Video summary
The Debian Project Board meeting focused on the operational status and future direction of the Debian.net hosting infrastructure. Historically, Debian Developers have self-funded their own services, but recent years have seen a shift where some critical services are now hosted by external providers in locations like Iceland and Ocean. The team highlighted that while current costs have risen slightly due to added services and general price increases, the financial burden remains manageable for individual developers. A key discussion point involved the challenges of managing daily backups for massive databases, which can consume significant server resources; consequently, the team is exploring automated solutions like Barman to handle these tasks more efficiently without overloading the systems.
A significant portion of the conversation addressed the evolving relationship between Debian.net and the core Debian.org infrastructure. The speakers clarified that while Debian.net currently hosts various community services, there is a strategic plan to migrate well-maintained projects to Debian.org in the future, particularly ahead of the Debian 25th anniversary. This transition aims to ensure that services meet strict security standards, are easily buildable from source, and receive timely updates. The team acknowledged that not all current Debian.net services will necessarily move, as some may lack the necessary packaging or infrastructure support required for the core project, but they remain open to contributions from sponsors or volunteers who can help bridge this gap.
Looking ahead, the board discussed expanding the administration team, emphasizing that trust and prior collaboration within the community are the primary criteria for new members rather than rigid technical requirements. They encouraged interested individuals to reach out via their mailing list to discuss how their specific skills could align with current needs, such as implementing configuration management or improving backup strategies. Additionally, the group proposed conducting a comprehensive census next year to better understand service lifecycles and upgrade plans, potentially integrating it with a broader Debian.org survey to identify underutilized but valuable projects like search engines or single sign-on systems that could benefit from shared maintenance and common UI libraries.
In conclusion, the meeting ended with an invitation for the community to stay engaged as the team prepares for the release of the Trixie distribution and plans subsequent upgrades. The speakers expressed gratitude for the attendees' contributions and reiterated their willingness to assist those struggling with service maintenance or security issues. With approximately twenty minutes remaining before the scheduled key signing session, the board thanked everyone for their participation and promised further communication regarding the upcoming census and any necessary actions for hosting providers within the next month.
Read the full video transcript
Thank you.
Uh
welcome everybody to the Debian project
board.
We plan to run a little bit shorter than
scheduled.
>> Oh, sorry, Stefano. It won't go It won't
cut.
>> It won't cut?
>> Ah.
>> Right. Now we're talking.
Um
so, we expect this talk to be a little
bit short. If I don't think we've got
enough to discuss to fill the 40-minute
slot, so we can probably all go to the
key signing
session that's downstairs after we do
the triple block here.
Um we would like to explain the Debian
project team.
>> Yeah, well, um
let me explain what we are going to do
where we are.
No, but we have Stefano here
and myself and Kyle but that's probably
Um
the the Debian project mainly is what
we're discussing because it's not
traditionally it's been about the
the dynamic aspect of that.
But we addressed the hosting side of it
because
historically DDs have hosted a a lot of
services. Some of them have become quite
important and crucial to the project. Um
but they host the things themselves and
they pay for it themselves and uh
along the years DDs have been funding
some of this but in the last
couple of years they've got one more
work so they decided now let's get
um
account services to Ocean and Iceland
and a few others and providers and we're
uh
the DD needs uh
the internet service.
We
have a DD service today
and administer and also there's some
master key as well so if someone
disappears, there is a possibility that
you can access back to the
system
and uh
Did I leave something off the team?
>> Yes, the opposite happened last year.
That happened.
When I look at the minutes from last
year, I see we were that plans to extend
the admin team. I don't think that
happened.
Uh we also did a census last year, which
we have no results but we said we
should.
So, we have been a little bit less in
the last year. But, that's also because
things have been quiet. There haven't
been very many requests.
>> Yeah, just noticed just looked at the
last month's bill. So, we're up from
around what was it? 102
euros
to 6 euros last year to about
152 euros just about in the last 50
euros up.
Not that much, but it's at least
services have been added and I think
actually prices in general went up a
little bit as well. So, it's a
combination of both.
And since this is the last year, my
ideal is if you have any suggestions or
complaints,
put your hand up anytime and we'll get
to the mic field and
you can speak up.
So, what you know
what we do is getting
one question.
What you know
big part of our work is
keeping this hosting up and
administrating the creation of the
machine. But, we also want to do some
common work to help
Um
I'll cover the needs that's needed for
these services I think. So, how about
that we suggested that it be done now
that we might do we should try to get
the
I think first grade at home
and the morality
and that could be best that
if we need the differences using a free
backup that we need
to do that.
And the performance is something like
that before I think.
Not that much.
Um but I think this is such a nice to
have to make it better to have the
in the next year that we require.
I would like to do this next next year
to get that.
Um
well that is something that we can do
but
it could be difficult to have.
And for daily necessities we're also
looking at that
uh um
verification of first grade because uh
for some services
daily backups is just
too much. Like if you look at the
metrics that we have,
it's in the hundreds of gigabytes. So,
every day when
auto post grace backup backs up this
huge database it's hours of the server
operating running a big scene
compressing that thing and
it is extremely efficient. So,
um and also again the storing of that
uh
might be a little bit risky so
um
there is this package called Barman in
the media which seems to be automating a
lot of it.
I can confirm anything but it's mighty
dangerous. Um
for daily necessities we can use that
for daily backup and
and it's I would take that easier than
that couple of coffees. So,
I know there is a technical problem but
uh um
um
also we need to start to see how it
goes.
It begins with Mike. We begin with
Mike's allocation.
>> Uh okay.
When did you start that?
>> I I don't think my system will be able
to cope there.
>> That's all right.
>> Okay.
>> That's great.
>> Hello.
>> Oh, yes.
>> Um so, I was just saying that the you
guys have a dedicated deal with the
first two goals.
Is that to meet to solve
Is there stuff that you would like
>> We can do that.
>> Do you need the service within the
oceans
Do you need to buy new servers for these
two goals?
Is it something that you can
reduce that deal because they just want
to listen to what that guy has to
Um and and the last one from feedback on
that.
>> I don't think it's either to be able to
sponsor this and that your side. I guess
I don't think it's zero.
Um ideally, hosting providers should
sponsor us because most hosting
providers make lots of money out of
Debian, so
they can give a little back. Um but you
know the cost of my things for Debian is
like nothing to pay this, so it's not
like it's a huge burden or problem, but
um sponsors are welcome and they can
certainly get in touch with you if you
want us to help. Um you definitely
mentioned that the open stack didn't
really work out. At what point were you
looking for
We talked to different sponsors, but
there was different problems with each
scenario, but the idea was to go
like a few racks to our servers and run
a Debian testing center.
If they wanted to do that
something big like relatively big like
the after three goals or
do some large scale testing, we could
set up a bunch of VMs and just run it,
or we could host stuff like this on
there.
Um but it just doesn't work out,
but it doesn't mean that it couldn't
work out in the future, so if uh
if someone [snorts] has lots of either
server and space or servers or
money or something to contribute then
we'd appreciate it. like to re- re- re-
that idea again. So,
So, yes, it's something that's really
good, but still good. And we we have
volunteers which willing to work on
that. Like you go to this team to do the
open stack training is quite
eager, but we just need the capacity.
>> Dennis, we need a mic for Nico, please.
>> Um I would also say that when people
request a VM
I usually push them to use a smaller VM
than they initially asked.
Um most of the time that works out.
Some of them run over time. I know that
the forum has been under attack in the
AI scraping world we live in now.
Um and they keep getting bigger and
bigger VMs and still scraping the
traffic.
Attach the cable. Attach the cable.
>> But yes, in in Nico's question, but
before he answers it, I wanted to re-ask
one of the question.
What can people who are citizens with us
do?
I think just keep your service
maintained like
um
let's say this particular Let us know so
that we can shut down the VM.
Um if you can stay more or less up to
date with your latest citizen of Debian,
that's really the issue. If you
struggle, let us know and then we can
help as well. We're all Debian security
team and
um
we're happy to We we rather help than
not helping and let something
get behind in our security issues and
things like that. So,
yeah, it's a general sense, but
>> That'd be also good if you have great
success.
>> Uh
I actually have a silly question that I
think is connected to the topic quite a
lot. So, um
but you just mentioned the private deals
and uh
in the Debian of netspace, somebody we
are setting up with Debian and
Um
but
it would still be interesting probably
in the sense that Debian can use
workers from everywhere.
Uh
It It's in Debian.net, it's not in
Debian.org
thing.
Which
leads to a question I was asking.
How's [snorts]
the relationship between Debian.net and
Debian.org?
I understand that
posting something in Debian.org is
a heavy weight commitment for Debian
and it makes sense not to worry and stay
with social networking.
But I wonder if there is
like a like transition plan. Like a
system starts at Debian.net and it
becomes Debian.org at some point.
The Debian hosting
wants to rely on different social master
instance.
So if there's
some kind of transition plan like that
or for monitoring
there's the
Debian services list
which is dormant but can be used to
reach all people maintaining all
services in in Debian.org
things
where there can be
some overlap of that can be had
because
it could be it can something where you
can reach people posting any kind of
services but the community doesn't have
to be fully
fully
uh
And for the question
So I just have an example of a service
going from Debian.net to Debian.org.
The reimbursement that system that we
mostly used to handle Debian claims but
also other conference expenses.
We spun up on a Debian.net VM because we
wanted it promised and provisioning new
things with TSA that takes some thinking
and time.
Uh
and we are now in the process of moving
that across to Debian.org and a VM has
been created.
The code should move
in the next week so we can do it in time
for the Debian 25th anniversary.
Um
so if
if you started your service and when
it's in your own self-created Debian.net
domain on our hosting or not,
um if it's something that you can switch
the TSA has value for Debian in the
future, you can move to Debian.org.
>> Also, TSA's quite a limited scope of
what Debian wants to do going forward.
They they focus on core Debian and
services that's infrastructure that's
needed to to to run the Debian
community. So,
um
some of the Debian.net services might
not be that pretty really. That's what
So, what I'm driving at there is that
closer to the TSA it it doesn't really
need to be
it doesn't really need actually to be
that is in Debian. Ideally it would, but
>> It doesn't.
>> It needs to be kind of it it needs to be
managed within the like
And we need to And if you if it's not
packaged in Debian, it needs to be easy
to build from source and provide
security updates and things.
Like something like that is difficult,
but the
the idea that security the
if it's well manageable, but if you look
at some of the stuff we have here at see
you getting
getting
uh I don't see you getting uh migrating
it totally.
Even if you like people
uh if you want to download it and
there's something in uh
I should have Debian.org or Debian.net
and the reality is something Debian.net
can be just as valuable and useful.
>> Can you all hear the stream now?
>> Right. Uh if if
if translation to that all things one of
two parts. It's the same and the hosting
not that can be designed with that in
mind.
So,
if you want to imagine it going to
debian.org
or then
why don't you start building? So, we can
host it in a similar way so you start
having
Django or use that in practice and
that
that kind of easy and when when you go
to debian.net
in that way you already know the
transition to the org is not dramatic.
Yeah.
>> I In the beginning I had a plan of
wanting to use DSA puppet for debian.net
machines to make that as easy as
possible. We never did that though.
>> [snorts]
>> It's It's also complicated.
>> The the the DSA puppet is is
complicated. I just looked at it briefly
a while ago because I wanted to help um
I'll change the Apache config so that we
can do HTTP/2 and I was like what is
going I don't I don't understand so
[laughter] I didn't
so
which is also interesting because
there's another transition from
debian.net to the to debian.org which is
admins.
So, this could be debian.net can be a
place to train new DSA members.
>> That was my hope too if we were using
the puppet.
But
maybe we can still get there. Yeah.
At the At the moment we are not
providing completely unmanaged um
VMs because we never really figured out
what our management would look like.
It's hard to choose a configuration
management system when there are five of
them and they've all got problems.
Um
>> And often the people who implement the
service wants to use their own
configuration management system as well.
But we did consider having a light touch
to it like at least configuring mail and
you know basics that you you working in
any VM,
Um but
>> And at this point, I think if we did it,
probably wouldn't be puppets unless
a new team member joins and makes that
happen. It'd probably be something what
Yeah, we have we can get going faster.
>> You still had a third question or did
did you cover it?
>> Well, last year, can we still twist your
arm?
Last year we were Last year we were
supposed to add you to an admin team.
>> [laughter]
>> Meh.
>> Uh so, uh you've mentioned you are going
to like you guys are going to plan to
expand the admin team. Is there any
criteria to actually be met like like
there's some like a hard limitations to
be one of the admin team?
>> I would say it's mostly trust. So, it's
going to be
um
Do we know you? Have we worked with you?
It's
>> be a DD, I guess.
>> Yeah, but
these aren't great answers, I know, but
it's the
It's It's how this is really going to
work.
Um
Yeah, I don't have better answer than
that.
>> Yeah, but also
if you're interested, let us know either
way and um
ping us on on RC and um you never know,
there might be a piece of work that pops
up that your skill set might align to
perfectly like uh
uh and let us know what your skill set
is. Maybe there's something on our wish
list or
um one of the users of the services wish
list that uh
we could make work and uh there's always
there's always space for some
collaboration somewhere.
>> And the way to build trust is come and
help us get started with I don't know
some configuration management and
>> Help us play with those grease backups.
>> Yeah.
Anything else?
Would someone like to do a debian.net
census for next year?
Should we wait till after Trixie is
released and ask when do you plan to
upgrade to Trixie?
>> That sounds like a good idea.
>> [laughter]
>> Enrico.
>> Uh when making a debian.net census, I
would
recommend including a debian.org census.
>> Ooh. Ooh.
>> In the sense that there's also the
people maintaining all sorts of things
on debian.org that
are not that known. Like
search.debian.org.
Does anyone know what that is?
It exists.
>> What does it do by the way?
>> Uh search engine on debian.org pages.
>> To search the website.
>> Uh
it's it's most I mean
there's not a lot to do, but there's not
a lot of people who do. There and it has
space for growth.
Um
integration with single sign-ons.
Uh
there's a
Django
package that isn't packaged that I
developed for nm.debian.org and I use it
on contributors.debian.org
which evolved for debusine. Uh
Uh I wouldn't mind
that being extracted from debusine into
a Django single sign-on that works for
salsa recently.
Um
building infrastructure like a Django
uh
module with the
Debian website layout or um
that that people or Django or something
else that that people can plug in
uh and get the UI.
I made it uh I rebuilt the Debian
website layout on Bootstrap. Uh
for an m.debian.org
uh uh
uh it's a bit more getting that bit
a bit common and if it's a library that
that we can build on it then it means
the web team updates the layout and the
CSS of all sort of uh services get
updated.
Uh
I'd be interested in these sort of
things to make life easier to to build
services in Debian.
>> Yeah, it might be nice to have a page
where we can say these are stuff that we
do or that we know works so that if
people do implement new services they
don't have to reinvent another wheel
somewhere else. They can reuse
components that's been
uh already been developed and used uh
>> And share maintenance of it.
>> Yeah, exactly.
Um so yeah, and do you have a line for
that?
Might be good to set up a page like
that.
Uh
Yeah.
>> Well, we have about 20 minutes. Should
we go and play key signing?
>> [laughter]
>> Good. Uh
thanks everyone for coming and for your
contributions.
Um
See you again in a year but hopefully
you hear from us before then.
And if you uh if you host a service
you'll hear from us um
about the census in
probably a bit over a month. I hope that
uh
I hope that in a month after DebConf
we'll be at at the point where Trixie is
more or less
either released or releasable. So, uh
I guess nothing is stopping us from
upgrade grading and testing stuff
anyway. So,
yeah. Um be in touch and uh
thank you.