6 ms·
Self-hosted is always good, if you can afford hosting own hardware.
by NikPuashkin 3y ago
Self-hosted is always good, if you can afford hosting own hardware.
- wutwutwat 3y agoI wonder what's cheaper, self hosting my own ci runner, or the risk of my company's source code being given to a random third party and trusting they won't do anything with it and that they will secure it to make sure nobody else gains access to it. It's a tough one, I'll let you know what I land on
- NikPuashkin 3y agoGood for you. Don't you think it's good to have a choice?
- wutwutwat 3y agoI sure do. There are countless open source CI systems I trust that I can choose from, and countless paid offerings with a very long track record of being stable and secure, with a papertrail of security audits and pen testing to back them up, some of them are even open source too. None of them are trying to compel me to act due to the very advertising $0.99 cent tactick. Price is the last thing I care about when it comes to my code and who has it, where it runs, and what I'm opening myself up to. Security and peace of mind are worth a price imo so I'll happily pay my SCM for runners, or pay to host my own, even if it's a bit extra. When your pitch doesn't hinge off of your price being way lower than everyone else, then you'll be worth glancing at. Racing to the bottom isn't something I'd expect to be around long, esp since others in your problem domain are commenting here saying it's not possible to not be running at a loss
- NikPuashkin 3y agoIt isn't about price, it's about effectiveness, so both speed and price. The solution is architecturally different from anything on the market, including the GitHub controller you've posted here. I guess, you didn't even open the link of the post, because there is a scroll #3, which gives you quite a detailed explanation of the service tech advantage.
- Kinrany 3y agoName three that you like?
- wutwutwat 3y agoOpensource ones are Jenkins/Jenkins X, Drone, Travis-CI, Argo, GitLab CI, Dager, etc Paid offerings I've personally used and liked, GitHub Actions, CircleCI (their docker layer caching was a game changer back in the day), and CodeShip
- NikPuashkin 3y ago> ProTip: Don't price shop for CI runners and give some random company access to your company's source code and secret keys/tokens > I've personally used and liked, GitHub Actions, CircleCI https://circleci.com/blog/january-4-2023-security-alert/ https://circleci.com/blog/january-4-2023-security-alert/ Yeah. Random company.
- wutwutwat 3y agoEven if I felt inclined to give your company my business, your attitude towards any valid criticism has made it so I would never go near your company or anything that you do in the future. You're expecting companies to trust you with the ability to literally destroy them. If you can't handle security skeptical people you picked the wrong fucking niche, buddy, you're handling their source code and secrets/tokens. Your response to me saying I trust companies that have been around for a decade and have a history of being secure was to share a post about one of them having security incidents. Got em, you dunked on me! I never said they never had any incidents, because I never would. No software is 100% secure. You missed the key part, which was the longstanding existence and the paper trail, which the thing you linked to is actually a part of, which is important. They get my business over a fly by night .cloud company being pitched by a person being defensive when people have security concerns, for a new saas, in another country, who has yet to link to any third party security audits, compliance certifications, disclosure policies, SLAs, protections, vetting/audit process, etc.