Skip to content

Internet software repositories considered harmful #176

@dpoirier

Description

@dpoirier

When our deploys pin a particular version of some software package, but fetch it from some repository on the Internet that we don't control, we risk that version not being available someday. Over time, package maintainers decide nobody will need that old version anymore. Or whole repositories vanish from the Internet.

We need our deploys to work indefinitely into the future. On the day 2 years from now when one of our servers melts down and we need to quickly deploy another one, we don't want to suddenly find half the software versions we had been running are no longer anywhere to be found on the Internet.

I think the only 100% safe approach would be to keep our own copies of things in some way - there are many ways we could do it.

This is obviously something we would need to address long-term.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions