korrents
Kenton Varda

What Kenton Varda thinks about design

@kenton-varda · 26 positions · 0 changes of mind

Engineer at Cloudflare who designed Workers, Durable Objects and Cap’n Proto; earlier the primary author of Protocol Buffers v2 at Google, and co-founder of Sandstorm.io.

Everything they publish, on ppll ↗ Who they are, on wiqqi ↗

Kenton Varda did not write this page.

We collected these quotes from things they published elsewhere, and every quote links to where it was said. They have no account here and have not endorsed this site. Quotes are word for word; the short line under each one is our own restatement, not their wording. Their own site. Is this you? Claim it or ask us to remove it. Or tell us what is wrong here.

10 dated positions, 2020 to 2024, in their own words. Our reading of what Kenton Varda has said — not written or endorsed by them.

  1. RPC is often accused of committing many of the fallacies of distributed computing. But this reputation is outdated. When RPC was first invented some 40 years ago, async programming barely existed. We did not have Promises, much less async and await. Early RPC was synchronous: calls would block the calling thread waiting for a reply. At best, latency made the program slow. At worst, network failures would hang or crash the program. No wonder it was deemed "broken".

    ↗We've added JavaScript-native RPC to Cloudflare Workersblog.cloudflare.com

  2. The fact is, RPC fits the programming model we're used to. Every programmer is trained to think in terms of APIs composed of function calls, not in terms of byte stream protocols nor even REST. Using RPC frees you from the need to constantly translate between mental models, allowing you to move faster.

    ↗We've added JavaScript-native RPC to Cloudflare Workersblog.cloudflare.com

  3. 4 days earlier
  4. Much of this pain comes about because connecting a server to a resource today involves two steps that should really be one step: Configure the server to point at the resource. Configure the resource to accept requests from the server.

    ↗Why Workers environment variables contain live objectsblog.cloudflare.com

  5. Designing code to be DI-friendly sometimes seems tedious, but every time I've done it, I've been incredibly happy that I did.

    ↗Why Workers environment variables contain live objectsblog.cloudflare.com

  6. 8 months earlier
  7. As discussed above, this is opt-in today, but in practice I find it’s almost always desirable, and disallowing it can lead to subtle problems.

    ↗Cap'n Proto 1.0capnproto.org

  8. 10 months earlier
  9. Some in the industry prefer to call nanoservices "functions", implying that each individual function making up an application could be its own service. I feel, however, that this puts too much emphasis on syntax rather than logical functionality.

    ↗Introducing workerd: the Open Source Workers runtimeblog.cloudflare.com

  10. 11 months earlier
  11. JavaScript

    In the old world, if the Node.js maintainers decide to make a breaking change to an obscure API between releases, it's OK. Downstream developers are expected to test their code before upgrading, and address any breakages. But in the serverless world, it's not OK: developers have no control over when upgrades happen, therefore upgrades must never break anything.

    ↗Backwards-compatibility in Cloudflare Workersblog.cloudflare.com

  12. documentation

    Second, part of the promise of serverless is that developers shouldn't have to worry about updating their stack. If we start letting people pin old versions, then we have to start telling people how long they are allowed to do so, alerting people about security updates, giving people documentation that differentiates versions, and so on. We don't want developers to have to think about any of that.

    ↗Backwards-compatibility in Cloudflare Workersblog.cloudflare.com

  13. 3 months earlier
  14. The worst thing an application can do is tell the user that their action was successful when it wasn't. If, for some reason, a write cannot be completed, then it's imperative that the application presents an error to the user, so that the user knows that something is wrong and they'll have to try again or look for a fix.

    ↗Durable Objects: Easy, Fast, Correct — Choose threeblog.cloudflare.com

  15. 12 months earlier
  16. Popular security culture often dwells on clever hacks and clean fixes. But for the difficult real-world problems, often there is no right answer or simple fix, only the hard work of building defenses thicker and thicker.

    ↗Mitigating Spectre and Other Security Threats: The Cloudflare Workers Security Modelblog.cloudflare.com