Alphabet Backs GitLab's Quest to Surpass Microsoft's GitHub
bloomberg.com
bloomberg.com
> Joel Spolsky in 2002 identified a major pattern in technology business & economics: the pattern of "commoditizing your complement"
> This pattern explains many otherwise odd or apparently self-sabotaging ventures by large tech companies into apparently irrelevant fields ...
> ...they are pre-emptive attempts to commodify another company elsewhere in the stack, or defenses against it being done to them.
After having read this article, it's been interesting how a lot of these investments have started making more sense. They often aren't primarily about the product itself, rather they serve the function of minimizing any leverage other companies could have over them.
As Github offers an access to a valuable resource for tech companies, developers, Microsoft could use it to promote its products/services and to attract talent. This isn't good for Google, so they are hoping to reduce Microsoft's leverage.
In some sense this is obvious, but I hadn't consciously identified this as a pattern before.
They are merging YouTube Gaming to YT itself (cited branding problems), discontinuing Inbox next March... Add that to a long list of canceled services. I am not saying they have to run a charity but they do seem very heavy-handed in these situations.
And so far we have not seen them innovate anywhere for a while -- correct me if I am wrong.
To me, it seems they entrench themselves even further in the business of using personal data for profit -- one example could be the upcoming laptop OS Fuchsia. Imagine how much more they will know about people if that takes off on a massive scale.
The major now seems to be on Google Cloud, but they have struggled there with bad marketing, lack of sales and support talent, and strange priorities. Seems to be growing now with the AI functionalities but there's a long road ahead.
Like sibling commentors have pointed out, it's easy for even relatively successful ventures to be completely overshadowed by the golden goose that is ads and search.
As for alternative revenues, they are heavily pushing Google Cloud platforms to businesses.
Tl;dr: High cost of entry for newcomers
(Note I said “users” not “customers”)
They've fully stepped out of the shadow of Github (for a long while, in my mind), and it's nice to see people taking attention.
why not? If it means gitlab can have the resources to keep improving...
and given that it's open-source, there's no fear of any shutdowns.
Google Reader iGoogle Google Talk Google Health Knol Picnik Buzz AARDVARK Sidewiki Notebook Wave Dictionary Labs SearchWiki Video Dodgeball Jaiku Lively Answers Page Creator
I won't even mention how bad android sucks with devices never seeing security patches, updates or new releases.
I'm just not a fan of choosing sides. Already saw google code die, why would i want them to own or have heavy influence over gitlab?
Well, not entirely. The community aspect of GitHub would largely be lost if it vanished overnight and was replaced by scattered competing clones, even if they were running the exact same code.
Which might not meet some definitions of fear, but it's not the best outcome for anyone who likes a product.
Apparently this, uh, 'innovation', is worth around $3bn.
As a self hosted product, it is difficult to be beaten.
but as a Saas product, its just horribly unreliable.
In the last two months it has improved, but there are still outages every two weeks or so. (https://twitter.com/gitlabstatus) I'm hoping that with this extra cash, they'll be hiring in some infrastructure people (people who will look at this in horror: https://about.gitlab.com/2016/12/11/proposed-server-purchase... ) who actually know how to make a stable platform using _proven "boring"_ stuff, not sexy slow and supposedly HA stuff like Ceph and forcing it to serve NFS.
According to Pingdom, over the last year our availability has been 99.81%, although this includes the large (multi-hour) maintenance window on 11 August 2018 when we migrated GitLab.com from Microsoft Azure cloud to Google Cloud Platform (GCP).
Since the migration, our availability has improved greatly (caveat: we obviously have much less data than from Azure).
Using the data publicly available from Pingdom, here are some interesting stats:
Mean-time between outages in Azure (September 2017 through August 11 2018): 1.3 days
Mean-time between outages in GCP (September 2017 through August 12 2018): 7.3 days (if you ignore some problems we experienced on the first day after the migration, this rises to 12 days!)
Since, migrating to GCP, our overall availability, according to Pingdom, has risen to 99.92%. Again, if you exclude the few hiccups that we experienced on the Monday immediately following the migration, this rises to 99.97%.
There are multiple reasons for this improvement. We chose Google Cloud Platform because we believe that they offer the most reliable cloud platform for our workload, particularly as we move towards running GitLab.com in Kubernetes. It is worth pointing out that we also used the migration as an opportunity to improve our infrastructure, simplify some components and otherwise make things more stable and more observable. Finally, we've also been focusing on building the infrastructure team up, having hired many new team members over the past few months. This means that the team has been better able to balance the job of running GitLab.com with making it more stable.
Part of the problem is that these, at least the ones making the fundamental decisions, are likely to be software people, with not enough ops/sysadmin experience.
> who actually know how to make a stable platform using _proven "boring"_ stuff, not sexy
The ones who do may have gotten bored of it, themselves, and no longer admit it, instead leaning toward as much of the "Dev" part of DevOps (as a title) as possible, since that's where the excitement (and decision making power) tends to be. The rest of us are borderline unemployable.
With the exception of my time at a financial news paper, virtually all professional life has been trying to make highly scalable pipelines that run as smoothly as possible.
In any project, you have about three innovation tokens to spend. Each token will cost you time and momentum, however they may give you lots of reward. Personally I like spending them on the bits of the software that give you the USP, Not something thats already solved.
To illustrate the point:
using loads of d blades with internal storage to create a Ceph storage mesh == expensive nightmare and slow, especially as you are going to be serving it over NFS. Storage bandwidth is contending serving bandwidth. Not only that you now have three SPOFs the NFS servers, the ceph cluster (no, its really not HA) and the blade fabric.
three or four real file servers with proper jbods/raid arrays if you want to go down the NFS route. the smaller the better, spread the load amongst them evenly, meaning that if one goes down it degrades but not totally wipes out access.
Better yet to use SAS/FC to route block access, and either pay for hardware duplication, or write the state to two different LUNs (its git after all, its fairly simple to duplicate.)
failing that, just us VMware and some decent block storage, and let it figure out how to do it. It has rather reasonable HA clustering, which don't need software changes.
or just host it in the cloud. Which is what they did in the end.
I didn't make a single statement, but I also made what is more of an accusation (i.e. stating the opinion of others I disagree with) than my own assertion.
> Personally I like spending them on the bits of the software that give you the USP, Not something thats already solved.
I'm suggesting that most people (or at least in my own "bubble", as it were) don't differentiate. Re-inventing the wheel is just fine to them, so long as it's fun.
That said, I'm not convinced large (enough) "global" filesystems are a solved problem. Of course, GitLab doesn't necessarily need such a thing, but implementing that kind of storage "sharding" (for lack of a better word) may well be spending an innovation token, too.
> or just host it in the cloud.
Except that doesn't magically solve any of the architectural/operational problems. For all we know they're still doing Ceph-with-NFS, just paying much more to do so, without the ability to optimize the hardware for cost and/or performance.
I do agree that, a lot of my time can be taken up with explaining why I don't want to replace a file server with a Cassandra cluster(yes really).
I was at one point all for single name space global filesystems. GPFS makes data affinity, HSM and provide rich event hooks.
However, its global, which means global outages. It has its user cases though.
Depending on your use case sharding a file system can be pretty simple. The root folder can be a directory of dynamic symlinks controlled by config management.
However its never as simple as that, as you know.
Adding the complexity of a DBMS (and a non-standard one at that) on top of a distributed system seems excessive, but I'd believe it.
> GPFS
I've never been a strong advocate for proprietary/enterprise solutions, as that's an easy way to spend more than a cloud provider would cost. Since storage (hardware) is the worst offender for markups, I'm extra-sensitive in that area.
> However its never as simple as that, as you know.
Indeed, which is why I suggested it would require innovation. For any non-trivial case, the app would need to be aware, and it may as well do all that work.
IMVHO today it's time to evalutare ZeroNet for project sites/blog and something like IPFS (not much convinced by this project but...) for code and repos to AVOID depend on someone else server's switching to relay only on us all.
For me there is no difference in GitHub or GitLab or Bitbucket etc, nor between Google and Microsoft. In an era of diversity companies are not a problem, in an oligopolistic era like today, in an era of proprietary platforms instead of open standard companies are a problem and should be avoided, especially if they are big, especially if they push mix of proprietary and FOSS solution.
But you're right, maybe IPFS plus something like Fossil (including issues in the VCS directly) could be a good solution to have a truly decentralized "platform".
So if I agree for instance that LaTeX for the classic stereotypical secretary it's a lock-out software despite it's excellent characteristics, I can't accept the same argument for an IT professional and even for a casual hobbyist programmer.
I don't miss it at all.
so how do you "spread the word" by using a peer to peer network that no one has signed up for? might as well share a link to the project on your google drive on a subreddit you maintain but don't publicize
However, that's an old blog-post, today GitLab is the only single product for the complete DevOps lifecycle. Here you can find out more references about GitLab DevOps https://about.gitlab.com/devops/.
As we're all aware by now, Google is an advertising company (with a heap of technology, but it's still a company which primarily sells advertising).
i skipped the part during installation where it says to enter a key. after install, it says windows is activated, no watermark, no countdown. i don't use it, though. i just don't trust free shit anymore.
It's a bit late.
https://martechtoday.com/google-posts-31-1b-in-total-revenue...
The one thing coming to mind which is not designed to boost advertising is their Pixel line (after they killed the rest of their hardware, of course) but even that is not as much of a standalone activity as it is a way to effectively steer the future of the Android ecosystem.
Ask yourself this: Which Google products or services would have justification as standalone P&L units, without collecting user data and sending it to the mothership? Not too many.
Cloud
X
Waymo
Play (the non-admob parts: app hosting/monetization, licensed content providing (music, movies/tv).
ChromeOS / Classroom
The entire Hardware division (which now includes Nest)
An awful lot of the Geo/Maps org is oriented away from direct advertising.
FWIW, you didn't ask, and my answer didn't include, other significant pieces of Google investment that are not remotely ad driven, like Deepmind & the entire RMI (Research & Machine Intelligence) organizations.
What I am trying to say: The whole online advertising business would not be that creepy if Google and Facebook wouldn't compete on who can track more out of the web users. The reason why we call them an advertising company, is that their core actions are driven by their advertising business. Otherwise, you would consider calling them a search company ;-)
This is what people said about Google too a few years back.
The reality is: Everything they're doing is designed to increase the company value for their shareholders.
That's not exactly true. Both companies have shown that they _will_ switch to selling something different when they believe they can make more money that way.
Also, both these companies spy on you while using their products, and both sell that data to their advertisers. It's not just Google.
You should use both their products as you want, when they help you. My point is mainly not to trust that the company behind the developer products is some kind of a good actor. They will sell you out when it fits them.
Also while MS is good to integrate third party open source projects, it also fails at the same time to address some core concerns of developpers from its own platform. For years people have wanted a portable UI framework for .net but the idea is always dismissed by the higher management. So, I think Microsoft is actually a developer-second, hype-first company.
More than a decade ago the behemoth was Microsoft. Now it's Google. I guess if those positions reversed again I'd go back to being more skeptical of Microsoft.
That's not even remotely true. Powershell core, SQL on Linux, WSL, vs code, etc etc. They're doing their best to give customers choice in just about every new product they release.
Their customers are still primarily enterprise/gov.
And the reason for giving choice and candy to the developers is to keep them onboard and happy to develop for the ecosystem, so that customers will continue to buy in as the ecosystem has what they need.
I'm not saying WSL or VS Code are evil. They make developing on Windows a joy. But they make it a joy with that goal in mind.
The only other apps they're selling on-prem to enterprises are Exchange and AD.
In both cases, their focus is on moving customers to a hosted/cloud based version, so it's not something I would ever expect them to spend a ton of time and effort porting to another on-premises OS. For SMB they've become far, far more open both licensing it to third parties as well as helping out the samba crew with the open source version.
Do you have a single example of them being openly hostile? Or you're just whining about them not open sourcing and giving away the farm?
The spyware literally built into Win 10 - and backported to previous windows - which can't be disabled without third party products?
To me, that's openly hostile to everyone. Note - "everyone" includes developers. I'm not sure why many people seem to give MS a free pass on this. :/
I'm not sure why everyone pretends this is an MS thing and not an industry thing :/
Maybe you're meaning some non-IT industry? eg Marketing?
Nowhere did I claim them to be hostile. I never expressed my thoughts on how they acquire business as good or bad.
All I did was state that "They're doing their best" isn't out of the goodness of their hearts, there's a biz decision behind it.
> Or you're just whining about them not open sourcing and giving away the farm?
Way to try and attack my character. Never said a word of what you're accusing.
With Google I’m not so sure any more. Hopefully I’ll soon be able to say goodbye as well.
Microsoft didn't take over the Evil Empire title until the late '90s, IMO.
If Google wants to throw some of their money on something that end user can fully control, then why not be happy about it?
GitLab is open core, not open source. They say so themselves:
https://about.gitlab.com/2016/07/20/gitlab-is-open-core-gith...
I'm planning on, once again, spinning up my own mailserver on a $5/mo VPS. Have lots of domains, but not that many users/traffic.
I'm slightly bothered by the fact that their servers are located in the worlds surveillance hotspots no. 2 and 3. but i guess email always has at least 2 involved parties, so it's not exactly "top secret".
I used to run my own mail server for years but spam was becomming a problem as it always does when running your own system and I thought the pricing of most of the services was poor if you had lots of addresses but didn't send/receive many emails. Spam hasn't been an issue for me with mxroute so far and their infrastructure seems to be pretty solid.
If you are the only actual user of those emails accounts, then it's a great option (I have 5+ domains under a single account with them)
I'm always very nervous when it comes to running docker in production. Also, it looks like it (by default) stores emails in a docker container, which in my book is just overcomplicating things. While i don't mind software being containerized, i much prefer having my data stored in the plain old filesystem.
AND they can import your gmail account. They imported mine in a few hours, 4.5gb of mails.
Anecdotally speaking, the culture enforced by Ballmer was not that popular among Microsoft's employees.
What I'm saying is, employees don't get to decide how a company is run.
Besides, the risk here is toxic managerial choices, and you can and do swap out VPs and similar over half a decade.
They haven't bought GitLab
Very transparent to users, open core, very modern tech stack, entirely remote workforce, what more could you ask of a company? They aim to do things basically the way we as a community would ask.
How will it turn out? Anyone's guess :)
Don't they have massive scaling problems? And didn't they delete their production database by mistake recently?
GitHub doesn't seem to have faced the same problems - so it seems difficult to argue GitLab has better practices.
> what more could you ask of a company?
Reasonable page response times?
[1] - https://gitlab.com/gitlab-org/gitlab-ce/merge_requests?label....
That was in February 2017 [0]. Not exactly recently IMO.
I recall that Github also had data loss and scaling issues back when they were starting up. Those days are now gone for them though.
[0] - https://about.gitlab.com/2017/02/01/gitlab-dot-com-database-...
The real question is did they learn from their mistakes and implement better guardrails to prevent this from happening in the future?
Support for plugins?
- gitolite: easiest to install and manage. But there's no web interface. Your entire workflow is with git itself (and maybe some SSH/Unix tricks/scripts).
- gitlab: huge, bloated beast. Many, many different components. Difficult to understand all the pieces. Uses a ton of ram and CPU cycles. UI and workflow is different from Github.
- gitea: single, stand-alone package. UI and work-flow is identical to Github. Given all that it does, it seems about as simple and light-weight as it could be. (My only pain point is that it's written in Go, with Go packages, and I don't really know anything about Go...)
There is mostly functional git remote - https://github.com/ipfs-shipyard/git-remote-ipld - It's still missing "full" remote tracking with IPNS, that will get implemented soon after next go-ipfs release, so it's a bit weird to use now
Git portal is also taking shape: https://igis.io/ (also accessible via any gateway - https://cloudflare-ipfs.com/ipns/igis.io/). Git repo is at https://github.com/ipfs-shipyard/IGiS (Dynamic features like pull-requests are hard).
Edit: formatting
It's good, by the way.
Single Sideband Radio?
I wasn't aware MS was critical of GitHub and GitLab. Does anyone has more info on this?
> historically critical of open-source tools that have its file hosted on GitHub and GitLab
Maybe it was overzealous editor and simplified it too much.
For the benefit of the reader, they explain that GitHub and GitLab are (more or less) open-source tools.
Can someone describe to me how bidding for companies like GitHub works? Is it a blind bid where the highest bidder is selected? Or are participants given the opportunity to up their bid against one another?
There was certainly more to it than comparing two numbers.
The market segment of web hosted Git repositories was a relatively new and small market segment when GitHub got started back in 2008.
GitLab didn't appear until 2011, and at the time it didn't feel to me like a direct competitor. So GitHub had quite a bit of extra time to establish its presence and capture a large share of a growing market.
For a large chunk of GitHub's users, GitHub fulfills their needs well enough that they don't feel much motivation to make a change. Even if GitLab is better than GitHub for a person or company, it has to be better enough to be worth the pain of switching.
And I think for most users, that just isn't the case. Speaking anecdotally, there are some things about GitLab I like more than GitHub. And if I were starting out, I'd likely pick GitLab. But all of my code is on GitHub, and although I pay a monthly fee for private repos, it's small enough that it doesn't bother me.
I haven't gone through that document yet, but I'll take a look.
I believe that GitHub is more popular mainly because it was first, gained traction and became synonymous for some people with git itself, and open source.
Right now, I've got several local machines hooked up to gitlab.com as runners. A mixture of virtual machines for various platforms, and docker hosts. No kubernetes yet; but likely at some point.
The main problems are that sometimes gitlab.com is flaky. Pipeline jobs fail, never get started, or never complete. Not often, but enough that I can't guarantee things will work without manual prodding. I saw quite a few instances of this a few weeks ago, but it's been OK this week. Stuff like the runner timing out pulling a docker image, the job completing but not actually finishing, or the pages job running but the deploy step getting stuck with no way to debug it.
Other things are UI annoyances, like the pipeline status not updating frequently enough, leading to repeated manual page refreshes, particularly on navigating back in the history to the pipeline page from a specific job page.
I'm really glad to hear you're excited about the way we integrate everything together.. that's something we're really proud of with our product and an area we're going to continue to invest in as well. This year we're going to explicitly plan things out so that we're building a breadcrumb trail back for all users to start taking advantage of those more advanced features.
You can check out the rest of our vision for 2019 here: https://about.gitlab.com/direction/verify - would love to hear your thoughts and feedback on it.
ducks in advance - I acknowledge that Microsoft and Google are not without sin, especially Google, but at least the coding and engineering teams of Google that I've been watching, namely the prolific #webperfmatters crowd behind free beer contributions such as SPDY, QUIC, WebM/WebP, mod/ngx_pagespeed, Brotli, HSTS pinning and leveraging other teams' Google assets like SERPs and Chrome padlock design to pressure the adoption of HTTPS use, at least that behavior, talent and energy seems to be in line with the gist of Github. These teams collaborate with organizations you (plural) find much less threatening, for example with Brotli (gzip alternative), there was collaboration between veteran Google and Mozilla developers, and now about 85% of us use browsers that have implemented Brotli support which, in addition to claims and my own testing, is across-the-board superior to gzip in this context. As for adoption on the server side, NGINX at least was open minded.
All the time independent developers cook up superior things to prevailing standards but, lacking the might of Google and Microsoft and Mozilla, their work seldom gains traction. Git* under control of Microsoft and Google could give the little guys with the superior code a better spotlight, a symbiotic win-win for everybody.
I am convinced guys like Ilya Grigorik and Colt Mcanlis show up to work, and to public lectures, with making the web faster as their objective. Were they pressured to insidiously exploit Gitlab to our detriment, they'd blow whistles to stop Google, like with AI collaborations with the military, or at least resign, I'd hope. They'd have better and nobler things to do than be party to that.
Judging from the pronounced skepticism and negative consensus among this crowd to such actions, I think you will do an effective job hedging the risks and "keeping them [Google, Microsoft] honest" with respect to treasures like Github and Gitlab, both in your scrutiny and the influence you wield.
I also think that, if they behave themselves, their control over Github/Gitlab may give them more return on their respective investments than were they to Do Evil. Further, if they can't resist their undesirable habits, or even if they do behave, a market has already been created for some sort of Lavabit-like set of competitors to emerge, and that should be regarded as a good thing as another consensus hereabouts has been, before Microsoft's involvement, that Github's growth was a threat and at odds with our interests.
That said, note the lack of citations in my comment indicating that this is nothing but unfounded devil's-advocate corporate-apologist Google-fanboy speculation on my part and that you all are probably right... Cheers everybody!
edit: Ouch, i thought that was more substantive than contrarian. Before this gets voted to death, could someone please offer a rebuttal? I'm often wrong and it could help me wake up.