Speaker
Abstract
WebAssembly represents the future of portable computing, providing an efficient and secure runtime for many languages. In the last year there has been an explosion of growth in Wasm on the backend, from managed platforms, tooling, and further standardization work around WASI. All of this leads us towards the vision of “Write Once, Run Anywhere”, building modular code with little knowledge of the underlying platform.
This necessarily leads to implementation questions. What is this concept of universal compute good for at the enterprise? How would we deliver a system that can decide where code should execute at runtime, not development time? Can we really empower developers to build code with little knowledge of not just the underlying runtime, but the platform and location it is running in? Is there business value in doing this in terms of developer velocity, performance or cloud spend?
In this talk, Sean will describe a framework for building this next phase of universal applications. Hear about how Adobe utilizes browser-based Wasm, server side Wasm, and what is coming next with edge compute, with some product use cases for a better client and developer experience. Learn about how scheduling decisions could be made programmatically using application heuristics and the power of the WebAssembly Component Model for managing dependencies.
Topics
QCon New York 2023 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.
Part of the track
Language Platforms and Software Supply Chain Hosted by Priya Wadhwa Software Engineer @ChainguardFrom the same track
Tuesday 13 June
10:35 Dumbo / Navy Yard Session WebAssembly Wasm: What is Universal Compute Good For? Sean Isom Senior Engineer @Adobe WebAssembly represents the future of portable computing, providing an efficient and secure runtime for many languages. In the last year there has been an explosion of growth in Wasm on the backend, from managed platforms, tooling, and further standardization work around WASI. 11:50 Dumbo / Navy Yard Session Security Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software Billy Lynch, Zack Newman Sigstore is an open-source project that aims to provide a transparent and secure way to sign and verify software artifacts. 13:40 Dumbo / Navy Yard Session WebAssembly Build Features Faster With WebAssembly Components Bailey Hayes Director @Cosmonic Wasm modules revolutionized portable application code. For the first time, they allowed us to write in a high-level language - like Go or Rust - and then target WebAssembly as the platform-agnostic bytecode. 14:55 Dumbo / Navy Yard Session jvm Virtual Threads for Lightweight Concurrency and Other JVM Enhancements Ron Pressler Technical Lead OpenJDK's Project Loom @Oracle Concurrent applications, those serving multiple independent application actions simultaneously, are the bread and butter of server-side programming. The thread has long been software’s primary unit of concurrency, and has also served as a core construct for observability and debugging, but… 16:10 Dumbo / Navy Yard Session Software Supply Chain Security Achieving SLSA Certification with a “Bring-Your-Own-Builder” Framework Asra Ali Software Engineer @Google Supply-chain Levels for Software Artifacts, or SLSA (pronounced “salsa”), is a security framework to reason about and improve the integrity of released artifacts. With the recent release of SLSA version 1.0, SLSA is seeing increased adoption, both from industry and open source projects. 17:25 Dumbo / Navy Yard Session Software Supply Chain Security Securing the Software Supply Chain: How in-toto and TUF Work Together to Combat Supply Chain Attacks Marina Moore PhD Candidate @NYU & Tech Lead for CNCF's TAG Security Software supply chain attacks have seen a 742% increase in the last three years. in-toto is a battle-tested and broadly deployed CNCF incubated project that counters these threats.