Live data from Hacker News

Introducing unlimited private repositories

github.com

551–560 of 662 posts

Re: Introducing unlimited private repositories

#551
If someone is unsure about this math, our (we're https://github.com/artsy) bill goes up from 450$ to 1051$ per month.

But it's not about just the money, it's about incentives.

- We have large amounts of open-source code, so we were encouraged to open-source more to avoid jumping to the next tier.

- We're going to probably close access to a bunch of code to a big chunk of our organization. We have hundreds of humans. Whereas before we would give them permissions to view as a default and hope they look at our code one day or at least know that they can, or sometimes would get a link to look at a change from a discussion, we'll now have to have to see whether it's worth 9x100s of people every month.

I am not complaining, Github provides excellent service. Seems worth it at 5K$ a year and probably 10K$ a year, too. I wish it didn't just double though and was more gradual.

Re: Introducing unlimited private repositories

#552
post #178
post #148

Earlier quoted context omitted.

Compared to products like Salesforce, GitHub seems cheap to me. What to you is a fair price and why?

> GitHub seems cheap to me At $9/user/mo, github is 900% more expensive than the $1/user/mo direct competitor BitBucket. BitBucket uses brackets rather than pure scaling, but their most expensive option - 101 users require the $200 unlimited accounts plan - is still only $2/user.

* 800% more expensive

Re: Introducing unlimited private repositories

#553
post #406
post #252

Earlier quoted context omitted.

Pricing is a function of what people will pay for it, not what it costs to make. Consider Slack as a fine example.

I read an article not long ago that Github had to spin up three physical machines, just to handle one customer. Although it was an extreme example. Compared to slack, who could probably have a million users one a single machine, making it almost zero marginal cost per new user. While a user for Github means buying more hardware and a notable marginal cost. If you for example are a reseller of commodity goods, you can…

I think you're referring to the GitHub Engineering blog post [1] about our git storage tier. We [2] store your code on at least 3 servers, which is an improvement in many ways from our previous storage architecture. There are a lot of servers [3] powering things but not the millions it would require to give every customer three dedicated machines. Developing efficient solutions to problems is a requirement (and a fun challenge!) for anything at GitHub's scale.

[1] http://githubengineering.com/introducing-dgit/

[2] I'm a GitHubber. https://github.com/jssjr

[3] https://twitter.com/GitHubEng/status/730429227896463360

Re: Introducing unlimited private repositories

#554
post #413

Earlier quoted context omitted.

Bitbucket is ok for private repos. I think private repos are relatively secure there because Atlassian has much of reputation to loose if there is a security breach. Another plus for Bitbucket is the integration with Jira and other Atlassians tools. Beside that plus points I will rather go to GitLab.com (more features, better UI and integration with 3rd party) but my trust in private repos is lower there than on Bitb…

How could we convince you that at GitLab we take security very seriously?

Make a dedicated site on gitlab.com about security (make it bold) and about private repos. Some buzzwords: Countermeasures, security tracking, rate limiting, DDoS attacks, Backups... what do you do to ensure security, privacy or that nothing is lost? It's a littlebit in the dark. I would love to see comparisons between gitlab, bitbucket and github if possible (but I'm guessing that's not easy) or I would love to see somehow you take that extremely seriously for gitlab.com. I only have this gut feeling (I cannot exactly say why) that bitbucket and github feel more secure for private repos than gitlab because their business is dependent on security of hosting private repos. On gitlab.com the hosted private repos are a bonus and not the business of gitlab (because the real business is selling gitlab enterprise software and their support).

Just ask yourself and imagine this: You have a new start up company based on very valuable closed source but you entirely do not want to host my own gitlab etc. server. Which service would you use? I'm guessing it is bitbucket or github because they are offering "premium" private repos and have a good reputation (at least I do not know that a private repo there was once disclosed).

Re: Introducing unlimited private repositories

#555
post #533
post #492

Earlier quoted context omitted.

This. I use bitbucket too and I can't understand why people are still paying github when bitbucket does exactly the same and is free.

Network effects make github more valuable, to an open source organization, than self hosting or hosting on another provider. Almost everyone has a github account and asking users to sign up for another account is a significant barrier to contribute.

Neither service charges for public repositories. We're talking about private ones here.

Re: Introducing unlimited private repositories

#556

I see absolutely no reason why one would pay GitHub for private repositories when there is Bitbucket, or much better alternative to GitHub altogether - GitLab.

Yeah, this makes internally hosted GitLab VERY attractive for us now. Even the Enterprise edition is going to be significantly cheaper than GitHub.

BitBucket Server (hosted) is better.

We switched from GH:Enterprise and saved $1000's a year. Worth it.

Re: Introducing unlimited private repositories

#558
post #500

Earlier quoted context omitted.

> Saying you shouldn't store it in git seems rather like saying you shouldn't store it in btrfs. Best practice is to avoid storing secrets in plaintext, or sharing secrets between users/roles. Yours isn't an argument in favour of git, it is an argument against btrfs. (I don't have any problem with storing passwords in that way, I'm just pointing out why it's not the best practice.)

> Best practice is to avoid storing secrets in plaintext How do you store them, then? If they're encrypted with a password, how do you store that secret? I'm pretty sure best practice is in fact to store things like SSL private keys, cookie HMAC secrets (e.g. Django's SECRET_KEY), and so forth on local disk unencrypted, protected by only filesystem permissions (and the host OS as a whole protected with standard means…

TPM.

It's just one role, but multiple users.

Re: Introducing unlimited private repositories

#559
post #439
post #269

Earlier quoted context omitted.

I work for a non-profit open source organization that collaborates on github ( https://github.com/edx/ ) We have lots of people who aren't employees, but have signed a contributor agreement with our organization and contribute changes to our software. Our bill will go up from $200/month to over $2000/month with this new pricing. We can afford it (it's still a small fraction of our AWS bill) but it will force us to lo…

I've used Bitbucket in the past. They charge per-user[1], and their pricing is significantly better free for 5 users and then once you eclipse 5 users it's $1/user up to 100 users and then $200 for unlimited users. [1] - https://bitbucket.org/product/pricing

Absolutely.

I use Bitbucket for a variety of small, personal projects. And when I teach Git courses, I use Bitbucket to illustrate (and practice) pull, push, and pull requests (among other things). Sometimes people wonder why I'm not using GitHub, which has made itself synonymous with Git for many people, but after a short explanation, they understand.

However: GitHub has a huge network effect. Most developers with any sort of open-source connection have a GitHub account; many fewer have Bitbucket accounts. This isn't the end of the world, but it does mean that GitHub has a leg up on the competition as far as name recognition is concerned.

Plus, there are lots of tools that talk to the GitHub API.

So, while I personally endorse using BitBucket, I can understand why many would stick with GitHub. It'll be interesting to see what this price change does.

Re: Introducing unlimited private repositories

#560

1. Take a gazillion dollars in funding on an over-hyped valuation, 2. Go through significant organizational changes that end up with the departure of a co-founder (and more suits in the building). 3. Notice that a significant segment of your growth (VC-funded startups) are running out of money. 4. Switch to a user-based pricing to generate more revenue for investors, but spin it as a freebie "Hey! Look at the cool un…

[deleted]
Post reply on HN