13 ms·
We need a federation of forges
- whereistejas 5mo agotangled is a really cool project; the most important feature it provides is that it is jujutsu first.
- Kye 5mo agoI assume you don't mean Tangled is an expert martial artist. Can you translate this to not-a-dev-but-uses-git?
- siarune 5mo agoJujutsu is a git-compatible version control system
- jakelazaroff 5mo agojujutsu is a different version control system: https://www.jj-vcs.dev/ https://www.jj-vcs.dev/
- DauntingPear7 5mo agoThey’re referring to the Jujutsu VCS https://docs.jj-vcs.dev/latest/ https://docs.jj-vcs.dev/latest/
- whereistejas 5mo agooopsie; should have added links. `jj` is a wrapper around git and offers a much better dev-ex for managing changes. it has features like: - conflicts are first class citizens - `rebase` is the default mode; there is no need for an interactive rebase mode. - all descendant changes automatically rebase - a much more intuitive version of `git reflog`. in `jj`, we have `jj op log` - cheap branching: branches in `jj` are just tags (or bookmarks) that can be moved around
- d12bb 5mo ago> `jj` is a wrapper around git and offers a much better dev-ex for managing changes. You are mistaken there: Git is just one (of currently two) backend of the jj version control system. It’s far from being a wrapper.
- whereistejas 5mo agoJust because `jj` wraps around git doesn't mean it cannot have another backend. My comment doesn't imply that it only wraps around `git`. More importantly, the other backend which `jj` offers is (afaik) exclusively used at Google. Unless you are a Googler you will be using `jj` with `git`. Also, the comment was aimed at a person who is obviously very invested in `git`. I was doing my best to offer them a description of `jj` they could swallow. PS: pedantic people are annoying.
- horsawlarway 5mo agoI don't really see it. I used JJ for a bit, but I personally really, really dislike the anonymous branch approach it forces you into. Branches are just useful conceptually, at least to me. For the same reason I like my documents grouped into folders. Frankly - I think JJ just ended up taking up far more mental bandwidth than git. Simple operations need generated ids, commands require complicated input (ex - the entire revset thing), I have to be constantly thinking about the tool and its structure. It feels really oversold to me. It's solving problems for people who live in source control, not problems for people who just want snapshots of code every now and then. Hell - just look at some of the example commands from the suggested tutorial: jj new ym z r yx m -m "merge: steve's branch" jj log -r 'ancestors(trunk, 2)' jj new o jj log -r '@ | ancestors(remote_bookmarks().., 2) | trunk()' --- With all due respect, if the intro tutorial to your tool includes a command having to literally write function names in quoted commands, or run a command with fucking 8 (EIGHT!) arguments... You've jumped the shark. Not trying to harsh anyone's buzz - if you like it... great, it's clearly quite powerful. But it misses the mark for me. I want "just powerful enough" with minimal mental overhead.
- steveklabnik 5mo agoIf you cherry pick complicated commands, and remove all context, sure, they look cryptic. I wrote that tutorial, and literally only one of those is relevant to my day to day work: jj new o, which means “make a new change on top of the change named o”. Yes, if you remove the context that “o” is on your screen and highlighted, it looks complex. It’s the same with the other “jj new” command: you’re producing a merge by giving it every branch you want to merge together. If you’re merging five branches into one, you need to provide five identifiers for those branches. It could not be simpler than this. And -m adds a message, same as git. The other two are showing off the power of the revset language; you’re not typing this stuff in yourself more than once, and if you are, you use an alias so that it’s shorter and easier to use.
- horsawlarway 5mo ago> If you cherry pick complicated commands, and remove all context, sure, they look cryptic. Sure I'm definitely not playing fair, but I am cherry picking from the intro tutorial you put together, so I'm not going crazy either :P I think my primary issue is that jj feels like it wants to control how I work more than git does. Mentally - I just don't want to have to think about changes as often as jj seems to want to think about them. And maybe it's an intro phase, or a thing you eventually build past (I only played with it for a week or two) - but it felt like a lot of focus went intro structuring my work, instead of doing my work. Basically - the vibe I got from it was: if you're a person who really likes making checklists, or complex tickets with subtasks and groupings and labels - jj is something you're going to like. If you're just interested in writing code and not so interested in source control outside of the ability to occasionally "snapshot this folder"... it's probably not going to be your thing. > The other two are showing off the power of the revset language; you’re not typing this stuff in yourself more than once, and if you are, you use an alias so that it’s shorter and easier to use. This is exactly my point. I use git every day on the command line. I have ZERO aliases for it (seriously). If my source control tool has reached the complexity where I feel like I need an alias for commands in it... it's gotten too powerful. And git is definitely not "off the hook" here, it's absolutely got the same deep end, and if you live in that space, sure - jj might be really nice. But I strive to avoid living in that space. basically: I don't want to do jujitsu, I want to do the occasional somersault and call it a day.
- d_silin 5mo agoFederated solutions seem to be the future, after once-beloved provider becomes the crumbling monopoly.
- mikepurvis 5mo agoIt's not a clear one-way trip though. The "original" blogosphere of the 2000s was heavily federated with MovableType supporting trackbacks and then later systems automating that further with pingbacks. Ultimately it all fell to spam and hosting complexity though, and now almost all blogs are on a handful of centralized hosts again. Spam/moderation is going to be the biggest hurdle to overcome with any distributed forge effort. It'll likely come down to some kind of web-of-trust/vouching system, but it's delicate balancing ease of access with not making it a slog to constantly manage spam.
- jauntywundrkind 5mo agoAt least with atproto, we can see if an account has history and activity, see if their public data looks at all legit. The ability to deal with spam and disinformation seems so much radically better than anything else we've been able to work from.
- hamdingers 5mo agoHas it ever worked?
- d_silin 5mo agoMastodon, Discord?
- hamdingers 5mo agoIs Mastodon successful enough to be called "the future" of its niche? MAU is 1/3rd what it was at the peak, and bluesky + mastodon MAU combined is microscopic compared to twitter (I use none of these services, no dog in this fight, just looking at numbers). Discord is not federated.
- ghc 5mo agoIs there really nothing like BitTorrent for git, or have we just not heard about it because of GitHub's network effects? It feels like this problem was solved long ago for binaries.
- icy 5mo agoThere is! https://radicle.dev https://radicle.dev :)
- swed420 5mo agoFrom today: HardenedBSD Is Now Officially on Radicle https://news.ycombinator.com/item?id=47944864 https://news.ycombinator.com/item?id=47944864
- ghc 5mo agoOh, that's pretty cool! Now I can't decide whether that approach or one based on AT is better...
- icy 5mo agoPick whichever. We <3 the Radicle team and they're admittedly solving a much harder problem (gossiping git!) and rather elegantly at that.
- pfraze 5mo agoYeah I’ve met the Radicle people a couple times. I’ve never given it a thorough review but, for their goals, their designs have always seemed strong, and they’re pleasant people to chat with. The main difference was atproto wanted to tackle scale, so we went with a servers & aggregation model. Radicle is going for device-to-device networking as a primary goal.
- Ericson2314 5mo agoDo you think it will be possible to use them together? Having some sort of unified distributed system is intriguing to me. (e.g. can the Radical foundation and AT-proto foundation integrate, even?)
- estimator7292 5mo agoI don't think calling your git server a "knot" is going to go over well with certain large subsections of the OSS community. Or rather, it will go over way too well.
- Kye 5mo agoFurry developers are all professionals and won't have a giggle fit every time they think about it.
- short_sells_poo 5mo agoI don't get the joke and I'm a bit too worried about googling this on my work pc, can you please enlighten me what's up with the word knot :D
- Kye 5mo agoThe knot is the bit that causes two canids to get en-tangled after getting frisky.
- icy 5mo agoHa, we heard this but decided to stick to it because hey, it isn't hurting anyone. No harm in a little bit of fun.
- jerojero 5mo ago"There are 4 standards that try to solve this problem, its too many, we need one that finally unifies it all and solves the problem once and for all" "There are 5 standards that..." Jokes aside, I think we need stronger arguments as to why something like activity pub is not good enough to solve the problem instead of trying to come up a new way of solving the "decentralized comms" problem.
- nerdypepper 5mo agoits linked in the original post as well, but here is an explanation of why activitypub is not a good fit for this problem, by the authors of ForgeFed themselves: https://forgefed.org/blog/actor-programming/ https://forgefed.org/blog/actor-programming/
- compyman 5mo agoReading that - I'm really not sure that AT Protocol has a much better story there either. (as I understand it) the data has to live in a PDS, PDS are keyed by accounts, so you are similarly stymied for collaborative projects? I guess AT Proto is still a real work in progress so maybe that story has improved since the last time I checked it out.
- knowtheory 5mo agoYeah, capability for group permissions is a key part of the work happening on permissioned data in ATproto right now. https://dholms.leaflet.pub/3meluqcwky22a https://dholms.leaflet.pub/3meluqcwky22a https://dholms.leaflet.pub/3mfrsbcn2gk2a https://dholms.leaflet.pub/3mfrsbcn2gk2a https://dholms.leaflet.pub/3mguviy6iks2a https://dholms.leaflet.pub/3mguviy6iks2a https://dholms.leaflet.pub/3mhj6bcqats2o https://dholms.leaflet.pub/3mhj6bcqats2o
- deleted 5mo ago[deleted]
- pfraze 5mo ago
- short_sells_poo 5mo agoSlight tangent: the post says that github is crumbling. Can someone get me up to date on what's going on please? Admittedly I'm not following tech drama particularly closely, but I thought I'd have heard if a major thing like github was going down the chute.
- gempir 5mo agoA simple search holds the answers https://hn.algolia.com/?dateRange=pastMonth&page=0&prefix=false&query=github&sort=byPopularity&type=story https://hn.algolia.com/?dateRange=pastMonth&page=0&prefix=fa...
- AnEro 5mo agoSo there has been increasing issues form the github side for the past year and I believe they also just lost alot of customer/user data on top of several critical vulnribilities and bugs in base service and in actions. My POV: Github actions are inconsistent in billing, security and require alot of attention to do right. Github has worse uptime than alot of free online videogame services, when most enterprise and business world leans on it for developers. Leaving a lot of users with terrible experience the past year having to constantly examine github firefighting for issues around availability, security, and billing instead of doing work that makes the company/people money. Example walk through of securing github actions for ci/cd and managing SBOM python dependancy/supply chains (giant complexity) [1], Github has remote code execution[2], Uptime by 3rd party tracker shows 86% past 90 days. (First quarter in 2 years where they didn't have atleast one month above 90% uptime) [3] [1] https://astral.sh/blog/open-source-security-at-astral https://astral.sh/blog/open-source-security-at-astral [2] https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-38... [3] https://mrshu.github.io/github-statuses/ https://mrshu.github.io/github-statuses/
- MYEUHD 5mo agoGithub has frequent downtime: https://mrshu.github.io/github-statuses/ https://mrshu.github.io/github-statuses/
- mbStavola 5mo agohttps://www.githubstatus.com/ https://www.githubstatus.com/ In particular: https://www.githubstatus.com/history https://www.githubstatus.com/history
- galbar 5mo agoI was just thinking about forge federation this morning. It'd be nice to base the federation on email, which has been working fine for decades (boring tech and all that), and build UIs on top of it to facilitate collaboration.
- bfrog 5mo agoradicle.xyz also does the distributed/seeded forge setup and I think does a nice job of it already.
- ddosmax556 5mo agoThis looks cool but the issue github is dealing with is exponential usage. They're trying to 30x their capacity right now - let that sink in! Microsoft here or there, any company would be struggling under this load. And I frankly don't think that any ideology driven alternative will ever be able to provide better uptime under the same load - or any alternative period, for that matter. We're just living in times where everyone is catching up with the capabilities of agents, and it was obvious that things like this will happen 12 months ago. Good luck for your project though!
- hmokiguess 5mo agoYou frame the symptom as the problem though. Others seem to be attributing this to Azure migration and Copilot overhead tightly coupled to GitHub infrastructure.
- ddosmax556 5mo agoNo the problem is that github has to stem exponential usage increase and prepare 30x of their capacity, that's not symptom, that's problem.
- hmokiguess 5mo agoIt's both and, it's a symptom of exponential usage and a problem with infrastructure. The question you aren't asking is "Why is it a problem with GitHub's infrastructure?" the answer to that lies somewhere in between: Microsoft + Azure + Copilot. Now tell me which of those have anything to do with GitHub as we know it?
- ddosmax556 5mo agoWhy is it a problem with Githubs infrastructure!? Bcs any website on the planet will struggle when they have to fulfill 30x capacity within 1-2y, no matter which tech stack they're built on, including federated networks. I'm not sure why you're throwikg Copilot in there, you don't like it? Github as we know it is gone, forever, it will never come back, except for niche hobby clones with .001% capacity that nobody will use. Agents are re-defining what software engineering means, they already have, right now,and are continuikg to do so, it's just that hackernews is lagging 6 months behind for some reason.
- colesantiago 5mo agoTangled is VC funded just like initially how GitHub was: https://blog.tangled.org/seed/ https://blog.tangled.org/seed/ It always ends the same way. enshittification. Also: > Bain Capital Crypto is an investor. A crypto VC is invested in this. This is not the solution.
- knotbin 5mo agoYou completely missed the point. The point isn't that you should find a company that you trust and think is ethical. The point is to shift the power dynamics so you don't have to trust anyone. That's what building on ATproto does. Tangled is also fully open source and anyone can host their own knot and AppView.
- colesantiago 5mo agoYou seem to have missed the fact that Bluesky is funded by the same crypto VC. Look how well that has turned out even though Bluesky is open source. Tangled is not funded by the community. It would be better if it was rather than it be owned by VCs.
- knotbin 5mo ago> Look how well that has turned out even though Bluesky is open source. ??? Bluesky can make decisions, mistakes, or moderation choices you disagree with and you can just go to https://blacksky.community https://blacksky.community, a completely independent AppView with different moderation that was up for the entirety of a 24hr outage Bluesky recently had. I'd say AT Protocol is turning out pretty well.
- colesantiago 5mo ago> ??? Bluesky can make decisions, mistakes, or moderation choices you disagree with Bluesky PBC still has major influence of the AT Protocol. > and you can just go to https://blacksky.community https://blacksky.community, a completely independent AppView Swapping one broken chair for another broken chair won’t cut it. Development and steering is subsidised by VCs funding Bluesky at this point. (especially a crypto VC) Have you ever asked whats in it for them? What plans are they going to put into the protocol? I can see the AT Protocol shoving crypto payments or whatever in their insatiable quest for growth and ROI, because when the funding money runs out when BS miss their growth targets, this is what happens. And for Tangled’s monetisation path, it is questionable. So no. Not a solution.
- code-blooded 5mo agoTangled is VC sponsored. It doesn't scream stability to me, but rather "we need to grow at all cost". I don't see the appeal. Even though it's federated, when development stops, who will be there to fix bugs and maintain it?
- icy 5mo agoTangled is built entirely in the open: https://tangled.org/tangled.org/core https://tangled.org/tangled.org/core, and our primary goal is to be "permanent software"—i.e. be fully reproducible and entirely self-hostable at minimal cost. VC money is a means to an end. We're both Indian founders in Europe, and grants are nigh on impossible to find (4–12+ months for anything to materialize). VC is quite simply the quickest way for us to build a team, setup infra and accelerate development. We're also incredibly aligned with our investors on our goals (we took 6+ months to find the perfect partner for this).
- xandrius 5mo agoMmmm still rather not support this. I prefer slow and steady wins the race kind of project. Good luck!
- baq 5mo agowhen in doubt, copy astral's exit strategy and get bought out by a foundation model lab. (yeah n=1, but that's still greater than 0 ;))
- shimman 5mo agoVC money is absolutely not a means to an end, what is signals is that the company doesn't care about community and only cares about profit. I'm with the OP you're replying to. Taking VC is an albatross that means a large portion of devs will never trust you or use your services (outside of bleeding your funds dry). If this place truly cared about community they should have made a non-profit or some type of NGO, basically anything with a true community governance model. Not the current model of caring about money over a community. We currently live in a society that solely cares about money and seriously doubt devs want to continue uplifting the current system that only benefits the rich at the expense of everyone else. How many board seats does the company plan on giving to the community to ensure enshittification doesn't occur?
- NetOpWibby 5mo agoLast time I tried Tangled they had no concept of private repos. That’s the only thing keeping me on GitHub (oh, and my massive likes collection, I use those as bookmarks). I’m self-hosting with cgit, maybe I could move my private repos to SourceHut? Idk.
- tao_oat 5mo agoThere's an AT protocol working group for private data: https://atproto.wiki/en/working-groups/private-data https://atproto.wiki/en/working-groups/private-data But you're right, the protocol doesn't currently support this.
- madamelic 5mo agoThe problem I feel with federated solutions is basically the 'cold start' problem. When you are wanting to join a federated network, you have two choices: join a pre-existing server thereby creating the exact same problem you are escaping, ie: a giant server that holds you to its whims, BUT you do get a big network to begin with. Or you start your own server but your network is zero, discoverability is zero, your feed is empty, and you have to convince other sites to federate with you / not block you for the crime of being a 1 person server / etc. Am I alone in this feeling or am I just doing federation wrong? (But also this may just be a problem / quirk of Mastodon)
- knotbin 5mo agoYeah that's why Tangled didn't go with ActivityPub (Mastodon protocol) and went with ATproto instead, which is specifically built to solve that problem, so individual servers are all aggregated by centralized AppViews (that anyone can host) that give a singular unified "view" of the network that is just as cohesive as a centralized network feels.
- madamelic 5mo agoAh ok! Thanks for digging up info that I didn't go looking for myself. That's fantastic news.
- class4behavior 5mo agoATProto simply ignores the need for decentralizing incentives on a human/community level. What we get is a sort of a "top-down" federation rather than a grass-roots one. Whoever invests in the infra ends up running a domain. I mean, practically no one is aware of any other ATPROTO provider other than Bluesky whereas the issue with AP is merely the lack of better implementations, so mastodon.social got the most attention and the hype died off with niche success.
- danabramov 5mo agoThere’s no such thing as “running a domain” or “atproto provider” in atproto. You’re approaching it with a Mastodon/AP mindset and it doesn’t match that. In atproto, there’s two axes. One is hosting. Bluesky offers hosting but some people host on their own (it’s just a Docker container with sqlite), some on Cloudflare, some on community-hosted nodes like https://npmx.dev https://npmx.dev and https://selfhosted.social https://selfhosted.social. From app perspective it looks exactly the same way (unlike in Mastodon where “hosting” = “choosing a community”) and you can switch hosting anytime. Another axis is apps. Apps aggregate from data from all hosts. Bluesky is an app, Tangled is an app, Leaflet is an app, Wisp is an app, Semble is an app, and so on. Those can all aggregate over the same data (which enables cross-app interop) but they don’t have to (eg Bluesky doesn’t overlap with Tangled much except that Tangled can reuse Bluesky avatar on login). Generally you don’t have people running copies of the same app (as in Mastodon) which is why there aren’t many “blueskyes”. But when someone has an incentive, they can. (Eg Blacksky is a complete fork including server and DB, allowing their own moderation decisions over same data.) Similarly you can build your own app on top of distributed Tangled data. Hope that helps clarify why “atproto provider” as a concept doesn’t make sense. You have hosting, which is as distributed as you want, and you have apps, which anyone can make.
- ecshafer 5mo agoWhy? I really don't see the purpose of a federation of git repos. Git is already totally decentralized. 99% of projects only have a small list of committers. Tangled just doesn't solve an actual problem. Github was used because it was an easy to set up, free, place to store code and share it, and it had source viewing which was a step up from sourceforge. With multiple solutions available that makes this easy, its just not necessary to federate anything. The common user account part of github just isn't critical.
- varun_ch 5mo agoThere’s a lot more to GitHub than just the git part. Issues, PRs, etc.
- ecshafer 5mo agoWhy does issues and prs need to be federated? I can't think of any part of Github that benefits from federation. Just set up your own instance.
- LelouBil 5mo agoIt's easier and enables more features to have 1 common platform. For example, the social features of GitHub, which I like (like stars, browsing repositories by tags etc..) But also For PRs, the way to make a pull request to a repo hosted at A, from your own node hosted at B. And like other commenters said, you can do this workflow with git over email like a lot of projects to, but the main goal of the federation here to me is the user experience, the UI being able to link all of theses separate repositories, issues, PRs, etc, like everything was hosted at the same place.
- haskman 5mo agoThey do if you want to collaborate with others. No one is going to want to create accounts on your personal instance
- 332451b 5mo agoI think initiatives for forge federation are trying to do too much. When running a forge for a project, I'd don't want to be dealing with spam or large amounts of data from other instances. And people should be able to report bugs and upload attachments, without having to give permission to share those with other instances. A good system to download and migrate issues and pull requests is important, but that doesn't require federation. I would love to see a smaller scoped federation of: - Forks across instances, including for the purpose of PRs (Git) - Activity feeds and notifications (Activity or ATproto) - Authentication and some user settings (OAuth)
- toastal 5mo agoWhy do we need to stick to Git? We need better tooling around the Patch Theory-based VCS which are better for decentralized working to begin with.
- MarsIronPI 5mo agoImmutable commits seem like a pretty good base for a decentralized VCS for me. In fact, Git was designed for this use case in the first place.
- toastal 5mo agoThe snapshot-based system requires that the patch order matters which Darcs/Pijul don’t require so long as the patches apply since they commute. This means you can pull in patches from other users at an time in any order & still get the same stable reference. If you apply patches in a different order in Git, you will get a different reference hash & some entity ends up needing to be the centralized source of truth when doing deployments & stuff—which is probably why everyone ends up having some code forge for their code base on a centralized server to “sync” the state. And with rebase, how are the commits immutable? Seems like MS GitHub found a way to mutably drop commits recently…
- danabramov 5mo agoIf anyone here’s curious about atproto data model, I wrote an into here: https://overreacted.io/a-social-filesystem/ https://overreacted.io/a-social-filesystem/ It’s a bit long but should give you a really crisp picture.
- whereistejas 5mo agojust wanted to share how much i loved this blog post :)
- kajman 5mo agoUnderstatement, probably. Your blog posts are so far the best introduction I've seen to ATProto. Is there any tagging I missed that collects them all in one place?
- danabramov 5mo agoAlas no, but it’s just a couple. I resisted adding tags so far…
- tynanpurdy 5mo agoI’ve gathered a few here! (On an atproto social bookmarking site :) https://semble.so/profile/tynanpurdy.com/collections/3m5epi5jubh26 https://semble.so/profile/tynanpurdy.com/collections/3m5epi5...
- fallinditch 5mo agoYes, excellent primer of atproto, nice one!
- willio58 5mo agoLots of negativity in the comments and while I'm as distrusting of VC funding as the next guy I think competition in this space is something we should encourage, and bootstrapping that is hard if not impossible at this point. Obviously this post was timed well with the 2-3 GitHub-hating posts that made it to the top of HN yesterday, but I commend the attempt here. I hope it takes off in a meaningful way.
- embedding-shape 5mo ago> and bootstrapping that is hard if not impossible at this point. What points towards bootstraping being impossible? Sure, it's difficult, that's almost in the name so makes sense, but impossible? Especially if you're aiming for the federation-angle, then you should be able to build cheaper infrastructure, not the same/more expensive.
- hnthrow0287345 5mo ago>What points towards bootstraping being impossible? Even just the security concerns and having any confidence in the implementation is likely a specialized skill, so you'll need to convince someone to work for free or be able to pay them. Now do that for other major lines of work like UI/UX, Ops, and QA. Take a look at all of the features from GitHub or any code platform that you'd need to get people to sign up these days (because they are used to GitHub/others) and it's a very tall list. Think something like https://www.enterpriseready.io/ https://www.enterpriseready.io/ but definitely larger (maybe 2x, 3x as large). Oh and if someone writes a long rant about it and it gets to the top here, it likely becomes dead in the water, and you can't get the time back, making it a risky proposition. At least with VC money, you got paid a salary.
- embedding-shape 5mo agoYou could theorize about all those things, or you could look at Codeberg, sr.ht or others that already are doing what you claim to be impossible, yet haven't took on VC money. People are signing up and using these already, despite not offering 100% the same features. The aim doesn't have to be "Be the next GitHub", but something else, and that's just as valid and "successful" as anything else, as long as they survive as communities.
- bkummel 5mo agoIn what sense do we need Tangled if there's already ForgeFed?
- austin-cheney 5mo agoI really don't understand this fear about a single pillar of failure, as people were in tears about the Ghostty thread yesterday. git is not GitHub. git is not HTTP. git is inherently decentralized with no concept of client/server. In git there is only local and a plurality of remotes. That said the solution is simple. Open a secondary, or a new primary, account with another provider and add it to your project's list of remotes. Here: git remote add <name here> <URI> If further explanation is needed see SO: https://stackoverflow.com/questions/42830557/git-remote-add-origin-vs-remote-set-url-origin https://stackoverflow.com/questions/42830557/git-remote-add-... Boom, problem solved: do it yourself redundancy/decentralization. If you want to make this federated then write a file containing a variety of remotes per addressed location and a script to dynamically update git according to your catalog at every location.
- tenacious_tuna 5mo ago> Boom, problem solved Not if your CI depends on github, or if you have specific actions to review things, or if you use SSO because you're an enterprise, or.... Workarounds exist for each of these cases, but they add significant friction. That's not terrible if you're one person, but if you're an org? big problem.
- u_fucking_dork 5mo ago> or if you use SSO because you're an enterprise Enterprise Cloud up time is 100% for last 90 days for most services, with a one being at 99.98 and one at 99.97. Enterprise customers get an SLA
- austin-cheney 5mo agoMost enterprises self host for all those critical things so they aren't blocked by third party service interruptions. SLAs might refund some money, but they won't recover the lost time.
- RobRivera 5mo agoThanks for the lead on the details, this has been on my spring cleaning todo list. Sounds like I have my weekend errand picked.
- kordlessagain 5mo agoIf anything starts with "we need" I just laugh.
- Synthetic7346 5mo agoWe need more humor in the world
- calvinmorrison 5mo agoIf only git was a distributed system!
- j3s 5mo agoit is - but dealing with code involves a lot more than just git. tangled distributes the rest of the stack - issues, comments, pulls, stars, etc.
- mrweasel 5mo agoPeople tend to focus a bit to much on the Git part of Github. Git is already relatively fine. It's nice to have a web view into the repo, users can just clone the repo, but many seems hesitant to do so as if it's some major operation (it can be for large repos, but normally it's not). The tricky part is the bugtracker and pull-requests. I don't really know how I feel about the Github issue tracker. In theory it's a good way for a community to report and manage bugs, but it's also what's driving maintainers crazy. Previously, in the olden days, you'd send an email to a mailing list and maybe get a reply, maybe got told to show up with a patch or bugger off. To some extend Github removed to much friction, and while quick drive by patches can be great, they don't build much community.
- MarsIronPI 5mo agoPersonally, I prefer mailing lists. The tooling is there, it's consistent, and it's powerful. And if it adds a higher bar of entry, in this day and age that seems like a plus to me.
- collinmanderson 5mo agoWhy not Just™ store all PR/Issues content as markdown on a separate branch along side the code itself? Why do we need a new protocol?
- spartanatreyu 5mo agoDevelopers don't want to have to deal with merge conflicts or silent auto-merge failures in their issue tracking.
- yodon 5mo agoGitHub is a huge and almost 20 year old company suddenly experiencing massive scale growth as a result of an externality it didn't cause and that no one predicted. That is an incredibly difficult scenario for any long-running, established organization to handle. Yes, GitHub is temporarily breaking under the increased load, yes, it's likely to still be a thing in 2 months, and no, it's unlikely to still be a thing in 12 months. It's very unlikely a cool new thing will peel enough developers off GitHub in the next six months to survive long term as GitHub inevitably gets its ability to handle the new normal scale back.
- noirscape 5mo agoForge federation seems like a bad idea to me. If you want to go the route of decentralized project management (note that git as a VCS tool is already decentralized for this purpose), you're probably much better off modernizing the git-over-email workflow instead. Decentralizing the code isn't an issue; cloning repo's between servers is so standard that any forge can import a code repo from any other forge. The difficulty is ancillary stuff like issue trackers, wikis and MRs, but using a federated protocol for that seems ill-advised given the much weaker safeguards against spam. Mailing lists have a very large existing body of work on the matter of dealing with spam and a proven method of mirroring/archival. (Most git wikis are just git repositories with a different renderer.) The main reason nobody likes doing git-over-email is mostly just because it's very user-unfriendly to set up (since modern mail clients typically aren't correctly configured to deal with them). It's a very developer oriented workflow in the worst way possible. A modernized mailing list program that automatically takes care of things like reformatting emails/not leaking email addresses to the general public would go a long way to make it easier to deal with.
- delf 5mo agoGitSocial solves this: https://gitsocial.org/ https://gitsocial.org/
- tombert 5mo agoI had never done the PR-over-email thing until I got an account on SourceHut; it was a bit of a chore to set up, but not that hard, and it did make me feel like it's very clearly the "correct" way of doing things.
- ctdinjeu4 5mo ago[dead]
- 999900000999 5mo agoYou will never get around the free rider problem. If I want to create 100 repos of vibe coded projects every month someone will have to pay for it. At this point, just give me an honest version of GitHub that tells me what things actually cost. 5$ a repo, and another 1 per gb stored in LFS, cool.
- icy 5mo agoThe cool thing is you can just host your own knot then. Host repos of whatever size you want.
- cedws 5mo agoMan I really want to like this thing but this jargon is so stupid.
- OneDeuxTriSeiGo 5mo agoThe jargon is just naming the free-standing components after rope/string related things. i.e. tangle, knot, spindle, etc.
- fgfarben 5mo agoI think they're mad because 'knot' is a furry fetish term.
- sakjur 5mo agoPretty much every word in English seems to have an innuendo meaning to someone, do anyone truly care past the age of 15? I find Tangled's language a bit annoying because I'm pretty sure if this caught on it's even more single word concept rather needlessly. If the protocol is called Knot, then call a server a Knot instance or Knot server. If the runner protocol is called Spindle, each server which responds to that could be a Spindle runner. That'll serve two functions: It'll let people contextually hook the terms up against existing terms and still retain the option of evolving into singular word concepts if they prove successful enough for that to happen. From my point of view as a non-native speaker, the frequent overloading of commonplace words add to the confusion of learning English. I don't like that. It's far from a big hurdle, but just big enough to earn a soft little sigh from me. Your comment was the only thing that made me even care to comment: Isn't it rather unlikely that the person you're commenting on takes issue with a kink rather than any other reason why "knot" and "spindle" might be poor choices? Who knows, they might even have a good reason, but you started out with assuming bad faith and at least I tend to just leave conversations at that point.
- steffs 5mo ago[flagged]
- CWwdcdk7h 5mo agoCan't we really go back to pre-github model? I mean all it did was to reduce the barrier for contributions. With current flood of AI generated PR it doesn't sound like a big inconvenience to have to register at code hosting service used by project you want to improve/participate in.
- carrja99 5mo agoCrazy... I actually hashed out a plan to begin bulding a successor to github earlier this week and this blog post describes EXACTLY what I was thinking about with atproto+git. Good validation imho.
- hayden_dev 5mo agoIf you've got ideas for things Tangled doesn't do, it's all open source too: https://tangled.org/tangled.org/core https://tangled.org/tangled.org/core So you could theoretically either fork it and use it as a good starting point, or (even better) contribute the ideas you have straight into Tangled itself! :)
- FatFingers23 5mo agoI'd like to preface I'm pretty active in atprotocol ecosystem, so my experience is more than likely a bit more biased, but thought I'd share some of my thoughts as a big fan of tangled. I've really enjoyed Tangled. It has so far been what I've wanted from a GitHub replacement, is simpler and does not have as many features, but it has been the main social/git provider I've been using for personal open source projects for about a year now (this me https://tangled.org/did:plc:rnpkyqnmsw4ipey6eotbdnnf https://tangled.org/did:plc:rnpkyqnmsw4ipey6eotbdnnf) - It has a social graph connected to it I know from the social media I use (Bluesky), it's nice to put a face/name I may have seen to their commits/prs/issues - Is nice it's login is the same as other things I use - They have recently added built in support for static sites, nice for those client side webites or simple index.htmls you want to host somewhere straight from your git repo. - Spindles is their build system/actions. Not a nix fan, but they do use some flavor of that and have worked really well for what I've needed - An open API that allows me to easily render information thanks to being built on shared standards I know (atproto). I've built bots and wrote a few features into npmx.dev that uses various things from tangled easily thanks to that. - Ability to run your own knot(git server) and runner (spindles), or easily use the ones they host, but the cool thing about this is the social features are separate so even if you have a separate git server the issues/prs/etc are all coming from that shared social layer, not like they need to make an account on it to partake in the convo. It's not perfect. It has alpha in the navbar and does feel like that sometimes. I am missing some features, but all in all I've really enjoyed using it for my open source work and will more than likely continue using it going forward.
- alper 5mo agoI'm afraid that atproto will suffer from Bluesky's irrelevance. Not sure if that's a valid fear.
- FatFingers23 5mo agoFair enough! We are a pretty small ecosystem all in all. I will say in Tangled's case their infrastructure is separate from Bluesky's for the most part, and the rest can be switched easily enough if ever needed. One example is if you don't care anything about atproto, you can create a new account on Tangled's website that creates the account on their servers, but thanks to how atproto works it's just like you made one on Bluesky and can still interact with Tangled and everyone on the protocol for it's social features.
- Croaky 5mo agoI'm hesitant to build anything load-bearing on AT Protocol given its PQ exposure: https://words.filippo.io/crqc-timeline/ https://words.filippo.io/crqc-timeline/
- tired_star_nrg 5mo agoHow does this impact AT Protocol? I’m just hearing about AT now, so I’m not familiar
- embedding-shape 5mo agoToday, not so much. But once the day is here where we have CRQC, if ATProto hasn't yet started using post-quantum cryptography for identities, users are either vulnerable or a bunch of stuff will break once they push a hotfix to make users not vulnerable. Alternatively, they fix these things now, so once CRQC arrives, it's already not a problem, and no gets compromised nor have to urgently update their software.
- Croaky 5mo agoDIDs are rooted in ECDSA keys (secp256k1). Each user identity is a non-PQ cryptographic commitment. These ecosystems must start migrating very soon because if CRQCs arrive before they're done, they face a choice between user compromise and bricking accounts.
- jerknextdoor 5mo agoI'm not sure it says much, but I met the person who wrote the post you linked to at ATmosphere this year. To me that says that maybe they're not as worried as you about ATProto's PQ exposure. I overheard lots of discussions about the topic, but I'm not an expert so I can't give much more insight than that.
- Kye 5mo agoThey're aware of it. https://bsky.app/profile/bnewbold.net/post/3miufj3cfhs2i https://bsky.app/profile/bnewbold.net/post/3miufj3cfhs2i
- 0xbadcafebee 5mo agoI'm sorry but I will never use this. I don't want a federated protocol and I absolutely do not want "social". The Git protocol is enough to distribute my source code to any Git server, so that part is complete. What I need, in addition and separate from Git, is a standard API schema for all the other SDLC bits: CI/CD, PRs, Issues, Packages, Containers, Branch Protection, etc. The API should not be a specific transport implementation, like HTTP, or AT. It should merely describe the schema, and then you implement that schema on anything else. "createIssue(title=string, body=string, labels=[string])" would be the same in Git's source code as it would be on a REST API server. The point of this is to standardize the software development lifecycle everyone uses around Git. That way you can do all the work we all need, with any VCS, without tight coupling. That's been the missing piece that nobody has made yet. Want just the CI/CD component? Use that part of the schema. Want just the Issues? Use that part of the schema. Now you can write any tool you want, and just implement the features you want, and say "this follows the SDLC v1 CICD standard", or "the follows the SDLC v1 Issues standard". Much simpler to add extensions or support different use cases, without implementing everything you don't need. Yet everything's compatible. We need that implementation-agnostic standard, so we can make transport-agnostic protocols, so different providers, clients, and servers can all talk to each other, without a hundred different bespoke "things". Rather than write your plugin-downloading app only against GitHub or against Federated-Whatever, you write it to use "httpSLDCs://some-server/v1". Don't want to use https? Use "grpcSDLC://some-server/v1", or "atSLDC://some-server/v1". You layer the application-specific protocol on top of the transport protocol, and express that in a URL. That's how we did 'federation' in the 80's/90's/2000's. (also: did nobody come up with a better name? Tangled? Knot? you want your solution to be a tangled knot?!)
- taintlord 5mo ago[dead]
- zeafoamrun 5mo agoI really like the concept of federated social networks and it's the next thing I want to get into. Maybe even work on it as a job but I doubt there are any that pay well. I think sovereignty over what information you consume is more important than ever. I had to use Twitter for work to get news about <topic> but the amount of virulent propaganda, totally unrelated to <topic>, that you end up absorbing is unforgivable. Even if you think you're smart and don't pay attention to propaganda, by design it hits you at the subconscious level so you can't block it. The only social media I have left is LinkedIn and I really hate it but it has made a direct positive material impact in my life ($$$) so I try to hold my nose while I use it. I really would rather use some kind of federated LinkedIn, but when I last checked nothing like that existed yet.
- bombcar 5mo agoI'm confused on what exactly we need to add to decentralized git to get where we want to be - if it's identities, why aren't we using what git itself supports (gpg keys; if someone has your private key, they are you no matter where)? Or in other words, what specifically does GitHub "do" that can't be done by using git as a backing store?
- nerdypepper 5mo ago> gpg keys; if someone has your private key, they are you no matter where how would you rotate such a key and still convince everybody that you are still you? > Or in other words, what specifically does GitHub "do" that can't be done by using git as a backing store? how would you build a social graph of follows/stars and what not using user-owned git repos as a backing store?
- bombcar 5mo agoGPG key rotation is a known issue with solutions (hint: it involves multiple keys) - https://danielpecos.com/2019/03/30/how-to-rotate-your-openpgp-gnupg-keys/ https://danielpecos.com/2019/03/30/how-to-rotate-your-openpg... > how would you build a social graph of follows/stars and what not using user-owned git repos as a backing store? I'm just spitballing and depending on how you want to display it, you may need more - but if I want to "follow" you I submit a signed commit to your "follow" repository, similar if I'm staring a repo; and then your system issues a signed commit back to my "followed" repo.
- tobylane 5mo agoAs a project member, I want users to already be logged in to the bug tracker. The lack of friction, likely from being the network effect winner, is key. I know fossil has this, but people don't have their private keys in fossil, they (I) don't even have fossil installed.
- tardedmeme 5mo agoWhatever happened to OpenID, anyway? That was supposed to be federated one-click login. If the problem is login, then only the login needs to be federated, and this approach leaves the rest of the system more flexible as sites can have different bug tracking features without becoming incompatible with the federation.
- liveoneggs 5mo agoIt took me a minute to figure out what this was even talking about. Tangles is, apparently, a gitlab-type project where PRs and bug reports and stuff are available on something called "at protocol" which is the bluesky social network "federated protocol". at protocol competes with ActivityPub, which is mastadon -- so you could, in theory, have a little federation of gitlabs peer-to-peering with each other, which is desirable for some reason.
- jonahx 5mo agoThe "some reason" isn't mysterious... it's redundancy and avoiding a single point of failure and ownership.
- liveoneggs 5mo agoBut the actual git part isn't federated
- ascorbic 5mo agoGit itself is already federated. Every clone is a repo. That's not the bit that needs fixing.
- liveoneggs 5mo agoso you would consider fossil a fully realized version of this?
- mikey_p 5mo agoexcept it isn't at all like ActivityPub and is implemented radically differently to avoid many of the problems with ActivityPub.
- liveoneggs 5mo agoI was saying at protocol is to bluesky as activity pub is to mastodon So it's as if all the github pull requests were tweets, I guess?
- divbzero 5mo agoIt appears that git format-patch + git send-email is a mature and widely used approach. Wouldn’t it make more sense for the open source community to work on streamlining that process instead of trying to build momentum with new approaches?
- OneDeuxTriSeiGo 5mo agoFor what it's worth, under the hood tangled is extremely similar to this approach. Personally as just a random person in the community I've been building an appview for tangled that lets you interact with it as if you were just using git format-patch + git send-email + some MUA. You can conceptually treat the tangled lexicon as a schema for encoding a git patchset based mailing list into IPLD/atproto records and vice versa. Doing this is slightly lossy but only barely. Otherwise it's pretty seamless.
- firebot 5mo agoThe problem with GitHub is from ... we all know it... AI. They're working on the scaling issues apparently due to huge demand.
- delf 5mo agoGitSocial allows cross-forge collaboration without any 3rd party dependencies as it keeps everything in git: <https://github.com/gitsocial-org/gitsocial/blob/main/documentation/GITREVIEW-FLOWS.md#2-cross-forge-contribution https://github.com/gitsocial-org/gitsocial/blob/main/documen...> Git IS the federation layer in this case.
- embedding-shape 5mo agoHow do you authenticate the identity when people are submitting patches between two repositories running on two different servers?
- delf 5mo agoThere's a federated identity spec and implementation: https://github.com/gitsocial-org/gitsocial/blob/main/documentation/IDENTITY.md https://github.com/gitsocial-org/gitsocial/blob/main/documen.... For GH/GL, just an api call to verify signature, for custom domains, it's .well-known/gitmsg-id.json
- jonstaab 5mo agoI don't know how new Tangled is, but there is a fairly mature github alternative being built on Nostr: https://gitworkshop.dev/ https://gitworkshop.dev/ The basic idea is that you can put your repository on multiple GRASP-compatible nostr relays (GRASP is a sub-protocol that glues nostr and git together), so even if one server goes down you can transparently sync using the others. This means in effect 100% uptime if you choose reliable servers, as well as cryptographically-signed repositories, activity, issues, etc.
- nerdypepper 5mo agoi am unable to access any repository on that website. for some, it complains that ssh or https URLs are not supported by my browser? and for others its just loading indefinitely with `Failed to load file tree`. maybe its not fairly mature.
- knotbin 5mo agoCorrect me if I'm wrong but the project you're referring to appears to be closed source.
- jonstaab 5mo agoIt's all open source, hosted on nostr itself. See the creator's profile for all related repos: https://gitworkshop.dev/danconwaydev.com https://gitworkshop.dev/danconwaydev.com
- Manfred 5mo agoPlease don't give your users a nickname like "tanglers", groups come up with their own nicknames. It's not as infuriating as when New Relic started calling everyone "Data Nerd", which is actually offensive to me and weirdly aggressive for a corporate product.
- throw5 5mo ago> Please don't give your users a nickname like "tanglers", groups come up with their own nicknames. What prompted this? I can't see "tanglers" in the OP. Did you see them calling their users "tanglers" somewhere? Honest question.
- Manfred 5mo agoIt's on the homepage under "Recent updates".
- mcepl 5mo agoLovely, so yet another promise to federate which will never materialise! Still going with the Drew’s reply in https://is.gd/5wwQy2 https://is.gd/5wwQy2 (yes, two years old, and he slightly softened his stand since then): > SourceHut is already federated via email. We have no intention of adding ActivityPub support at this time. Federated repositories is something very similar to paperless office, distributed authentication (OpenID), and distributed computing … it has been promised since forever, and nobody has ever seen it in the real life, and even less supported by somebody who matters. And yes, those who matter don’t help by sabotaging any efforts towards it.
- NooneAtAll3 5mo agohasn't distributed computing being around and successful for a long time? nowadays it only cooled down, but that's far from "never seen"
- well_ackshually 5mo agoDevault being a gigantic dick head has no bearing on whether or not tangled does things. If sourcehut wants to remain the isolated hermit of forges because the greybeards that be think it was better before, let them do so and remain their island of weirdos. We already do the same with the freebsd guys (except that freebsd is actually good and impressive unlike sourcehut) Sourcehut does not matter, and federation of repos is already a real thing. The ones that don't want to federate just.. don't?
- catapart 5mo ago[flagged]
- hayden_dev 5mo agosource for the fuck the users quote please lmao
- psionides 5mo agoI don't think there's a good reason to call the creators of Tangled "libertarian dickheads", tbh.
- fgfarben 5mo agocatpart is definitely NOT someone with a long history of railing against anything vaguely connected to ATproto: https://news.ycombinator.com/item?id=46670016 https://news.ycombinator.com/item?id=46670016 catpart has totally 100% provided a citation for the "fuck the users" moment (sike): https://news.ycombinator.com/item?id=46672904 https://news.ycombinator.com/item?id=46672904 the actual "fuck the users" moment is described here [4,3095771], wherein a group of activists failed to get a person (Jesse Singal) they deemed unpalatable deplatformed from Bluesky, mostly by claiming that this person broke the ToS, and the Bluesky moderators mocked the activists in public. [4] https://techcrunch.com/2025/10/05/waffles-eat-bluesky/ https://techcrunch.com/2025/10/05/waffles-eat-bluesky/ [3095771] https://en.wikipedia.org/wiki/Jesse_Singal#Subsequent_events https://en.wikipedia.org/wiki/Jesse_Singal#Subsequent_events
- fgfarben 5mo agoin your world, literally who isn't a dickhead? yourself, presumably? you must make a living somehow.
- illadvised 5mo agonah, I'm you're run-of-the mill dickhead, I'm afraid. righteous and principled but ignorant and overbearing. classic asshole, by nature. doing my best to be better every day, though. hoping the same for everyone else. as far as who isn't, the first names that come to mind are Fred Rogers - he seems like kind of the summit of what a soul can aspire to be. Randall Munroe seems like a pretty awesome guy. Haven't looked too much into him, though. most names that come to mind are personal acquaintances that wouldn't mean much to you, but I find that it's not very difficult to find non-dickheads in my day to day life. probably around 30% of the people I encounter in passing are a-okay in my book! but it is true that the number of dickheads I encounter skyrocket when I start approaching cultures that glorify personal gain over community success and health. abstract or practical; the business community is rife with awful people and los angelos is terrible for entirely different reasons. anyway, yeah. I make a living. dealing with wonderful people who have a shred of humility and who - when they get called out - just sheepishly say "oh! wow, that is awful. I'm so sorry for saying/doing that." and everybody moves on with their business. I hope you work with wonderful people as well!
- fiatjaf 5mo agoA federation of forges makes no sense if everything gets centralized again in the hands of the people operating Tangled (sure, someone else could run an alternative AppView, but then if you are only on the alternative you are invisible to anyone who is only on Tangled). https://gitgrasp.com/ https://gitgrasp.com/ fixes this.
- d12bb 5mo ago> alternative AppView, but then if you are only on the alternative you are invisible to anyone who is only on Tangled That’s misunderstanding the at protocol. There is a difference between a pds, where the data lives, and the appview. Tangled (the appview) happens to also provide a pds (they didn’t always do), but displays data which lives on other pds’s just as well.
- account42 5mo agoThere is no misunderstanding - that difference is just irrelevant in practice.
- tardedmeme 5mo agoA federation doesn't mean the forges talk to each other. It only means there's more than one, and data flows between them. This can occur by developers pushing and pulling from different remotes. You already have a different remote for each fork, you lose nothing if they're also on different servers. Communication about the project can also happen in many places.
- altairprime 5mo agoRelated: Show HN: Tangled – Git collaboration platform built on atproto (1 year ago, 15 comments) https://news.ycombinator.com/item?id=43234544 https://news.ycombinator.com/item?id=43234544 Tangled, a Git collaboration platform built on atproto (6 months ago, 86 comments) https://news.ycombinator.com/item?id=45543899 https://news.ycombinator.com/item?id=45543899
- nightpool 5mo agoI'm a huge supporter of federation, but I've never understood the use-case for a "federation of forges". What data are the forges exchanging? Why should the forge for Blender have any connection to the forge for Ubuntu? Most of the value I get from Github is having a single login that I can take from project to project. Independent forges can get the same value simply by supporting social login, without needing the complexity of a "forge federation" system.
- Scaled 5mo agoThe biggest problem IMO is discoverability. I need an easy way to find open source projects that are on scattered servers. GitHub project search is limited to GitHub.
- nightpool 5mo agoThe OP says that tangled only supports event federation. How does it help with discoverability?
- OneDeuxTriSeiGo 5mo agoEvents in atproto speak are changes to metadata/records, i.e. repo/MST events on a PDS. So for tangled that means federation of issues, PRs, comments, follows, stars, and anything defined in an atproto lexicon. i.e. everything except the actual git repo itself. Those repos are singularly hosted on a given knot for the time being. Now it's not a huge leap to imagine extending functionality to support cross-knot mirrors but that's not a supported feature yet. And of course you can always just fork a repo instead.
- hirako2000 5mo agoGit is decentralized by design. It can support federation, it just happens that GitHub solved the UI, issues, PR so that even new comer can come in and do git stuff and track issues on the screen. But centralized it. Federation would be closer to git, but not so decentralized that when one node goes offline you may not have any upstream to pull from, or not be able to find them. Git doesn't solve availability. Federation may solve it, by staying closer to the decentralized philosophy. That's my read.
- rafram 5mo agoHow will this end up going any better than Mastodon has? Near inevitabilities: - All the small instances defederating from the largest due to politics/spam/annoying noobs/whatever, effectively killing the easiest path to entry into the community - Pointless debates about whether it’s OK to federate with instances that host pirated content, disagreeable politics, furry VNs, etc., which everyone has to take a side (the correct side) on - Relatively little actual work/productive discussion going on, since many users are there mostly for the politics / fediverse posturing than for actual work
- knotbin 5mo agoATproto federates in a very different way than Mastodon. There is no concept of "instances" on ATproto. Your account is hosted on a PDS and you sign into the app with your PDS sign-in and records go to your PDS, but everything on the app is from what's called an "AppView" which provides a centralized view of all data in all PDSes so it feels just like you're using a regular centralized app. But there can be multiple AppViews and AppViews can be self-hosted. So unlike with Mastodon, it doesn't matter what PDS "instance" you're on because the app layer is completely separate from it.
- fc417fc802 5mo ago> There is no concept of "instances" on ATproto. Regardless of name and precise technical details, there are central service components that can ban you. If a proper ecosystem of those ever springs up then the equivalent of fediblock (ie guilt by association) oriented at individual accounts or PDS is the next logical step. At present (last I checked) there's only (approximately) one primary provider plus blacksky making the situation even worse. This isn't some wild hypothetical - we also see guilt by association in the matrix ecosystem.
- what 5mo agoDon’t they already have extensive block lists that you can “subscribe” to? I think some official blue sky account was added to some and they got super mad?
- renewiltord 5mo agoI only use GitHub for unified login git access to a bunch of repos. These other “forges” (didn’t know that was the term - cool) are all almost certain to put Anubis in front and make a logged out user be unable to access the code. I get why, but it seems inevitable. I think Codeberg already does and for some reason it takes ages to complete the challenge on my phone. Undoubtedly these various hosts will come under pressure from spammers and the like and they will react by placing extraordinary barriers around accessing the code. That’s fine but it reminds me of the later stages of online forums, where it was impossible to browse most threads because you had to create an account and then build up community points until the screenshot of the kernel panic on the ZTE phone would be visible so you could see if it’s the same problem as yours. GitHub was big and powerful enough to not need all of this but now we’re going back to the era of decentralization and I suppose with that come the pros and cons.
- Galanwe 5mo agoIf we are going the distributed way, then why not host everything on a blockchain, instead of federating thousands of small instances? I would be happier with my code distributely hosted on every participating node, rather than federating it on my crappy instance. Also your wallet can be auth + sign so no need for third party auth layers
- 4lx87 5mo agoLooks really cool but ATProto means I won't be using it. I'm not going to invest in another network when we already have an open one. We already have the web. The web already has OAuth. OAuth is already widely supported. IndieAuth already offers a very simple and standard approach to personal OAuth servers, if people really want to run their own identity server. "Feeds" are perfectly doable using the web. It's already pull-based. We don't need another protocol to listen for changes at a URL. The web already has support for different content types and document schemas, we don't need to reimplement content types and schemas as ATProto "lexicons".
- mikey_p 5mo agoThe web still has other protocols on top of it, like RSS. Just because the "web" exists doesn't mean that solves every problem. Also OAuth only handles auth and permissions and doesn't do anything for provided federated views of disparate data sources. Also this isn't about identity either, you're really misunderstanding what this is about.
- 4lx87 5mo agoYou're right. RSS builds on top of the web. ATProto does not. I'd say RSS is a resource format / content type, not a communications protocol. A resource format intended for syndicating updates – exactly what ATProto and ActivityPub do (but decided to invent new formats instead of extending RSS/Atom. JSON all the things!). It is very much about identity. To use tangled you need to use ATProto and authenticate using ATProto – rather than using the existing open standard for authentication used by pretty much everyone at this point (missed opportunity to login to Tangled using GitHub). What's crazy is people still use the web to interact with tangled anyway.
- mikey_p 5mo agoThat's like saying that DAV doesn't build on HTTP. And just because an existing standard exists does not forgo the creation of other standards that incorporate other features. I don't know how to build a social graph based on OAuth logins, but this would be fairly easy with ATProto.| Genuinely don't know why you are even using HTTP when Telnet and Gopher are right there...
- pasto421 5mo ago[dead]
- praseodym 5mo agoForgejo also has a roadmap for federation but it looks like development is progressing rather slowly: https://codeberg.org/forgejo-contrib/federation/src/branch/main/FederationRoadmap.md https://codeberg.org/forgejo-contrib/federation/src/branch/m...
- taintlord 5mo ago[dead]
- miki123211 5mo agoI don't think we need a federation of forges. What we need instead is just richer git repos. Fossil gets 90% there with integrating tickets (issues), forums and wikis as part of the repo itself. When you clone a fossil repo, those are also part of the clone, and can be browsed offline on an airplane. Replies can also be written offline and, permissions willing, synced back up to the remote, either immediately or when the internet connection is regained. I think this is the direction we should go in, but without hardcoding any specific artifact kind as part of the VCS. Instead, repos should be able to contain apps, which would define policies on what artifacts are acceptable, what rules they must follow, and who's allowed to upload and download them and at what times. The job of the forge would then be to execute those policies and render the artifacts for web users in whatever way the app desires. With such a setup, moving to a different forge would entail nothing more than pushing the repo there.
- wild_egg 5mo agoHey, so... Thanks for this. I've been building ticket systems and agents and whatever else as flat files in git repos lately and now I see I have to extend that to actually managing the repos themselves. This is going to be so nice.
- jauntywundrkind 5mo agoI think this idea is additive not contrary. I still would like to be able to send and receive issues and pull-requests, to/from anyone. Your idea here seems to be about how to encode the data. You talk about web interfaces & who is allowed to do what. But it's not clear to me how my repo/forge gets my PR in front of you. The social networking technology feels like it has to come into play somewhere, and I don't see that as described in your system.
- bawolff 5mo agoNot everything needs to be federated. There is almost no benefit of having federated forges. Just self host if you want.
- ksymph 5mo agoTangled is pretty cool. I'm not particularly into atproto, and I think the connection kind of distracts from the reality of what it is and can do. You can host your git repo on their servers, or your own. You can host issues/pull requests/runners/etc on their servers, or your own. Regardless of where a repo is hosted, you can interact with it from a single account, and with that same account interact with others' repos connected to tangled. Plus it has native jujutsu support, though you can use plain ol' git if you want to, too. Do I think a forge with those features necessarily needs to use atproto to exist, or that atproto is the ideal version of itself? No, not really. But the site is there, and it has some pretty neat features I want; I don't need to love the stack to use it, any more than I do Github's.
- parentheses 5mo agoThis type of thing requires an economic driver to monetize the service. I'd have a strong inclination to run such software if I knew that I was both helping host repos and getting paid.
- jauntywundrkind 5mo agoOh! Posted some replies here, but: I forgot to mention one other incredibly awesome atproto based social coding decentralization system! Jeremie Miller's v-it, which lets folks share "caps" changes, "vouch" for each others caps, share skills. https://v-it.org/ https://v-it.org/ It's so so so early. But I love how it moves from a world of maintainers & pull requests to a more ambient "this is what is working for me". I think this really is a next kind of leap. I don't know if we can keep relying on maintainer folks to guide each project forward like we have, if our agentic selves can be bandwidth limited & still go where we need to, channeling all our energy through individuals. We need a federation of maintainers. A distributed of maintainers. Maintain ought be social. Tangled is great and I hope we can go beyond federation to many tangled, to widely widely tangled. And I hope we can go past maintainers too, past pressuring single people to have to decide it all. I think v-it really preceeda such an interesting agentic leaping off point that we are at, so interestingly.
- evbogue 5mo agoWe need git-ssb
- khimaros 5mo agoalternatively: https://radicle.dev/ https://radicle.dev/
- ierukah 5mo agoForgejo is working on federation powered by ActivityPub and their ForgeFed extension: https://forgefed.org https://forgefed.org
- Aeolun 5mo agoMy opinion is we need a new Github. It was fine for a decade, and can be again. As long as it’s like Steam and stays private it’ll be fine.
- AuthAuth 5mo agoI saw Radicle posted yesterday and tried it out. Its pretty much exactly what is being asked for here. The main issue I see is its impossible to search through peoples projects you have to be linked to them from somewhere that isnt radicle explorer.