Arm Open Source makes a seamless migration to GitLab
about.gitlab.com
about.gitlab.com
It's really slow and unstable. It's also constantly trying to push different messages into my face that I don't care about nor can I switch off those messages (Autodevops for example). Some of the ui tooltips constantly block the links I want to click on, search it REALLY slow and almost useless. This is the paid gitlab.com SaaS.
Also after reading one of their postmortems about an incident where someone deleted a production DB, it just did not inspire confidence.
Also they have taken a ton of VC money, not sure how long the "not Microsoft" argument is going to stand.
Current client is on GitHub and the experience is definitely much better. Not happy about their MS ties and tech-bro misogyny problems. Hopeful for sourcehut tho.
I have never really had a project generic enough that autodevops would work. But I think I did at one point copy one of their templates as a basis for my own gitlab-ci.yaml file.
I think it also handles automatically configuring some things that you can't configure in your ci files, like prometheus monitoring.
The company I work for is in finance, but we manage a lot of things on gitlab to take advantage of git, gitlab can just about facilitate this, whereas GitHub I just don't think would be able to.
Also what's this about tech-bro misogyny? As a regular code reviewer on GitHub I actively don't really want to know anything about the contributors, so not sure what this refers to. Internal culture?
> Also what's this about tech-bro misogyny?
GitHub has kept some widely disliked (for good reasons) people on its board, and censored user content on several different directions by now. Including completely deleting some projects. It's the kind of thing that doesn't really matter to you, until it does, and if it eventually does, it really sucks.
But yeah, avoiding that kind of problem is one of the reasons to self-host.
Why not provide something, anything non-vague to go on? That's a bit of a dead end if anyone wants to know more.
To be fair these are quite old. I thought there were newer things as well but not sure.
I hope that the powers that be are listening.
I still think they're the best of the AIO SCM tools, but I think people are starting to consider disrupting them because of bloat (UI, performance).
A few years ago (when I used gitlab.com regularly), the hosted version was quite slow and felt like a buggy beta-testing environment. Not sure if it's better nowadays. On the other hand, I'm running two on-prem instances of GitLab for a few years now, and they've been working flawlessly and are fast. (One of them is now upgraded to the Premium plan.)
The problem is Gitlab has really gone off the deep end of "heavy", and - combined with inconsistent / confusing UX throughout - it makes it a poor fit for even the most well-resourced bigcorp install.
It's a pity Phabricator didn't take off. It seemed like a great contender in that space.
maybe this will be the shot across the bow Microsoft needs to hopefully improve the github experience, but i doubt it. they have a track-record of splurging cash for things they really want that could absolutely drive revenue, but without much qualified ability to shepherd the product lifecycle past the initial commitment of IP and marketing.
Arm was using GitHub for source code hosting. But most of the new core infrastructure that Arm is deploying is on proprietary hardware, and "GitHub is a black box and so we would have to work with them or let them do the work, and it wouldn't necessarily be correct," Wafaa says. "Then we'd have to do reviews. We wouldn't necessarily be able to do the patch reviews because it's all private and proprietary code… that was a big factor for us choosing GitLab."
Seems garbled, what does the proprietary nature of GitHub have to do with code review process?
Are they just saying they can’t host a lot of the code publicly?
That's my guess but not very clear at all...
But is not a great reason they probably have more products where the source is not available to them...
I don’t think you can handroll github dedicated runners (e.g. I read recently that there’s still no support for M1 dedicated runners).
If ARM wants to run CI directly on the ISAs they’re developing, or with complicated custom toolchains such that they can run tests on ISA under development from a host machine, they probably need pretty extensive customisations on the runner site, which would require contracting github to do that for them, or having to work directly on github code, for ARM-exclusive needs.
Either way a lot of collaboration work for something which isn’t really collaborative, or of any concern or value to github as a company. And with possible risks of information leak one way or another.
But it's nearly impossible to do that for the forge itself (GitHub).
I recommend https://slsa.dev (vendor-neutral effort from the Linux Foundation) for a better picture of a secure supply chain.
Simply put, the open source is a beneficial thing for Arm here.
Seems like by adopting Gitlab, you're adopting their view of how stuff should work. YMMV.
Do you have a source for this bold claim?
HN should be for facts, not Reddit FUD.
https://en.m.wikipedia.org/wiki/NSAKEY
You can scoff at the resulting fears, but the variable existing is factual.
Backdoors do exist but they're usually disguised as bugs, not so obviously in-your-face like that.
really good.
Are you talking about the programmer who wrote the website? If so, OK, I guess.
The technology itself is the opposite of opinionated or ideological. It's just git.
I'm a paying customer because I really like the UI and the base git.sr.ht service. However, hosted Git today is much more than Git. And so my overall experience is similar to the parent, I find it opinionated and stubbornly ideological. I'm close to being fed up with the "my way or the highway approach" at every corner.
Some examples off the top of my head:
1. I'm fine with sending patches via email, not every contributor is. So give me the option to accept pull requests. Instead, you'll be directed to tutorials teaching how to send patches. Needlessly increases the friction for a large portion of my peers.
2. I want to love build.sr.ht too. But, there's no Docker support. Instead you end up in discussions like "what did society do before Docker?". Give me the option to build some of my repos using my Dockerfile. Again, an ideological choice creating friction.
3. I want to use pages.sr.ht with Cloudflare. "Connections from CloudFlare’s reverse proxy are dropped." Why? "Do not help one private company expand its control over all internet traffic." OK.
All these small restrictions and gotchas with the finger wagging tone amount up to a very oppressive experience for the user. At least, that's my experience.
On 3, I agree with you. There is a lot of this sort of thinking within the product.
I don't really see 1 as a huge barrier to entry. SourceHut does have a web UI however for generating a patchset.
IMHO, Microsoft is absolute trash and their reputation isn't great, but since buying Github there have been very good improvements still being made to Github (CI.. though slowly, UI, etc). Better than being bought by Salesforce......
I haven’t evaluated it in many years but it’s supposed to have all the same features as regular GitHub.
[0] https://docs.github.com/en/enterprise-server@3.2/admin/overv...
GitHub offers self-hosted CI runners, but it's infamously limited. Last I checked there's still no official GH runner release for arm64-darwin (for which community, including yours truly, provided reliable workarounds through Rosetta that still lands you in an arm64-darwin bash, and now IIUC actual native builds[1]), there's no way to select anything else than x64 in the UI for Windows and macOS, which sets some tags on the runners that you can't remove, and there's no way to say "Other" with a custom value. Comparatively, gitlab-runner is a crazy adaptable piece of code, that allows for quite unique setups[0], combined with the loose way one can automatically assign jobs to runners using tags GL pipelines trounce GHA workflows†.
[0]: https://docs.gitlab.com/runner/executors/
[1]: https://github.com/actions/runner/issues/805
† GHA covers 80% of cases (from basic to a bit more involved) somewhat nicely, but when it starts to fall short it's terrible.
> A large bonus for Arm was that GitLab is open source and the company wanted to use its own tools to support its open source ecosystem.
> minimize vendor lock-in
> Because Arm is an IP company, security is paramount
When GNU-ish philosophy meets business requirements. GitHub can be self-hosted (at a price!) but GitLab is FOSS, so it can be audited, and if necessary, forked. From code to data, it can be owned, end to end.
Github seems to be primarily focused on becoming a social network. That might be why it’s so popular for open source and individuals, but when I’m actually working, the extensive feature set of Gitlab is much more useful.
Also Gitlab CI is a Maybach, Github CI is a PT Cruiser.
I think I understand why people say this. However, I hardly ever see any of that so it just doesn’t matter to me / isn’t a problem for me.
One thing is their org structure is weak. They don’t allow sub-orgs or any organization. So if you have a big organization, it’s just chaos and their solution is to set up profiles and complex notifications.
There’s no way to just set up groups and watch those while also being part of an overall org.
I have 500 people and 250 projects in my org. It’s all private so they expect people to use social features for team awareness. A new member has to get a list of repos worked on by their team (maybe permissions are granted based on a team) and then go star and watch them.
This is not a problem for a single coder or someone who’s on a few projects. But it’s not very good for an enterprise that already has an organization.
Instead of tidying this up, github seems to be getting worse with feeds and stuff.
I never hit the GitHub.com homepage so I never see any of this work. I always start directly on a repo, notifications, or search.
I'm still a strong gitlab supporter but tbh their development backlog is overflowing for the last 4 years at least. They have a TON of work to do and they seem to be focusing dev resources on what major clients want, instead of making the whole platform more robust. It's sad for us simple open source free tier users.
There is work to do, and product and engineering are putting more focus on fixing longstanding issues, and increase reliability. Specifically for GitLab Runner, 15.0 and later bring many fixes, next to supporting podman.
https://gitlab.com/groups/gitlab-org/-/issues/?sort=updated_...
I'm looking at this move/marketing of theirs as a show of being in opposition to Bitbucket which (along with other Atlassian's products) is made for managers.
There's no way we'll pay $4000/mo for something people barely use, but we'd have paid for something everyone uses. I think they really shot themselves in the foot with that change.
I had added most of the company to a GitLab org I created, and we were using more and more things there, we even have a private CI runner. It was a good way to gradually migrate the organization to GitLab. Now I have to move everything back because there's no way we'll pay thousands of dollars per month for it for the few things we use, and everyone but 5 people will lose access to it in a month.
Basically, the "only 5 free users" thing removes the trojan horse of gradually moving to GitLab until we realize it's worth paying for.
I couldn’t justify paying the same per seat for an every day developer vs someone who might log in once a year (or never).
They should have concurrent users or something for the PM/analyst/browser. Paying for named seats is too much.
Charging by code committers maybe make more sense…
We went with GitHub over it and it’s kind of a shame because GitLab has so many great features.
I can’t bring myself to pay for 1000 seats so 50 developers can use GitLab. Not to mention for pages viewers where there’s probably 2-5k who view project docs and stuff. Paying for users to log in and view web sites is pretty crazy.
As far as running the service goes, they do represent non-zero cost (they're going to be looking through stuff, triggering async jobs maybe, maintaining Gitlab pages setups, etc. They also represent possibly increased security burden (though I don't think anyone is pricing risk like that in the SaaS world just yet).
If you don't mind me asking, what price would you happily pay for non technical contributors? Would you want a percentage of the developer/"full contributor" rate? Or do you have a specific number that would be reasonable in your opinion?
I don’t have a specific number, but I’d prefer to just be charged for developers and have non-dev be free since their marginal cost is so low.
Same for “system accounts” and whatnot.
The key metric should be how many developers are using so there’s not much profit in adding more users other than it makes the devs happy.
If it has to be a non-zero amount then maybe $1/year or something. I have 25,000 people in my org so that’s still a lot of money even though there’s maybe only 100-200 actual devs.
Wondering if there's more space in this niche simply by listening to what customers here on HN and elsewhere have been saying.
Its a big reason we don't pay for GitLab. And will be one of the reasons we will switch to GitHub (which is sad)
Edit: Dang! I just checked it is roughly 3-4x as much as listed (just going on CI minutes). So I take my "logic" back. I don't see how they can survive at those per user rates vs the competition. The software itself is certainly not 3-4X as good.
There were recent changes to user limits on the Free tier of GitLab SaaS. We are limiting the number of users per namespace on the Free tier to 5 users per namespace. Details are in this blog post: https://about.gitlab.com/blog/2022/03/24/efficient-free-tier.
GitHub does seem a bit simpler to use in my mind. My needs are simple, though.
What does this mean? ARM needed to scale back their number of contributors because it was migrating to GitLab? I'm not sure how that can be great marketing?
I'm glad ARM thinks the same.
I'm glad a company that was willing to sell off it's IP to one of the most closed source companies on the planet fell through...
Slightly less now. But still not great.
Self-hosting is indeed the way to go; especially for companies like ARM.
Or are they just (ab)use open source projects to spend less money? (They had to pay $$$ to github).
And typically such organisations, like arm, want to have a contract, and be it only to make lawyers happy. (clearer liability etc )
Bonus: something about 5G networks.