← कोर्सच्या मुख्य पानाकडे परत

⏮️ आधी काय होते & फायदे-तोटे

प्रत्येक साधनाने काहीतरी वाईट गोष्ट बदलली — आणि तेच साधन कुठेतरी चुकीचे ठरते. प्रत्येक मोठ्या कल्पनेसाठी: आधी जीवन कसे होते, प्रामाणिक फायदे ✅ / तोटे ❌, आणि कुठे वापरावी 👍 विरुद्ध कुठे नाही 👎.

🍪 Server sessions vs JWT access tokens — lessons 03–05

⏮️ दोन्हीपैकी काहीही येण्याआधी

A password sent with every request.

✅ फायदे

  • sessions: revocable at once, small cookie, server holds state
  • JWTs: stateless checks, work across services and APIs

❌ तोटे

  • sessions: shared store needed to scale
  • JWTs: hard to revoke before expiry, easy to misuse (alg none, long lifetimes)

👍 वापरा जेव्हा

  • web apps: an HttpOnly session cookie
  • APIs and service-to-service: short-lived JWTs from an identity provider

👎 दोनदा विचार करा जेव्हा

  • JWTs in localStorage for a web app
  • sessions that never expire

🚪 RBAC vs ABAC — lesson 06

⏮️ Before roles

Permissions per person, copied by hand.

✅ फायदे

  • RBAC: simple, readable, easy to audit
  • ABAC: fine-grained rules from attributes (owner, class, time)

❌ तोटे

  • RBAC: role explosion for fine-grained needs
  • ABAC: harder to reason about and test

👍 वापरा जेव्हा

  • RBAC for coarse actions; ABAC / ownership checks for records
  • always an object-level check on data APIs

👎 दोनदा विचार करा जेव्हा

  • RBAC alone for per-record data (IDOR)
  • ABAC rules nobody tests

🗝️ Environment variables vs a secret manager — lesson 07

⏮️ Before managers

Passwords in the code and in the wiki.

✅ फायदे

  • env vars: simple, universal
  • a manager: rotation, audit, access control, no copies in images

❌ तोटे

  • env vars: leak into logs, crash dumps, child processes; no rotation
  • a manager: one more dependency and an IAM policy to get right

👍 वापरा जेव्हा

  • a manager (Secrets Manager, Vault) with short-lived credentials
  • env vars only for non-secret configuration

👎 दोनदा विचार करा जेव्हा

  • secrets baked into container images
  • one shared secret for every service

📦 Scanning dependencies vs pinning + allow-lists — lesson 13

⏮️ दोन्हीपैकी काहीही येण्याआधी

pip install whatever the tutorial said, never updated.

✅ फायदे

  • scanning: finds known vulnerabilities fast
  • pinning + allow-lists: stop surprise and malicious packages

❌ तोटे

  • scanning: only knows published advisories
  • pinning: you must keep updating or you pin old bugs

👍 वापरा जेव्हा

  • both: lockfiles with hashes, automated update PRs, audit in CI
  • an internal allow-list for new packages

👎 दोनदा विचार करा जेव्हा

  • no lockfile
  • auto-merging every update without tests

🕸️ NetworkPolicy vs a service mesh (mTLS) — lesson 11

⏮️ दोन्हीपैकी काहीही येण्याआधी

Every pod can reach every other pod in plain text.

✅ फायदे

  • NetworkPolicy: built in, simple allow-lists by label
  • mesh: mutual TLS identity, encryption, per-request policy

❌ तोटे

  • NetworkPolicy: L3/L4 only, needs a CNI that enforces it
  • mesh: complex, more resources, more to operate

👍 वापरा जेव्हा

  • default-deny NetworkPolicies everywhere
  • a mesh when you need mTLS identity and L7 rules

👎 दोनदा विचार करा जेव्हा

  • no default-deny
  • a mesh without anyone who can run it

🤖 Prompt filters vs tool permissions — lesson 16

⏮️ Before agents

Chatbots that only produced text.

✅ फायदे

  • filters: catch obvious injected instructions
  • tool permissions + confirmation: the damage is limited even when a filter misses

❌ तोटे

  • filters: easy to bypass
  • permissions: less automation, more prompts to the user

👍 वापरा जेव्हा

  • treat retrieved content as data; least-privilege tools; confirm actions; log calls
  • filters as one layer, never the only one

👎 दोनदा विचार करा जेव्हा

  • an agent with delete and email tools acting on web pages
  • relying on 'the model will ignore bad instructions'