AntiMalwareAugust 5, 2026🇷🇺Translated from Russian

Yandex Go Develops Custom DSL to Handle Complex Dynamic Ride Pricing Logic

Yandex Go has introduced a custom domain-specific language to manage the intricate logic behind calculating ride costs, replacing what would otherwise become an unmaintainable collection of conditional statements in the core service code.

Trip pricing at Yandex Go is far more complex than simple multiplication of distance and time. It incorporates geozones, real-time demand, discounts, toll roads, additional stops, and special requirements such as transporting a cat, bicycle, or skis. The same pricing engine is invoked not only when a ride is ordered but also when the route or payment method changes, when a trip ends, when support staff intervene, and when analysts verify data.

Pricing can be fixed, interval-based, or calculated by taximeter. To support this flexibility without constant redeployments, developers first gather parameters from multiple sources in parallel: tariff category, geozones, discounts, surge multipliers, and additional services. These dependencies form a graph executed asynchronously on userver, ensuring that failure of a non-critical source does not halt the entire calculation.

Previously the algorithm resided in C++, but because pricing rules change on average twice a week, frequent service updates became impractical. Redeploying the service across 50 pods takes approximately 40 minutes, and the growing set of dynamic configuration files would have turned the codebase into a museum of conditional statements.

Instead, Yandex created its own DSL featuring conditions, functions, immutable values, and fold operations in place of traditional loops. Rules are organized into sequential chains where each transformation receives the current price and parameters and returns a new result together with metadata. The language grammar is defined with ANTLR 4, and the Z3 theorem prover verifies that no program can generate an incorrect price.

As a result, changes to pricing logic no longer require service recompilation, erroneous versions can be rolled back instantly, and every calculation can be reproduced from input data and intermediate results. The pricing platform is already shared with Yandex Taxi, Delivery, and the electric-vehicle charging service.

Related articles

HabrOther

Simple Bridge Panel Offers Self-Hosted Management for Xray and AmneziaWG Connections

A developer frustrated with shared-IP VPN services and growing configuration management overhead has released Simple Bridge Panel (SBP), a lightweight self-hosted interface for administering Xray and AmneziaWG on personal VPS instances. The panel installs on fresh Ubuntu 24.04 servers via a single command and provides one-click deployment of Xray TCP with REALITY, Xray XHTTP, and AmneziaWG, along with group-based access expiration and traffic accounting. It separates the web UI from a privileged local agent that communicates over a Unix socket, allowing controlled management of Docker containers, systemd services, and network routes without granting the interface full root access. Fixed versions of Xray 26.3.27, v2rayN 7.20.4, and v2rayNG 2.2.6 are bundled to avoid compatibility issues encountered with newer releases. Additional features include Whitelist Bypass routes, monthly traffic tracking stored only in SQLite, automatic rollback on failed updates, and QR-code or subscription link generation for clients. The project is published under Apache 2.0 and deliberately targets clean servers to minimize risk of interfering with existing configurations.

HabrOther

Avito Details Security Gates Implementation to Enforce Vulnerability Remediation Without Disrupting Developers

Alexander Trifanov, head of Application Security at Avito, shares a detailed case study on building security gates that block risky deployments while preserving developer experience. The approach relies on asynchronous scanning pipelines using SAST, SCA, secret detection, and YAML Security tools aggregated in ASOC or SOAR systems. Gates are placed at multiple lifecycle points including pre-receive hooks, CI/CD deployment stages, and manual unit-level overrides via a red-button mechanism. Strict false-positive management, deduplication, and emergency bypass controls are highlighted as essential for scalability across thousands of developers. The article covers pre-receive gating limited to ten-second scans, separate library update flows, and Kubernetes integration attempts with Kyverno. Avito reports that even unused red-button capabilities significantly improve SLA compliance without frequent enforcement actions.

AntiMalwareOther

SafeTech Lab Expands SafeTech CA with CDM Module for Automated Certificate Delivery and Renewal

SafeTech Lab has released a new module called CDM (Certificate Delivery Management) for its SafeTech CA platform. The update allows the certificate authority to not only issue digital certificates but also deliver them to endpoints, install them in required stores, and automatically renew them before expiration. Administrators can now manage agents centrally, eliminating the need for custom scripts or separate heavy PKI solutions. The system supports GOST algorithms and operates independently of domain infrastructure, functioning in isolated network segments without LDAP. Additional improvements include root and subordinate CA certificate rotation without breaking trust chains, web-based configuration management, and integration with HashiCorp Vault for centralized credential storage and rotation. Future plans focus on increasing agent autonomy through the web interface.

HabrOther

InfotecsTech Builds Custom Kubernetes-Based Traffic Generator for NGFW RnD and Performance Testing

InfotecsTech developed an in-house traffic generator to support development and testing of its high-performance NGFW cluster in active-active mode. The team rejected commercial solutions from IXIA and Xinertel due to high cost, insufficient flexibility for complex NGFW functions, and geopolitical restrictions. The resulting platform runs on Kubernetes with a master node managing Registry, Discovery, and Crux components while worker nodes host containerized generators. Supported generators include Cisco TRex for throughput and connection testing, SIPp for VoIP scenarios, pyftpdlib-based FTP generator, Yandex Tank with Nginx for live TLS traffic, and Selenium-based legitimate clients against OWASP Juice Shop. Practical scenarios cover VoIP call storms, maximum concurrent connections, 400 Gbit/s UDP throughput, 5 million CPS, and IMIX traffic at 300 Gbit/s with packet loss analysis. The system integrates Camunda for full automation of test scenarios and device configuration.