4 ms·
Good for you. Don't you think it's good to have a choice?
by NikPuashkin 3y ago
Good for you. Don't you think it's good to have a choice?
- wutwutwat 3y agoI sure do. There are countless open source CI systems I trust that I can choose from, and countless paid offerings with a very long track record of being stable and secure, with a papertrail of security audits and pen testing to back them up, some of them are even open source too. None of them are trying to compel me to act due to the very advertising $0.99 cent tactick. Price is the last thing I care about when it comes to my code and who has it, where it runs, and what I'm opening myself up to. Security and peace of mind are worth a price imo so I'll happily pay my SCM for runners, or pay to host my own, even if it's a bit extra. When your pitch doesn't hinge off of your price being way lower than everyone else, then you'll be worth glancing at. Racing to the bottom isn't something I'd expect to be around long, esp since others in your problem domain are commenting here saying it's not possible to not be running at a loss
- NikPuashkin 3y agoIt isn't about price, it's about effectiveness, so both speed and price. The solution is architecturally different from anything on the market, including the GitHub controller you've posted here. I guess, you didn't even open the link of the post, because there is a scroll #3, which gives you quite a detailed explanation of the service tech advantage.
- Kinrany 3y agoName three that you like?
- wutwutwat 3y agoOpensource ones are Jenkins/Jenkins X, Drone, Travis-CI, Argo, GitLab CI, Dager, etc Paid offerings I've personally used and liked, GitHub Actions, CircleCI (their docker layer caching was a game changer back in the day), and CodeShip
- NikPuashkin 3y ago> ProTip: Don't price shop for CI runners and give some random company access to your company's source code and secret keys/tokens > I've personally used and liked, GitHub Actions, CircleCI https://circleci.com/blog/january-4-2023-security-alert/ https://circleci.com/blog/january-4-2023-security-alert/ Yeah. Random company.
- wutwutwat 3y agoEven if I felt inclined to give your company my business, your attitude towards any valid criticism has made it so I would never go near your company or anything that you do in the future. You're expecting companies to trust you with the ability to literally destroy them. If you can't handle security skeptical people you picked the wrong fucking niche, buddy, you're handling their source code and secrets/tokens. Your response to me saying I trust companies that have been around for a decade and have a history of being secure was to share a post about one of them having security incidents. Got em, you dunked on me! I never said they never had any incidents, because I never would. No software is 100% secure. You missed the key part, which was the longstanding existence and the paper trail, which the thing you linked to is actually a part of, which is important. They get my business over a fly by night .cloud company being pitched by a person being defensive when people have security concerns, for a new saas, in another country, who has yet to link to any third party security audits, compliance certifications, disclosure policies, SLAs, protections, vetting/audit process, etc.
- NikPuashkin 3y agoI'm always open to discuss any security concerns, which are based on technology. However, you started here from the toxic biased comments. If my company is 3yo, I can't make it 10yo in one day, obviously, so there's no point to discuss it seriously. The age of the company is not an objective security criteria for an engineer, that's why I referred you to the CircleCI security breche. Regarding the paper work, it's to be done yet. New company can't start from applying for ISO 9002. If you would like to discuss the technical security aspects of the solution (there are many), you're welcome to my DM or to the channel in Discord.