5 ms·
Let me give you an alternative perspective. My startup pays Docker for their registry hosting services, for our private registry. However, some of our producti
by rjst01 2y ago
Let me give you an alternative perspective.
My startup pays Docker for their registry hosting services, for our private registry. However, some of our production machines are not set up to authenticate towards our account, because they are only running public containers.
Because of this change, we now need to either make sure that every machine is authenticated, or take the risk of a production outage in case we do too many pulls at once.
If we had instead simply mirrored everything into a registry at a big cloud provider, we would never have paid docker a cent for the privilege of having unplanned work foisted upon us.
- hkwerf 2y agoI get why this is annoying. However, if you are using docker's registry without authentication and you don't want to go through the effort of adding the credentials you already have, you are essentially relying on a free service for production already, which may be pulled any time without prior notice. You are already taking the risk of a production outage. Now it's just formalized that your limit is 10 pulls per IP per hour. I don't really get how this can shift your evaluation from using (and paying for) docker's registry to paying for your own registry. It seems orthogonal to the evaluation itself.
- gcapu 2y agoIf you offer a service, you have some responsibility towards your users. One of those responsibilities is to give enough notice about changes. IMO, this change doesn't provide enough notice. Why not making it a year, or at least a couple of months? Probably because they don't want people to have enough notice to force their hand.
- deleted 2y ago[deleted]
- lukeschlather 2y agoDidn't they institute more modest limits some time ago? Doesn't really seem like this is out of nowhere.
- hirako2000 2y agoYes they have. They are reducing the quota further.
- cratermoon 2y agoThey altered the deal. Pray they don't alter it any further.
- rad_gruchalski 2y agos/Pray/Pay/
- grayhatter 2y agoWhat principal are you using to suggest that responsibility comes from? I have a blog, do I have to give my readers notice before I turn off the service because I can't afford the next hosting charge? Isn't this almost exclusively going to effect engineers? Isn't it more of the engineer's responsibility not to allow their mission critical software to have such a fragile signal point of failure? > Probably because they don't want people to have enough notice to force their hand. He says without evidence, assuming bad faith.
- deleted 2y ago[deleted]
- Aurornis 2y ago> Why not making it a year, or at least a couple of months? Announced in September 2024: https://www.docker.com/blog/november-2024-updated-plans-announcement/ https://www.docker.com/blog/november-2024-updated-plans-anno... At least 6 months of notice.
- SkiFire13 2y agoThis is not announcing the 10 (or 40) pull/hr/ip
- jmb99 2y agoI use docker a few times a week and didn’t see that. Nor would I have seen this if I hadn’t opened HN today. Not exactly great notice.
- rad_gruchalski 2y agoIf you had an account you’d receive an email back in September 2024. I have received one…
- 4ndrewl 2y agoYou don't. You have responsibility towards your owners/shareholders. You only have to worry about your customers if they are going to leave. Non-paying users not so much - you're just cutting costs now zirp isn't a thing.
- gcapu 2y agoIf this was a public company I would put my tin foil hat and believe that it's a quick buck scheme to boost CEO pay. A short sighted action that is not in the shareholders interest. But I guess that's not the case? Who knows...
- 4ndrewl 2y agoAt this stage of the product lifecycle, free users are unlikely to ever give you money without some further "incentives". This shouldnt be news by now, especially on HN. If you're production service is relying on a free-tier someone else provides, you must have some business continuity built in. These are not philanthropic organisations.
- withinboredom 2y agoYes. But they are paying for this bandwidth, authenticated or not. This is just busy work, and I highly doubt it will make much of a difference. They should probably just charge more.
- rad_gruchalski 2y agoThey charge more.
- themgt 2y agoI don't really get how this can shift your evaluation from using (and paying for) docker's registry to paying for your own registry Announcing a new limitation that requires rolling out changes to prod with 1 week notice should absolutely shift your evaluation of whether you should pay for this company's services.
- guhidalg 2y agoI mean, there has never not been some issue with Docker Desktop that I have to remember to work around. We're all just collectively cargo culting that Docker containers are "the way" and putting up with these troubles is the price to pay.
- tomnipotent 2y agoHere's an announcement from September 2024. https://www.docker.com/blog/november-2024-updated-plans-announcement/ https://www.docker.com/blog/november-2024-updated-plans-anno...
- themgt 2y agoYou're right, that is "an announcement": At Docker, our mission is to empower development teams by providing the tools they need to ship secure, high-quality apps — FAST. Over the past few years, we’ve continually added value for our customers, responding to the evolving needs of individual developers and organizations alike. Today, we’re excited to announce significant updates to our Docker subscription plans that will deliver even more value, flexibility, and power to your development workflows. We’ve listened closely to our community, and the message is clear: Developers want tools that meet their current needs and evolve with new capabilities to meet their future needs. That’s why we’ve revamped our plans to include access to ALL the tools our most successful customers are leveraging — Docker Desktop, Docker Hub, Docker Build Cloud, Docker Scout, and Testcontainers Cloud. Our new unified suite makes it easier for development teams to access everything they need under one subscription with included consumption for each new product and the ability to add more as they need it. This gives every paid user full access, including consumption-based options, allowing developers to scale resources as their needs evolve. Whether customers are individual developers, members of small teams, or work in large enterprises, the refreshed Docker Personal, Docker Pro, Docker Team, and Docker Business plans ensure developers have the right tools at their fingertips. These changes increase access to Docker Hub across the board, bring more value into Docker Desktop, and grant access to the additional value and new capabilities we’ve delivered to development teams over the past few years. From Docker Scout’s advanced security and software supply chain insights to Docker Build Cloud’s productivity-generating cloud build capabilities, Docker provides developers with the tools to build, deploy, and verify applications faster and more efficiently. Sorry, where in this hyped up marketingspeak walloftext does it say "WARNING we are rugging your pulls per IPv4"?
- hedora 2y agoThe big problem is that the docker client makes it nearly impossible to audit a large deployment to make sure it’s not accidentally talking to docker hub. This is by design, according to docker. I’ve never encountered anyone at any of my employers that wanted to use docker hub for anything other than a one-time download of a base image like Ubuntu or Alpine. I’ve also never seen a CD deployment that doesn’t repeatedly accidentally pull in a docker hub dependency, and then occasionally have outages because of it. It’s also a massive security hole. Fork it.
- martinsnow 2y agoYou don't have to run docker. Containerd is available.
- leoqa 2y agoBlock the DNS if you don’t want dockerhub images. Rewrite it to your artifactory. This is really not complicated and your not entitled to unlimited anonymous usage of any service.
- a022311 2y agoThat will most likely fail, since the daemon tries to connect to the registry with SSL and your registry will not have the same SSL certificate as Docker Hub. I don't know if a proxy could solve this.
- ndriscoll 2y agoRight but then you notice the failing CI job and fix it to correctly pull from your artifact repository. It's definitely doable. We require using an internal repo at my work where we run things like vulnerability scanners.
- hkwerf 2y ago> since the daemon tries to connect to the registry with SSL If you rewrite DNS, you should of course also have a custom CA trusted by your container engine as well as appropriate certificates and host configurations for your registry. You'll always need to take these steps if you want to go the rewrite-DNS path for isolation from external services because some proprietary tool forces you to use those services.
- popalchemist 2y agoIt's bait and switch that has the stakes of "adopt our new policy, that makes us money, that you never signed up for, or your business fails." That's a gun to the head. Not an acceptable interaction. This will be the end of Docker Hub if they don't walk back.
- hirako2000 2y agoTo think of malice is mistaken. It's incompetence. Docker doesn't know how to monetize.
- atkailash 2y ago[dead]
- josteink 2y ago> If we had instead simply mirrored everything into a registry at a big cloud provider You would have had to authenticate to access that repo as well.
- lowercased 2y agoWouldn't they get a choice as to what type of authentication they want to use then? I'd assume they could limit access in multiple ways, vs just the dockerhub way.
- rjst01 2y agoAmazon ECR for instance provides the option to host a public registry.
- wiether 2y ago> Data transferred out from public repositories is limited by source IP when an AWS account is not used. https://aws.amazon.com/ecr/pricing/?nc1=h_ls https://aws.amazon.com/ecr/pricing/?nc1=h_ls > For unauthenticated customers, Amazon ECR Public supports up to 500GB of data per month. https://docs.aws.amazon.com/AmazonECR/latest/public/public-service-quotas.html https://docs.aws.amazon.com/AmazonECR/latest/public/public-s... I don't see how it's better.
- a022311 2y ago`mirror.gcr.io` works fine for many popular images on Docker Hub.
- orochimaaru 2y agoThey should have provided more notice. Your case is simply prioritizing work that you would have wanted to complete anyway. As a paying customer you could check if your unauthenticated requests can go via specific outbound IP addresses that they can then whitelist? I’m not sure but they may be inclined to provide exceptions for paying customers - hopefully.
- rjst01 2y ago> Your case is simply prioritizing work that you would have wanted to complete anyway It's busy-work that provides no business benefit, but-for our supplier's problems. > specific outbound IP addresses that they can then whitelist And then we have an on-going burden of making sure the list is kept up to date. Too risky, IMO.
- troutwine 2y ago> It's busy-work that provides no business benefit, but-for our supplier's problems. I dunno, if I were paying for a particular quality-of-service I'd want my requests authenticated so I can make claims if that QoS is breached. Relying on public pulls negates that. Making sure you can hold your suppliers to contract terms is basic due diligence.
- rjst01 2y agoIt is a trade-off. For many services I would absolutely agree with you, but for hosting public open-source binaries, well, that really should just work, and there's value in keeping our infrastructure simpler.
- cpuguy83 2y agoThis was announced last year.
- icehawk 2y agoThis sounds like its only talking about authenticated pulls: > We’re introducing image pull and storage limits for Docker Hub. This will impact less than 3% of accounts, the highest commercial consumers. For many of our Docker Team and Docker Business customers with Service Accounts, the new higher image pull limits will eliminate previously incurred fees.
- dbalatero 2y agoYou might try complaining and see if they give you an extension.
- londons_explore 2y ago> take the risk of a production outage in case we do too many pulls at once. And the exact time you have some production emergency is probably the exact time you have a lot of containers being pulled as every node rolls forward/back rapidly... And then docker.io rate limits you and suddenly your 10 minute outage becomes a 1 hour outage whilst someone plays a wild goose chase trying to track down every docker hub reference and point it at some local mirror/cache.
- wat10000 2y agoI mean, don’t build your production environment to rely on some other company’s free tier, and then act surprised when they throttle high usage. And yes, you’re still using the free tier even if you pay them, if your usage doesn’t have any connection to your paid account.
- prepend 2y agoCompanies that change their free tiers also change their paid tiers. I just don’t build my environment to rely on unstable companies. That’s sort of the comedy of second order effects as by reducing the amount of free stuff, I think Docker will end up reducing their paid customers.
- rad_gruchalski 2y ago> If we had instead simply mirrored everything into a registry at a big cloud provider, we would never have paid docker a cent for the privilege of having unplanned work foisted upon us. Indeed, you’d be paying the big cloud provider instead, most likely more than you pay today. Go figure.
- zmgsabst 2y agoI’d you’re using popular images, they're probably free. https://gallery.ecr.aws/docker/?page=1 https://gallery.ecr.aws/docker/?page=1
- rad_gruchalski 2y agoPlease reread the comment I replied to.
- jjfanboy 2y agoI just cannot imagine going into public and saying, roughly the equivalent of I want free unlimited bandwidth because I'm too lazy to do the very basics of managing my own infra. > If we had instead simply mirrored everything into a registry at a big cloud provider, we would never have paid docker a cent for the privilege of having unplanned work foisted upon us. I mean, if one is unwilling to bother to login to docker on their boxes, is this really even an actual option? Hm.
- SSLy 2y ago> mirrored everything into a registry at a big cloud provider https://cloud.google.com/artifact-registry/docs/pull-cached-dockerhub-images https://cloud.google.com/artifact-registry/docs/pull-cached-...
- cyanydeez 2y agoYou can setup your own registry. You're complaining about now having to do your own IT. this isn't a counterpoint is rewrapping the same point: free services for commercial enterprise is a counterproductive business plan
- vv_ 2y agoHow can you make Docker pull debian:latest from your own registry instead of the official Docker registry, without explicitly specifying <my_registry>/debian:latest?
- cyanydeez 2y agoUh. https://stackoverflow.com/questions/33054369/how-to-change-the-default-docker-registry-from-docker-io-to-my-private-registry https://stackoverflow.com/questions/33054369/how-to-change-t...
- fennecbutt 2y agoSo it goes. You're a business, pay to make the changes. It's a business expense. Docker ain't doing anything that their agreements/licenses say they can't do. It's not fair, people shout. Neither are second homes when people don't even have their first but that doesn't seem to be a popular opinion on here.
- jdhendrickson 2y agoDevsec/ops guy here, the fact that you were pulling public images at all ever is the thing that is insane to me.
- rjst01 2y agoWhy? We are running the exact same images that we would be mirroring into and pulling from our private registry if we were doing that, pinned to the sha256sum.