A casual security evaluation revealed that all of the 20+ processes in the quay.io registry container run as real root. Worse, the system has no authentication for image uploading allowing -anyone- clobber any existing image. Auth only exists for reading images which is entirely backwards. Requests for to patch these and other holes myself were denied.
Don't even get me started on general instability or that on a failed build it would hang and never accept new ones without a manual container restart.
Had to pull the plug on the whole thing and replace it with a few git hooks and a vanilla docker registry... Which has been simple and rock solid.
1. You have big rectangular elements that represent repositories, but 90% of that rectangle is dead space. Apply the click event to the whole rectangle, not just the title of the repo.
2. As a user, I am solely a member of an organization. I don't need to see a dashboard with just 3 starred project, 3 random projects from my org, and 3 of my personal projects (of which there are 0). Just let me start at my org's page, or let me see every project from my org on the dashboard.
3. Wtf is the "list view" link on my dashboard? It appears to just show me 3 random projects out of the 9 in my organization, and completely hide the "starred" and "personal" sections?
Bugs:
1. Until recently, the Sign Out link 100% always threw an HTTP 500 error. Today, that is not happening? Who knows. Weird.
2. My IT guy created an account for me. As a result, I received an email with a login link. However, 24 hours later, I was logged out and could not log back in, because I never had a password set. Had to get the IT guy to send me another welcome email. IF PEOPLE NEED TO SET UP A PASSWORD, YOU SHOULD FORCE THEM TO, NOT HOPE THEY EVENTUALLY POKE AROUND AND FIND THE SET PASSWORD SCREEN.