7 ms·
GitHub Packages Is Down
- alexellisuk 4y agoI’m also having issues pulling images from ghcr.io
- deleted 4y ago[deleted]
- bin_bash 4y agoFYI: this breaks homebrew
- giancarlostoro 4y agoDoes it break all of Homebrew or just some packages? I never knew homebrew started using GitHub Packages.
- mfer 4y agoHomebrew uses it to store bottles (the built assets).
- 0xbadcafebee 4y agoFun fact: Linux distributions (and some older open source programming language package managers) use hundreds of mirrors distributed around the world to distribute their assets. If any mirror goes down, you just pick a different one. Even when they could just use SourceForge as a mirror (formerly the largest repository for open source software), they still used hundreds more mirrors. Distribution was made easy with rsync, and mirrors could choose what files they mirrored (just the latest release, or all releases, or just binaries and not source code)
- naikrovek 4y agoGitHub uses pools of mirrors, too, they're just transparent. twice this year I've had to spend an hour or more with a user because a mirror was down. that's one more time than I've had to deal with a GitHub packages outage this year. the latest was yesterday. they chose another pool of mirrors and the mirror continually chosen from that pool was down as well. finally I manually checked a mirror, made sure it was up and that signatures matched, then gave them that specific hostname. the Linux package distribution system is not better. it's just different.
- jacobsenscott 4y agoSo this is why hb started asking for access to my keychain all the time? (macos) Does it need to log in to gh to install open source software now?
- naikrovek 4y agoyou don't have to, but hb will ask you to if you have a saved credential because your quota on GitHub for downloading packages is much higher if you are logged in. anonymous stuff on GitHub is usually limited to 60 requests per hour per ip address. if you're authenticated, it's several hundred if not several thousand.
- bin_bash 4y agoanything you don't install via `--build-from-source`
- ducktective 4y agoNix too I presume
- lom 4y agoOnly if you pull from master
- mananaysiempre 4y agoYou presume incorrectly. GitHub Packages, the package registry and binary hosting service, does not even support Nix. As for GitHub in general— The binary hosting at https://cache.nixos.org/ https://cache.nixos.org/ is independent of GitHub, and so are the old-style channels at https://channels.nixos.org/ https://channels.nixos.org/. The new-style flake registry used to be fetched from GitHub but has now been moved to https://channels.nixos.org/flake-registry.json https://channels.nixos.org/flake-registry.json. Admittedly in a new-style situation you’re likely to be using unlocked flake references that refer to GitHub (e.g. Nixpkgs), but it’s on you to lock them and pull them into your Nix store in that case. Of course, you also get GitHub references for upstreams that host their code there, but that applies to almost any distro(’s build system) except the oldest of the old-timers which host the source for the whole distro on their own infrastructure, like Debian. (I happen think the old-timers are right here, but that’s beside the point.)
- pxc 4y agoNope. This is actually the second (maybe third; I didn't even know about GitHub's outage a week and a half ago so idk how Nix was or was not affected) time in three months or less that a partial GitHub outage or GitHub change has taken down Homebrew while leaving Nix unaffected.
- orwellg1984 4y agoaffirmative
- VWWHFSfQ 4y agoI think it will break any of the open source package managers that rely on GitHub's proprietary hosting and distribution. Cargo, etc.
- kreco 4y agoI did not know package managers relied on Github, this is the most unwise thing to do from a package manager perspective. Anyone could just change username/organization and break thousands/millions of build.
- chisquared 4y ago> Anyone could just change username/organization and break thousands/millions of build. GitHub redirects you to the new name in the event of a rename and you look up the old one.
- JamesonNetworks 4y agoFor now, hopefully
- naikrovek 4y agoyeah. if GitHub is even real.
- JamesonNetworks 4y agoWell, we know GitHub is real. But we should also remember that they can change their API at anytime and basing a package manager on their priorities is not the best situation for the long term success of that package manager, unless they are owned by Microsoft
- adders 4y agountil someone claims the old name as a new org/repo
- 4y ago
- josephd79 4y agohow so? It's working for me.
- taywrobel 4y agoMan, this disappoints me. I was a tech lead on the packages project about 3 years ago, specifically on the redesign for OCI container support and making anonymous downloads of public packages as reliable as possible was a top priority. If that flow was broken there’s only a handful of things it could be; specifically azure blob store or azure MySQL, but both of those should have layers of redundancy. Public anonymous download bypasses most everything else; no auth services, rails monolith, or metered billing. It does emit some events to the message bus for metrics, but that’d effect much more than packages if there was an issue with it. As far as I’m aware this is the first time anonymous public package download broke since I left a few years back.
- hummus_bae 4y ago[dead]
- rvz 4y agoOh dear, Last time this happened was 11 days ago when more than just packages went down. [0] Perhaps relying and going all in on GitHub doesn't seem to be good in the long run. Especially GitHub Actions. This is where OpenAI is now feeling the effects of instability [1] on Azure since their recent outage. I expect them to also have issues like GitHub has every month. [0] https://news.ycombinator.com/item?id=34843748 https://news.ycombinator.com/item?id=34843748 [1] https://news.ycombinator.com/item?id=34958375 https://news.ycombinator.com/item?id=34958375
- jbergknoff 4y agoPackages had an incident two days ago, also: https://www.githubstatus.com/incidents/sn4m3hkqr4vz https://www.githubstatus.com/incidents/sn4m3hkqr4vz. I noticed it when a Terraform provider download was failing, citing a 404 from objects.githubusercontent.com.
- VyseofArcadia 4y agoMicrosoft, historically, has not had much competitive pressure to be reliable. For decades, they've had a lock on the PC OS market, and there basically is no larg2 business that doesn't rely on MS. Even world governments rely on MS. Now even in the few areas where MS actually does have this pressure (e.g. Azure) they're struggling to make it part of the culture.
- aninteger 4y agoThe "is" seems to be used confusingly here. This reads better as either: * GitHub's Packages Service is down * GitHub Packages are down
- jasonlotito 4y agoYou are getting down voted. I'll explain. The name is GitHub Packages. It's singular. The use of "is" is correct here. GitHub uses "is" in similar circumstances as well.
- chatgptfan 4y ago[flagged]
- dijit 4y agoThe idea of the instability of a Microsoft platform moving you back to.. Microsoft, is funny. Notwithstanding that services on third party systems are a weird reason to buck a first party platform.
- mrweasel 4y agoI'm disappointed that this is an issue for some package management systems. 20 years ago I helped run a mirroring service, it's still running today. Distributions such as Debian have hundreds of mirrors. This is a solved problems, but we just decided to but everything in the hands of one for-profit company.
- BonoboIO 4y agoMove fast and break things ... /s
- naikrovek 4y agojust yesterday I was stuck for an hour because a debian package mirror went down. took a long time to talk the user through changing their sources.list so that another mirror was chosen, and the mirror chosen out of that pool was down also. finally I had to manually check for a good mirror and give them the URLs. the user's take was "why don't they use GitHub packages?" "still running today" doesn't mean 100.0% uptime.
- ddtaylor 4y agoThis is not how this works anymore. The system that is behaving this way must be relatively old at this point since almost all modern Debian based distros use the "mirror://" URI syntax now that automatically falls back to another mirror if one fails.
- pxc 4y agoI don't think a clean Debian stable install uses that today. But even so, at least the mirrorlist.txt file that appears in the mirror:// URI must be available for it to work, right?
- ddtaylor 4y agoYou are correct. While it's supported and part of the APT version in Debian, they don't make much use of it themselves, whereas most downstream distros are making use of it (eg. Ubuntu) https://manpages.debian.org/bullseye/apt/apt-transport-mirror.1.en.html https://manpages.debian.org/bullseye/apt/apt-transport-mirro... You can still use it in vanilla Debian, but they don't make their mirror list available easily in the correct format, so you would have to basically curl + awk the URLs into a text file and use that. My guess is that Debian itself probably sees less than 1% of the traffic on their mirrors compared to Ubuntu and they haven't been as motivated to make this change.
- lopkeny12ko 4y agoWhat I find funny and unexplainable is that this class of problem was solved decades ago with distribution mirrors. It's not really clear to me why, within the last decade or so, we collectively decided to centralize hosting on one specific cloud service whose downtime now affects builds across nearly every company. What's perhaps even more surprising to me is that, after a repeated track history of severe and frequent Microsoft-Github outages in the last three years, it is still a hard dependency for so much of the modern software stack.
- taeric 4y agoMostly agreed, but I'd hazard a guess that the scale of github is far larger than distribution mirrors of old.
- schainks 4y agoThere are many distribution mirrors that are financed by universities that are on the the Internet backbone in the US Heck, even in Asia I did not have trouble with finding a good mirror.
- taeric 4y agoI suspect this is the kind of advice that works for anyone, but would fail for everyone. That is, for most, it is a valid cost/benefit tradeoff to use the central option. Specifically, not just for them, but for everyone. If everyone was following this advice, it would likely start hitting scale/cost problems that would make running the mirrors of dubious value.
- schainks 4y agoIf you install packages on your linux infrastructure or docker images to provision anything, and those things are based on the “default” install, you are relying on the mirrors. That infrastructure is already “web scale”. It’s just a matter whether you make one image once and copy it thousands of times or if you actually spawn thousands of instances that talk to the mirrors. Setting up your own mirrors for internal use isn’t overly difficult either, and it is definitely a trade-off as you pointed out. However, it basically works for everyone, whether or not they are fully aware of it. I have also run my own mirrors with minimal fuss. I haven’t had a business need to use GitHub packages, but I am glad it exists, as it is another tool to do a thing that needs doing in the right circumstances.
- fulafel 4y agoDid this include the container registry service?
- asdf123wtf 4y agoIt's never been up in the first place, for those of us who are waiting for python package support. Poke, poke!
- nijave 4y agoAnnoyingly, pypi has a pretty simple API and you can host it directly from a static webserver like Apache or Nginx if you skip some of the optional features in the spec