Docker is sunsetting Free Team organizations [pdf]
web.docker.com
web.docker.com
- what actually will happen to teams that don't become paid
- what will get deleted on which timeline
- whether others will be able to typosquat the images after the teams get deleted
- how folks might handle cases where a team is owned by an oss org and has no central billing thing (fairly common)
- how we might better handle bot users as part of paid teams
Also great is that the only way I'd know this was going on is by checking my email - I quickly went to their blog to look and didn't find anything relating to this email.If anything, I'd want to convert my teams (dokku and gliderlabs) _back_ to single accounts, but there doesn't seem to be a way to do that.
I get that there is a need to make the company profitable but maybe spend more than 5 minutes crafting the email and thinking of outcomes for your users (who are already pissed at your pricing changes). This only makes me feel like I should move my hosting to something paid (ECR?), delete the org, and then typosquat the images.
Meaning if you do
docker pull rust
it'll get it from https://hub.docker.com/_/rustThen there are namespaced things, for example your new product, mattrick/awome-flobbergator
How to install? Docker.
docker pull mattrick/awome-flobbergator
Using default tag: latest
Error response from daemon: pull access denied for mattrick/awome-flobbergator, repository does not exist or may require 'docker login': denied: requested access to the resource is denied
Every time someone needs to prefix it with ghcr.io to make it pull from GitHub.We shouldn't do
1) default registries
2) when we post documentation online we should be explicit as to what the registry is
You can see it with more clarity here:
https://github.com/moby/moby/issues/11815
or here:
https://stackoverflow.com/questions/33054369/how-to-change-t...
so redhat's podman clone of docker allows this:
https://halukkarakaya.medium.com/how-to-configure-default-se...
Since the Docker daemon defaults to using Docker Hub, this feels like a dirty move to me. If I want 2 members to ensure someone can always control that namespace, do I have to pay $240 per year now?
I’d pay $20 per year for that since it helps prevent large scale squatting, but $240 per year under the threat of deletion feels like extortion.
The wording seems clear that they are going to delete all data and lock access unless payment is received within 30 days, whether there are public or private repos in the organisation.
I pay for a personal account, however my main concern is people taking over the official account names and publishing poison images which people are used to pulling already, and won't even think to check if the account ownership has changed.
I've asked the CTO to comment on Twitter.
https://twitter.com/alexellisuk/status/1635679295891812359?s...
The PDF has been updated to address that:
> Can someone else “squat” my namespace?
> No. Even if your organization is suspended, deleted, or you choose to leave Docker voluntarily, your organization’s namespace will not be released, so other users can’t “squat” your images.
> Docker is sunsetting Free Team organizations
> Free Team organizations are a legacy subscription tier that no longer exists. This tier included many of the same features, rates, and functionality as a paid Docker Team subscription.
> After reviewing the list of accounts that are members of legacy Free Team organizations, we’ve identified yours as potentially being one of them.
> If you own a legacy Free Team organization, access to paid features — including private repositories — will be suspended on April 14, 2023 (11:59 pm UTC). Upgrade your subscription before April 14, 2023 to continue accessing your organization.
> If you don’t upgrade to a paid subscription, Docker will retain your organization data for 30 days, after which it will be subject to deletion. During that time, you will maintain access to any images in your public repositories, though rate limitations will apply. At any point during the 30-day period, you can restore access to your organization account if you upgrade to a paid subscription. Visit our FAQ for more information.
Basically giving everyone ~30 days to migrate their data (to another host or paid Docker plan) or lose access to it.
As a funny side-note, the PDF seems to have been made so you cannot copy-paste text out from it, so no interactivity. But that also means that the "How much does a Docker subscription cost?" doesn't actually have any information about how much a subscription cost, and the link to the page doesn't work. Great work Docker Inc.
Big corporate players were already paying, so from a MBA penny counting move, it is brilliant.
They aren’t quite Novell/SCO levels of dumb, but it’s sad to see such a good company spiral into nothingness.
I don't get why they couldn't charge by usage, or have more granular tiers. For small teams and projects $300/yr is not an insignificant amount.
What a tonedeaf and greedy decision, communicated in a terribly unclear way.
Some comments in this discussing refer to projects with many millions of hits.
Mine has 5000. A free tier with 10GB of image storage and some small number of pulls per month would be fine.
while slowly killing their brand one cut at a time.
The name of their company is synonymous with container technology, because they made a nice UI. I think it's fair to say they have a brand.
> but what does Docker the company have to offer me? Container registry? I can get that at a number of providers who will do their best to offer an API compatible service.
That's exactly how they're killing their brand. Maybe it would be better to say they are failing to keep their brand relevant.
It is brilliant, until it's not, I'm very sure they are trying to squeeze as much as they can from the cash cow before it dies, there's almost no reason to actually pay Docker for what it is, and they lost the support from the techies who championed them 10 years ago after these pricing changes. I was one of them, had been using Docker since pre-1.0 days...
DockerHub still seems to have the most images out there and is what many people reach for when they need to run some pre-built image.
I have my own Nexus which acts as a caching proxy and is also where I upload my own custom container images to use on my own servers, but that sort of setup probably isn't for everyone.
Also, Docker Desktop still seems to be the most popular way to run containers in Windows, unless something like Podman Desktop or Rancher Desktop seem stable enough for you.
Docker wants to be a sticky default, not a commodity that has to compete with ECR and GCR on cost and features.
Now I don't use it and actively recommend a competitor. Indeed it seems more and more companies will stop using it.
With this change we'll have to move the free org somewhere else... If we do that we may as well move the paid org too. So now they're losing out on revenue, because I'm not splitting my stuff between two different registries. We'll just migrate to a new one and that registry will get our paid team too.
BUT, there's a massive brand-value to being the place, and the company that everyone goes to.
Losing that status is something they might not survive, especially in the user-hostile manner they are acting. The hate-your-user approach works only if there are no alternatives and competitors who would like to eat your lunch (github, gitlab).
What services does Docker actually provide? You don't need a crystal ball to know hosting image tarballs is going to be a very low margin business, even if you have the HUGE advantage of baking your URL into the client.
And once you kill that goose, even if it only lays copper eggs, it's not coming back. Once users don't use docker.io, what relevance will the Docker client have?
https://docs.github.com/en/billing/managing-billing-for-gith...
(Don't get me wrong, I like nix, but it's nothing like a drop in replacement for a container-based workflow)
"For our next act, let's hold their images hostage and threaten to kill them in 30 days unless they pay a ransom!"
I mean, it's ok to hate your users, but maybe just don't make it so obvious?
https://github.com/docker/hub-feedback/issues/2314
https://twitter.com/justincormack/status/1635704358355468307
---
key takeaways
> Any organizations suspended or deleted will not release the namespace, so squatting previous namespaces will not be possible.
I feel like once you have registered a namespace you should always be able to reclaim it using the same communication medium in use when it was active.
Maybe I'm not thinking deep enough on the issue though?
I got bit by that back then as a commercial customer and sent a complaint to them. Response was an offer for tickets and travel to a just upcoming Docker Con. Well, thanks but no thanks. I don't need to go to their conference when I'm busy migrating my org to a different service provider.
Presumably the publicly accessible DockerHub projects can continue, business as usual.
Are there alternative docker registry hosts which provide free private image hosting?
Edit: I found a gist with an extensive list!
https://gist.github.com/JakubOboza/fbd6259f5b6321f17e8c3cdb1...
[edit: email removed to reduce noise since it appears elsewhere in these comments: https://news.ycombinator.com/item?id=35154060]
> If you don’t upgrade to a paid subscription, Docker will retain your organization data for 30 days, after which it will be subject to deletion. During that time, you will maintain access to any images in your public repositories, though rate limitations will apply. At any point during the 30-day period, you can restore access to your organization account if you upgrade to a paid subscription.
There is no Teams for free tier. Likely everything is affected.
That'd be a great way to make Docker-the-company 100% irrelevant. I hope we're misunderstanding and they wouldn't do such a move.
We will see what will happen.
the sooner everyone moves on from docker and let it fade into the history book the better the ecosystem will be
What is different in its architecture exactly?
Docker is daemon-based and and Podman is not. Podman uses SELinux by default with additional features and other practices for better security. You can use it without root user.
No, I usually use sudo with a slightly extended timeout.
This move by Docker does not inspire any confidence in their long-term management, and will very likely drive us away from DockerHub entirely. It's really sad to watch this company fall from grace. I was an early adopter and always rooted for them from the very beginning.
> To use organization features, convert your account from a User to an Organization.
> You can't undo this action.
EDIT: I seem to have answered my own question... https://forums.docker.com/t/how-can-i-delete-old-previous-ac...
Don’t want all my images for github.com/pion/webrtc to not be available, but paying is a bit much.
However I don't see how that game play will work out, considering that each cloud provider got their registry, which ties better to the cloud platform, each code hosting site (GitHub, gitlab) have their registry, which ties to their CI offerings ... why should anybody pick Docker Hub, which is another commercial contract and ties in, in a worse manner?
You only get help if you live in poverty without any path to being paid for your time and work. Tips are "permissible"
Running your own gitea/forgejo is an option, as they can host packages as well
[1] https://www.projectquay.io/
Has Docker ever garantied that if a project closed is account another hostile one wouldn't be able to reuse the name? Outside of name takover, you could have been pulling abandonned non updated images for weeks/months without knowing it.
Now I have a small GitHub Action project that mirrors from hub.docker.com to a private registry running on fly.io. Took all of 10 minutes to set up and now I don't have to worry about getting throttled or docker hub going away.
The best (automated cleanup, permissions management etc.) in my opinion is something like Sonatype Nexus: https://hub.docker.com/r/sonatype/nexus3/ which also handles various other formats, not just OCI containers.
Others might also suggest looking in the direction of Harbor: https://goharbor.io/ but it's a bit more complex.
Here's an approximation (slightly outdated, but close enough) of how I run my own Nexus instance: https://blog.kronis.dev/tutorials/moving-from-gitlab-registr...
Not having a lot of users yet, so not sure I'll bother with the Docker Open Source Program which takes time to apply and wait for manual review. Also the email and faq doesn't mention the existence of Docker Open Source Program, which is seems a sign of no guarantee that rule won't change again.
Wondering which would be better alternative, Codeberg vs Github CR?
We keep our repositories on AWS ECR, so we don't need it on Docker.