Running an ASP.NET Core 2.0 app on Raspbian Stretch Linux on a Raspberry Pi with HTTPS

Today’s challenge: Serve a public API over HTTPS from a Raspberry Pi. I’ll follow up with an article about containerising the app and running it from docker on the Pi.

This article is a fast-paced guide to getting started without stopping to dwell on the details.

Some details will be mopped up in the last section for those wanting to know more.

Prepare the Pi

On your development machine (you won’t need to interact with the Pi directly, so no 2nd keyboard or monitor required):

  • Grab an 8Gb or larger microSD card and use Etcher to flash the Raspbian Lite image to the card.
  • Create an empty file in the root of the microSD card called “ssh”, with no extension, this will enable ssh on Raspbian.
  • Put the microSD card in the Pi, plug in a network cable and then plug in the power
  • After a minute attempt to ping the pi:
ping raspberrypi
  • If you get a response, ssh into the pi from a Bash shell (on Windows, you can use the bash shell that comes with Git):
ssh pi@raspberrypi
  • The “pi@” means you’re logging in as the “pi” user account. The default password is “raspberry”.

Installing the .NET Core prerequisites

This bit looks hard but is quite easy (thanks Dave).

At the ssh prompt, install the .NET dependencies by running each of the following commands (you can copy and paste these commands straight into bash):

sudo apt-get install curl libunwind8 gettext
curl -sSL -o dotnet.tar.gz https://dotnetcli.blob.core.windows.net/dotnet/Runtime/release/2.0.0/dotnet-runtime-latest-linux-arm.tar.gz
sudo mkdir -p /opt/dotnet && sudo tar zxf dotnet.tar.gz -C /opt/dotnet
sudo ln -s /opt/dotnet/dotnet /usr/local/bin

you can check if the .NET Core runtime has been installed by running:

dotnet --help

You should now see some the runtime command line options.

Configuring the App

If you don’t already have an ASP.NET Core app:

  • Download the SDK for your platform (Mac, Linux, Windows) from https://dot.net and install it
  • Make a new directory and navigate to that directory at the command line.
  • Run:
dotnet new react

By default, a new ASP.NET Core application will be set to only listen to requests only from the TCP/IP loopback address (127.0.0.1 or localhost), so:

Open up Program.cs in your ASP.NET Core app and change the BuildWebHost method to add the following:

public static IWebHost BuildWebHost(string[] args) =>
    WebHost.CreateDefaultBuilder(args)
        .UseKestrel(options => {
            options.Listen(System.Net.IPAddress.Any,
                5000,
                listenOptions => {
                    listenOptions.UseHttps("raspberrypi.pfx", "<your-password>");
                }
            );
        })
        .UseStartup<Startup>()
        .Build();

This means that when the app runs on the Pi it will accept requests to port 5000 from external clients.

Please note, Kestrel is not a supported edge server, it is designed to run behind a reverse proxy such as nginx, Apache HTTP Server or Microsoft IIS when exposed to the outside world. Read and understand this before you open up your Pi to the big bad interwebs.

Deploying the App to the Pi

I’m not offering DevOps perfection here, I’m afraid we’re just going to FTP the app across to the pi. But first we need to compile the app so it works with the Raspberry Pi’s low-power ARM processor.

On your development machine, drop to the command line, navigate to your project directory and publish your app so it works on Raspbian by executing the following command:

dotnet publish -r linux-arm

This creates a bin/Debug/netcoreapp2.0/linux-arm/publish directory that contains the binaries for your ASP.NET Core app.

Grab your favourite FTP client. If you don’t have one, FileZilla will do the trick.

Connect your FTP client to your Pi by entering the following details:

Host: raspberrypi
Username: pi
Password: raspberry
Port: 22

The FTP client should show you the directory structure on the Pi. Copy the contents of your linux-arm/publish directory to any path on the pi (I chose /home/pi/piservice/) using the FTP client.

HTTPS

We’re going to use a self-signed certificate to show HTTPS is possible. In a real-world scenario you’d sign a relatively short-lived RSA keypair with a certificate signed by a trusted root cert (and also, you’d probably not use a Raspberry Pi and publicly-exposed Kestrel Web Server to run your services, but hey ho).

SSH into your Pi again and run the following command to create a public and private key pair that will be valid for a year.

openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365

Next, generate a .PFX file from the two generated PEM files (thanks to Pete S Kelly):

openssl pkcs12 -export -out raspberrypi.pfx -inkey key.pem -in cert.pem

This creates the “raspberrypi.pfx” file that your ASP.NET Core app now refers to in Program.cs.

Running the app

At the SSH prompt, tell the .NET Core runtime on teh pito start your app:

dotnet <yourappname>.dll

<yourappname> will be the name of the project you created if you used Visual Studio, or the name of directory you created that you ran dotnet new in. Typically this will be something like HelloWorld.dll or Acme.Web.dll, etc.

If all has been successful you’ll see the following echoed in your SSH session on the Pi:

pi@raspberrypi:~/piservice $ dotnet src.dll
Hosting environment: Production
Content root path: /home/pi/piservice
Now listening on: https://0.0.0.0:5000
Application started. Press Ctrl+C to shut down.

(My emphasis). From your development machine you should now be able to begin making requests to your app hosted on the Pi, https://raspberrypi:5000/

You will get errors about the certificate being untrusted, this is expected as your development machine has no reason to trust the little $30 computer, but you can skip past them – or read the final section of Peter Kelly’s article to learn how to trust the Pi’s self-signed certificate.

Making it Public

This is where things turn a bit vague as it’s up to you how you set up your network.

At the most basic level you need to tell your router to send traffic to port 5000 on your Pi. This usually involves adding a Port-Forwarding Rule. You’ll need to know your Pi’s IP address to set up the rule, so it makes sense to either give the Pi a static DHCP lease. Please refer to your router’s user guide for specific information.

To call your Pi from the outside world you’ll need your router’s public IP address – of course it’s best if this is static, ask your ISP if this is an option – and then you can set up a domain name to point to this IP address.

You can get a proper SSL certificate for your domain name from LetsEncrypt, or any other certificate provider.

Note: You’ll get SSL certificate errors when using a self-signed certificate, and browsers may stop allowing access to sites where the certificate doesn’t match the public domain name.

Follow Up

I’ll follow up soon with an article on containerising the ASP.NET Core app and running it on Docker on the Pi.

 

How Reliance Jio Disrupted Digital India

On a recent business trip to New Delhi, I was out for lunch with colleagues when conversation turned to the price of mobile data. Us foreigners at the table bemoaned the price-per-Gb in our home countries, meanwhile, the locals could barely contain their laughter…

Overnight Success

An overnight success in the world’s 2nd most-populated country is nothing short of breathtaking.

In June 2015, IDC estimated there were 5.8 million 4G LTE subscribers in India. In a country with a population of 1.3 billion that’s a rounding error.

Yet, as I type this now in October 2017 India has 81.56% 4G LTE coverage, better than most countries in Europe and snapping at the heels of city-nation, Singapore.

Isn’t that a huge waste of bandwidth?

Well no… Just months after the IDC estimate was published a new service, Reliance Jio, was launched, and everything changed.

Reliance Jio

Reliance Jio launched commercially on 5th September 2016 and… *deep breath*… acquired 50 million subscribers in 83 days.

That’s 400 new subscribers every minute.

That’s a faster user acquisition rate than any consumer company in history, including Whatsapp, Facebook and Skype.

They hit 100 million subscribers within 6 months.

How did they achieve this?  Continue Reading “How Reliance Jio Disrupted Digital India”

The Rise of the Blockchain

knights_ni
Not the Knights Templar, yesterday

Within a few short years we could find our banking system is bankrupt. No, I’m not trying to predict another subprime mortgage collapse, and this isn’t another anti-Trump message of doom (although his lack of understanding of ‘the cyber’ and affinity with traditional business models will not help the United States of America weather such disruption). Instead, the rise of the ‘Blockchain’ simply renders banks unnecessary.

Why do banks exist?

Banks exist because storing your cash under your mattress isn’t very secure. But what is it about banks that makes them a safer place for your hard-earned wedge?

According to legend, the the Knights Templar invented the first form of modern banking in the 12th century. They would take in money from Christian crusaders, pilgrims and travellers in return for a slip of parchment that detailed their deposit. Further along their journey they could swap their parchment at a ‘Templar House’ for gold, silver and whatever-the-hell-myhrr-is up to the value they had deposited. Sound familiar?

As for security, the Knights Templar were some of the most fearsome warriors around. They didn’t need to chain their pens to the desks, if you nicked one you’d do well if you only lost a hand…

The first Templar banking system relied on low literacy levels. Basically, the hope was that the parchment could easily be overlooked by groups of medieval chavs rifling through your pockets looking for gold coins. Eventually, the parchments were written in code (encrypted) to avoid them being tampered with. Ironically, it is encryption which is the basis for Blockchain, which may end up destroying this old-style of banking.

By the way, the legends are all bollocks because the Chinese Yuan dynasty had banknotes in 1000 ADContinue Reading “The Rise of the Blockchain”

Why do people only read things that back up their way of thinking?

Remember when the internet was in its infancy? We all had to put up with little 468 x 90 banner ads everywhere you looked – and sometimes we clicked them because we didn’t know better.

As time went on we grew smarter, we were able to tell the bad adverts from the good, and the emergence of online advertising  bumped the ugly out of the marketplace entirely. And now, our brains automatically blank out adverts to keep us focused on the content we went to the site in the first place for. Many of us use ad-blocking tools so our brains don’t even need to perform the mental airbrushing.

But what if those adverts were trying to tell us something really important?

What if the Emergency Broadcast System was hooked into those banner ads trying to give us forewarning of an avoidable cataclysm?

Social Engineering

Social Engineering refers to psychological manipulation of people into performing actions or divulging confidential information.

It is becoming increasingly common by malicious actors (bank and identity fraud, for example), but is also becoming a core part of many companies’ business models.

It all started innocently enough with the Social Graph. The ability to link people with other people, events, photos and products via rich, meaningful relationships turned the one-size-fits-all internet into a personalised window where the chaos suddenly started to shape itself into something we recognised and could engage with on a more emotional level.

Instant social gratification through ‘likes’ and ‘follows’ became our norm, information relevant to us started to travel at a speed that made some high school students, even back in 2008, say “email is too slow“. The relevancy-engine that is the Social Graph began to play on our most base motivations. Continue Reading “Why do people only read things that back up their way of thinking?”

Google Watch: Time to DuckDuckGo

You can't spell
You can’t spell “Don’t be evil” without “evil”! Coincidence?

Google do a lot of good things. They host free webfonts to make the web a nicer place to be. Their cloudy PaaS service, Engine Yard, gets rave reviews. Their maps are better than anyone’s, their mobile OS is the most popular in the world, and their photo hosting offer is second to none. But they can be very evil sometimes too.

Remember when Google forced you to sign up to Google+ to comment on Youtube videos, or stole your email passwords while they took pictures of your house and then “forgot” to delete it after they got found out and all the Governments told them to, or made you type extra characters to include all your words in their search, or when their CEO said there was no place for privacy and anonymity on the Internet?

* big breath*

Well they are at it again.

And I’ve had enough.

The Devil’s In The Detail

For the last few days I’ve been seeing this ‘privacy reminder’ popup whenever I go to Google (including by searching in Chrome’s address bar). And it stops you dead in your tracks. You have to read through all the legalese before it lets you search for pictures of cats. Well I just don’t have time for that, I need instant cat gratification now!.

That sounds so wrong.

Anyway, I had a quick scan through the privacy reminder and immediately smelled a rat… It all seems really un-evil at first, you can choose to switch off some of Google’s invasive behaviour by following the handy-dandy links in the privacy reminder itself. Wowzers! What a nice thing to do. I opted to switch off all the weird adverts-following-you-around settings. They’re here, in case you’re wondering.

But then I noticed it says these settings are just for this browser. Your other devices and PCs will still track the living crap out of you. Continue Reading “Google Watch: Time to DuckDuckGo”

aspnetcore.dll failed to load. The data is the error

This morning, while trying to debug our big ol’ web project in Visual Studio 2015 I encountered a problem – it held me up for a while so I wanted to quickly blog about the solution in case it hits you too. When hitting F5 to start debugging, Chrome launched but then immediately Visual Studio detached from IIS Express and showed the following error:

A process with the ID of <id> is not running

True enough, IIS Express wasn’t running…

Open Wide and Say ‘Ahh!’, Mr Windows

I ran a Repair on IIS Express 10.0 in case it was an issue with that, or the self-signed SSL certificate it uses to host web projects over a secure connection…. but still had the same problem.

I then created a brand new ASP.NET MVC 5 project and hit F5… but that ran fine. Hmm, curious. That let me know IIS Express was fundamentally OK, and the issue lay with the big ol’ web project.

Microsoft are usually pretty good at logging when things go wrong so I fired up eventvwr, the Windows Event Viewer, and saw the following  error being thrown by IIS Express:

The Module DLL C:\Program Files (x86)\Microsoft Web Tools\AspNetCoreModule\aspnetcore.dll failed to load. The data is the error

Strange… We don’t have any ASP.NET Core projects in that solution so why aspnetcore.dll is being loaded was beyond me. Furthermore, that path didn’t exist on my disk. Continue Reading “aspnetcore.dll failed to load. The data is the error”

Things I learned at my last job

Today I closed a chapter in my life. After nearly 4 years tenure at a company I wanted to reflect on the things I learned over that time.

I have been very lucky to have a few excellent – world-class even – mentors here who have taught me things that will stay with me for the rest of my life, and I wanted to share the reflection process with you in the hope you gain something valuable too.

Individual Success Isn’t Success

For a long, long time I  adopted the ‘aircraft oxygen mask’ approach to my career: I’ll get to where I want to be first, then I’ll help others. This company has taught me that isn’t the right thing to do.

ubuntumeme

My thinking was always “I’ll be in a better position to help others” once I hit my objectives, but that simply doesn’t work in practice: without respectful, cooperative development across your team(s), you risk yourself hitting your goals at all, and if you haven’t helped others hit theirs too, nobody wins.

Dare I use the management-bullshit-bingo term ‘synergy’?

My current role here is a technical leadership role – that means I don’t have people reporting to me but I do have authority over technology direction and a remit to ensure conceptual integrity of the solution. I have led project teams before, I have even run small businesses before, but being a leader in a larger company was new to me when I began this chapter of my life, and I wanted to be good at it.

I’ve seen all the memes about the difference between a boss and a leader but for some reason I struggled to enact the differences. However, after some time spent being (in retrospect) a terrible boss, some sage advice from one of those mentors made everything ‘click’, and I was given the mental tools to develop the techniques required to become a good leader instead. (Note, a good mentor won’t give you the answer, but the means of finding it on your own!).

boss-vs-leader

“Take people with you.”

So what does that look like in practice? Last year I was offered the chance to travel to our American HQ to present some new work to 1,500 customers. ‘Prestigious’ isn’t even close – this is a huge event, so compelling that our customers pay us to listen to our plans and roadmap. The trip dripped with a significant amount of attached ‘kudos’ and the opportunity to rub shoulders with the highest of the high in the business. Not only that – the opportunity to ask probing questions to 1,500 customers about our technology direction is such a rare occurrence it was unmissable. The old me would have started packing immediately. Continue Reading “Things I learned at my last job”

The Sharing Economy

Your house, yesterday. Probably.
Your house, yesterday. Probably.

The ‘Sharing Economy’ is disrupting established industries and sending huge, powerful incumbents into a tizzy. Uber and AirBnB have shaken the taxi and hotel sectors, shifting power, control and profits from the RadioCabs and Hiltons of this world and into the hands of ordinary citizens armed with nothing more than a smartphone and a mobile data plan.

The question on everyone’s lips is: which industry will be disrupted by the Sharing Economy next?

A couple of years ago, I was in Portland, Oregon, for meetings with some colleagues. One lunchtime, our discussion diverged from work topics to an issue plaguing our home-lives, an issue common to both the US and UK: the reduction in bin-pickup frequency.

It’s a hot topic.

Dude, Where’s My Trash?

We tossed around some ideas to solve our overflowing bins issues, to solve the problems caused by local authorities switching from weekly to two-weekly pick-ups, and to solve that awkward situation we have all faced: that middle-of-the-night walk of shame, bin-bag over shoulder, roaming the streets like a crazed, ferral cat to find a neighbour’s bin with a bit of space left in it to deposit last night’s curry leftovers and beer bottles.

What does this have to do with the Sharing Economy?

A lightbulb lit: why not create a location-aware, social app to help out? Share My Trashcan was born, $5 per bag, with a $1 kick-back to us, it scales and is simple. But then one of our team mentally cycled through a Lean Startup build-measure-learn cycle and developed the concept, discovering that communities can come together to buy a shared dumpster, which would provide even more space (some of which could be shared with other communities!) and would also be picked up weekly.

Share My Trashcan was dead, long live Share My Dumpster!

Later in the day (after doing some actual work) we revisited the idea and the real, Lean, magic happened: we pivoted.  Continue Reading “The Sharing Economy”