10 ms·
When you always published and built Docker images for the public you are creating an expectation, people will rely on that and will chose your software based on
by weli 1y ago
When you always published and built Docker images for the public you are creating an expectation, people will rely on that and will chose your software based on that expectation.
You suddenly deciding that you won't be offering updated Docker images especially after a CVE and with no prior notice (except a hidden commit 4 days ago that updated the README) is approaching malicious-level actions.
If they truly cared about their community and still wanted to go through the decision of not offering public docker builds the responsible thing to do is offer a warning period, start adding notices in the repo (gh and docker) and create an easy migration path, even endorse or help some community members who would be fine with taking care of the public builds of the image.
But no, they introduced the change, made no public statement about it, waited for someone to notice this, offered no explanation and went silent. After a huge CVE. Irresponsible.
- blueflow 1y ago> you are creating an expectation thats entitlement but seen from the other side.
- phatfish 1y agoThis only inconveniences open source freeloaders. Maybe you can volunteer some time to build Docker images?
- Ekaros 1y agoFork and build your own. Isn't that the whole open source ethos? Why it was invented and how it is intended to operate.
- bitfilped 1y agoIndeed, it feels like most people today treat open source as a placeholder for "work I don't have to do myself" and then get confused/upset when the project and their own interests no longer align and requires effort to bridge that gap in alignment.
- jraph 1y agoRant about the concept of open source freeloaders: there's no such thing as open source freeloaders. If the license explicitly gives you the right to use the stuff for free, there's nothing wrong in using this right. While it would be the right thing to give money / otherwise support the projects you rely on, it's on the software developers who decide to give these rights (I also think it's the right thing to do though) to figure out the business model. There's also nothing wrong in being upset about something you relied on disappearing overnight. If someone decides to provide something for free, they should give time for people to stop relying on this free stuff if they can. However, I also believe you should own it if you decide to ever rely on prebuilt Docker images. More specifically, if you are relying on prebuilt Docker images, you are letting someone else decide on a part of your infra. And yes, this someone else can decide to stop providing this part of your infra overnight. This is on you. I also don't find anything wrong in deciding to not provide binaries for your open source project, or to stop providing binaries, including docker images.
- supermatt 1y agofreeloader (OED): a person who takes advantage of others' generosity without giving anything in return. Sounds exactly like freeloading to me. You may think of that term negatively, but it is exactly what it is.
- jraph 1y agoWe also find the Wiktionary definition [1]: > One who does not contribute or pay appropriately; one who gets a free ride, etc. without paying a fair share. Which I believe is a bit more generic (giving back might not be the only way of being fair). > You may think of that term negatively But the term carries a negative judgement, what's the point of this term otherwise? Without the judgemental part, you'd just say "using for free" or something. The whole question is: is it fair to use open source software for free? And I believe it is. Actually, this is stronger than this: I believe people should feel free to use free software for free, and should not be looked down for doing so. This is key for freedom 0 to be an actual thing. (I'm not set in stone in this position and would be happy change my mind on this though). The notion of "giving back" can be discussed. I believe it is fair to get stuff from Person A for free and then helping B for free (later or earlier), in the hope that some person P will eventually help / have helped Person A for free for instance - this has the potential to provide everyone with a strong, helpful society and it would be even more enjoyable and reliable than a society that enforces pair to pair transactions. Indeed, if someone always takes stuff for free and never contributes to anything, I would find this unfair (unless for some reason they can't contribute back, because of a disability or something). I would call this freeloading. Society cannot work like this. But you need the bigger picture to assess this. When you start to try thinking about all this, the concepts of giving back, fairness, etc, it gets quite complicated. You also need to take in account the way society and the economical system works as a whole. What are the incentives, the motives, etc? Basically, qualifying someone as a "open source freeloader" without context just because they use freedom 0 without paying is quite bold and might not be fair. What if a company uses MinIO for free but provides some nice open source software? Just don't judge someone too fast. [1] https://en.wiktionary.org/wiki/freeloader https://en.wiktionary.org/wiki/freeloader
- Imustaskforhelp 1y agohttps://github.com/coollabsio/minio https://github.com/coollabsio/minio Coolify is already doing it but your comment is on the verge of being passive agressive. I wouldn't say these are open source freeloaders because they could be using things like watchtowers etc. which automatically update and it could be a very huge deal for automated updates especially after I saw that some recent CVE of minio happened. Simply put this just hurts the security of people running minio, I wouldn't say its freeloading, its actively harming the community. There are people in that thread who are paid customers as well saying that they lost a customer. I wouldn't say its freeloading. Minio already has some custom license or paid offering and I think that they make decent enough money out of it, providing docker files and then stopping to is kinda a shitty behaviour if they are unable to explain the reasons exactly why. I couldn't find the exact reasons on why they are doing what they are doing except making it hard for people to self host.
- crote 1y agoIt also inconveniences people who aren't freeloaders - or are you forgetting about the community? People submitting PRs aren't freeloaders: they are building the product for you. People filing bug reports aren't freeloaders: they are helping you solve the bugs in your code. People writing blog posts about setting up MinIO aren't freeloaders: they are writing documentation for you. People holding talks about it at conferences aren't freeloaders: they are essentially doing free marketing for you. Even someone leaving a "thumbs up" on a Github issue isn't a freeloader anymore! MinIO is also screwing over those active contributors, who are volunteering their time to improve the value of MinIO's product. That's not just "no longer helping freeloaders", that is "actively hurting the community". Besides, I'm sure the community has plenty of people who would be more than happy to volunteer time to build Docker images. Do you really think MinIO is going to let them publish it under the official "minio/minio" name so the community can still benefit from it without MinIO having to "support freeloaders", or do you think there could be an ulterior motive behind nuking the image - such as pushing people to the paid version?
- eptcyka 1y agoNobody signed any service level agreements, the docker images were provided on good will. If this is business critical for you, consider paying someone to solve this problem for you. Maybe even consider paying for a F/OSS solution so you are not the only one funding what should be a community effort. I do concede that they could’ve done a better job communicating these changes. But they don’t have to.
- jraph 1y agoTo me, there are two aspects: - if you rely on something, you should make sure you can reasonably rely on it (indeed, for instance by paying someone) - if you provide something, even for free, you should expect people will rely on it and you shouldn't pull the plug overnight if you can help it (of course, if you run out of business or something bad happens to you, that's something else). There is some kind of implicit commitment. Nobody should be entitled to receive free pre-built Docker images, but OTOH what's the point of even providing pre-built Docker images if you expect people not to rely on them? This feels pointless and you probably shouldn't start providing them in the first place if you have this expectation.
- cies 1y ago> if you provide something, even for free, you should expect people will rely on it and you shouldn't pull the plug overnight if you can help it Do you know their reasons for discontinuing? Are you even entitled to know that? It's their private matter. > of course, if you run out of business or something bad happens to you, that's something else Huh? So now everyone should let you know "it was out of their hands"? You have no idea how entitled you behave. > There is some kind of implicit commitment. No. That's just between your ears. It's putting fancy words on a feeling you have, not something that actually exists. > what's the point of even providing pre-built Docker images if you expect people not to rely on them? How do you know they had that expectation? And why do you care? > This feels pointless and you probably shouldn't start providing them in the first place if you have this expectation. You are excusing yourself for these commenters that behave like spoiled children: not thankful for what they got for free, but only bitching when it stops.
- arghwhat 1y agoThere is absolutely nothing malicious or suspicious about deciding not to provide docker images or binaries. Doing so does not hide or guard you against CVE's, which are entirely unrelated to such optional processes. Building minio is not only trivial, but is standard procedure - the latest release is in my distributions standard package repo, and they would not use prebuilt binaries. If you want that dockerized, the Dockerfile is shorter than the command-line to run said container. Dealing with Docker themselves, the corporation that has famously gone on a tax collection spree, is however quite the pain in the arse for a company. I can't stand the entitlement people (everyone, not one particular person) feel when they are provided things for free. Sure, minio is run by a corporation these days and this applies a bit more to smaller FOSS projects, but the complaint is that the silver spoon got replaced with a stainless steel one. You're still being fed for free, despite having done nothing for it. </rant>
- fragmede 1y agoIf it were for a feature request, it would feel more justified. People feeling entitled to making feature requests is one thing. Like they can get fucked. Contribute code or pay me. But if I let something loose out into the world that suddenly started causing problems because someone discovered you could stab people with it, I'd be going around making sure all of the copies I gave out it had a knife guard put in place.
- arghwhat 1y agoWe're not going around making kitchen knives illegal. I would go out of my way to mitigate footguns where an entirely legitimate use or legitimate source of confusion would turn foul, but if you chose to go out of your way to misuse it as a hammer or ignore documentation, then you're on your own. In this case, we're not even talking about that though, it's just a redundant prebuilt binary getting janked. I don't think it makes sense to provide prebuild binaries in the first place.
- weli 1y ago> There is absolutely nothing malicious or suspicious about deciding not to provide docker images or binaries. Doing so does not hide or guard you against CVE's, which are entirely unrelated to such optional processes. Agree. But that's not my point. If you start an oss project from scratch and you don't want to provide builds that's fine. If you start your oss project, provide public docker images since the beginning, start getting traction, create a commercial scheme for you to monetize the project and then suddenly make a rug pull on the public builds; that is indeed irresponsible, and borderline malicious when you do it without: 1. sufficient warning time. 2. after a recent cve. Is it malicious? I don't know. I prefer to believe in Hanlon's razor. Is it irresponsible? 100% yes.
- Hendrikto 1y ago> When you always published and built Docker images for the public you are creating an expectation That expectation does not entitle anybody to anything though. > people will rely on that and will chose your software based on that expectation That is their decision. Without any contract or promise, there is no obligation to anybody. > You suddenly deciding that you won't be offering updated Docker images […] is approaching malicious-level actions. I really don’t get this entitlement. “You are still doing unpaid work I benefit from, but you used to do more, therefore you are malicious.” is something I really cannot get behind.
- jphoward 1y agoHave you not seen some of the replies at the link? For example: "You are joking ?! The commit about source only is 4 days old (9e49d5e) We are currently paying for a license while using the open source version, you already removed the oidc code from UI console and now docker images. We are not happy by this lock-in. We will discuss this internally, but you may loose a paying customer with this behavior."
- jamespo 1y agoWhy would a paying customer use the open source version? Deployment in non-prod?
- fires10 1y agoI do this frequently. To prevent vendor lock in and allow us to easily pivot if pricing gets out line. We pay to support the project and get technical support when needed. Considering how little we use technical support. It should be a good deal for the company.
- johannes1234321 1y agoFor one: Using open source version often is a lot simpler. Commercial versions are hidden behind authentication and other weird systems to download. User experience can be a lot better. Then there are ideological reasons: Purposly trying to make the open source version sustainable. And then reduced lockin etc. by not using Enterprise only features by accident/convenience, which leaves the door open to leave the contract.
- hansmayer 1y ago> You suddenly deciding that you won't be offering updated Docker images especially after a CVE I hate to break it to you, but you know the CVEs are fixed in the source code, not in the Docker Image? Just build it yourself, the good folks have even provided a Dockerfile for it.
- itopaloglu83 1y agoThis is also becoming a trend with open source projects turning into source available projects with obscure and hidden ways to deploy them to prevent average users from running the software in their homelabs etc.
- jotaen 1y agoI don’t know much about the MinIO project specifically, but to me it seems to be a common misconception that just because a maintainer provides their software project under a permissive license (such as AGPL, MIT, etc.) would necessarily imply that they do this for particular ethical reasons, like caring about “the community” (whoever that is) or contributing something for the greater good. In the end, it’s just software made available under specific terms. While I understand the inconvenience for users if things change, it feels like part of the disappointment might stem from one-sided expectations.
- __s 1y agoCompare to bitnami: https://github.com/bitnami/charts/issues/35164 https://github.com/bitnami/charts/issues/35164 Recently switched from bitnami to minio here, with plenty heads up & they scheduled brown outs etc, along with legacy images to fallback on for users who don't get informed by anything until image gone
- deleted 1y ago[deleted]