(This isn't to take away from Rancher, by the way - good on 'em, I'm all for competition in developer tools)
(This isn't to take away from Rancher, by the way - good on 'em, I'm all for competition in developer tools)
1. Not every widely-used tool needs to be a VC-powered unicorn startup. I'd be pissed if Linus/the Linux Foundation started to demand a per-core licensing fee. I'd probably convince my organization to switch to a BSD, on principle.
2. No one likes a bait-and-switch, and lately, lots of companies see Free/Open Source Software as a "growth hack technique" rather than an actual philosophy, because they'll otherwise face headwinds with a closed-source product. This is akin to the underwear gnome strategy:
1. Author Open Source product
2. Get wide adoption
3. ???
4. ProfitSure, there are alternative repositories and for your own needs you can use anything from Sonatype Nexus, JFrog Artifactory, Gitlab Registry or any of the cloud based ones, but Hub disappearing would be a 100 times worse than the left pad incident in the npm world.
Thus, whenever Docker Inc releases a new statement about some paid service that may or may not get more money from large corporations, i force myself to be cautiously optimistic, knowing that the community of hackers will pick up the slack and work around those tools on a more personal scale (e.g. Rancher Desktop vs Docker Desktop). That said, it might just be a Stockholm Syndrome of sorts, but can you imagine the fallout if Hub disappeared?
Of course, you should never trust any large corporation, unless you have the source code that you can build the app from yourself. For example, Caddy v1 (a web server) essentially got abandoned with no support, so the few people still using it had to possibly build their own releases and fix the bugs themselves, which was only possible because of source code availability, before eventually migrating to v2 or something else.
Therefore, it makes sense to always treat external dependencies, be it services, libraries, even tools like they're hostile - of course, you don't always have the resources to do that in depth, but for example seeing that VS Code is not the only option but we also have VS Codium (https://vscodium.com/) is encouraging.
> but can you imagine the fallout if Hub disappeared?
I wish that would actually happen - not forever - if it'd go down for a day or 2 with no ETA for a fix, and the thousands of failed builds/deploys will force organizations to rethink their processes.
I think Go's approach on libraries is the way forward - effectively having a caching proxy that you control. I know apt (the package manager) also supports a similar caching scheme.
https://www.docker.com/increase-rate-limits
Large orgs started hitting the rate limits since many devs were coming from the same ip. Most places probably put in a proxy that caches to a local registry.
I'm sure Rancher is great for personal desktop use, but there's no reason large companies can't pay for Docker.
And I don't really see this as an open source bait and switch, either. Parts of Docker are open source but Docker Desktop was merely freeware.
That said, I believe in healthy competition, and so it was quite worrisome to me that Docker Desktop seemed to be the only legitimate game in town when it came to bringing containerization with decent UX and cross-platform compatibility to non-Linux development workstations. So I'm happy to see Rancher Desktop arrive on the scene, and very much hope to see the project gain traction. Even if we stay with Docker, they desperately need some legitimate competition on this front in order to be healthy.
> I wish that would actually happen - not forever - if it'd go down for a day or 2 with no ETA for a fix
Do people not run their own private registry with proxying enabled? If Docker Hub went down at this point, I think my company would be fine for _months_. Only time we need to hit Hub is when our private registry doesn't have the image yet.
You are obviously not part of this problem.
This is really overdramatic. If Docker Inc. went out of business and Docker Hub was shutdown then the void would be filled very quickly. Many cloud providers would step in with new registries. Also, swapping in a new registry for your base images is really easy. Not to mention the tons of lead time you’d get before docker hub goes down to swap them. Maybe they’d even fix https://github.com/moby/moby/issues/33069 on their way out, so we can just swap out the default registry in the config and be done with it.
This is the exact problem! Sure, MySQL, PHP, JDK, Alpine and other images would probably be made available, but what about the other images that you might rely on, but the developers of which might simply no longer care about them or might not have the free time to reupload them to a new place.
Sure, you should be able to build your own from the source and maintain them, but in practice there are plenty of cases when non-public-facing tools don't need updates and are good for the one thing that you use them for. Not everyone has the time or resources to familiarize themselves with the inner workings of everything that's in their stack, especially when they have social circumstances to deal with, like business goals to be met.
In part, that's why I suggest that everyone get a copy of JFrog Artifactory or a similar solution and use it as a caching proxy in front of Docker Hub or any other registry. That's also what you should be doing in the first place, to also avoid the Docker Hub rate limits and speed up your builds, not downloading everything from the internet every time.
Otherwise it's like saying that if your Google cloud storage account gets banned, you can just use Microsoft's offering, while it's the actual data that was lost that's the problem - everything from your Master's thesis, to pictures of you and your parents. Perhaps that's a pretty good analogy, because the reality is that most people don't or simply can't follow the 3-2-1 rule of backups either.
The recent Facebook outage cost millions in losses. Imagine something like that for CI/CD pipelines - a huge number of industry companies would not be able to deliver value, work everywhere grinding to a half, shareholders wouldn't be pleased.
Of course, whether we as a society should care about that is another matter entirely.
Imagine something like this getting abandoned, or someone running a year old version of it: https://github.com/crazy-max/swarm-cronjob/blob/master/READM...
Its only job is to run containers on a particular schedule, no more no less. There are very few attack vectors for something like that, considering that it doesn't talk to the outside world, nor processes any user input data.
Then again, it's not my job to pass judgement on situations like that, merely acknowledge that they exist and therefore the consequences of those suddenly breaking cannot be ignored.
Things get abandoned all the time. When you make them part of your stack, you now are forever indebted to keeping them alive yourself until the point in which you free yourself from that burden.
I miss a version of hub with _only_ official images.
Given that it is extremely trivial to run your own container registry, I think the focus on this as some great common good is overstated. As it is 99% of the containers on it are for lack of a better word absolute trash, so it is not very useful as it stands.
So you think that Docker Hub is Docker Inc's entire value proposition? And if Docker Inc is nothing more than a glorified blob storage service, how much do you think should company be worth?
It'd be about as bad as that one time when Debian updates broke GRUB and my server could no longer boot: https://blog.kronis.dev/everything%20is%20broken/debian-and-...
Imagine that, but industry wide:
- you no longer can use your own images that are stored in Hub
- because of that, you cannot deploy new nodes, new environments or really test anything
- you also cannot push new images or release new software versions, what you have in production is all that there is
- the entire history of your releases is suddenly gone
I don't pass judgements on the worth of the company, nor is there any actual way to objectively decide how much it's worth, seeing as they also work on Docker, Docker Compose, Docker Swarm (maintenance mode only though), Docker Desktop and other offerings that are of no relevance to me or others.Either way, i suggest that anyone have a caching Docker registry in front of Docker Hub or any other cloud based registry, for example the JFrog Artifactory one. Frankly, you should be doing that with all of your dependencies, be it Maven, npm, NuGet, pip, gems etc.
If open-source helps the product grow and the community benefits then what's the problem? Who lost here? And why are there headwinds with closed-source products anyway? Open-source doesn't mean free, so what's the objection?
Docker the company executed poorly in monetizing their product but there's a lot of undue hate compared to the value it has created. If you don't like it when it's closed-source, and you don't like it when it's open-source, then what do you want exactly?
Counterpoint: yes it does. Hardly anyone pays for external open-source products. Managed solutions, yes, but we've seen multiple times that trying to close an open system so you can charge for it is very unpopular. For example, my workplace has a company-wide edict against using or even downloading the Oracle JDK.
And that’s sort of the problem. I don’t want the Docker Desktop that exists. I want something that does all of the behind-the-scenes stuff that Docker Desktop does and gives me a nearly-identical experience to developing on Linux even though my preference is macOS. I might even pay a _reasonable_ subscription for it.
But the Docker Desktop that is? Not exactly something that I think is worth paying for.
The problem is not with the open-source approach: in chasing growth, they commoditized both areas they could have monetized - the client and the service. If they had charged for either (or both) at first, they wouldn't have gained traction, and some other company would have ate their lunch.
The community still benefited greatly from all the development and new projects that came from this. And what is this other company that would've ate their lunch? How would that company survive exactly?
The only objection seems to be the license change, which is still free for the vast majority. Only larger commercial users have to pay, but that seems commensurate with the value they gain from it. Should companies never try to alter terms as the market changes? I don't see why people are entitled to products and services forever, and then hate the company if they try to be sustainable but also hate them if they abandon it.
Nobody is entitled to anything. Users aren't entitled to free services/products in perpetuity, but the other side of the coin is that companies also aren't entitled to those users. Nor companies are entitled to being free of any criticism.
Let me distill my thinking: a tool does not have to be a company, or be backed by a single-product company.
IMO,the more successful tools tend to be backed by a maintainer & contributors who work on it in their free time, or by a consortium of companies that do not directly make money from the tool, but are willing to put money into it. Docker-like functionality can be replaced by such models, so we are not stuck in a perpetual cycle of ${ToolName}, LLC
Ok, which tools need to be a VC powered unicorn? I’m serious.
Honorable mentions: R and Rust, maybe? But I don't see how they'd make the money back (which perhaps is the challenge Docker is running into)
edit: Also SQLite!
2nd edit: I completely misunderstood your question, I think. The answer is "none" - there are no tools that need to be unicorns, at least for those that are downloaded and can be run locally. Those that I listed could be.
Not quite bait & switch as you put it, and frankly polishing and idiot proofing tools for production workloads is expensive, and requires competent professionals that definitely need to feed themselves and their family.
You're not cornered when you can freely choose to buy the enterprise product depending on whether you get any value from it or stick with the open-source version which remains available and has plenty of competition (like Rancher).
In fact that entire issue with Docker is that they have too little value to charge for and too much competition to defend against, the exact opposite of dumping to clear out the market.
Obviously this stuff costs effort and time, you can’t expect that to be available for free.
It’s also a great opportunity to commercially exploit your knowledge and taste and make a living out of it; rather than curse “the powers that be” on a daily basis, while struggling with closed software whose only purpose has always been milking as much profit possible
+ opinions about Docker are generally not universally positive, which doesn't help. It's not a niche thing only used by superfans, but something that has been promoted and pushed widely. Not everybody who uses it likes it, and it's more infrastructure than "cool tool".
I have never seen such user-hostile behaviour from an established company like this and I for one will never ever give them a cent to reward them for it.
Chrome for example has update button in similar placement.
To me they are the definition of worse is better, but clearly only for a while.
Not only that, but it was a bait and switch. Lots of people are using docker because of the previous licensing rules and might have chosen another tool if the new licensing was already in place.
I don't fault docker but I can see why people are annoyed and looking for a drop in replacement as well.
There are no gifts, Docker isn't owed billions for trying to monetize cgroups.
That is true and that is why the Docker runtime is still free.
However this is about Docker desktop, which is mostly used on Mac and other platforms, where docker actually manages virtual machines etc.
And yeah, all software is just a layer on top of moving bits around ... some of those layers create value, some less.
The cognitive dissonance and entitlement with some is just funny to watch. They have no problem buying stuff from billion dollar companies who treat workers as crap and don't pay taxes, but a smaller developer wants to make money off of their hard work? Nah...
It's probably because a good chunk of the community is composed of privileged people, who never experienced the struggle.
That’s not on offer. Instead we get a client that’s almost as bloated as the Dropbox client.
Think of those "by the pound" frozen yogurt and toppings places. One day they charge a fair price and sometime later they up their prices and start charging different amounts for different stuff, etc.
I'm not angry if I dip on over to the grocery store and get my own stuff instead. Disappointed that we lost something cool, maybe, but that's on THEIR dumb choices.
Thankfully that's not the case. Even kubernetes, that still uses containers, moved away from docker.
anything from centralized authentication/auditing/monitoring/provisioning/reporting to checklist certifications gov demands.
I for one mostly use GPL or similarly licensed tools for my development workflow to be able to make sure my building infrastructure doesn't rot, and can be completely replicated by someone when I open the code (with a xGPL license, no less).
OTOH, I pay for some good developer tools, since they make my life easier. However, they're not irreplaceable and they're definitely not "code pipeline infrastructure" tools.
a) pretty much any closed source project or online service can be done just as well by gluing together parts of open source projects…
Which may be true in some cases, but the real misapprehension is the final part:
b) …and it won't be difficult to do.
The classic is the HN comment about Dropbox, but I see at least one comment a week saying something similar. No doubt there are many more.
Outside of very specialized tools, open source tools tend to attract more contributors and quickly overtake incumbents (see compilers). JetBrains is one of the few companies that bucks the trend, and one I gladly give money to regardless of my increasing VSCode usage.
Had Dropbox been marketed at developers only, it would have been a spectacular failure in a world where inotify, rsync, cron and scp already existed.
Large parts of IntelliJ are open-source as well, and sometimes they do get used in other open-source editors. Afaict they're pretty good citizens in terms of F/OSS.
The optimism bias is a problem even for programmers.
I struggle to remember a single paid Java library I've used in the last 10 years. Everything is free.
There was commercial ecosystem around Delphi. Paid IDE, paid components. There's paid Lisp IDEs. But it's definitely not mainstream today.
(and of course, don’t forget about Visual Studio)
The tools aren't created in vacuum and the creators also have bills to pay, just like I do as well.