12 ms·
The Deletion of Docker.io/Bitnami
- Unirely01 1y ago[dead]
- notimetorelax 1y agoIs anyone working on mirroring the images and keeping them updated?
- kappuchino 1y agoThat only works for weeks or so, since they won't be updated, according to the PR. It's time to build your own from core / foundational images - something I recently learned and now seek to master.
- shellwizard 1y agoWould you kindly share how to do it?
- KronisLV 1y agoNot OP, but in general the process goes like this: - you pick a base image you want to use, like Alpine (small size, good security, sometimes compatibility issues) or Debian or Ubuntu LTS (medium size, okay security, good compatibility) or whatever you please - if you want a common base image for whatever you're building, you can add some tools on top of it, configuration, CAs or maybe use a specific shell; not a must but can be nice to have and leads to layer reuse - you build the image like you would any other, upload it wherever you please (be it Docker Hub, another registry, possibly something self-hosted like Sonatype Nexus): docker build -t "my-registry.com/base/ubuntu" -f "ubuntu.Dockerfile" . && docker push "my-registry.com/base/ubuntu" - then, when you're building something more specific, like a Python or JDK image or whatever, you base it on the common image, like: FROM my-registry.com/base/ubuntu - the same applies not just for language tooling and runtimes, but also for software like databases and key value stores and so on, albeit you'll need to figure out how to configure them better - as for any software you want to build, you also base it on your common images then Example of cleanly installing some packages on Ubuntu LTS (in this case, also doing package upgrades in the base image) when building the base image, without the package caches left over: FROM ubuntu:noble ... (your custom configuration here, default time zones, shells etc.) RUN apt-get update \ && apt-get upgrade -y \ && apt-get install -y \ curl \ wget \ net-tools \ traceroute \ iputils-ping \ zip \ unzip \ && apt-get clean \ && apt-get autoremove -y --purge \ && rm -rf /var/lib/apt/lists/* In general, you'll want any common base images to be as slim as possible, but on the other hand unless you're a bank having some tools for debugging are nice to have, in case you ever need to connect to the containers directly. In the end, it might look a bit like this: upstream image --> your own common base image --> your own PostgreSQL image upstream image --> your own common base image --> your own OpenJDK image --> your own Java application image In general, building container images like this will lead to bigger file sizes than grabbing an upstream image (e.g. eclipse-temurin:21-jdk-noble) but layer reuse will make this a bit less of an issue (if you have the same server running multiple images) and also it can be very nice to know what's in your images and have them be built in fairly straightforwards ways. Ofc you can make it way more advanced if you need to.
- shellwizard 1y agoThanks a ton for the lengthy explanation
- nofunsir 1y agoTo add, it's really satisfying to build your own, push it and host it on your own internal repo that anyone in your group can use. "Just go get the DEV image, Josh."
- nofunsir 1y agoWait... this whole time reading this thread, I'm racking my brain for what bitnami provided (I used to use them before docker came around. I never would have got Redmine up and going without them -- the install seemed so foreign.) that building a docker image couldn't, because surely everyone knows how to build one from scratch, right?... right? Is all the panic because everyone is trying to avoid learning how to actually install the pieces of software (once), and their magic (free) black boxes are going away? I recommend VS Code remote connections and docker builds via the docker extension to do rapid build-run-redo. Remember to make sure it works from scratch each time. You can automate them with Jenkins... (which came first, the Jenkins or the Jenkins Docker image?) I also recommend Platform One. (you'll need a smart card) I also recommend reading the particular software's documentation ;)
- Alcatros552 1y agoThats super silly, it's so easy to make docker images... especially if you have a fast connection you can build a proper image which is production ready in a few hours.. (eg.30-40 builds)
- runamok 1y agoIn brief you need to switch the registry from (iirc) docker.io/bitnami to docker.io/bitnamilegacy. Note that as of iirc tomorrow those images will no longer be updated. So the moment there is a high or critical cve you better have a plan to use a new image and likely helm chart or send broadcom cash. The old registry will continue to have a "latest" tag but this should not be used for production.
- finaard 1y agoAccording to the article the current situation already is a bit of a clusterfuck: The Photon images provide many other benefits not previously available to users of Debian images, including: - Drastically reduced CVE count (e.g., 100+ CVEs to in some cases 0)
- runamok 1y agoSure. My company is demoing Chainguard which is quite pricy for hardened images. Bitnami premium reportedly goes for $50k to $72k per year: https://devoriales.com/post/402/from-free-to-fee-how-broadcom-s-bitnami-monetization-disrupts-devops-infrastructure https://devoriales.com/post/402/from-free-to-fee-how-broadco...
- mrweasel 1y agoUpdating the Bitnami images is probably a bit of a challenge. From looking at them last year, I believe that they are build around a Bitnami style/framework. They are confusing at best. If you're Bitnami it probably made sense to do it the image the way they did, but for everyone else, it's just a massive complication. Personally I don't understand why anyone would have opted to use the Bitnami images for most things. They are really large and complex images and in most cases you'd probably be better of building your own images instead. My guess is that there's a very small overlap between people who want to maintain Docker images, and the people who chose to run Bitnamis images.
- tux3 1y agoThe Docker images are complex for the sake of the Helm charts, which sometimes need to pass down tons of parameters These aren't just for your laptop, they're supposed to be able to run in prod I'm still stuck with 3 bitnami charts that I keep updated by building from source, which includes also building the images, all on our private registry.
- mrweasel 1y agoThat makes some sense. I've only used Bitnami images with Docker compose or as standalone containers. In those case you're frequently better of just mounting in a configuration file, but that won't really work in Kubernetes. I would argue that if you run Kubernetes, then you frequently already have the resource to maintain your own images.
- raziel2p 1y agoYou'd also have to maintain the helm chart, which is arguably far more work. If you don't need the bitnami helm chart functionality, using more stock container images is easy and preferable.
- wink 1y agoI had not used bitnami images for.. probably 5 years at this point and they always seemed servicable in a pinch, usually used for testing and I when I brought this up recently I was also told (by k8s users) that the helm stuff is probably what actually has most people up in arms because it is very common. We're the minority who remember bitnami as a non-critical choice among many.
- MathiasPius 1y agoBetween the VMware licensing changes and this, it looks like Broadcom is making a serious play at dethroning Oracle as the most evil software vendor. It's a shame that competition for this position has been ramping up lately.
- elephantum 1y agoSo, are they evil because they decided to stop sponsoring free network egress?
- systemswizard 1y agoBroadcom is deciding to host it on their own registry and bear the associated cost of doing so. Not sure what this has to do with sponsoring network egress
- buzer 1y agoThe images are currently in Docker Hub. If $9/month (or $15, not 100% sure if $9 includes organizations) to keep those images available is too much for Bitnami I'm sure there are many organizations who wouldn't mind paying that bill for them (possibly even Docker Hub itself).
- runamok 1y agoDoes said network egress cost $50k per user?
- MathiasPius 1y agoOthers have already provided good answers. I wouldn't classify it as evil if all they did was to stop maintaining the images & charts, I recognise how much time, effort and money that takes. Companies and open source developers alike are free to say "We can no longer work on this". The evil part is in outright breaking people's systems, in violation of the implicit agreement established by having something be public in the first place. I know Broadcom inherited Bitnami as part of an acquisition and legally have no obligation to do anything, but ethically (which is why they are evil, not necessarily criminal) they absolutely have a duty to minimise the damage, which is 100% within their power & budget as others have pointed out. And this is before you even consider all the work unpaid contributors have put into Bitnami over the years (myself included).
- pveierland 1y agoWill any source to build new images remain available without subscription?
- elephantum 1y agoThey write in the press release, that the sources remain under Apache 2 license, they just stop distributing prebuilt images for free. Edit: As I see it's true. Source code for OCI images: https://github.com/bitnami/containers/tree/main/bitnami https://github.com/bitnami/containers/tree/main/bitnami Charts: https://github.com/bitnami/charts/tree/main/bitnami https://github.com/bitnami/charts/tree/main/bitnami
- pveierland 1y agoIs it clear whether the Debian image sources will continue to be maintained?
- elephantum 1y agoI do not see direct statements that they will stop maintaining sources in open source. We'll see :)
- Beltran 1y agoIt is at the top of the announcement. This only affects OCI images, not source code "The source code for containers and Helm charts remains available on GitHub under the Apache 2.0 license."
- elephantum 1y agoIt looks like setting up a mirror and CI/CD on top of Github might work for some time. ghcr is free for public images
- aeijdenberg 1y agoI've been thinking a lot about this kind of thing recently - and put a prototype up of htvend [1] that allows you to archive out dependencies during an image build. The idea being that if you have a mix of private/public dependencies that the upstream dependencies can be saved off locally as blobs allowing your build process to be able to be re-run in the future, even if the upstream assets become unavailable (as appears to be the case here). [1] https://github.com/continusec/htvend https://github.com/continusec/htvend
- temptemptemp111 1y ago[dead]
- raesene9 1y agoGood to see they decided to delay a bit and do some brownouts first. I took a quick look at the Docker hub stats (https://raesene.github.io/blog/2025/08/21/bitnami-deprecation/ https://raesene.github.io/blog/2025/08/21/bitnami-deprecatio...) and it looks like some of those images are still getting hundreds of thousands or even millions of pulls a week.
- zdkaster 1y agoThe list of images for the first brownout: external-dns, Kafka, Memcached, WordPress, Grafana, Cassandra, Prometheus, OpenLDAP, Thanos, Python.
- usrme 1y agoThanks for mentioning these! Do you know what are the official channels they're doing the announcements in? In the post they just mention the word "usual" with no clarification.
- carrodher 1y agohttps://github.com/bitnami/containers/issues/83267 https://github.com/bitnami/containers/issues/83267 I.e https://github.com/bitnami/containers/issues/83267#issuecomment-3232234927 https://github.com/bitnami/containers/issues/83267#issuecomm...
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- gexla 1y agoSnooping around, it seems the license costs $50K+ annually. I'm not their target market. ;)
- Valodim 1y agoFrom TFA > BSI is effectively democratizing security and compliance for open source so that it doesn’t require million-dollar contracts from vendors with sky-high valuations. I suppose 50k isn't a million dollar contract, but it's certainly also not "democratizing" anything
- gexla 1y agoDepending on your needs, this could be a bargain as advertised. It's only expensive relative to what you can build on your own, or what competitors offer.
- zdkaster 1y agoThe easiest strategy to be profitable as biz without acquiring new users base, lol :P
- deleted 1y ago[deleted]
- gexla 1y agoIt's a bit tricky to work through all the jargon, but it's my understanding that they are simply pulling the mass of things that they provide for free. You can still get the Docker files for their offerings (not sure they offer all tags though?") and you can even use the images from Docker Hub. But. What they are offering is considered "development" regardless of what you are using it for? In other words, NOT a production environment, because they aren't giving you a production environment (or at least what they define as a production environment.) What they give you for free is the "latest" and on a Debian system. What they offer as "secure" is running on Photon OS and goes through a security pipeline, etc. They aren't holding anything back aside from the services they provide.
- deleted 1y ago[deleted]
- quectophoton 1y agoUnderstandable. The way I see it, a software project has only (1) code you maintain or pay someone to maintain for you, and/or (2) throwaway code that you will eventually need to replace with an incompatible version. Nothing wrong with a project that is just gluing throwaway code because it's a gamble that usually pays off. But if that code is from third-party dependencies, just don't believe for a second that those dependencies (or any compatible forks) will outlive your project, or that their developers have any incentive at all to help you maintain your project alive.
- asimovDev 1y agoAnyone using their PHP images? Have you switched to FPM or started to build the bitnami images from source?
- repox 1y ago> Anyone using their PHP images? With FrankenPHP, I can't imagine why I'd choose Bitnami anymore.
- bjornsing 1y ago24 hours? Wouldn’t it be better to do shorter bouts of scheduled unavailability so unknowing people’s systems will boot up without manual intervention, but still generate lots of nasty logs / alerts?
- rollulus 1y agoI thought the opposite: 24h seems too brief to me, since many of their images are typically for long running servers, some people will receive a painful heads up only next year or later when their K8s pod gets scheduled to a new machine, requiring a (failing) pull.
- alias_neo 1y agoI'm glad this was top of Hacker News because I hadn't heard about this until now, and we'd only have found out once deployments started failing. It's not always a 5 minute job to switch to a different image with different configuration and retooling required. Fortunately, I started moving us away from Bitnami a little while ago because they started giving me the ick some time back, but a few stragglers remain.
- ctippett 1y agoIf I had to hazard a guess, it's so the downtime is noticed across various different timezones.
- prmoustache 1y agoIs "brownout" a common or standard term in the industry? First time I see it.
- aabhay 1y agoFirst heard about this when docker started rate limiting
- 01HNNWZ0MV43FF 1y agoYes I heard of GitHub doing it I think You intentionally break something just a little to force dependents to notice, before turning it off completely
- znpy 1y agoYes. Going from green to red is called “browning out”.
- mattkrause 1y agoIs that the origin? I thought it was an analogy to the electrical problem: flickering lights due to high demand.
- wafflemaker 1y agoDon't know the origin, but with no technical background past using Linux, I only ever heard of brownouts in contexts of failing (often 3rd world) electrical infrastructure. Mostly Africa and South America (don't mean to offend anybody living there, I know they're vast continents with many rich/infrastructure-stable countries too).
- lstodd 1y agoOrigin is the electrical grid overload which caused incandescent lights to literally "brown out", as has been mentioned here. Later is was coopted to mean any problems with power supply not including outright drop to zero-zero/disconnections. cf microcontroller brown-out handling, also mentioned above. Then later it seems it was generalized to mean sort-of-non-terminal problem with supply of most anything.
- rahkiin 1y agoIt is sad to see how Broadcom cannot do padding right for mobile… But on topic: why not create docker.io/bsi and let /bitnami as is without new updates? Then nothing breaks; it just won’t be possible to do upgrades. You’ll then figure out why and possibly seamlessly switch to your own build or BSI.
- orthoxerox 1y agoBecause "bitnami" has brand value. It makes business sense to reuse the name for the new service you are trying to sell.
- Aeolun 1y agoAny brand value that bitnami has will be entirely destroyed by this incomprehensible change. People will associate the ‘bitnami’ namespace with “can’t possible utilize for long term production use”
- cube00 1y ago> It is sad to see how Broadcom cannot do padding right for mobile… It's on brand when you consider how badly the styling in Rally needs an update.
- david_allison 1y ago> But on topic: why not create docker.io/bsi and let /bitnami as is without new updates? If people are relying on you for automatic security updates, and you've decided to no longer provide these updates [for free], users should opt in to accept the risk. This would normally require user action (after a period of warnings/information), and having the fix look 'obviously' unsafe (`/bitnami ` ->`/bitnamilegacy`) feels reasonable.
- greatgib 1y agoI don't want to discount the work they are doing, and that it has no value, but a little bit shocking that they expect to go all commercial with this, in the Oracle way, while just "packaging" and so relying on open source software that they will not contribute to. Also, I'm a little bit wondering at how much all of this is really copyrightable in the end. Because if you keep it private I understand, but here it is basically for each package just a few lines, recipes to build the components that they don't own. Like trying to copyright the line "make build". And it might be each the single and obvious way to package the thing anyway. And speaking at the built artefacts, usually a binary distribution of third party open source software with common license should preserve the same rights to the user to access the source code, the instructions to build, and the right to redistribute...
- nopurpose 1y ago"Makefile" they have written and copyrighting is very non trivial and there are many man-months of effort. Configuring all sorts of software just with env vars and make it usable is not an easy feat. Have a look at https://github.com/bitnami/containers/tree/main/bitnami/postgresql https://github.com/bitnami/containers/tree/main/bitnami/post... as example. It might be worth a commercial license for some of their current user-base, no doubt.
- tomalbrc 1y agoThis has to be a joke, right? Months of effort for a makefile? In which world do people live these days
- WesolyKubeczek 1y agoTell me you haven't ever written even a moderately complex Makefile without telling me you haven't ever written even a moderately complex Makefile.
- majkinetor 1y agoYou seriously underestimate this in general case. Build system may be made in weeks, but is polished in months or even years, to account for all the different usage and environment scenarios. Otherwise, it's typically very fragile.
- r9l 1y agoI understand the vision behind trying to monetize these images for enterprise use, and can get down with the idea of maintaining both a “less secure but free” and “more secure but paid” model. But it appears that Broadcom’s intent is to over time force everything on to their enterprise offerings, which seems like a short sighted thing to do. Over time it will limit adoption and ultimately just make everyone go back to the native open source offering, cutting bitnami/Broadcom out of the loop. Broadcom really took the open source community backwards with this move IMO.
- imiric 1y agoI was never a fan of images from Bitnami. They always used complicated entrypoint and setup scripts, and introduced weird quirks to the software. More than once have I experienced issues or ran into configuration limitations with Bitnami images that didn't exist in official ones. So good riddance, as far as I'm concerned. I recommend anyone to avoid using them, and switch to official images or to build them yourself if they're not provided. That's the more secure approach, anyway.
- Xeago 1y agoI concur. There was supposedly a migration path from their postgresql image & chart to the postgresql-ha image & chart. Aside of having to re-mount the data disk and move things around manually; the -ha chart has numerous other issues where it always requires the master to be node-0. And with pods being rescheduled within a statefulset, good look having the master be on node-0. If there was an outage and the master is anywhere else, node-0 will just 'wait' for a master to come online, time out and shoot itself in the head thinking it is in a network partition and that retrying may help. The algorithm implemented by postgresql-ha turned out to be plain broken. Only able to survive pods neatly shutting down.
- zdkaster 1y agoAgreed, Bitnami images often feel over-engineered.
- raziel2p 1y agoSometimes, over engineered approaches are necessary to make older software work with environment variables and configmaps, because said software is still designed for traditional VM deployments.
- nloomans 1y agoWebsite got hugged to death: https://archive.is/plsp9 https://archive.is/plsp9
- skibz 1y agoIs anybody familiar with the differences between the new Bitnami Secure Images compared to images from, say, Chainguard?
- firesteelrain 1y agoIronBank is free though more DoD focused “If you’re looking to deploy multiple images, Chainguard’s per-image charges could quickly exceed Bitnami’s flat subscription cost. For example, licensing 3 images at $30K each would already reach $90K/year.” via Reddit. There is a new Catalog option. Their pricing is “custom” and not published online so all we have is Reddit anecdotes like here https://www.reddit.com/r/cybersecurity/comments/1ihy9sr/chainguard_users_is_paying_30k_per_docker_image/ https://www.reddit.com/r/cybersecurity/comments/1ihy9sr/chai...
- davidAlm 1y agoWhat timing…
- _cenw 1y ago> However, in order to sustain and support the dedicated team of engineers who maintain and build new charts and images, a subscription will be required if an organization needs the images and charts built and hosted in an OCI registry for them. This is such a naive take. Bitnami images were a sign of goodwill, a foot in the door at places were the hardened images were actually needed. They just couldn't compete with the better options on the market. This isn't a way to fix it, it's extortion. This is the same thing Terraform Cloud did, and I don't think that product is doing so hot. > Essentially, Bitnami has been the Jenkins of the internet for many years, but this has become unsustainable. It's other people's software, so it's very rich of Bitnami to accuse anyone of freeloading when their only contribution is adding config options to software that maybe corresponds to a level 2 on the OperatorFramework capability scale[1] - usually more of a 1. [1]: https://operatorframework.io/operator-capabilities/ https://operatorframework.io/operator-capabilities/
- debarshri 1y agoBuilding Infrastructure company is challenging in 2025. Previously, you would prioritize traction among developers over focusing on revenue. But that does not work in 2025. You are expected to make money from the get-go and are left with only enterprise customers and boy, that category is hard, as everyone is competing for that slice.
- esseph 1y agoThe outcomes of this behavior will be devastating and the problems will last for generations.
- philipallstar 1y agoWhy?
- withinboredom 1y agoAsking the billion dollar questions I see.
- niemandhier 1y agoIn the end, they have to do it because of the CSR, and they can do it because of the CSR. The European Union Cyber Residence Act has the potential to drastically change the open source ecosystem. The new regulation pushes the due diligence for security according to the Act towards any entity making a commercial offer based on open source software. Caveat emptor! For any enterprise, that means that they either do extensive documentation and security on open source components they use or they use foundation or enterprise-backed products. Note that pure uncommercial open source projects are exempt from the Act. I see this as a chance; we can still create open and free software, and those of us who desire financial compensation from those who make money with their work can offer as a necessary compliance framework as a service via a different entity.
- sofixa 1y agoI don't agree, they have to do all the CSR due diligence for the commercial offerings based on those open source projects, so there is no difference. The effort has to be done regardless if there's part of it that is open source and free, or not.
- tecleandor 1y agoThey don't have to. They can do the paid secure images for the commercial offerings and keep the other ones free. Or they could free the secure images for everyone if they feel like that.
- rcxdude 1y agoHmmmm, I'm not sure that's how it would be read. If there's any 'associated commercial activity', it falls under the CSR, even if the images themselves are free and open source. (That said, the overhead of the CSR is really not much, from what I can tell. It's pretty lightweight as EU standards go)
- ehnto 1y agoI advocated an enterprise to migrate away almost two years ago now. In enterprise time that means the project to do so is just about complete, so I am feeling pretty vindicated just now.
- lrvick 1y agoMeanwhile if anyone wants images with dramatically higher supply chain security than anything Bitnami ever offered, and free to the public forever, check out stagex. https://stagex.tools https://stagex.tools As the only multisigned, full source bootstrapped, reproducible, and container native distro that exists, it does not matter what registry you pull from because the digest is the same everywhere. We publish all images to both dockerhub and quay and signature checks pass either way so mirror anywhere you want. Anyone claiming they need to host in a particular registry for security is gaslighting you.
- mananaysiempre 1y agoI believe Guix also borrowed[1,2] the bootstrap chain[3,4,5] written by Jeremiah Orians, same as you did. [1] https://guix.gnu.org/en/blog/2023/the-full-source-bootstrap-building-from-source-all-the-way-down/ https://guix.gnu.org/en/blog/2023/the-full-source-bootstrap-... [2] https://www.gnu.org/software/mes/ https://www.gnu.org/software/mes/ [3] https://bootstrapping.miraheze.org/wiki/Stage0 https://bootstrapping.miraheze.org/wiki/Stage0 [4] https://savannah.nongnu.org/projects/stage0/ https://savannah.nongnu.org/projects/stage0/ [5] https://github.com/oriansj/bootstrap-seeds https://github.com/oriansj/bootstrap-seeds
- lrvick 1y agoThey absolutely did, and beat us to it. They were a fantastic reference, and we link to their blog posts in our readme. We even have a comparison with Guix there too. https://codeberg.org/stagex/stagex/#comparison https://codeberg.org/stagex/stagex/#comparison Guix optimized for maximizing package and architecture variety quickly and focused on retrofitting supply chain security tactics as a secondary goal later where possible. For example it allows for untrusted packages with binary blobs in the supply chain in cases like Haskell, Ada, and Qemu. Their supply chain security efforts are on a package by package basis and not mandatory, and still assume that all maintainers are unable to be compromised. Stagex by contrast is a supply-chain-security-first distro that can trust no single maintainer or computer by design. As such, Haskell and Ada are impossible to add support for right now as no bootstrap path exists for them. With Qemu we did the hard work of learning how to build all those binary blobs ourselves from source because we really needed it. Guix has by far the best supply chain security of any workstation distro out there, but I would never ever use it in the supply chain of anything bound for high value production use where no single person should be trusted. Guix is also very difficult to use in container environments as it has no signed/reproducible OCI images so you would have to build all that yourself. That is what stagex was built for.
- wilonth 1y agoI never understood the point of Bitnami. Every time I tried one of their image / package, it's a complicated mess full of custom and strange stuff, really hard to work with. Instead of a simple package of the software based on some familiar base, you get some weird enterprise garbage that follows strange conventions and a nightmare when you need to customize anything.
- andsens 1y ago100% agreed. I don’t understand the point of throwing all conventions out the window and building their own brittle scripts on top of it. All their images require docs to configure because none of the upstream documentation applies.
- ryeats 1y agoWhat are some resources for these conventions? As far as I can tell everyone else rolls their own bespoke images based off of of a projects image in order to customize the configuration.
- CodeCompost 1y agoBack in the day, Bitnami was a way to run Wordpress on Windows. They packaged it nicely so that you could install it on Windows Server. Nowdays that could get you fired, but back then Linux was not so widespread.
- eyegor 1y agoI've used them as a quick way to get rootless configured base images. Not sure if official repos provide those now, but it used to be a big hassle to get things like postgres images running without root in their containers. Although I often had to read through their dockerfiles to figure out the uid setup, where configs live, etc because they were not consistent between the various bitnami images.
- gadders 1y agoBitnami has changed. It used to just be an easy way for me to get a fully configured wordpress installable exe.
- zdkaster 1y agoYes, that was worth it. But, other images apart from WP are ...
- jolanlan 1y agoHack Tagalog
- HelloNurse 1y ago> The Photon images provide many other benefits not previously available to users of Debian images, including: Drastically reduced CVE count (e.g., 100+ CVEs to in some cases 0) This implies that they are deliberately offering Debian images with known unfixed security vulnerabilities. Sounds evil.
- hiatus 1y agoWhat are you talking about? Their images have _fewer_ CVEs.
- HelloNurse 1y agoAren't these Debian images equally "their", but available for free? Aren't the free images what Bitnami is discontinuing?
- daitangio 1y agoBitnami K8s helm charts was very well done but overall we can live without them. I would suggest boradcom to offer two tie: one free on they repository and one se t of more specific images. Burning the docker.io images is a dumb move.
- zoobab 1y agoI long advocated for a proper mirror and archive of the docker hub.
- de6u99er 1y agoAt my last gig I avoided Bitnami container images and Helm charts wherever possible. We (me plus an AWS consultant) used Karpenter Autoscaler, Envoy Gateway API, Gatekeeper OPA, Loki/Prometheus/Grafana Stack, EDB Postgres Operator, ... and deployed all through a single comprehensive terraform script to an EKS cluster. I tried to keep reliance on one single company as low ad possible. I even had a Plan B to replace S3 with MinIO in case the company decided to move to another cloud provider or an On Prem Kubernetes cluster. My recommendation to everyone is to avoid Cloud Vendor Lock-In from the start, and even if it's more initial work, to try to have as much as possible running on Kubernetes.
- brewmarche 1y agoAnyone know what happens to their Helm charts? As far as I know they remain available but do they work with non-Bitnami images? Can I use the official redis image instead of bitnami/redis with the Bitnami redis chart for example?
- usrme 1y agoThis is covered in the official GitHub issue: https://github.com/bitnami/charts/issues/35164 https://github.com/bitnami/charts/issues/35164 Q: What will happen to the existing OCI Helm charts? A: The already packaged Helm charts will remain available at docker.io/bitnamicharts as OCI artifacts, but they will no longer receive updates. Deploying these charts will not work out-of-the-box unless you override the bundled images with valid ones. *except for the BSI images included in the free community-tier subset.
- brewmarche 1y agoThat’s the first part, but will the charts work if I override the image name with a non-Bitnami one (e.g. docker.io/library/redis for redis)? Or do they bake in special stuff in their images that their charts rely on?
- zdkaster 1y agoIt is hard to tell if it will work or not. Just need to compare the image and test the override out.
- tux3 1y agoYou need the images that go with the charts. They have their own config system, which usually involves elaborate shell scripts in the images that receives parameters from the chart.
- zoobab 1y agoI visited Bitnami in San Francisco in 2017, still have a hoody. Broadcom is a rat.
- liveoneggs 1y agoThis is great new for me. I've always disliked bitnami's busy file layouts and other weird preferences.
- micw 1y agoI wonder what the effect of their helm charts will be. As far as I know the charts play well together with their own images but not necessarily with other images (like the official images). Also in some cases particular versions of helm charts are needed for particular versions of the application/images. So then there are no tagged versions of the images. How will this affect the future of the charts? The old (existing) charts can easily point to the old images in the legacy repository. But how about future development? Will this be stopped, so the charts will remain in the existing state? Or will it be continued but point to the new "latest" images - which means the chart/image combination could break at any time?
- vbezhenar 1y agoThis is such a weird state. > The Photon images provide many other benefits not previously available to users of Debian images, including: > Drastically reduced CVE count (e.g., 100+ CVEs to in some cases 0) How can Debian image contain 100+ CVEs? It's nonsense. Surely Debian is as secure as most other "commercial" distros. This CVE scanning stuff is clear FUD to promote commercial distros.
- indigodaddy 1y agoMaybe they're still counting back ports as CVEs? (Seems like scanning software still always false positives on a listening port that flags for a version and doesn't take into account backport and doesn't actually test for the CVE/vuln-- it's so exasperating weeding through reports thrown at you by "Security") But yeah seems unlikely that official Debian images would be full of CVEs unless they are not being regularly updated.
- ajd555 1y agoI use a few bitnami charts, and I'm now going to have to migrate them. For everyone here surprised that anyone would use them, here's some context from my perspective: as a small startup, having a pre-configured Kafka chart was a lifesaver, where I only needed to tweak the parameters I was interested in, which took me a lot less time than setting up a whole Kafka environment from scratch. It was relatively quick to setup, and felt like the right move to put something like Kafka in production (and not have to pay for Confluent when everything else is self hosted)
- spacemule 1y agoAlmost the same situation here. The only thing I used was Kafka, and I only used that to allow horizontal scaling of Argo Events sensors. Moved over to jetstream, saved a bunch of compute and memory, and realized I didn't need to scale Argo's sensors horizontally. Really, Bitnami's decision made my life easier in the end.
- morellonet 1y agoIf you’re looking for an alternative here, we (the team that built Twistlock) launched Minimus a few months ago to provide near zero CVE images built continuously from source. We have long experience in this space (we even wrote NIST SP 800-190) and I’d love to talk if we could help anyone. We also have drop in replacement images and charts for Bitnami, as we describe here: https://www.minimus.io/post/the-bitnami-pricing-changes-what-you-need-to-know https://www.minimus.io/post/the-bitnami-pricing-changes-what... If anyone has tech questions about how it all works, tools we use, customer scenarios, etc I’d be happy to discuss.
- CubsFan1060 1y agoThe main question as always is price. I was also interested in things like Chainguard and Docker secure images until I had a sales call with them and found out the price. I can’t seem to find the price anywhere on your site… I assume the reason for that is that it’s also nearly impossible for a non-fortune 500 to afford?
- morellonet 1y agoNope - we're early stage so we're really flexible not just on pricing but licensing terms too. We have many customers that are smaller startups, not just typical F500 types.
- mdaniel 1y agoPlease offer an implementation of the docker-credential helper, just like chainguard does with docker-credential-cgr[1], and don't put throwaway text that says "docker supports credential stores, so good luck to you" on your website https://docs.minimus.io/foundations/authentication#using-a-credential-store https://docs.minimus.io/foundations/authentication#using-a-c... 1: https://edu.chainguard.dev/chainguard/chainguard-images/chainguard-registry/authenticating/#authenticating-with-the-chainctl-credential-helper https://edu.chainguard.dev/chainguard/chainguard-images/chai...
- morellonet 1y ago
- sc68cal 1y agoBitnami has a number of docker images that are returned by search results (https://hub.docker.com/r/bitnami/redis-sentinel https://hub.docker.com/r/bitnami/redis-sentinel was one that I came across a while ago), and even before this I was concerned about how their images keep getting returned by search results. I thought I was paranoid, not wanting to have containers that rely on an organization that I didn't know much about (I didn't know that Bitnami was part of Broadcom/VMW), but this just proves my worries were well founded.
- silverwind 1y agoA shame that the docker.io registry is not immutable and allows deletion. I think many people are unaware images from that registry can break anytime.
- mdaniel 1y agoI'll be very curious to see if public.ecr drops theirs, too e.g. https://gallery.ecr.aws/bitnami/redis https://gallery.ecr.aws/bitnami/redis -> public.ecr.aws/bitnami/redis:8.2.1
- carrodher 1y agoJust to be crystal clear about the open source part: the code for all container images will continue to be maintained, kept up to date, and publicly accessible on GitHub (https://github.com/bitnami/containers https://github.com/bitnami/containers) under the Apache 2 license. What Bitnami is discontinuing is the publishing of prebuilt images to public registries. However, the build code remains available, so users can still build the images themselves and push them to their own registries by running a couple of commands.
- mmda-2 1y agoThank you thanos-io: https://github.com/thanos-io/thanos/issues/8381#issuecomment-3165102688 https://github.com/thanos-io/thanos/issues/8381#issuecomment...
- joseph2024 1y agoTo continue Bitnami within the community, I just created bitmoa yesterday. The goal is to replace bitnami image with minimal changes (e.g. ENV Names). https://github.com/bitmoa/containers https://github.com/bitmoa/containers https://github.com/bitmoa/charts https://github.com/bitmoa/charts
- geoman21 1y agoRapidFort has bitnami compatible images community (free) and curated images - www.hub.rapidfort.com