https://www.theregister.com/2021/08/31/docker_desktop_no_longer_free/ [user] [user] Sign in The Register(r) -- Biting the hand that feeds IT [magn] [burg] [burg] Topics Security Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem All On-PremServersStorageNetworksHPCPersonal Tech (X) Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Vendor Voice All Vendor VoiceAdobeAmazon Web Services (AWS)Amazon Web Services (AWS) MigrationGoogle CloudGoogle Cloud's ApigeeGoogle Workspace NutanixRapid7Red hatSophosVeeamVirtru (X) Resources * Whitepapers * Webinars * Newsletters Situation Publishing * The Next Platform * Devclass * Blocks and Files Get our Weekly newsletter [devops] Devops Docker Desktop no longer free for large companies: New 'Business' subscription is here Search for sustainable business model continues, but most usage will still be free Tim Anderson Tue 31 Aug 2021 // 15:00 UTC 10 comment bubble on white --------------------------------------------------------------------- 10 comment bubble on white # reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy Docker will restrict use of the free version of its Docker Desktop utility to individuals or small businesses, and has introduced a new more expensive subscription, as it searches for a sustainable business model. The company has renamed its Free plan to "Personal" and now requires that businesses with 250 or more employees, or higher than $10m in annual revenue, must use a paid subscription if they require Docker Desktop. There are no changes to the command-line Docker Engine. The $5/month Pro and $7/month Teams subscriptions continue as before, but a new $21/month Business subscription adds features including centralized management, single sign-on, and enhanced security. The new Docker plans The new Docker plans The Docker platform has a number of components, of which Docker Desktop is just one part. Docker images define the contents of containers. Docker containers are runnable instances of images. The Docker daemon is a background application that manages and runs Docker images and containers. The Docker client is a command-line utility that calls the API of the Docker daemon. Docker registries contain images, and the Docker Hub is a widely used public registry. Much of Docker (but not Desktop) is open source under the Apache v2 licence. Whereas most Docker components are available for Windows, Mac and Linux, and despite the fact that most Docker containers run on Linux, Desktop is only available for Windows and Mac... Docker Desktop is a GUI tool for managing various Docker components and functions, including containers, images, volumes (storage attached to containers), local Kubernetes, development environments within containers, and more. Whereas most Docker components are available for Windows, Mac and Linux, and despite the fact that most Docker containers run on Linux, Desktop is only available for Windows and Mac. What is the rationale for the changes? Docker has become a corporate standard, CEO Scott Johnston told us, but there are security challenges with the software supply chain which the company wants to address. Further, and perhaps most importantly, the company needs a viable business model. "We continue to see growth in the developer market. The latest stat we have is that by 2030 there's going to be 45 million global developers, up from 18-some million today... that requires us to have a business that is sustainably scalable," Johnston told The Register. [devops] Most Docker users use it for free, Johnston confirmed, though he hopes that paid subscriptions will increase as a result of the changes. "We estimate that there's double the number of subscribers today that are likely to find it compelling to sign up to a subscription, but that is still less than 10 per cent of overall usage of Docker," he said. [devops] [devops] Is there a risk that some users will simply decide to avoid using Docker Desktop, and continue with the free command-line tools? "There is always a non-zero risk, but we've tried to draw lines such that it's those organizations that are already getting a lot of value from Docker Desktop, that will see $5 a seat as modest," said Johnston. Businesses need only subscribe to the Pro or Teams plans to be compliant. What is the added value in the new Business subscription at three times the price? "The Business tier at $21 a seat does add a lot more value," Johnston said. "First, it has what we call secure software supply chain features. Users can set, in a centralized control plane, what they want to allow developers to access. That is distributed out to the Docker desktops which is able to enforce those policies in the development environments. [devops] "We're also providing centralized SaaS-based management to control the configuration of CPU usage, memory, ports and firewall access. Single sign-on is another example of the security and user management that we're providing only in that Business tier." There are also options in the Business tier to purchase premium support bundles, and to scale up consumption of Docker images if it exceeds package limits, again at extra cost. Docker used to list "Premium customer support" as a feature of all its paid plans, but this is now called "email support". Penguin-shaped hole There are also a few snags with the focus on Docker Desktop, not least the fact that it does not run on Linux. "By our estimates, Linux is 20 to 25 per cent of development environments," Johnston told us. "We want to have a consistent management control plane across all of those, and so watch this space." In the meantime, "the Docker Desktop updated terms only apply to Mac and Windows." * Ably blog claims company doesn't need Kubernetes to scale, surge in traffic takes down entire website * CentOS replacement AlmaLinux free on Azure, Microsoft to provide global network of mirrors * Windows 11 still doesn't understand our complex lives - and it hurts * Will containers kill VMs? There are no winners in this debate Another issue is with remote development environments like GitHub Codespaces or Gitpod. "We do have customer requests for that use case," Johnston said, which will be addressed in part by Docker Desktop for Linux when it comes. "We still see the vast majority of our users on dedicated local machines, Windows Mac and Linux," he said, but the company is aware of the trends. "Users want the same experience remotely as they have locally, and that Docker experience can be delivered remotely. It's a matter of productization and delivery." The new terms will be a hard sell for some, but one area that Docker may be able to exploit further is security. "Every container image on the Internet is built with Docker Build. Build goes off to the Git repos, pulls the source code, builds the image. So Docker Build gives us an opportunity to be at the very start of the inception of that image. There's a standards conversion going on where we can trace the provenance of each and every layer of the image, we can start signing those layers, and with that metadata, we can start doing automated decisioning, automated reporting, automated visibility into what's been done to that image at each step of the lifecycle." Johnston envisages tooling built on this that "helps compliance officers go: 'Show me who's in compliance, update all those desktops with the latest images'... this feature set that we're introducing [now] is just the start of what will be a multi-year build-out of additional secure software supply chain patching features." [devops] Such a scenario is some way off though. The signing standard is to be Notary v2, a CNCF project, and progress is slow, with plans for 2021 focused on prototypes and to "begin a Notary v2 spec." In the meantime, Docker already offers vulnerability scanning based on Snyk technology. (r) Get our Tech Resources #Share reddit Twitter Facebook linkedin WhatsApp email [https://www.theregis] Copy 10 Comments Similar topics * MORE * Docker Corrections Send us news --------------------------------------------------------------------- [devops] Other stories you might like * IBM sued again by its own sales staff: IT giant accused of going back on commission payments promise When it a contact not a contract? When it's an incentive plan letter Thomas Claburn in San Francisco Tue 31 Aug 2021 // 21:11 UTC 4 comment bubble on white IBM has been sued by sales manager Mark Briggs for allegedly capping sales commission payments despite a written commitment not to do so, joining dozens of cases claiming Big Blue screws its sales staff. The lawsuit [PDF], filed in a US federal district court in Northern California on Friday, challenges IBM's practice of insisting that it does not have a contractual obligation to pay commissions spelled out in written documents provided to its employees. It is at least the 30th lawsuit since 2014 in which IBM has argued its "incentive plan letters" are not enforceable contracts. IBM provides its salespeople with different compensation plans that outline sales quotas, and spell out how they will be paid. Those plans typically specify that a salesperson's total compensation will be composed of something like 55 per cent base salary and 45 per cent commission, calculated as a percentage of revenue from sales deals closed. Continue reading * Google delays back-to-office recall until at least 2022 Chocolate Factory says never-ending pandemic threw spanner in October plan Iain Thomson in San Francisco Tue 31 Aug 2021 // 20:17 UTC 1 comment bubble on white Google has delayed recalling its staff to their office desks until at least January 10, 2022. In an open email today, Alphabet CEO Sundar Pichai told his staff they can choose to remain working from home until that date as the COVID-19 coronavirus continues to spread. He said "tens of thousands of Googlers" had already come back to the office to some degree voluntarily, and that there would be no mandatory recall until the New Year, and even then it would depend on local conditions. Continue reading * US officials, experts fear China ransacked Exchange servers for data to train AI systems Plus: T-Mobile US apologizes, security holes found in medical pumps, and more Iain Thomson in San Francisco Tue 31 Aug 2021 // 19:23 UTC 3 comment bubble on white In brief The massive attack on Microsoft Exchange servers in March may have been China harvesting information to train AI systems, according to US government officials and computer-security experts who talked to NPR. The plundering of these Exchange systems was attributed to Chinese government cyber-spies known as Hafnium; Beijing denied any involvement. It's said the crew exploited four zero-days in Redmond's mail software in a chain to hijack the servers and siphon off data. And what started small turned into what Chang Kawaguchi, CISO for Microsoft 365, told NPR this month was the fastest scale-up of a cyber-attack he'd ever seen. Continue reading * Windows 11 will roll out from October 5 as Microsoft hypes new hardware Staged updates mean potential wait till 2022 - particularly for those looking forward to Android app support Tim Anderson Tue 31 Aug 2021 // 16:26 UTC 54 comment bubble on white Microsoft has named October 5 as rollout day for Windows 11, though the IT giant's determination to support only relatively recent hardware will limit adoption. General manager Aaron Woodman posted the new date, and said that it is "the first version of a new era of Windows," highlighting its refreshed design, new Microsoft Store, and integration with Teams and Microsoft 365. The rollout will be gradual, with the free upgrade coming first to "new eligible devices," then to existing compatible models based on "hardware eligibility, reliability metrics, age of device and other factors that impact the upgrade experience." Continue reading * Leaked Guntrader firearms data file shared. Worst case scenario? Criminals plot UK gun owners' home addresses in Google Earth Bang out of order Gareth Corfield Tue 31 Aug 2021 // 14:19 UTC 71 comment bubble on white Updated The names and home addresses of 111,000 British firearm owners have been dumped online as a Google Earth-compatible CSV file that pinpoints domestic homes as likely firearm storage locations - a worst-case scenario for victims of the breach. As an exercise in amplifying a data theft to levels that endanger public safety, the latest evolution of the Guntrader database break-in is likely to become an infosec case study in how security breaches can become worse over time as stolen information is put to ever more intrusive uses. Leaked online last week via an animal rights activist's blog, the stolen reformatted Guntrader database was explicitly advertised as being importable into Google Earth so randomers could "contact as many [owners] as you can in your area and ask them if they are involved in shooting animals." Continue reading * Gartner predicts surge in government IT spending in post-pandemic catch-up 'Unprecedented public demand' as dear leaders heave services for world+dog online Lindsay Clark Tue 31 Aug 2021 // 13:15 UTC 5 comment bubble on white Gartner is forecasting that governments the world over will splash more than half a trillion dollars on IT next year, a year-on-year growth in spending of 6.5 per cent. The analyst and research organisation said public sector IT budgets would hit $557.3bn in 2022, 64 per cent of which would go on IT services and software to improve responsiveness and resilience of public services. To put that in perspective, the analyst said the world's governments spent $459.425bn on IT in 2020 - so the 2022 figure would be a 21 per cent increase on the first year of pandemic spending. Continue reading * Minnow Freshworks nips at tails of SaaS giants Salesforce and Servicenow with IPO plans Bach to basics: The well-funded IPO-er Lindsay Clark Tue 31 Aug 2021 // 11:52 UTC comment bubble on black Enterprise application minnow Freshworks has filed for IPO in the hopes that its SaaSy software can take on the likes of Salesforce. The India-founded CRM specialist has published a Form S-1 registration statement with the US Securities and Exchange Commission relating to a proposed initial public offering, which reports earlier this year suggested might achieve a valuation of $10bn. Freshworks specialises in providing both CRM externally and internal employee services for things like HR and IT, on the same platform, which it claims eases rollouts. Continue reading * NHS England's release of 'details' on access to Palantir COVID-19 data store: Good enough? We're in a 'dialogue' says national data watchdog Critics, meanwhile, voice incredulity over how little data has been shared Lindsay Clark Tue 31 Aug 2021 // 10:34 UTC 15 comment bubble on white The National Data Guardian declined to endorse NHS England's effort to be transparent with its recently published detail on data flows from a patient medical information project that put US spy-tech firm Palantir at the heart of the government's response to the pandemic. The COVID-19 data store was launched in March 2020, and would pull together medical and operational data about the spread of the virus. Campaigners had to force the government to publish details of the contract supporting the project awarded to AWS, Microsoft, Google, Brexit-linked analytics firm Faculty, and Palantir, whose technology has been employed by the CIA and controversial US immigration agency ICE. Continue reading * In Microsoft's world, cloud email still often requires on-premises Exchange. Why? Use third-party tools 'at your own risk' - but what of the risk of Exchange itself? Tim Anderson Tue 31 Aug 2021 // 09:32 UTC 12 comment bubble on white Comment Microsoft customers who use Exchange Online for all their email still often have to run on-premises Exchange to be supported - and that is a burden they could do without as new vulnerabilities appear. "This past week, security researchers discussed several ProxyShell vulnerabilities, including those which might be exploited on unpatched Exchange servers to deploy ransomware or conduct other post-exploitation activities," warned Microsoft's Exchange team yesterday. "It is critical to keep your Exchange servers updated with latest available Cumulative Update (CU) and Security Update (SU)." It's good advice, but many affected organisations would rather not run Exchange on-premises at all. They do so because Microsoft insists on it - even when all their mail is handled by Exchange Online. Continue reading * How to stop a content filter becoming a career-shortening network component He's not just a Big Cheese. He's a very naughty boy Richard Speed Tue 31 Aug 2021 // 08:36 UTC 38 comment bubble on white Who, Me? "Be careful what you wish for." Words that might strike a chord with the IT boss in today's edition of Who, Me? "Lee", for that is not his name, told us of his time as an IT consultant in the Far East, working for a family-owned bank. The bank was extremely wary of this new-fangled internet thing and allowed a favoured few members of staff online, but not much else. "We were hired by the head of IT and tasked with reviewing their information security posture," said Lee, "and it quickly became clear they needed something better than their simple firewall, to include content monitoring and logging, as well as the usual internal firewalls and other protections." Continue reading * Former Cisco exec jailed for fraud, dodging taxes Lean in for a tale of shell companies, fake CEOs, bribes, prison time and $3.6m in fines Laura Dobberstein Tue 31 Aug 2021 // 07:43 UTC 12 comment bubble on white A former Cisco executive was this month sentenced to 36 months in a US prison, and ordered to pay more than $3.6m in fines, for wire fraud and tax violations. Former senior director of Cisco's global supplier management operation, Prithviraj "Roger" Bhikha, admitted in November last year, as he pleaded guilty, that he took kickbacks to the tune of $1.15m while sourcing suppliers on Cisco's behalf. A supplier that hoped to do business with Cisco paid money to a Hong Kong company Bhikha created, called Lucena. Lucena was later transferred under his wife's name. Bhikha then hired Lucena to provide Cisco with price negotiation services. Continue reading ABOUT US* * Who we are * Under the hood * Contact us * Advertise with us * Seeking client-side dev MORE CONTENT* * Latest News * Popular Stories * Forums * Whitepapers * Webinars SITUATION PUBLISHING* * The Next Platform * DevClass * Blocks and Files * Continuous Lifecycle London * M-cubed Situation Publishing The Register - Independent news and views for the tech community. Part of Situation Publishing SIGN UP TO OUR DAILY NEWSLETTER Subscribe Twitter Facebook LinkedIn feeds no-js Biting the hand that feeds IT (c) 1998-2021 Do not sell my personal information Cookies Privacy Ts&Cs