5 ms·
ElasticSearch and many other repos are gone
- tison 2y agoFound https://status.elastic.co/incidents/9mmlp98klxm1 https://status.elastic.co/incidents/9mmlp98klxm1 "Some public repositories are temporarily unavailable"
- mendym 2y ago> Our teams are working on the restoration path for returning our impacted git repositories to a public state. Cant they just make them public? Am i missing something?
- sqeaky 2y agoIf they posted it on an error or outage page then they probably didn't mean to set it that way, and that implies that there was a non-obvious mistake. They might be doing something silly with their permissions. And that is presuming that this is some sort of technical issue.
- JensRantil 2y ago...or they mistakenly droppen them. :)
- dadoonet 2y agoNot that easy as there are some consequences when you move from public repo to private repo.
- martypitt 2y agoI seem to remember someone posting about this once -- you lose all your stars / followers when going public -> private, and they're not restored when you go back.
- horsawlarway 2y agoYou can see this now on the link in the post. The repo is currently sitting at Watch: 194 Forks: 0 Stars: 183
- colechristensen 2y agoI would bet, as a result of this and other things like fork management, that they'll be working with GitHub support to try to reverse the go-private and all its consequences.
- Retr0id 2y agoIt's perhaps an issue on GitHub's end
- lutoma 2y agoI'm guessing someone accidentally pushed something they shouldn't have
- parsimo2010 2y ago"As part of an internal change task" is the justification listed. Maybe this is a genuine accident. Someone paranoid might think that the for-profit management at Elastic is trying to pull some of their previously free software behind a paid-for product. Perhaps they accidentally marked all repos private when they only intended to make a few of them private. They have had beef with AWS in the past where they changed their licensing due to things AWS was doing. So I'll fully believe that it was a genuine accident if all the formerly public repos become public again.
- winddude 2y agounlikely, over the summer they announced that they were going to be more opensource, <https://www.elastic.co/blog/elasticsearch-is-open-source-again https://www.elastic.co/blog/elasticsearch-is-open-source-aga...>
- xeraa 2y agoIt's a configuration error (sorry!). Also with thousands of forks this would be a pretty pointless operation. Once something is out (and that includes a license), you cannot just take it back — it will be there forever. [I work for Elastic]
- debarshri 2y agoit could be that they might have discovered some credential leak or secrets leakage in the repo and they are fixing it right now.
- ajb 2y agoIf it's this: https://news.ycombinator.com/item?id=41060102 https://news.ycombinator.com/item?id=41060102 Then they will need to delete(or rename), remake the repos and push again. Any security problem would also require doing some due diligence to make sure you really squashed it.
- pokstad 2y agoOpenSearch
- wg0 2y agoAll the way.
- rokkamokka 2y agoI'm betting someone pushed a secret key somewhere and they made the repo private to try to limit the damage...
- ajb 2y agoCould be, or maybe that just discovered the GitHub private repo leak issue that was discussed a few months back: https://news.ycombinator.com/item?id=41060102 https://news.ycombinator.com/item?id=41060102
- xeraa 2y agoNo need to spread rumours: It was a configuration error. GitHub support is helping with restoring everything, since the fork network, stars,... are otherwise all off. And if you leak credentials, you'd just have to rotate them. Taking the repo offline would probably be too late anyway and causes a major mess, so not something I could recommend for popular repos [I work for Elastic]
- ajb 2y agoIt would be a "rumour" if I had stated that it was the truth. If it's not the right explanation then fine, but I see no need for defensiveness. I mentioned that possibility not to criticise elastic, but because it's a security property of GitHub that very much violates the principle of least surprise and that I suspect of causing a security problem for at least one of my previous employers. Well worth spreading awareness IMO.
- xeraa 2y agoA: "I'm betting..." B: "Could be, or maybe..." — once you reach E it's probably a statement. That sounds almost like the definition of how to start a rumor... Since we don't maintain private forks for the Elasticsearch repository (maybe for someone's short lived feature development), the problem of private or deleted forks shouldn't be an issue here.
- jimberlage 2y agoI would bet money that Elastic uses a Terraform provider for Github and they marked repos private in an automated way, and the reverse API operation doesn't function in the same way. It's possible that any delay is them trying to figure out how to get Terraform back to a good state rather than making the repos public being this inherently hard thing.
- bilekas 2y ago> It's possible that any delay is them trying to figure out how to get Terraform back to a good state rather than making the repos public being this inherently hard thing. I don't know if it is Terraform, but if that was the case, it would actually be trivial to rollback the IaC terraform itself, or even from a previous statefile. All things considered it doesn't seem to be a destructive mistake, and not 18:00 on a Friday :)
- jimberlage 2y agoMy experience with non-AWS providers in TF is that they're less maintained and buggy - in theory this should be easy, but people seem very afraid of TF and I can picture this getting chaotic. But you're quite right that if they're comfortable enough, they should go into S3 and get a statefile they were happy with!
- xeraa 2y agoPermissions aren't the problem. But the upstream source of all the forks is wrong if you take a repo private, all stars from folks outside your organization are gone,... So you need GitHub support to restore everything. And the details how it happened are a bit different but it was a configuration error (making things too secure ) [I work for Elastic]
- luke-stanley 2y agoThis bears out the idea that the fastest way to get the truth on the Internet is to say something wrong first.
- hazzjm 2y agoThis may not be fully reversible: https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/managing-repository-settings/setting-repository-visibility https://docs.github.com/en/repositories/managing-your-reposi... "GitHub will detach public forks of the public repository and put them into a new network." "Stars and watchers for this repository will be permanently erased"
- OskarS 2y agoIf it's a serious enough issue, GitHub staff can almost certainly still step in and manually restore all that stuff if needed.
- dmezzetti 2y agoIt's back with 181 stars.
- wg0 2y agoNow probably Github can update the starts in the database with an adhoc query.
- dmezzetti 2y agoThey didn't in this case: https://news.ycombinator.com/item?id=31033758 https://news.ycombinator.com/item?id=31033758
- ffsm8 2y agoThat's a foss tool though, elastic is a for profit company and might be willing to pay money to have it restored/might already be a paying GitHub customer. And GitHub might have implemented something that let's them restore it after it wasn't possible before, as it's been 2 yrs since. Lots of possibilities that might change the outcome if elastic is lucky
- dmezzetti 2y ago
- dmezzetti 2y agoThis is a brutal mistake. "Stars and watchers for this repository will be permanently erased, which will affect repository rankings." https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/managing-repository-settings/setting-repository-visibility#consequences-of-changing-a-repositorys-visibility https://docs.github.com/en/repositories/managing-your-reposi...
- jve 2y agoIs it really a big deal for megaproject? Not like someone wouldn't know what elasticsearch is or where to look for source code. Yeah, there are billions of people on planet and some may be casually exploring some repository tops and stumbling upon and getting to know elasticsearch that way. But if one wants to find solution for search, I don't think github stars matter.
- horsawlarway 2y agoYeah, stars/watches don't seem like a huge deal to me - but the fork part is pretty bad. It breaks the upstream connection between repos for all the forks.
- xeraa 2y agoGitHub support can (and currently is) restore all of that. The fork network should already be fixed for Elasticsearch again [I work for Elastic]
- dmezzetti 2y agoGood to know. There was a similarly popular project that didn't get this benefit (https://news.ycombinator.com/item?id=31033758 https://news.ycombinator.com/item?id=31033758).
- xeraa 2y ago8 years ago someone accidentally deleted the elasticsearch repository (thinking it was their private fork ). Back then everything was restored, so I hope we get there again this time too
- leohonexus 2y agoAnd it's back up again.
- sansgame999 2y ago[flagged]
- sansgame999 2y ago[flagged]
- hggigg 2y agoIt's back now but I'll add we have private clones of everything we use and automation that pulls them daily. Has been very handy over the years.
- deleted 2y ago[deleted]