Valkey Is Rapidly Overtaking Redis
devops.com
devops.com
antirez retired from Redis development a few years ago.
From https://github.com/redis/redis/graphs/contributors it looks like activity since he left has been mostly from people who didn't overlap with him much.
Redis Labs have not shown themselves to be outstanding stewards of the project as far as I can tell. Why shouldn't people support the fork?
https://devboard.gitsense.com/redis?id=f66d8a46ef
If you ignore comments and just look at people raising issues and pull requests, Valkey has more contributors
https://devboard.gitsense.com/redis?id=f66d8a46ef&comments=i...
Full disclosure: This is my tool
https://devboard.gitsense.com/redis?id=f66d8a46ef&comments=i...
Redis has 14 contributors vs 48 for Valkey. I think it is very unlikely that Valkey is adding a lot of new code right now, so the activity is probably related to the rebranding to Valkey.
Maybe version number/release cadence is also helpful.
I had (and will reintroduce in the future) a contributions insights tab that focused on labels, which I think can also help you understand how things are changing without actually digging into the code.
That's a valid question and to be fair to Redis, we should also ask ourselves what are the incentives for Redis (or any other commercial oss) to continue development of truly free and open-source Redis?
If the answer is opensource ideals, it is not an honest or realistic answer.
If the answer is they can always get paid through hosted offerings and product support, Redis folks are saying that's not a sustainable option because of cloud providers.
Redis users fall into broad categories of individual developers, startups, medium level companies and enterprise scale companies. Individual users are unlikely to pay. Enterprise customers are big enough to have dedicated resources for support. It leaves startups and medium level companies. These users are leaving on-premise and moving to cloud providers and if there's a frictionless hosted solution by the provider itself they are likely to prefer that over paying Redis. There are always exceptions but I don't think this is far from reality.
If the quip is, Redis should offer a better product, they cannot! Not when competing with cloud provider's own offerings. They will be always be at a disadvantage in terms of total cost(for marketplace products) and resources spent for development of the core product itself.
I believe their license changes is about them trying to reduce the impact of cloud offerings.
I don't know if there is a better approach for Redis and the community but as users of their product we are also responsible to provide a sustainable path for development and come up with a solution for this common problem. Otherwise, Redis will not be the only product to take this direction.
PS: There are exceptions like postgres but there aren't enough of them at that scale.
We need more communities and projects like PostgreSQL. Why can’t Valkey be another one?
This describes Redict, not Valkey. I think it's actually great we have two forks, so they can focus on different things.
Were you self-hosting redis in all your companies, or how were you using it?
I honestly don't think that was the issue. The issue, unlike Elastic vs Amazon is, this change affects a lot of big players like Google, Amazon, and Oracle.
I think the real difference is that Redis Labs never hired the majority of contributors.
It's sort of how I don't hire junior people. When others have trained them up, I can just hire them for more. The other guys have to pay to train them so they hope to get some reward for that, but switching costs are low. I can just take pre-trained guys.
And just like the pre-trained guys in this scenario, AWS can always offer a better deal. You need to moat your stuff in some way. Elastic License is ideal if you want to build a company around this. If you just want to make things for the good of mankind or whatever, you can use BSD/GPL/MIT/whatever, but you're doomed if you want to build a company around those licenses.
Elastic made it by being quick to the jump. Others have followed. The only really successful model that's different has got to be Kong and RHEL and they've both been around a while. Kong's adoption is troubled because once you get successful, using their OSS thing is better than the enterprise because their pricing tiers go up. But they seem to have good enterprise sales team. Don't know about RHEL.
But if I were starting a company around this stuff, I'd be very careful about having core tech be true OSS. Source-available yeah, but true OSS is too risky.
You could always just like, not do that? There is nothing preventing anyone from simply not open-sourcing their software. Complaining that "people can use your open source software" is like complaining about how trees split water
Based on what I've seen, a lot of people contribute to VC/commercially backed projects for resume/career growth reasons.
Commercially backed is a pretty big bucket and includes things like Linux and a lot of Apache Foundation projects (iirc Apache projects need to maintain a sponsoring organization but it doesn't have to be for profit)
I understand that position, but I think it depends on a few more factors.
Google doesn't monetise Go, so I would have less problems contributing to it. Redis, before the license change, is a perfect example of what I wouldn't contribute to.
Any project with a permissive license (BSD/MIT) can always be made into a commercial product. I could fork Valkey any minute, change the name and start selling it.
Community willingness to maintain popular software under the old license means that attempting to make free non-free will result in a fork taking over.
As a prior example look at what happened a few years back when Oracle tried to make Hudson non-free. Now nobody has heard of Hudson, but everybody uses Jenkins. Which name was chosen for the sheer mockery value and reference to the then infamous https://www.youtube.com/watch?v=mLyOj_QD4a4.
There are people who think we need the legal protection of the GPL. But there are others who trust in community pressures to make the right thing happen.
It's a kind of pun that programmers like. For example when I asked, Larry Wall said that he named Perl, Perl after he had two acronyms. Namely Practical Extraction and Reporting Language and Perfectly Eclectic Rubbish Lister.
I think both opinions are fine, if you don't want your contributions to end up in a commercial product, you can't contribute to a project with BSD/MIT license. On the other hand most companies prefer to support projects with a permissive license over projects with copyleft (GPL). For many projects (except the big ones like GNU/Linux) copyleft seems to be more of a burden.
Valkey (12k stars): Excluding merges, 41 authors have pushed 147 commits to unstable and 181 commits to all branches. On unstable, 473 files have changed and there have been 10,635 additions and 9,663 deletions.
You may as well just start mentally teaching yourself to alias redis to valkey.
Let's check the numbers in 6 months or a year for a truly meaningful figure about the health of each project.
I'm fine with using the activity comparison to declare a winner.
But valkey was created a few weeks ago, obviously it's going to have a burst of activity. However most forks die off rather quickly after the initial burst of enthusiasm. That one might be different, because it has corporate sponsors.
So, in 6 months, do the exact same comparison (recent activity, # of recent contributors) and it'll be good enough for me.
Valkey just released their first stable version 3 days ago. So it might take another week or two until it's popular ;)
That’s my take away from this anyway!
I have the feeling that CEOs are mostly stupid people.
Run away screaming as fast as you can.
It affected us when upgrading Sidekiq to version 7, which dropped support for older Redis, and their Envoy proxy setup didn't support HELLO and RESP3: https://github.com/sidekiq/sidekiq/issues/5594
The OSS and Cloud divisions of most companies are very different beasts. The engineers that staff them are different, and their focus is different. This has often lead to issues where the company that creates the project doesn’t always have the capability to support it at scale.
TBH, while I don’t support that kind of behavior, the cloud providers probably provide the best SaaS support for most OSS projects, just because of the operational capabilities they have created.
Also, nothing of value was lost. The new forks have all the source code.
What about the community fragmentation and the eventual rise of incompatibilities as the development will take on slightly different directions? E.g. what happened with MySQL and MariaDB.
An issue with databases is that unlike browsers, there’s not that much incentive to standardize, since most apps pick one and stick with it, and their users don’t care.
The one thing I take as a bit of a potential bitter irony is that if Redis had had the level of support & contributions ValKey has, Redis Labs might have been able to keep doing what they were doing?
Seemingly a bunch of companies are happy to start paying for open source, when weeks ago many were passive consumers.
I wouldn’t sign a CLA to anyone other than maybe the FSF.
Point remains: there's a more than small irony here that a company wasn't doing well/was struggling with open source, but could perhaps have done great if the help freshly created has been at all available when they were fully open source.
https://github.com/vulhub/vulhub/tree/master/redis/CVE-2022-...