8 ms·
(from Docker DevRel team) > Given these statements directly contradict each other Actually... they aren't contradictory. The organization data will be retaine
by mikesir87 4y ago
(from Docker DevRel team)
> Given these statements directly contradict each other
Actually... they aren't contradictory. The organization data will be retained for 30 days and is subject to deletion. That data includes the teams, memberships, etc. But, it wasn't clear what we were going to do about the images. Keeping the public images is important as many other images build on top of them.
> It feels like they changed the actual strategy
We recognize it might feel that way, so apologies. But, that's part of where we are recognize it wasn't clear the technical details... we didn't talk at all about the images. After the feedback, we recognized this, so wanted to make that clear.
- bragr 4y ago>Actually... they aren't contradictory. They are. Your intent may not have been contradictory, but the messages received by everyone else were contradictory. You should own that if you are serious about doing better. Your intent doesn't really matter in these situations.
- travisjungroth 4y agoYeah, really weird that after an apology announcement they’re still defending the original message at all. Not too hard to say “Yes, those messages contradict each other. The first one did not communicate our actual plan. The second message is a correction and clarification.”
- chasil 4y agoIt is important to understand that most corporations do not apologize, ever, unless there is a direct threat to cash flow. This behavior is now demonstrated, it is the desired relationship, and it will be the baseline, all protestations aside. The apology is meaningless. If this is not what you want, then take steps to limit the damage done to you, and do it now.
- xboxnolifes 4y agoThat's.... why they are saying it was poor communication.
- throwwwaway69 4y agoThey did in the OP link. To say now in comments "It's not contradictory" is not owning up to it being bad communication
- deleted 4y ago[deleted]
- burnished 4y agoWhat? That does not follow at all.
- HelloNurse 4y agoMore cynically, the intent might be blaming image maintainers: since obsolete images that appear current are a problem, responsible maintainers will delete them before losing access; then Docker will be able to tell inconvenienced end users that the maintainers autonomously and unnecessarily decided to remove their images.
- angelbar 4y agoThis...
- patmcc 4y ago>>>During that period you will maintain access to any of your public images. What did this mean in that case? That the images will continue to exist but the maintainers cannot update them? They'll just become orphaned?
- mikesir87 4y ago(from the Docker DevRel team) "During that period" refers to the 30-day period. During that time, the images are accessible. After the 30-day period, they will still be pull-able, but not able to be updated.
- bragr 4y ago>accessible >pull-able To any reasonable average person, these mean the same thing.
- diffeomorphism 4y agoAbsolutely not. For users, yes. For the person uploading/modifying the image, hell no.
- yencabulator 4y agoSo, any public image where the maintainer doesn't jump through hoops gets frozen in time, unable to be updated, and starts accumulating CVEs? This sounds worse than deleting the image. Any smart FOSS maintainer will find alternate hosting...
- setr 4y ago> Any smart FOSS maintainer will find alternate hosting... I think that’s obviously the point of the whole exercise — pony up or leave. They’re just doing it in an annoying manner
- eyegor 4y agoCan't believe how soon this announcement came after the redhat "we're killing centos support now, best of luck". It's pretty clear how this industry reacts to major support changes with no heads up.
- deleted 4y ago[deleted]
- vertis 4y agoDeleting 'organization data' absolutely read that they would delete everything. Changing direction and back pedaling with a non-apology is borderline insulting. I understand the need to make money as a company, but it really is biting the hand that fed messing with open source maintainers
- nikolay 4y agoThey really think we're idiots!
- bombcar 4y agoWe have learned that public images are NOT organization data!
- golem14 4y agoWith the organization data gone, will there be a way to update the retained images, like security fixes etc? If not, then this could become very dangerous.
- mbreese 4y agoReally, if they delete the org data and images can’t be updated, it might just be better to delete them all just to avoid these inevitable issues (maybe with a longer delay). Just rip the band-aid off and be done with it.
- brianwawok 4y agoMarketing people try to explain away mistakes with doublespeak. Isn’t it grand? They keep digging deeper at this point.
- jrumbut 4y ago"Actually" is not a great word to use in the context of an apology.
- hgsgm 4y agoCan the images be updated after the organizational data is gone? If not, is there a security concern, since vulns are likely to be discovery in future?
- HDThoreaun 4y agoCommunication isn't about you meant, it's about what the person you're communicating to thought you meant.
- deleted 4y ago[deleted]
- terom 4y agoIf you are deleting the organizational data and effectively archiving [1] all the images, keeping only the option for public images to be pulled but not updated... then how will affected maintainers be able to delete their now out of date public images after the 30 day cut-off? You will have to retain enough of the organization data to allow that to happen. Keeping the public images available in an archived state is okay for specific image references, but questionable for specific image tags and somewhat irresponsible for the `latest` tag. A `latest` tag that cannot be updated is ... worse than no `latest` tag. Responsible maintainers that are unable to apply for open-source status or otherwise sponsor their usage of organization public repos should be advised to delete their public repos. Responsible users of public images on Docker Hub need to have a way to determine which images will be affected, and which will continue to be maintained. Archiving the public repos gives an extended grace period, but users will still need to be prepared to notice if they end up using a now unmaintained, archived repo and migrate to alternative image sources. [1] https://news.ycombinator.com/item?id=35188691 https://news.ycombinator.com/item?id=35188691
- pmoriarty 4y ago"somewhat irresponsible for the `latest` tag. A `latest` tag that cannot be updated is ... worse than no `latest` tag" What's irresponsible is relying on a "latest" tag for updates.
- paranoidrobot 4y agoIt's not* just `latest` tags, it will also affect any other image tag. If you've been referencing org/image:tag where tag=major-minor, and gets updated when there's a patch, then that's going to stop getting updated. Without either the tag being deleted (and thus your pulls failing), or going out to find updates on that container - you may not notice that it's fallen out of date and the image/tag is no longer being updated. With the entire organisation being removed from Dockerhub, it sounds like there's not even going to be a way for people to say "We've moved off Dockerhub, our images/source/etc is now over here". You'll just have to search and hope you can find where it's moved to.
- 4y ago
- 2h 4y ago> Actually... they aren't contradictory. you're on the Docker DevRel team, why are you talking like this? why do you feel the need to be confrontational? not a good look.
- zamnos 4y agoSomewhere in Silicon Valley are the people who were passed over for this job, yelling at their phones. Maybe they should get a call back.
- steponlego 4y agoFace it, you're on heavy damage control and it just seems... untrustworthy.
- foobiekr 4y agoSo you’re going to continue to host images that have severe remote code execution exploits? With no way for the person who posted them to ask people not to use them?
- ilyt 4y agoIt appears that even after nonapology they still don't get the fucking problem. The whole thing only needs docker infrastructure getting hacked because it used some of the now-orphaned containers to complete the shitshiw
- bigiain 4y agoI wonder what a court would think about who'd be legally liable there? BigCo or GovDepartment gets popped via a known exploit against a fixed bug in an OSS project, but GitHub has prohibited the project from updating the explicable image they host without paying a ransom of $420/year?
- Twirrim 4y ago> So you’re going to continue to host images that have severe remote code execution exploits? That seems an great way to take some very significant reputation hits.
- ilyt 4y agosooooooooooooooooo orgs that didn't want to upgrade are still left with users pinned to old address of the image with no option to push security updates?
- Lazare 4y agoI understand you are in a difficult position, but this is a bit absurd. > During that period you will maintain access to any of your public images. The only reason that sentence would be in there is if after that period you would lose access to the public images! And from Merriam-Webster, "access", verb, definition two: "to open or load (a computer file, an Internet site, etc.) a file that can be accessed by many users at the same time". > it wasn't clear what we were going to do about the images. No, it was quite clear; after the 30 day period we would not be able to pull the images. That's what the announcement said. It was not ambiguous. That may not have been the policy or what was intended to be announced, but the issue here isn't a lack of clarity. (Also, letting the images stay accessible but disallowing any changes is only marginally better than just removing them, so the current policy - whether or not it's the same as the originally announced policy - is still terrible.)
- derefr 4y agoI’m guessing they mean “write access.”
- Lazare 4y agoWrite access is a subset of all access, so I don't think we can really argue that the plain meaning of the original statement was about removing write access. But yes, a missing word is certainly a plausible explanation for how they issued a statement that meant the opposite of what they apparently intended.
- tremon 4y agoBut the original statement did not say all access, it merely said access: > During that period you will maintain access to any of your public images Assuming that the you in that sentence is the organization and not the general public (given the use of your organization earlier in the paragraph), the logical interpretation is that they meant write access here, and not all access -- since read access is not limited in any way to the you in that sentence. Yes, I agree the original messaging was terrible. But claiming that the original can only have meant all access is not consistent with the wording of the announcement.
- deleted 4y ago[deleted]