Perhaps your release of Homebrew is better and safer than you expected? :D
While I share your misgivings about sticking stuff like this at the "system" level, I think they are right to do so in this case, for simplicities sake.
For me these locations are an artifact of multiuser systems days, it's generally more desirable for me to store most stuff in my home directory, such that when I upgrade computers, there's only one thing to copy over.
I mean, I understood you, I'm fairly sure brew is the only Ruby command I run on a regular basis...
The multiuser features are used to provide defense in depth, especially for developer machines.
For me these locations are an artifact of multiuser systems days, it's generally more desirable for me to store most stuff in my home directory, such that when I upgrade computers, there's only one thing to copy over.
Apple's migration tool and cloning have always worked for me.
Annoyingly, the FHS isn't POSIX (nor SUS) and thus not Unix. There's thus no real standardisation on what the filesystem should look like and thus even Guix or Gobolinux can be POSIX candidates.
Even macOS takes advantage of this nonstandardisation by putting stuff in /Applications, /Library and /Users.
The debate about what belongs in /usr, /usr/local, /opt (and hahaha, /opt/local) is mostly subjective opinions about just how local these local things are.
EDIT: The rationale for using /usr/local has been explained in the FAQ: https://github.com/Homebrew/brew/blob/master/docs/FAQ.md#why...
1. /usr/local/bin is already in your PATH
But not /usr/local/sbin, which I had to add anyway. 2. Tons of build scripts break
Not that much anymore, and gems can now be configured much more easily thanks to bundler. It's indeed a chore to tell configure to link against this or that, but most of the time you just build a package anyway (trivial with pacman/abs) for things to be managed. 3. no need to worry about messing up existing tools.
But many third party tools install stuff in /usr/local. Also, SIP prevents any mess from happening to system stuff.Also, regarding sudo:
But do you trust the multi-megabyte Makefile that Homebrew runs?
No I don't, that's why make/make install gets run as a regular user but under fakeroot when packaging with, say, pacman/abs.Running the install phase as root allows the package manager to make things just work, such as installing OpenVPN (which depends on tuntaposx kexts), or install daemons under their own user and have them launched on system boot (not user login) by /Library/LaunchDaemons, or install Python under /Library/Frameworks (which ironically, brew builds as a framework but stores somewhere else).
Again, those are tradeoffs and it's good that a stance is taken either way.
Disclaimer: long-time tentative maintainer of Arch OS X