Live data from Hacker News

A faster heart for F-Droid

f-droid.org

11–20 of 231 posts

Re: A faster heart for F-Droid

#11
post #6

So.. what kind of hardware did they buy?

Yeah kind of conspicuously absent! They said > The previous server was 12 year old hardware which is pretty mad. You can buy a second hand system with tons of ram and a 16-core Ryzen for like $400. 12-year old hardware is only marginally faster than a RPi 5.

Unfortunately you can’t even get the RAM for $400 anymore.

Re: A faster heart for F-Droid

#12
post #4

Hmm: “F-Droid is not hosted in just any data center where commodity hardware is managed by some unknown staff. We worked out a special arrangement so that this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access.”

I never questioned or thought twice about F-Droid's trustworthiness until I read that. It makes it sound like a very amateurish operation. I had passively assumed something like this would be a Cloud VM + DB + buckets. The "hardware upgrade" they are talking about would have been a couple clicks to change the VM type, a total nothingburger. Now I can only imagine a janky setup in some random (to me) guy's closet. In…

For a single server why would you use cloud services rather than go the self-owned route?

Re: A faster heart for F-Droid

#13
Ugh. This 100% shows how janky and unmaintained their setup is.

All the hand waving and excuses around global supply chains, quotes, etc...it took pretty long for them to acquire commodity hardware and shove it in a special someone's basement and they're trying to make it seem like a good thing?

F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid.

I understand this is a volunteer effort, but it's not a good look.

Re: A faster heart for F-Droid

#14
post #6

Earlier quoted context omitted.

Yeah kind of conspicuously absent! They said > The previous server was 12 year old hardware which is pretty mad. You can buy a second hand system with tons of ram and a 16-core Ryzen for like $400. 12-year old hardware is only marginally faster than a RPi 5.

Unfortunately you can’t even get the RAM for $400 anymore.

I was able to find 2 x 16GB DDR4 for $150...

Building a budget AM4 system for roughly $500 would be within the realm of reason. ($150 mobo, $100 cpu, $150 RAM, that leaves $100 for storage, still likely need power and case.)

https://www.amazon.com/Timetec-Premium-PC4-19200-Unbuffered-...

https://www.amazon.com/MSI-MAG-B550-TOMAHAWK-Motherboard/dp/...

For a server that's replacing a 12 year old system, you don't need DDR5 and other bleeding edge hardware.

Re: A faster heart for F-Droid

#15
> Another important part of this story is where the server lives and how it is managed. F-Droid is not hosted in just any data center where commodity hardware is managed by some unknown staff.

> The previous server was 12 year old hardware and had been running for about five years. In infrastructure terms, that is a lifetime. It served F-Droid well, but it was reaching the point where speed and maintenance overhead were becoming a daily burden.

lol. if they're gonna use gitlab just use a proper setup - bigco is already in the critical path...

Re: A faster heart for F-Droid

#16
post #6

So.. what kind of hardware did they buy?

Yeah kind of conspicuously absent! They said > The previous server was 12 year old hardware which is pretty mad. You can buy a second hand system with tons of ram and a 16-core Ryzen for like $400. 12-year old hardware is only marginally faster than a RPi 5.

> 12-year old hardware is only marginally faster than a RPi 5.

A Dell R620 is over 12 years old and WAY faster than a RPi 5 though...

Sure, it'll be way less power efficient, but I'd definitely trust it to serve more concurrent users than a RPi.

Re: A faster heart for F-Droid

#17
post #13

Ugh. This 100% shows how janky and unmaintained their setup is. All the hand waving and excuses around global supply chains, quotes, etc...it took pretty long for them to acquire commodity hardware and shove it in a special someone's basement and they're trying to make it seem like a good thing? F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid. I underst…

As someone that has run many volunteer open source communities and projects for more than 2 decades, I totally get how big "small" wins like this are.

The internet is run on binaries compiled in servers in random basements and you should be thankful for those basements because the corpos are never going to actually help fund any of it.

Re: A faster heart for F-Droid

#18
post #5
post #4

Hmm: “F-Droid is not hosted in just any data center where commodity hardware is managed by some unknown staff. We worked out a special arrangement so that this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access.”

"F-Droid is not hosted in a data centre with proper procedures, access controls, and people whose jobs are on the line. Instead it's in some guy's bedroom." Not reassuring.

It could just be a colo, there are still plenty of data centres around the globe that will sell you a space in a shared rack with a certain power density per U of space. The list of people who can access that shared locked rack is likely a known quantity with most such organisations and I know in the past we had some details of the people who were responsible for it

Re: A faster heart for F-Droid

#19
post #10
post #5

Earlier quoted context omitted.

"F-Droid is not hosted in a data centre with proper procedures, access controls, and people whose jobs are on the line. Instead it's in some guy's bedroom." Not reassuring.

Eh... The set of people who can maliciously modify it is the people who run f-droid, instead of the cloud provider and the people who run f-droid. It'd be nice if we didn't have to trust the people who run f-droid, but given we do I see an argument that it's better for them to run the hardware so we only have to trust them and not someone else as well.

You actually do not have to trust the people who run f-droid for those apps whose maintainers enroll in reproducible builds and multi-party signing, which only f-droid supports unlike any alternatives.

Re: A faster heart for F-Droid

#20
post #10
post #5

Earlier quoted context omitted.

"F-Droid is not hosted in a data centre with proper procedures, access controls, and people whose jobs are on the line. Instead it's in some guy's bedroom." Not reassuring.

Eh... The set of people who can maliciously modify it is the people who run f-droid, instead of the cloud provider and the people who run f-droid. It'd be nice if we didn't have to trust the people who run f-droid, but given we do I see an argument that it's better for them to run the hardware so we only have to trust them and not someone else as well.

The cloud isn't the only other option, they could still own and run their own hardware but do it in a proper colocation datacenter.
Post reply on HN