kentonv changed the topic of #sandstorm to: Welcome to #sandstorm: home of all things sandstorm.io. Say hi! | Have a question but no one is here? Try asking in the discussion group: https://groups.google.com/group/sandstorm-dev
TC01 has quit [Ping timeout: 260 seconds]
TC01 has joined #sandstorm
_whitelogger has joined #sandstorm
_whitelogger has joined #sandstorm
robbt has quit [Quit: Connection closed for inactivity]
_whitelogger has joined #sandstorm
<CaptainCalliope> <dckc "Lyre Calliope, I know some folks"> Hold off until we've had a few more conversations. I'd like to at least be able to communicate how we intend to move forward in making decisions in allocating resources before starting to pitch orgs. Also, one pattern I've seen with open collectives is creating contributor teirs specifically for organizations which is one way we might consider structuring these
<CaptainCalliope> relationships.
<CaptainCalliope> I spoke with ocdtrekkie earlier today about some governance things and I'm writing out some proposals I'll share in the next day or two.
<isd> kentonv: I'm perusing the source and noticed there's some logic for launching the supervisor directly as a command. Is that actually used for anything? It looks like a historical artifact.
<isd> Ah, found the use in backend.c++, nvm.
_whitelogger has joined #sandstorm
<isd> 3/quit
dckc has quit [Ping timeout: 268 seconds]
frigginglorious has joined #sandstorm
dustyweb has joined #sandstorm
<dustyweb> hello hello
ocdtr_web has joined #sandstorm
<ocdtr_web> dustyweb: Hey!
<isd> Ahoy!
<isd> ...so I just got an email from npm letting me know they got bought by GitHub.
<ocdtr_web> That seems very no-brainer-y to me too WRT GitHub Packages.
<ocdtr_web> I think a package repository built directly on GitHub has a lot of opportunities to demonstrate safety and authenticity.
<ocdtr_web> Presumably GitHub Packages can provide the capability to verify/ensure that a package is built from the source contained in the repo.
<isd> It mostly makes me nervous abou the increasingly centralized infrastructure used for FOSS development.
<ocdtr_web> There's definitely an irony to it. Given that the company in question is Microsoft.
<ocdtr_web> :P
<isd> Frankly, there's no good reason to have a centralized package index anyway. Go does this right: just have the package tools support URLs.
<ocdtr_web> Package repositories like NPM have already been a very uncomfortable level of centralization to me.
frigginglorious1 has joined #sandstorm
<ocdtr_web> And in NPM's case specifically, the source of a lot of problems from a security standpoint.
frigginglorious has quit [Ping timeout: 246 seconds]
frigginglorious1 is now known as frigginglorious
<isd> ...but I think only because of its popularity. Architecturally it's not different from most package managers.
<isd> (Go again being an exception: the build tool doesn't just run arbitrary code for you).
<CaptainCalliope> Ugh. GitHub has always made me uncomfortable. More and more so.
<isd> Thought experiment: what would be needed for sandstorm to self-host the community infrastructure that is currently on GitHub?
<isd> Also: what are other possible GitHub alternatives, and what would the pros/cons of switching be?
<isd> I'm not necessarily pushing for us switching away, esp. on any particular timeline. But maybe it's worth actually thinking about the implications.
frigginglorious has quit [Read error: Connection reset by peer]
frigginglorious has joined #sandstorm
<ocdtr_web> We'd probably want to update the GitLab package so it had all of modern trimmings, things like CI and stuff are part of GitLab, so we would have to rework our Actions and the like.
<ocdtr_web> We'd also need the standalone domain type functionality at least so we could have something like git.sandstorm.io.
<ocdtr_web> The largest issue I see is losing a lot of drive-by contributors and issue submissions. The community effects would be very unfortunate to lose.
<ocdtr_web> I am much less likely to bother trying to submit a PR or report an issue if it's not GitHub.
<ocdtr_web> Drew DeVault's sr.ht is fully open source and very affordable (currently it's pay-as-you-want, actually) and includes mailing lists. I was intrigued by just the ability of getting off Google Groups potentially there.
<isd> GitLab CI requires a separate service set up and we (1) won't be able to do that in Sandstorm because it needs to launch VMs and containers and such, and generally needs access to stuff we block, and (2) We need root in CI anyway o actually set up sandstorm, and gitlab's CI currently will only run (unprivilidged) docker containers afaik.
<isd> The drive-by contributions is my biggest concern as well.
<isd> But it's also my biggest concern with GitHub -- the fact that that attiude is common is what worries me, and I feel like if a community project focused specifcially on user autonomy and decentralization is not going to challenge that norm, we're in deep trouble.
<ocdtr_web> It's possible if the experience is smooth enough at a easy-to-access subdomain, with GitHub login enabled, as Sandstorm generally does, people may find it still easy enough to.
<ocdtr_web> I would say the point where we can meaningfully push "we should self-host this" over "GitHub brings nice perks" is when self-hosting it provides more perks than GitHub. Which for Sandstorm, generally means the benefits of Powerbox integrations and the like.
<ocdtr_web> A lot of entities aren't going to embrace decentralization until it is more beneficial to them than centralization. Either because the central entity is now doing bad things or because they glean actual value from the control and separation.
<ocdtr_web> My biggest concerns with centralization is privacy-oriented, personally, but that isn't really something that holds up for hosting Apache-licensed code: It's public anyways.
<isd> I agree it doesn't make sense to switch until the software actually meets our needs.
<ocdtr_web> Re: GitLab CI on Sandstorm, could we still host GitLab on Sandstorm and use the Powerbox to grant it ability to talk to a separately hosted CI setup then?
<isd> We could probably integrate a separate GitLab CI setup, yes.
<xet7> I'm worried about GitHub because of this https://news.ycombinator.com/item?id=22593595
<xet7> recent example
<xet7> Some have asked about integrating Wekan with Gogs/Gitea/GitLab . There is also https://github.com/wekan/wekan-gogs integration that is not directly in Wekan packages yet.
<xet7> At Gitea issues they are discussing could they self-host Gitea
<xet7> Yes.
<xet7> What do you think about fossil-scm ?
<ocdtr_web> I know nothing about it.
<isd> fossil is really neat, and I feel like would make a great sandstorm app.
<ocdtr_web> It may be worthwhile at least, at some point, particularly if we have standalone domain capability, to mirror Sandstorm repos between GitHub and git.sandstorm.io or something like that.
<xet7> https://www.fossil-scm.org Single binary, saves data to sqlite database
<xet7> Takes much less disk space than git files
<ocdtr_web> Perks of using a decentralized version control solution is we could provide a GitHub-free interface people could participate in, and also have access to the GitHub community.
<xet7> big files are compressed
<isd> ...but for sandstorm's purposes, "scm that's not Git" worries me more than "not GitHub"
<isd> I think mirroring/syncing to GitHub would be a good thing.
<ocdtr_web> Fossil probably would package fantastically on Sandstorm, SQLite-based things tend to be happy Sandstorm packages.
<xet7> Git repos can be imported to Fossil
<isd> I think the main annoying thing is that it has its own user/auth system. Haven't dug in enough to know how easy that would be to fix.
<isd> xet7: yeah, migrating isn't so much the concern as I think it would be a bigger barrier to contributors, just because it's not the thing everybody uses.
<xet7> Yes.
<xet7> Fossil is very bandwidth efficient, so it would be a improvement
<isd> I'm not really concerned about git's performance.
<isd> ...maybe I'll fuss with porting it.
<isd> re: the hacker news article: npm already has some weird words on their list of "can't put this in a username."
<isd> I couldn't register my usual handle (zenhack)... apparently, on a site used by programmers, hack is a no-no?
<isd> Like, I expect this from a bank or something...
<xet7> wow
ocdtr_web has quit [Remote host closed the connection]