the synchronous world is pleasantly simple, asynchronous communication still lacks interoperability in terms of protocols, brokers and registries. Going cloud-native with the CloudEvents project for common event metadata and xRegistry as an approach to standardising the management of this metadata in registries will increase this interoperability and ultimately make your life easier when working with event-driven architectures.
Navigating the Post-OpenAPI Era with Innovative API Design Frameworks - Danie...Nordic APIs
A presentation given by Daniel Kocot, Head of API Consulting at codecentric AG, at our 2024 Platform Summit, October 8-9.
The Post-OpenAPI Era in API design marks a pivotal shift towards innovative frameworks like Microsoft TypeSpec, TaxiLang, Fern, and Apple Pkl, offering solutions beyond OpenAPI’s constraints. This talk dives into how these frameworks transform API design, providing flexibility, expressiveness, and improved developer experiences. We’ll explore the features and advantages of each framework, demonstrating their potential to enhance API documentation, client generation, and collaborative design processes. Highlighting real-world case studies, we illustrate the positive impact on development speed, usability, and end-user satisfaction. Attendees will gain insights into integrating these frameworks into development workflows, understanding the future landscape of API development, and envisioning the possibilities this new era brings.
Using Typespec for Open Finance Standards - Chris Wood, Ozone APINordic APIs
A presentation given by Chris Wood, Principal Architect, Ozone API, at our 2024 Platform Summit, October 8-9.
The development of API standards is critical to helping markets grow their open finance ecosystem. Standards bodies typically use OpenAPI to help create API standards, but their efforts can be accelerated by using compatible design tools like TypeSpec. In this talk we’ll uncover what it means to use TypeSpec for design-first standards development, and dig into the lessons learned from the approach.
Schema-first API Design Using Typespec - Cailin Smith, MicrosoftNordic APIs
A presentation given by Cailin Smith, Senior Software Engineer at Microsoft, at our 2024 Platform Summit, October 8-9.
TypeSpec is a relatively new open source schema language coming out of Azure. In this talk, I will introduce you to the basics of using TypeSpec, and how apps.methodscript.com uses a Schema-First API design, allowing for developers to skip writing glue code, while maintaining a gigantic client support matrix, minimizing bugs, and speeding up API development.
A presentation given by Naresh Jain, Founder & CEO of Xnsio, at our 2024 Platform Summit, October 8-9.
As we build more complex distributed Applications, the resilience of APIs can be the linchpin of application reliability and user satisfaction. This demo will delve into practical tools and techniques used to enhance the resilience of APIs. We will explore how we utilise API specifications for simulating various input data, network conditions and failure modes to test how well the API handles unexpected situations.
Our demo will begin with an overview of API resilience — why it matters, and what it means to build robust APIs that gracefully handles flaky dependencies in real-world operations. We'll discuss the role of contract testing in achieving resilience and how to turn API specifications into executable contracts that can be continuously validated.
We'll also cover how to integrate with CI/CD pipelines and practices to foster better collaboration between API stakeholders through shared understanding and executable documentation.
How to Build an Integration Platform with Open Source - Magnus Hedner, BenifyNordic APIs
A presentation given by Magnus Hedner, Manager of Integration Platforms at Benify, at our 2024 Platform Summit, October 8-9.
The talk of the town is "the great unbundling". We've added "... using open source."
There are a lot of tool vendors, offering complete bundles including all components you need (Yes I have worked with a few of those). But there is also an alternative, if you want to have full control of the components of your integration platform.
This is a talk on how we have built an integration platform, comprising API gateways, an integration tool, security, monitoring, and how we tailor it to our needs.
API Design First in Practise – An Experience Report - Hari Krishnan, SpecmaticNordic APIs
A presentation given by Hari Krishnan, Co-founder & CTO at Specmatic, at our 2024 Platform Summit, October 8-9.
API Design First requires that all stakeholders adhere to the spec that has been agreed. Come join me in this talk where I share our experience helping team instantly convert API specs into executable contracts to help them independently develop and confidently deploy their components. This approach of using API specs as executable contracts addresses several shortcomings associated with code generation based techniques we had tried in the past. I will also be sharing how we went about iterative API Design to allow for collaborative evolution of features. And mainly avoiding breaking compatibility during API evolution. Key takeaways:
1. API Specifications to API Tests in seconds – Also generative API coverage report (similar to code coverage, but for APIs) to verify adherence for API implementations
2. API Specifications as API Mocks
3. Backward Compatibility Testing – API Spec vs API Spec
4. Using Linters effectively
5. Extracting common API Specification elements and reusing them
6. Single source of truth for API specifications to promote collaboration between all stakeholders
The Right Kind of API – How To Choose Appropriate API Protocols and Data Form...Nordic APIs
A presentation given by Sumit Amar, Vice President of Engineering at WEX , at our 2024 Platform Summit, October 8-9.
In this session we will evaluate various data formats (JSON, XML, Protocol Buffers, and YAML), and discuss their pros and cons in varying scenarios. We will also evaluate how they pair with adequate data channels (HTTP/S, Binary over gRPC, gRPCweb in browsers, or Web Sockets). We will review various API use cases and map them with the right combination of data formats and channels for best performance, scalability, and maintainability.
Why Frequent API Hackathons Are Key to Product Market Feedback and Go-to-Mark...Nordic APIs
A presentation given by Per Lange, Founder at Cillers, at our 2024 Platform Summit, October 8-9.
An API hackathon is an event where developers learn how to build something interesting on top of a specific company’s API. These gatherings are crucial for software companies targeting developers. Frequent API hackathons are particularly valuable because they quickly reveal and address fundamental platform issues. Getting the basics right is essential—a trait that distinguishes the world's fastest-growing tech companies. And with the next hackathon fast approaching, there's a renewed urgency within the CTO and product teams to address these persistent issues. This ensures that developers won't encounter the same problems at successive events. Additionally, API hackathons enhance product awareness and familiarity. When developers become acquainted with your technology and realize that your software significantly improves upon critical business use cases, many will switch to your solution.
In this speech, Per Lange will detail how to run world-class API hackathons effectively and frequently.
Maximizing API Management Efficiency: The Power of Shifting Down with APIOps ...Nordic APIs
A presentation given by Dominic Lüchinger, Senior Platform Engineer at SIX Group, at our 2024 Platform Summit, October 8-9.
APIOps is a methodology that combines GitOps and DevOps to streamline API management. Learn how it empowers product teams, ensuring regulatory compliance, reducing cognitive load, and accelerating time to market. Discover the power of shifting down with a self-service platform approach. Does your organization need a platform engineering team for this? With real-world examples and actionable insights, this session will enable you to bootstrap APIOps effectively in your organization to continuously improve your API offerings.
APIs Vs Events - Bala Bairapaka, Sandvik ABNordic APIs
A presentation given by Bala Bairapaka, Solution Architect Sandvik AB, at our 2024 Platform Summit, October 8-9.
Event-Driven Architecture (EDA) and APIs (Application Programming Interfaces) offer distinct approaches to system design. EDA uses asynchronous communication where components emit and react to events, making it highly scalable and suitable for real-time applications like IoT and financial transactions, though it can be complex to manage. In contrast, APIs typically use synchronous communication with a request-response model, resulting in tighter coupling but easier implementation, ideal for CRUD operations and microservices. While EDA excels in scenarios requiring real-time processing and scalability, APIs are better suited for web services and applications needing straightforward, synchronous interactions. Understanding these differences can help you choose the right architecture for your project’s specific needs. In this talk I will highlight how EDA’s real-time processing can revolutionize industries by enabling instant data analysis and decision-making. Imagine the power of a system that can react to events as they happen, driving innovations in fields like IoT and financial services. You will learn the simplicity and ease of use of APIs, which can significantly speed up development and integration processes, allowing businesses to bring new features to market faster than ever before. I will share real-world examples to make these concepts tangible: how EDA powers high frequency trading platforms, ensuring transactions are executed in milliseconds, or how APIs streamline interactions in popular web services, making our daily digital experiences seamless. When I illustrate these practical applications, you’ll not only informed but also take inspired actions and learn transformative potential of choosing the right architecture for your projects.”
GraphQL in the Post-Hype Era - Daniel Hervas, Reckon DigitalNordic APIs
A presentation given by Daniel Hervás, Lead Engineer / Technical Coordinator at Reckon Digital, at our 2024 Platform Summit, October 8-9.
Around 2019, the year of the creation of the GraphQL Foundation, GraphQL saw a huge boom in popularity and started getting mass adoption from API devs worldwide. Now, in 2024, other technologies and trends have taken the spotlight (crypto, LLMs, AI...), and the buzz around GraphQL APIs seems to have died down somewhat... so what happened to it? Is it still relevant? Should you be building a GraphQL API in 2024 if you want to be one of the cool kids? Mature, stale, boring, or still trendy and useful? In this talk, we'll go over the current state of the GraphQL ecosystem, what the community, through extended usage throughout these years, has found to be good and bad use cases for GraphQL, and in which situations it makes sense to expose a GraphQL API layer. This talk will be of interest to both technical and non-technical audiences.
From Good API Design to Secure Design - Axel Grosse, 42CrunchNordic APIs
A presentation given by Axel Grosse, Global Head of Presales at 42Crunch, at our 2024 Platform Summit, October 8-9.
- How to fortify your APIs leveraging AI assistants and static and dynamic testing -
85% of enterprises acknowledge suffering an API attack in 2023. This practical session demonstrates how security and development teams can collaborate to improve the overall security posture of an API implementation. Attendees will learn how to test and harden their OpenAPI Description to support a rock solid runtime protection and in parallel how to find and fix vulnerabilities in code for secure end-to-end API delivery. During the session you’ll see how Static and Dynamic API test and assessments are run and learn how to utilize the Copilot API assistant to lend a helping hand with code remediation.
How to fortify your APIs leveraging AI assistants and static and dynamic testing 85% of enterprises acknowledge suffering an API attack in 2023. This practical session demonstrates how security and development teams can collaborate to improve the overall security posture of an API implementation. Attendees will learn how to test and harden their OpenAPI Description to support a rock solid runtime protection and in parallel how to find and fix vulnerabilities in code for secure end-to-end API delivery. During the session you’ll see how Static and Dynamic API test and assessments are run and learn how to utilize the Copilot API assistant to lend a helping hand with code remediation.
API Revolution in IoT: How Platform Engineering Streamlines API Development -...Nordic APIs
A presentation given by Alina Astapovich & Gang Luo, Site Reliability Engineer & SRE Manager at Electrolux, at our 2024 Platform Summit, October 8-9.
As the IoT landscape continues to expand rapidly, the role of APIs in managing and controlling connected devices becomes increasingly critical. At Electrolux, where we support over 10 million appliances globally, API development is essential for delivering meaningful digital experience to our consumers.
In this talk, we dive into our journey of transforming API development through Platform Engineering at Electrolux Digital Experience Organization. We will look at the challenges we overcame, addressing critical aspects such as managing public and private APIs, implementing diverse security mechanisms, and enforcing API governance. Furthermore, we will explore strategies for enhancing developer experience through self-service API provisioning, empowering developers to innovate more efficiently.
Join us to gain insights into how Platform Engineering has streamlined API development at Electrolux.
Unlocking the ROI of API Platforms: What Success Actually Looks Like - Budhad...Nordic APIs
A presentation given by Budhaditya Bhattacharya, Developer Advocate at Tyk, at our 2024 Platform Summit, October 8-9.
By 2026, 80% of software engineering organizations are expected to have a platform engineering initiative, with APIs and API management platforms playing a key role in driving the platform engineering success. While this journey has already begun in several organisations, there are several questions that are being asked over and over again:
What does a good API platform actually look like?
Which KPIs should we pursue, and how would they translate into ROI?
How are more mature API platform teams achieving their objectives?
In this presentation, we will explore the answers to these questions through real-world case studies across industries. We will take a closer look at:
The key metrics and KPIs they set out to achieve
Challenges they faced
Strategies they implemented to overcome them
How you can apply these strategies to evolve your platform maturity
Increase Your Productivity with No-Code GraphQL Mocking - Hugo Guerrero, Red HatNordic APIs
A presentation given by Hugo Guerrero, Sr. Principal Developer Advocate at Red Hat, at our 2024 Platform Summit, October 8-9.
You're about to embark on a new adventure that incorporates GraphQL! Here's a filthy method for becoming a ten-time engineer: fake it until you make it! Mocking GraphQL allows you to better serve the business by providing clear descriptions of schemas, types, and examples. This also aids in the separation of front-end and back-end activities. Join this session to learn more about getting started with GraphQL mocking without having to worry about coding or constructing your own fake server.
Securely Boosting Any Product with Generative AI APIs - Ruben Sitbon, Theodo ...Nordic APIs
A presentation given by Ruben Sitbon, Lead Solution Architect at Theodo Fintech, at our 2024 Platform Summit, October 8-9.
ChatGPT has changed the way people and companies perceive the value of artificial intelligence. Many startups have launched products with generative AI at their core, and innovative SaaS players have all integrated GenAI extensions or plugins, but it’s now clear that users will continue to expect bigger and better GenAI upgrades to the features of products they use on a daily basis. Ruben Sitbon describes how a framework relying on generative AI in-house APIs can be used to easily boost product features, and bundle security and continuous compliance.
Integrating FME with Python: Tips, Demos, and Best Practices for Powerful Aut...Safe Software
FME is renowned for its no-code data integration capabilities, but that doesn’t mean you have to abandon coding entirely. In fact, Python’s versatility can enhance FME workflows, enabling users to migrate data, automate tasks, and build custom solutions. Whether you’re looking to incorporate Python scripts or use ArcPy within FME, this webinar is for you!
Join us as we dive into the integration of Python with FME, exploring practical tips, demos, and the flexibility of Python across different FME versions. You’ll also learn how to manage SSL integration and tackle Python package installations using the command line.
During the hour, we’ll discuss:
-Top reasons for using Python within FME workflows
-Demos on integrating Python scripts and handling attributes
-Best practices for startup and shutdown scripts
-Using FME’s AI Assist to optimize your workflows
-Setting up FME Objects for external IDEs
Because when you need to code, the focus should be on results—not compatibility issues. Join us to master the art of combining Python and FME for powerful automation and data migration.
This guide highlights the best 10 free AI character chat platforms available today, covering a range of options from emotionally intelligent companions to adult-focused AI chats. Each platform brings something unique—whether it's romantic interactions, fantasy roleplay, or explicit content—tailored to different user preferences. From Soulmaite’s personalized 18+ characters and Sugarlab AI’s NSFW tools, to creative storytelling in AI Dungeon and visual chats in Dreamily, this list offers a diverse mix of experiences. Whether you're seeking connection, entertainment, or adult fantasy, these AI platforms provide a private and customizable way to engage with virtual characters for free.
Ivanti’s Patch Tuesday breakdown goes beyond patching your applications and brings you the intelligence and guidance needed to prioritize where to focus your attention first. Catch early analysis on our Ivanti blog, then join industry expert Chris Goettl for the Patch Tuesday Webinar Event. There we’ll do a deep dive into each of the bulletins and give guidance on the risks associated with the newly-identified vulnerabilities.
UiPath AgentHack - Build the AI agents of tomorrow_Enablement 1.pptxanabulhac
Join our first UiPath AgentHack enablement session with the UiPath team to learn more about the upcoming AgentHack! Explore some of the things you'll want to think about as you prepare your entry. Ask your questions.
Digital Technologies for Culture, Arts and Heritage: Insights from Interdisci...Vasileios Komianos
Keynote speech at 3rd Asia-Europe Conference on Applied Information Technology 2025 (AETECH), titled “Digital Technologies for Culture, Arts and Heritage: Insights from Interdisciplinary Research and Practice". The presentation draws on a series of projects, exploring how technologies such as XR, 3D reconstruction, and large language models can shape the future of heritage interpretation, exhibition design, and audience participation — from virtual restorations to inclusive digital storytelling.
Google DeepMind’s New AI Coding Agent AlphaEvolve.pdfderrickjswork
In a landmark announcement, Google DeepMind has launched AlphaEvolve, a next-generation autonomous AI coding agent that pushes the boundaries of what artificial intelligence can achieve in software development. Drawing upon its legacy of AI breakthroughs like AlphaGo, AlphaFold and AlphaZero, DeepMind has introduced a system designed to revolutionize the entire programming lifecycle from code creation and debugging to performance optimization and deployment.
In-App Guidance_ Save Enterprises Millions in Training & IT Costs.pptxaptyai
Discover how in-app guidance empowers employees, streamlines onboarding, and reduces IT support needs-helping enterprises save millions on training and support costs while boosting productivity.
React Native for Business Solutions: Building Scalable Apps for SuccessAmelia Swank
See how we used React Native to build a scalable mobile app from concept to production. Learn about the benefits of React Native development.
for more info : https://www.atoallinks.com/2025/react-native-developers-turned-concept-into-scalable-solution/
accessibility Considerations during Design by Rick Blair, Schneider ElectricUXPA Boston
as UX and UI designers, we are responsible for creating designs that result in products, services, and websites that are easy to use, intuitive, and can be used by as many people as possible. accessibility, which is often overlooked, plays a major role in the creation of inclusive designs. In this presentation, you will learn how you, as a designer, play a major role in the creation of accessible artifacts.
Join us for the Multi-Stakeholder Consultation Program on the Implementation of Digital Nepal Framework (DNF) 2.0 and the Way Forward, a high-level workshop designed to foster inclusive dialogue, strategic collaboration, and actionable insights among key ICT stakeholders in Nepal. This national-level program brings together representatives from government bodies, private sector organizations, academia, civil society, and international development partners to discuss the roadmap, challenges, and opportunities in implementing DNF 2.0. With a focus on digital governance, data sovereignty, public-private partnerships, startup ecosystem development, and inclusive digital transformation, the workshop aims to build a shared vision for Nepal’s digital future. The event will feature expert presentations, panel discussions, and policy recommendations, setting the stage for unified action and sustained momentum in Nepal’s digital journey.
BR Softech is a leading hyper-casual game development company offering lightweight, addictive games with quick gameplay loops. Our expert developers create engaging titles for iOS, Android, and cross-platform markets using Unity and other top engines.
A national workshop bringing together government, private sector, academia, and civil society to discuss the implementation of Digital Nepal Framework 2.0 and shape the future of Nepal’s digital transformation.
OpenAI Just Announced Codex: A cloud engineering agent that excels in handlin...SOFTTECHHUB
The world of software development is constantly evolving. New languages, frameworks, and tools appear at a rapid pace, all aiming to help engineers build better software, faster. But what if there was a tool that could act as a true partner in the coding process, understanding your goals and helping you achieve them more efficiently? OpenAI has introduced something that aims to do just that.
Refactoring meta-rauc-community: Cleaner Code, Better Maintenance, More MachinesLeon Anavi
RAUC is a widely used open-source solution for robust and secure software updates on embedded Linux devices. In 2020, the Yocto/OpenEmbedded layer meta-rauc-community was created to provide demo RAUC integrations for a variety of popular development boards. The goal was to support the embedded Linux community by offering practical, working examples of RAUC in action - helping developers get started quickly.
Since its inception, the layer has tracked and supported the Long Term Support (LTS) releases of the Yocto Project, including Dunfell (April 2020), Kirkstone (April 2022), and Scarthgap (April 2024), alongside active development in the main branch. Structured as a collection of layers tailored to different machine configurations, meta-rauc-community has delivered demo integrations for a wide variety of boards, utilizing their respective BSP layers. These include widely used platforms such as the Raspberry Pi, NXP i.MX6 and i.MX8, Rockchip, Allwinner, STM32MP, and NVIDIA Tegra.
Five years into the project, a significant refactoring effort was launched to address increasing duplication and divergence in the layer’s codebase. The new direction involves consolidating shared logic into a dedicated meta-rauc-community base layer, which will serve as the foundation for all supported machines. This centralization reduces redundancy, simplifies maintenance, and ensures a more sustainable development process.
The ongoing work, currently taking place in the main branch, targets readiness for the upcoming Yocto Project release codenamed Wrynose (expected in 2026). Beyond reducing technical debt, the refactoring will introduce unified testing procedures and streamlined porting guidelines. These enhancements are designed to improve overall consistency across supported hardware platforms and make it easier for contributors and users to extend RAUC support to new machines.
The community's input is highly valued: What best practices should be promoted? What features or improvements would you like to see in meta-rauc-community in the long term? Let’s start a discussion on how this layer can become even more helpful, maintainable, and future-ready - together.
How Top Companies Benefit from OutsourcingNascenture
Explore how leading companies leverage outsourcing to streamline operations, cut costs, and stay ahead in innovation. By tapping into specialized talent and focusing on core strengths, top brands achieve scalability, efficiency, and faster product delivery through strategic outsourcing partnerships.