13,903 karma · joined February 21, 2007
Nothing I say should be construed as legal advice. I encourage you to seek licensed counsel in your jurisdiction if you need legal advice.
[ my public key: https://keybase.io/otterley; my proof: https://keybase.io/otterley/sigs/ciQxqIniqjt0qP_lKGryssgeBpYEjANIzawbvj_1Yt4 ]
Central banks don’t take the cause of inflation into account when they adjust borrowing rates. This is a feature, not a bug.
> The more time you spend with real people out in the world, the less you will emotionally rely upon abstract intellectual models to infuse your life with a sense of connection and purpose.
> Hold all of your opinions lightly. Be proud of your ability to change your mind. Actively seek out evidence of your own ignorance and failings.
Amen, brother.
We don’t know that for certain.
Show us the math.
A plumber comes over to repair a broken water heater. He looks at it, taps a pipe with his wrench, and it's fixed. He hands the customer a bill for $500. The customer becomes angry because all the plumber did was tap a pipe, and demands to see an itemized bill.
The plumber dutifully provides the bill:
* Pipe tapping: $5
* Knowing where to tap: $495
How so? Whether a dependency is vendored or not, you still have to update it to integrate a security update to that dependency, don't you? The alternative is to not pin your dependencies, but that is far riskier overall.
> Whether or not the benefits are worth the inconvenience is a different question
I would contend that it is the most important question. :-)
I edited my comment above to explain in more detail what these charges are covering (and it’s not egress bandwidth alone). This has been a fast moving conversation and I’ve tried to add more context, unfortunately after the fact. My bad for posting too quickly.
Again, these egress fees are not paying for egress alone. They are defraying the cost of operating a massive, complicated, low-latency, reliable cloud network infrastructure, much of which is free of charge when used internally.
Some, like you, are expecting that cloud providers operate on a “cost plus” model where what you pay is strictly based on what marginal costs for the same thing. But it’s not that simple in reality. Charges levied for one thing can be used to pay for another.
Many of us are aware that ISPs charge less for bandwidth. But they are not offering the same thing as a tier 1 cloud provider.
You may find these interesting:
https://aws.amazon.com/video/watch/c37546e1558/
https://cloud.google.com/blog/products/networking/speed-scal...
And kindly refrain from accusing others of Stockholm Syndrome here. It’s incredibly rude.
This isn’t just AWS BTW; all tier 1 cloud providers recoup their costs this way.
Is this a significant risk in reality? MBPs today come with a minimum of 1TB of storage. Even 5 years ago I think the minimum was 256 GB. This is more than large enough for all but the most massive repositories, even with vendored dependencies. And you can always plug in external SSDs or HDDs or connect to a network server.
> And what’s the advantageous scenario for vendored dependencies? Is it just when the mod proxy and the upstream code host go down at the same time?
This is a useful homework assignment. Ask your favorite LLM or consult some respected release engineering books. Also consult your local AppSec and infosec teams.
Recursive dependencies have the same issues whether you vend them or not.
Ensuring that diffs to updated dependencies remain within a vendor folder is trivial.
So, what’s left?