cloudonaut

Transcript

Back to episode

00:00:21: Welcome to the Cloud or not podcast.

00:00:23: It's been a while since we dropped our last episode, and I'm glad you're still around.

00:00:30: Episode number ninety eight is a first.

00:00:33: This is the first time i am recording without Michael And without any guests and also i'm trying a new format for the first.

00:00:41: So I'm going to share insights into our day-to-day work at Vidix, the software company.

00:00:48: And running together with my brother Michael where we built Bucket AV, our virus scanner for Amazon S three and Cloudflare R two as well as attachment A V our malware protection solution for Atlassian Salesforce another cloud platforms.

00:01:08: So it's still about all things AWS, because we are building on AWS.

00:01:14: But its also how to build our business.

00:01:20: Okay and one thing that is really hard when creating new services or selling products Is getting the pricing right And I want you share a story with that.

00:01:33: With Attachment AV We provide a virus and malware scan API for developers as a SAS offering.

00:01:42: So it's pretty simple, developers sign up they choose the plan They get an API key And then they send their files to our API.

00:01:53: in our backend We are running a fleet of easy-to instances with the Sophos engine And so when we started this as software-as-a-service offering, We needed to come up with a pricing plan.

00:02:15: So our idea was of course... ...we looked into the market there are few competitors that are providing similar solutions and we calculated our costs for the ECU fleet & AWS infrastructure.. ..and came out with a Pricing Model!

00:02:33: that we started with is pretty simple.

00:02:35: So, we had three different plans.

00:02:38: the smallest plan starts at nine euro and what you get?

00:02:43: You get ten thousand API requests per month And then we have larger plants medium-large up to ninety nine Euro and up to one hundred thousand request per month.

00:02:58: So this seemed to be fine.

00:03:00: It was similar, too what our competitors were offering and the numbers worked for us And everything seem to be good.

00:03:08: However over-the-month that we have been running with this plan We realized we are growing really slowly.

00:03:19: Most customers that sign up where?

00:03:22: What you would call kind of prosumers so often developers building a small project, maybe on the asset side project and they were adding virus scanning.

00:03:37: So basically ninety percent of our customers.

00:03:40: we're choosing to small plan for only nine euros per month And you can imagine how many customers do need?

00:03:47: To build a sustainable business with nine euro per subscription.

00:03:52: so quite a lot!

00:03:55: This is what I noticed.

00:03:57: Also, the number of support requests were really high.

00:04:01: So many developers had troubles with using our API and so yeah this wasn't really cool not turning out to be a good business.

00:04:13: in August we decided let's start an experiment.

00:04:17: it was very simple.

00:04:19: We just removed small plan from our website.

00:04:23: So the new entry point was the medium plan for a forty-nine euro and granting fifty thousand API requests per month.

00:04:34: And we added two additional larger plans as well, mostly to signal that we can handle much larger workloads than the Medium and Large Plan that we had previously.

00:04:48: so yeah nothing changed for our existing customers.

00:04:52: We didn't need to raise any prices or something, we just removed the small plan from our offering.

00:04:59: And this was really a success!

00:05:02: So the revenue in August grew by forty two percent compared to July and even more important maybe the churn rate.

00:05:18: so number of customers that are canceling within a few weeks is down to less than five percent and still falling.

00:05:28: The number of support increase has decreased dramatically, we see that new signups are no longer prosumers but our BtoB clients signing up really integrate the API into their production applications.

00:05:52: an important step for us.

00:05:54: So the funny thing or embarrassing I would say about all this is, we heard from other bootstrapers that it's important to have a entry price which isn't too low.

00:06:08: To be honest, € forty-nine is still not very high on our BtoB plan but compared with our nine euro plan per month and this was huge.

00:06:21: So yeah, actually this turned all the numbers and whole business.

00:06:26: And it seems now to be on a much better track than we are really happy with those results.

00:06:34: so pricing getting pricing right is always difficult.

00:06:41: This was lesson that will learn here again.

00:06:44: I hope you don't make mistake next time we start new project.

00:06:50: Okay, so next I want to give some insights in what we built.

00:07:00: We are using a newsletter tool called KIT formerly known as ConvertKIT and have been using that for years to send newsletters to our customers of Bucket Davy, Attachment Davy.

00:07:21: To make sure we are keeping in touch and this is an important communication channel for us.

00:07:30: We also use automated emails.

00:07:34: For example classical examples for new subscribers to the virus and malware scan API be sent them an email sequence every day helping them to get started with the API, to explain it step by step.

00:07:52: And ConvertKit is overall a great service.

00:07:59: so they focus on building your email lists and newsletter lists allowing you to send newsletter emails to those who build automations or to sent automated e-mails like sequences and similar things.

00:08:14: however Over the years, we noticed that KIT is not really the best fit for our use case.

00:08:22: One problem that we had was a lot of fake sign-ups to our newsletters and this is technical problems.

00:08:32: so We need to do double opt in which means you enter your email on our website And then get an e-mail a link to say, I really want you subscribe to the newsletter.

00:08:47: The problem with that is many big enterprises use email security systems that automatically check links in emails and when they do so They automatically Subscribe the user to your newsletter.

00:09:07: And now there are spam bots that basically enter real email addresses from real people to random newsletters and they just auto accept those double-opt in mails.

00:09:18: So this was a huge issue for us, we had many, many subscribers on our newsletter lists that were just fake and from spam bots And KIT doesn't really have a solution for it.

00:09:33: so... This is one reason why we're looking for an alternative.

00:09:38: The other is that it was not really that flexible and easy to integrate into our processes.

00:09:48: So for many, many months we have something in our backlog that says maybe we should find an alternative to KIT And of course you can build on your own or natively.

00:10:03: yes We always knew that but we shied away from the effort.

00:10:10: But now this seemed to be a cool project, too.

00:10:16: Try some new things and build a greenfield project from scratch basically with Claude code And so that was what motivated us To go for it and finally build our own solution.

00:10:32: I want you share Some insights into how this turned out a full blog post going into every little detail of what we built, the newsletter and it's also kind of small CRM system for us.

00:10:51: And you will find link in show notes that can open AWS architecture diagram for example.

00:11:00: So... What did we build?

00:11:03: We built solution to send newsletters to collect email addresses on our websites, and also send automated e-mail sequences for on and off boarding.

00:11:17: For example new customers... To build that we basically stitched together AWS building blocks And the first learning was by telling Cloud Code exactly which AWS Building Blocks We want to combine and how to combine them.

00:11:37: The outcome was really astonishing because the whole system is exactly designed in a way that we would have been doing it by giving this input, so what do you think?

00:11:52: We learned if you know basically using AWS building blocks or pitfalls.

00:12:02: give that context to Cloud Code, it can really build little tools fast.

00:12:09: So what are we using?

00:12:10: Obviously you use SES to send emails and also important is to handle bounces and complaints.

00:12:24: then we decided as our database system to store the newsletter lists and contacts.

00:12:34: We have an API gateway in Lambda, to serve design up confirmation and unsubscribe endpoints.

00:12:42: Then we use step functions for automated email sequences For example on onboarding of a new customer.

00:12:51: Basically this step function is quite simple.

00:12:54: it's just calling a Lambda function which sends an email over SES.

00:12:59: Then it sleeps, waits and then continues with the next e-mail.

00:13:05: So that's basically it.

00:13:06: And we use CloudFront and F-III to distribute images.

00:13:13: I thought do need web interface where can manage our subscribers but i decided against because only Michael and me are using this tool And that's why I decided let's build just the CLI.

00:13:30: So basically sending emails, adding new subscribers manually all of this stuff is possible with a small CLI built and authentication is just authenticating against AWS API via IAM.

00:13:48: so it was pretty neat to use.

00:13:52: All configuration like email templates are in a Git repository, so yeah it's very simple to use and doesn't require to build the fancy interface.

00:14:07: So what are the outcomes of that project?

00:14:10: As I said i was really impressed about the quality.

00:14:17: When reviewing the code, I stumbled above a few little things like iron policies and stuff.

00:14:31: But overall i was very happy with that result.

00:14:36: Kit charged us around six hundred dollars per year And The solution now costs less than a few dollars per month Because all of our services we use are pay-per-use so serverless services.

00:14:51: They have no baseline cost.

00:14:53: they often have free tiers that we can use.

00:14:58: So, that's great!

00:14:59: It took me around forty hours in total to migrate the templates... ...the users build a solution deploy it CICD pipeline and so on And I've been using my cloud subscription for that.

00:15:15: overall i think this is really cool project and learned about building something from scratch with Cloud Code And also I learned about DSQL, your database system.

00:15:30: I'll talk about that later in more detail.

00:15:34: Okay so again if you're interested in more details check out the blog post and can really encourage to build little tools that are customized for requirements by sticking together as serverless AWS services with the help of cloud code.

00:15:58: So that's really, I think something.

00:16:00: um...that hasn't been possible before.

00:16:05: Okay!

00:16:05: The next topic might be boring but it is important to us and i want you share a little insights into it.

00:16:16: so its about tax compliance or In more detail, it's tax compliance for AWS market sellers from the EU.

00:16:28: So this is a very specific topic but something that caused us many headaches in past month and I want to share what we learned there and what sellers need to know.

00:16:49: Maybe it can help to spread the knowledge here.

00:16:53: Okay, so first of all what's the big deal?

00:16:56: So the AWS Marketplace is great.

00:17:00: we sell bucket AV and parts of attachment AV through the AWS marketplace And as you probably know It's a very simple experience for the buyer.

00:17:10: You go there You choose your solution Subscribe To The Solution.

00:17:20: It shows up on your monthly AWS bill.

00:17:22: it's simple to use.

00:17:23: in our case you just deploy the solution to your AWS account.

00:17:29: So, its a really great way.

00:17:30: we reach over thousand customers Over the AWS marketplace all over the world.

00:17:36: nothing that would be possible without such a Marketplace for two person company obviously Okay.

00:17:43: But here is the challenge.

00:17:47: When you are a European customer and your selling in the AWS Marketplace, one thing that you have to know is that AWS charges value added tax on the listing fees for the European marketplace.

00:18:08: So basically you're paying value-added tax.

00:18:16: get back those fees if you return value at a tax sheet.

00:18:25: So that's important, the problem here for us is we got so-called listing fee invoice from AWS for every transaction through the AWS marketplace and this has hundreds of PDF files.

00:18:46: We need to process them somehow, so it's not possible to do it manually.

00:18:51: So we needed to automate that system.

00:18:55: Also the handover of PDFs through the now web interface The partner portal or marketplace portal is cumbersome.

00:19:04: Often pdfs are missing and we need to reconcile basically the pdf files with the billing event data feed, so that is how we can ensure we are not missing any PDFs.

00:19:22: So this is a great challenge!

00:19:24: We have automated that process now and so we can parse all those PDFs, get reports about missing ones, request them from AWS Marketplace Support... ...and then hand over CSV to accounting to hand in the tax sheet.

00:19:44: Okay, so listing fees for sellers in the EU is important that you make sure to process those value-added taxes.

00:19:56: The second thing again it's about value added tax and this is crazy complicated in Europe AWS Marketplace team that we discussed with.

00:20:06: they tell us It's that simple in the US and everywhere else in the world but its complicated in the U. Okay, so there it is.

00:20:15: But if you SVR a German company based in Germany... If we sell to German customers then the AWS marketplace does charge customer the value at a tax but V as a company We need to pay those taxes To the tax authorities.

00:20:35: So basically what we must do?

00:20:37: Is we need to issue an invoice to AWS Then we get the value added tax from them, and then we need to pay those taxes to the tax authorities.

00:20:50: And so what happened here is that AWS helped to automate this process.

00:20:56: So they're called on.

00:20:58: deemed supply.

00:21:00: Invoices are now showing up in the marketplace portal and you can submit your invoices together where you add a tax from AWS so that you can pay it to your tax authorities through a form in the marketplace portal nowadays.

00:21:19: So again, um... You need to automate this!

00:21:23: It's hundreds of transactions that you need to sum up and generate invoices out of it.

00:21:30: And we are using basically a mixture of the billing event data feed and the tax item data feed.

00:21:39: And now the third thing is, so this is something that there's no automated way to do it from AWS.

00:21:47: So you need to build on your own.

00:21:49: is if we as a German company sell two customers in the EU but outside of Germany.

00:21:58: then the reverse charge mechanism applies for the value added tax.

00:22:03: So AWS shows the value at attacks on the invoice.

00:22:09: We in that case do not have to pay the value at a tax to the fax authorities, but we have to submit a monthly return for each country in the EU.

00:22:21: That we are selling too so I don't know how many.

00:22:25: it's about fifteen countries that we sell two and we need to file a tax report for those countries.

00:22:37: So again, we needed an automation to fetch those numbers and hand them over to accounting and our tax consultant.

00:22:47: Yeah so those three things is what you need to keep in mind if you are a marketplace seller from the EU.

00:22:53: it's the listing fee invoices It's the what called on deemed supply VAT invoicers And its the reverse charge for value added tax reports.

00:23:07: So this is kind of complicated if you are a seller in the AWS marketplace from the EU and You're interested in more details.

00:23:18: Please let me know.

00:23:19: If ten people express interest I'm promised to putting all that into a blog post.

00:23:27: Okay, enough taxes.

00:23:29: Let's jump to AWS technology again.

00:23:34: And What I learned and what i found interesting is learning about Aurora DSQL.

00:23:45: So as mentioned when building the newsletter in CRM tool, I decided to go with DSQL for the first time.

00:23:55: The Aurora DSQL was announced on December twenty-twenty four so it has been around almost two years now And until now, I have never used it in a real world project.

00:24:12: I once thought about using it to replace a Postgres database of web application that we run but decided against because it was missing important features.

00:24:28: But now let's give another try.

00:24:34: I want to summarize what i have learned about dsql when using it in the first project.

00:24:41: So, First of all... ...I'm thinking of ds.

00:24:45: ql is like a mixture of DynamoDB and classic SQL database on RDS so its kind-of.

00:24:56: between those two things DSQL is charged pay-per-use, so it's like a serverless service like DynamoDB or Lambda.

00:25:08: You basically pay for the storage and you pay to compute that used for queries.

00:25:16: Then DSQL Postgres Compatible which really simplifies database access.

00:25:22: So think about tooling querying language migration tools and so on.

00:25:28: So you can just use the tools that probably every developer is familiar with.

00:25:36: DSQL supports either single region or multi-region deployments, which are interesting.

00:25:42: And DSQL is a distributed database – it's not an active standby like classic RDS.

00:25:53: It's really a distributed database similar to DynamoDB.

00:25:57: It is providing ACID guarantees for transactions, but important to know it uses optimistic concurrency control instead of traditional locking.

00:26:11: So what that means?

00:26:13: if you have another transaction running in parallel and they both try to modify the same data one of them wins And the other basically fails and you have to retry the query.

00:26:28: So, basically a client needs to handle those failures when two of them are trying to change the same data in the database.

00:26:41: Overall I think because of their pay-per use pricing model DSQL is good fit for low usage workloads, not only but especially for those because the baseline costs are just a storage cost.

00:26:56: By the way I didn't do full comparison yet from the first calculations that i made DSQL is little more expensive than DynambyDB if you compare storage costs and also querying costs.

00:27:16: Also interesting, so the first time when I thought about using DSQL in a project.

00:27:22: The reason that decided against it was missing sequences and identity columns as well as foreign key constraints.

00:27:33: So this basically hindering me to migrate the database of a legacy web application because needed those features.

00:27:43: but now Over the course of a twenty-twenty six and eight hours shipped exactly those two things.

00:27:50: So now you have foreign key constraints as well as Sequences and identity columns, so I think that makes it an option for Yeah lack or applications built for classic Postgres And to be able to be migrated?

00:28:08: So I will try retry basically to migrate my workload because it would be a perfect fit from a cost perspective.

00:28:18: Okay, and even I'm not yet decided on this but really i enjoyed working with Aurora DSQL And It might even replace DynamoDB as our go-to database option for new projects on AWS.

00:28:36: Not hundred percent um decided on that yet.

00:28:38: so uh...I'll keep you posted.

00:28:43: Okay, so next topic.

00:28:47: So this is something that we observed in our AttachmentAV inbox.

00:28:54: So Attachment AV is a set of software as-a-service offerings for scanning malware and Atlassian Salesforce WordPress make an eight N and many more.

00:29:09: It's classical SaaS business which means process data for scanning it for viruses and malware.

00:29:18: So what we observe, especially in the past months we observed quite a lot is that many new prospects interested in our solution.

00:29:29: they are asking the following questions.

00:29:32: first question this top number one question Is the data processed within the EU?

00:29:38: And never transferred to the US?

00:29:40: so even if On our website, people are asking this over and over again.

00:29:46: The next question is your company based in the EU?

00:29:51: And sometimes even there's personal outside you have access to your systems?

00:29:57: another question that came up quite a lot!

00:30:01: And then classic questions as all are also how do you ensure GDPR compliance and Do You Offer Data Processing Agreement?

00:30:11: And so all those questions.

00:30:13: they made us wonder, is this really a shift in the SaaS market?

00:30:18: So are European buyers increasingly looking for suppliers from Europe.

00:30:24: In our observation... This was not a big deal of few years ago but it seems like new buying decisions have been made.

00:30:33: European buyers look for suppliers and providers from Europe.

00:30:38: We did little research did some, found somethings on Reddit from our competitors and it really seems like US softwares service offerings are observing that trend as well so your customers no longer signing up in the same way they did a few years ago.

00:30:59: And this is for one perspective interesting because of course its kind of business opportunity or important messaging so that you ensure people understand there.

00:31:13: We are processing the data in the EU, we're a company based Germany and on... On other side it might be around as well.

00:31:20: So US companies may not be willing to buy from European companies anymore.

00:31:26: And even harder question came for us is As we build everything on AWS The question was will customers demand that we host our services on European cloud providers as well.

00:31:46: So far, we have never had a complaint about using AWS and of course the region in Europe at AWS In general.

00:31:54: but We are thinking about this might become an issue for business And maybe we need to Yeah half that in mind and plan.

00:32:03: four there That we were able to basically move out workload to a European cloud provider.

00:32:10: Of course, the AWS European Servering Cloud comes to mind and we have been migrating our product bucket AV for that.

00:32:21: but question is really helping us here or do you need real European cloud providers?

00:32:29: So this definitely an interesting need to think about moving forward and plan for the future.

00:32:41: Okay, so... To end this episode I want share a little what is next in October.

00:32:52: So three things.

00:32:53: number one we are working together with a lawyer to improve our contractual documents like the terms of services privacy policy and data processing agreement for attachment AV.

00:33:08: So this is an interesting learning for us, so to discuss things like liability risks speed in the sales process together with a lawyer.

00:33:20: we have never been doing that until now.

00:33:22: We just used standard contracts And now it's interesting about all the challenges there.

00:33:32: We're looking really forward to that and hope we can also speed up our sales process a lot.

00:33:41: Number two is from technical perspective, we are working on replacing the Amazon API gateway for our virus and malware scan API.

00:33:54: We are running into the limits of sixty second request timeout, as well as to ten megabyte requests size.

00:34:01: So those are really not fitting our use case.

00:34:06: so they're restricting us from providing better service for customers and we need to replace Amazon API gateway And have started working on that.

00:34:18: The challenge here is find another way quotas and throttling.

00:34:24: So that's the main challenge here, probably a solution will include elastic cash in red is but yeah we're still working on it.

00:34:33: then can hopefully share our learnings there next month at number three.

00:34:41: so um We are going to reactivate the cloud one out blog The newsletter and podcast.

00:34:47: sort of first step has been taken with this episode.

00:34:53: Please, please send us your feedback.

00:34:56: It will help to improve and also stay motivated for the upcoming month!

00:35:03: Yeah so thank you very much for listening.

00:35:07: that's it subscribe to The Cloud or Not Newsletter, the podcast or YouTube channels?

00:35:13: do not miss our upcoming episodes.

00:35:18: Also again we're looking forward.

00:35:21: either hello at claudonaut.io or find us on LinkedIn and also please help spread the word about our podcast.

00:35:31: so please recommend it to a friend, leave a review in your favorite podcast.

00:35:38: Okay see you next month!

00:35:40: Bye.

cloudonaut podcast

We are two brothers focusing 100% on Amazon Web Services (AWS). Every other week, one of us prepares the topic of the podcast. The topic is not known to the other one, which results in surprising conversations about all things AWS.

Typically, we are covering the following topics: DevOps, Serverless, Container, Security, Infrastructure as Code, Container, Continuous Deployment, S3, EC2, RDS, VPC, IAM, VPC, and many more.

by Andreas Wittig and Michael Wittig focusing on AWS Cloud

Subscribe

Follow us

Imprint - Privacy Policy