11 ms·
I work for a non-profit open source organization that collaborates on github (https://github.com/edx/ https://github.com/edx/) We have lots of people who aren't
by fps 10y ago
I work for a non-profit open source organization that collaborates on github (https://github.com/edx/ https://github.com/edx/) We have lots of people who aren't employees, but have signed a contributor agreement with our organization and contribute changes to our software. Our bill will go up from $200/month to over $2000/month with this new pricing. We can afford it (it's still a small fraction of our AWS bill) but it will force us to look at other alternatives. Github's code review tools are already pretty mediocre compared to other tools like gerrit, and we've long since moved off of github issue tracking due to lack of features compared to JIRA.
- jnmandal 10y agoIf you are non profit and open source do you really need private repos?
- fps 10y agoWe have about 100 private repos at the moment, including internal tools, branding related components, infrastructure code and pre-release stuff that we're not developing in the open. We may just move those to AWS code commit, gitlab or gogs and switch back to a free org.
- Q6T46nT668w6i3m 10y agoFWIW, I work for an academic non-profit and we use public repositories with an appropriate LICENSE. We like it because we don't need to manage read permissions.
- VLM 10y ago"that we're not developing in the open" Honest question... why? I totally understand the mindset of "gotta go all secret squirrel to protect our profits" but if your org isn't in it for the profits there's not much to protect? I have seen examples of people performing very naughty acts like private repos to hold plain text passwords, plain text cloud service keys, plain text corporate credit card numbers for expense payments, etc.
- geofft 10y agoNon-profit organizations still have a mission that they need to protect, and they almost always have revenue they care about, though not profit. Private repos are a good way to review code for things like plaintext passwords and service keys before it's in production. If a developer commits something with a key, and code review goes "Oh, you shouldn't have put that there," and it was public, now you have to rekey. Private repos allow that code review step to take place. (They're also pretty useful for legacy code where eliminating all the private keys is difficult and not an immediate priority, and for the rare but existent cases where including private keys in source is the right engineering tradeoff for new development.) There's also no way to disable pull requests and other outside comments on your code, other than making a private repo. Having it private is a simple way to avoid inviting the public to have opinions all over your repo.
- slantyyz 10y agoMy first job out of university was at a not-for-profit, and it is a surprisingly cut-throat sector. We had two main competitors in our space, and while the ultimate goal for everyone including our competitors was to do a common good, we were competing for a limited pool of donation dollars. Because of that, sharing any intellectual property that made us better at what we did (i.e., raise more money, hire more staff, fund more initiatives) could result in a competitor using that same IP to put us out of business. I get that in the big picture, it's not the way things should be done, but in the small picture, you're usually talking about individuals with their own agendas.
- __jal 10y agoThere are a ton of reasons not to develop in the open, no matter what your structure. - You're experimenting - You don't want comments from the peanut gallery while things are in progress - It is not for external use, specific to an institution or project, or otherwise nobody else will care - It deals with something sensitive - You've made an agreement with someone else that requires it - etc. etc. etc. People seem to have weird notions about nonprofits. Your tax structure doesn't change the fact that you operate in a world of other human beings.
- 10y ago
- woah 10y agoWhat kind of bad things will happen if people are able to see what you are doing?
- sytse 10y agoYou're very welcome to switch to GitLab.com, we are free forever https://about.gitlab.com/gitlab-com/#why-gitlab-com-will-be-free-forever https://about.gitlab.com/gitlab-com/#why-gitlab-com-will-be-... and it can import directly from GitHub.
- puddintane 10y agoGitLab CE (Community Edition is Free) and is truly great we use it in our own internal software development process. However for a bigger enterprise they require more functionality here is a comparison of the differences between the Community and Enterprise Editions. https://about.gitlab.com/features/#compare https://about.gitlab.com/features/#compare Several pricing options for EE but essentially the base cost is $39 /year per user. https://about.gitlab.com/pricing/ https://about.gitlab.com/pricing/
- gpm 10y agogitlab.com runs EE though doesn't it? You only need to pay if you want self hosted EE.
- puddintane 10y agoI've only ever seen the trial but I could be wrong!
- connorshea 10y agoIt does, yes :)
- puddintane 10y agoGreat to know, thank you! However our requirements were offsite and must be why I never knew about the free EE hosted on GitLab!
- X-Istence 10y agoYou are replying to the CEO of Gitlab... :P
- BHSPitMonkey 10y agoYour first comment stated the problem was your large number of non-employee contributors. You said in another comment that non-employees don't contribute to your private repos. I don't see the problem here. Your employees will have access to your private repos, and the volunteers will not (thus you won't be paying for their seats).
- Xylakant 10y agoIn a non-profit that I collaborate with [1] we use private repos to keep the server setup and some tickets that contain sensitive information (user data). All other code is open source. Obviously we don't want to keep api keys etc. in the public repos. [1] https://github.com/sozialhelden/wheelmap https://github.com/sozialhelden/wheelmap
- imdsm 10y ago> we use private repos ... that contain sensitive information (user data). Wait, what?
- Xylakant 10y agoemail addresses and (account) names of people reporting bugs in private. Some people prefer it that way. Nothing "sensitive sensitive". Sorry for being unclear.
- cloverich 10y agoYou shouldn't be keeping api keys or other sensitive information in git at all. And please note -- if you do remove it from git, it will be available in your git history so that needs to be taken care of as well (should the repo ever become public -- a common "exploit").
- Xylakant 10y agocare to explain why? I need to keep my API keys somewhere so I can roll them out to the machine. Keeping them in git is as good as any storage - what would you propose instead? A shared dropbox account?
- uxp 10y agoThe newfangled approach is something like HashiCorp's Vault, which is a dream when you're looking at more than half a dozen systems with similar roles. A different approach that I like to use for single or smaller cluster systems is Ansible's Vault and rolling out config files based on templates per environment. All actual config files are gitignored so I don't have do deal with conflicts on the server if I use a git-pull style deployment, and ansible itself can backup/version whenever they change. Additionally, git does keep that history (as it's supposed to), so if you just delete the key from a private repo as you're trying to make the repo public, it's trivial for someone to walk the commit history looking for historical API keys that might not have been rotated. In order to purge that information from git, you then have to go re-write the commit graph from the point of the key's insertion (with it removed) all the way to the present. It's not impossible to do, it's just a major pain.
- jeff_tyrrill 10y agoNonprofits need CRUD apps just like any other organization. "Being a nonprofit" doesn't mean "developing open source software".
- deleted 10y ago[deleted]
- WillAbides 10y agoIf you are a non-profit, your bill can be $0. You just need to sign up here[0] and send in the data requested. [0] https://github.com/nonprofit https://github.com/nonprofit
- cstejerean 10y agoIt doesn't seem this is valid for academic nonprofits (from the linked page) so I don't think EdX would qualify.
- WillAbides 10y agoThat's right. I didn't notice it was academic. GitHub has a similar deal for education[0]. The bottom of the page has a link to apply for a free educational org. [0] https://education.github.com/ https://education.github.com/
- emidln 10y agoI've used Bitbucket in the past. They charge per-user[1], and their pricing is significantly better free for 5 users and then once you eclipse 5 users it's $1/user up to 100 users and then $200 for unlimited users. [1] - https://bitbucket.org/product/pricing https://bitbucket.org/product/pricing
- taytus 10y agoThis. I use bitbucket too and I can't understand why people are still paying github when bitbucket does exactly the same and is free.
- slantyyz 10y agoGithub does seem to be the gold standard for open source projects. Having said that, I used to pay for Github's personal plan and found the cap on private repos (5 when I subscribed) to be a little too limiting. I ended up canceling the subscription and using a Bitbucket free account for private repos and Github for public repos. After using Bitbucket for a while, I think if I had to upgrade to a paid service, I'd just stick to Bitbucket.
- maerF0x0 10y agoPeople use github over bitbucket if they like the features that github provides, the diffs, issues etc. Not sure which features are unique to github alone, but each provider (including gitlab) has their own flavor. Many are just used to github flavor.
- tokenizerrr 10y agoI use bitbucket at work, and it has many of the same features as github. The UI is a bit clunkier, and it does lack some of the flashy features such as automatically squashing commits when merging a pull request. However it does work fine, and it is well integrated with atlassian's other offerings which we also use. Mainly JIRA and hipchat, though bitbucket also has a per-repository issue tracker.
- ssharp 10y agoFor non-profits, you could reach out and see if they'd do something special for you. I used to work in for a higher ed institution and they were gracious enough to give me a free account.
- deleted 10y ago[deleted]
- sequoia 10y ago> We have lots of people who aren't employees, but have signed a contributor agreement with our organization and contribute changes to our software. So you have volunteers, working on your proprietary, private software for free. The labor is free & now you're complaining that you'll have to pay a per-free-laborer fee for the infrastructure to manage all these free-laborers? I hope I'm missing something here...
- wlesieutre 10y agoThe problem being that a minor volunteer who donates 4 hours of coding over the course of a year would now incur a $108 github bill for having that access. It's totally out of proportion with how much they're using the service. Or say you have 80 very-part-time contributors who together match the output of 1 full-time employee, github is going to charge you as much as they would for 80 full-time employees. Any pricing structure is going to have some people who get a great deal and other people who get screwed, but it sucks when you've selected a platform, invested in getting set up on it, and then have the pricing rug pulled out from under you.
- fps 10y agothe software is AGPLv3'd, and run by hundreds of educational organizations around the world. Those organizations typically contribute changes back via Github. Non-employees don't contribute to our private repositories. We gain quite a bit from maintaining a large open source community, but it's not "free labor."
- sgk284 10y agoIt's a non-profit and open source? Why not just use public repos like Code.org and many other non-profit software teams. $0/mo is surely better for a non-profit.
- OJFord 10y agoAt that scale of developers and cost, surely it makes sense to host your own instance of, say, GitLab? Especially as you note AWS costs are much more - I'd have thought it would be much more economical to consolidate into AWS and run a VC server there.. but I'm not trying to tell you what's good for you, I'm just a guy with no experience of responsibility for things at that scale who's curious ;)
- a2m 10y agojust use gogs. https://gogs.io https://gogs.io