4 ms·
Does SourceHut still have an aversion to Kubernetes and Docker? Last year I was trying to setup SourceHut on my home infra (which is Docker/SystemD based, but w
by _ktx2 4y ago
Does SourceHut still have an aversion to Kubernetes and Docker? Last year I was trying to setup SourceHut on my home infra (which is Docker/SystemD based, but was Kubernetes based) and I was told I'd be banned if I asked about it, and that they don't support that kind of software. Super weird interaction from someone I otherwise used to admire.
- dspillett 4y agoSome Kubernetes and Docker people get somewhat religious about it, and rather than taking “I/we don't support that and don't have any immediate plans to, but feel free to try it yourself” as a valid response will plead, nag, and otherwise try to cajole a project's maintainer's to reconsider, sometimes being irritatingly persistent and calling into question a person's overall intelligence because they don't currently want to directly support that plumbing. Such discussions can become time-consuming, tiresome, and (if really persistent in trying to convert them to the cause) difficult to just ignore. > be banned if I asked about it I assume this means the maintainer(s) have experienced the above a few times, and have given up trying to be more polite about it! Don't take it personally. If you want to use a tool with that plumbing then feel free to DIY. If you make it work well, perhaps publish your process and/or images and support it for others who need/want that support.
- sph 4y agoBah, what a dumb argument. There's a whole ocean between "we don't really support Docker, you're on your own" and "if you dare ask this again, you'll get banned." That's not the Kubernetes guys being religious here. Also, it doesn't even make sense on the engineering point of view. I understand not liking Docker the company or Kubernetes the product, but Linux namespaces are a kernel level facility, and banning people because they dare ask how to integrate this product with a native subsystem seems absolute zealotry from people with oversized ego. Nothing wrong with that, but let's call a spade a spade. It's their project, so it's their right to be a prick about it, but that shouldn't stop other people to call them out on it.
- dspillett 4y ago> There's a whole ocean between "we don't really support Docker" and "if you dare ask this again, you'll get banned." There is. And I'm suggesting that the water filling that ocean has come from having the same discussion over and over again with people who have asked in the past, each thinking they might be the one to finally help you see the light. I've not personally dealt with it from the point of view of infrastructure choices, but I hear tale of those who have, and I've been subject to it with regard to people who didn't agree with a licence choice so can speak for how much it makes you not want to engage at all just-in-case. I'm not suggesting you'd be like that, but I understand not wanting to engage on the matter based on previous experiences.
- d3nj4l 4y agoPerhaps there is a difference between "not wanting to engage on the matter" and "banning someone on sight"? Maybe there's polite ways to say, "Sorry, but we're not interested in supporting docker, and we don't care about any arguments for it" that would take less effort than rudely telling someone to fuck off?
- dspillett 4y agoOf course the suggestion of “banning on sight” could have been an attempt at humour by way of hyperbole, something I should have noted in my previous reply. > that would take less effort than Unfortunately, not always. Sometimes the only way to convince people that it isn't worth their time continuing to try to change your mind, is to blatantly be a dick about it. I try not to jump straight to dickishness though: I'll state my position politely once, I may have time to repeat that once or twice more, then out come the big guns. On a public mailing list or similar I might be more blunt: linking to past discussions in the first instance then jumping to DickCon1. On a public group the discussion is taking more than just my time and might encourage others to chime in and drag the matter instead of letting it close. And again: the suggestion of “banning on sight” could have been intended as an attempt at humour by way of hyperbole, rather than the direct “off you fuck” that was felt. Communication of sentiment online is very prone to errors like that.
- kodah 4y ago> Some Kubernetes and Docker people get somewhat religious about it I asked once and didn't get a response for what I think was 3-5 days and asked again (it is a low frequency channel, but that gap seemed appropriate). I wasn't making a religious argument, literally just asking about the availability of images. > Don't take it personally. If you want to use a tool with that plumbing then feel free to DIY. If you make it work well, perhaps publish your process and/or images and support it for others who need/want that support. I mean Drew was pretty clear that I couldn't even ask questions related to either subject in that channel. I don't take it personally, but it certainly affected the way that I view the project and Drew as a human being.
- js2 4y agoThis is Drew's position: https://paste.sr.ht/~sircmpwn/78cc21e1661d5a9d8038f47e532d286807ac89ad https://paste.sr.ht/~sircmpwn/78cc21e1661d5a9d8038f47e532d28...
- sph 4y agoPretty feeble argument. Basically it boils down to "if you use Docker you risk not learning how it works and hurting yourself." As I mention in the sibling comment, it would feel less patronising just saying out loud "we do not like containers, roll your own."
- bayindirh 4y agoI don't think so. I was researching Keycloak integration with Kubernetes (a project needed it at the office). I installed it on bare metal, set-up its TLS certificates and enabled native HTTPS. While searching for integration I found a video. The person installed Keycloak Docker image, and dropped an HTTPS proxy container in front of it to enable TLS/HTTPS. If this is not both bad practice and being misinformed about Keycloak in one step, I don't know what it is. The person didn't learn how to use and administer Keycloak, didn't make good judgement calls about security and published bad information while doing that. Docker is easy to abuse and creates people who think know stuff, but do not in reality. Docker. Pull Responsibly (TM).
- sph 4y agoOh, so there's people that don't know how to use containers, so they're bad? What kind of patronising, nanny state kind of argument is that? Listen, I understand not liking containers. That's fine. But just say so, or try to give more concrete arguments to the table than "I saw a guy in a video creating an insecure container. Thus Docker creates ignorance." As if configuring servers by hand isn't prone to misconfiguration or bad security practices. Perhaps we have namespaces today because people have been creating insecure, unmaintainable pet systems since the stone age, yet it doesn't save you from hurting yourself if you don't know what you're doing.
- toastal 4y agoSpeaking from the user side on CI usability, SourceHut, while not supporting a cache (which would be dope), has been pretty good with Nix and supports running NixOS unstable as an image for CI. This has been better for me than wasting steps building containers from Nix and then running the containers that some CIs require. I believe the SourceHut setup is in nixpkgs too to run yourself easily.
- gavinray 4y agoDrew seemed irritated when I posted a Dockerfile for setting up the Hare language language compiler for development on the mailing list, trying to save other folks the effort. https://gist.github.com/GavinRay97/e3c166c5ba24c2c1bc4a09d7bf31a24c https://gist.github.com/GavinRay97/e3c166c5ba24c2c1bc4a09d7b... He said "Docker isn't a supported installation mechanism." I wasn't aware of Drew's anti-docker stance, whoops.
- ddevault 4y agoWe're going to start looking into k8s and Docker soon as one of the candidates for infrastructure in our new datacenter rollout, but don't hold your breath. It will be a while before this bears any fruit and we may decide it's not worth it.
- kodah 4y agoOrchestrators and runtimes should always be carefully chosen, if at all, so that's great. Sounds like you have some smart people working on it. My post was less about the tech and more around the culture that's been established at SourceHut with respect to those technologies. If I can't even join #sr.ht and ask about images or strategies others are using that's going to be an issue.
- ddevault 4y ago#sr.ht is an on-topic channel for end-user support and development discussion. Since Docker/k8s has been rejected upstream, it's off-topic for #sr.ht. The channel needs to keep quiet and keep a high signal:noise ratio to make sure that users get attention when they need support. That said, you could discuss it on the off-topic channel, #sr.ht.watercooler, if you like.