Live data from Hacker News

A faster heart for F-Droid

f-droid.org

211–220 of 231 posts

Re: A faster heart for F-Droid

#211

Earlier quoted context omitted.

So that they can pay 100x more expenses for.. no gain? They would pay an arm just for traffic.

It's OpEx. MBAs will pour unlimited money into OpEx to avoid CapEx.

Clearly I don't have an MBA because this mindset doesn't make sense to me. Burning money unnecessarily is burning money unnecessarily, no matter where it's burned.

Re: A faster heart for F-Droid

#212

> this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access. I can’t be the only one who read this and had flashbacks to projects that fell apart because one person had the physical server in their basement or a rack at their workplace and it became a sticking point when an argu…

Is colocation not considered to be "self-hosting" in the cloud era?

In these times, even running your own software on a provisioned VM is considered self-hosting sometimes.

Re: A faster heart for F-Droid

#213

I think there are quite some misconceptions about F-Droid in the comments : - you can be your own F-Droid server In fact it's a basic static HTTP(S) server that is generated with the list of .apk and meta-data so it rely doesn't require much. I think what is concerning to people is that the most popular INSTANCE of F-Droid, the one that is by default when one downloads the F-Droid CLIENT, is "centralized" but again t…

"It's only popular, it's not really central to F-Droid itself." I've used F-Droid for years and I've never used the client ("the F-Droid app") For me the value of F-Droid is as a list of open-source software with (a) pointers to source code and (b) sample binaries The goal of F-Droid could be to enable Android users to read, edit and compile the software they choose to run on their "phones" But F-Droid promotes their…

Is F-Droid intended for "the vast majority of users"

Is popularity, e.g., user majorities versus user minorities, always equivalent to "importance". For web traffic and associated data collection, ad services, etc., popularity is obviously important. But what if one is not focused on such things

Consider the statement "It's only popular, it's not really central for F-Droid itself"

Re: A faster heart for F-Droid

#214

Earlier quoted context omitted.

A home setup might be able to rival or beat an “edge” enterprise network closet. It’s not going to even remotely rival a tier 3/4 data center in any way. The physical security, infrastructure, and connectivity will never come close. E.g. nobody is doing full 2N electrical and environmental in their homelab. And they certainly aren’t building attack resistant perimeter fences and gates around their homes, unless they’…

> The physical security, infrastructure, and connectivity will never come close. E.g. nobody is doing full 2N electrical and environmental in their homelab. And they certainly aren’t building attack resistant perimeter fences and gates around their homes, unless they’re home labbing on a compound in a war torn country. Why would you need all of that if what they have works? Nobody is going to raid a repo of open sour…

I'd bet F-Droid probably is colocated. Nothing in their statement precludes this.

But the assertion by commenters above that home-hosting is a viable or even a better option for a project like this is silly. Colocating a single server is cheaper than a single a Comcast Business internet connection. Air conditioners fail. Electrical failures happen. These things might not be a problem for a personal project, but they're easily and cheaply mitigable risks at commercial scale.

Re: A faster heart for F-Droid

#215
Is there anything that can be done about F-Droid downloading very big files (over 50MB) every time it needs to update the repository? I'd expect at the very least regular checkpoint files, then difference files that get you from one checkpoint to the next.

Re: A faster heart for F-Droid

#216

Earlier quoted context omitted.

A "single server" covers a pretty large range of scale, its more about how F-droid is used and perceived. Package repos are infrastructure, and reliability is important. A server behind someone's TV is much more susceptible to power outages, network issues, accidents, and tampering. Again, I don't know that's the case since they didn't really say anything specific. > not hosted in just any data center where commodity…

The F-Droid repos are provided by redundant mirrors: https://f-droid.org/en/docs/Running_a_Mirror/ If this is the hidden master server that only the mirrors talk to, then it's redundancy is largely irrelevant. Yes, if it's down, new packages can't be uploaded, but that doesn't affect downloads at all. We also know nothing about the backup setup they have. A lot depends on the threat model they're operating under. If…

Even if it's just the build server, it's really hard to defend just having 1 physical server for a project that aspires to be a core part of the software distribution infrastructure for thousands of users.

The build server going down means that no one's app can be updated, even for critical security updates.

For something that important, they should aspire to 99.999% ("five nines of") reliability. With a single physical server, achieving five nines over a long period of time usually means that you were both lucky (no hardware failures other than redundant storage) and probably irresponsible (applied kernel updates infrequently - even if only on the hypervisor level).

Now... 2 servers in 2 different basements? That could achieve five nines ;)

Re: A faster heart for F-Droid

#217
post #5

Earlier quoted context omitted.

"F-Droid is not hosted in a data centre with proper procedures, access controls, and people whose jobs are on the line. Instead it's in some guy's bedroom." Not reassuring.

It could just be a colo, there are still plenty of data centres around the globe that will sell you a space in a shared rack with a certain power density per U of space. The list of people who can access that shared locked rack is likely a known quantity with most such organisations and I know in the past we had some details of the people who were responsible for it

For some reason I'm reading emphasis on "just any" in their statement "not hosted in just any data center". I feel like it's at a data center run by this long term contributor.

Re: A faster heart for F-Droid

#218
post #210

Earlier quoted context omitted.

Joe's got bought out by Patmos. The jury's still out on whether or not this is a good thing.

Love finding other metro area folks on hn!

I'm actually Canadian, not a metro area person, just a happy customer

Re: A faster heart for F-Droid

#219
post #210

Earlier quoted context omitted.

Love finding other metro area folks on hn!

I'm actually Canadian, not a metro area person, just a happy customer

Ah, well, it's a great spot. I walked around when Joe was building it from the ground up. Power, HVAC, and racks of wire shelving initially.

So glad it grew into what it is now!

Re: A faster heart for F-Droid

#220

Earlier quoted context omitted.

CloudFlare is free/cheap and hey presto, no servers to manage!

And when your Cloudflare site is down, most of the Internet is down too! There's no downside!

That's true. It will be down much less often than a single server in someone's basement.
Post reply on HN