Let’s put together an agenda for this week’s meeting together. I’d love for your input. Some topics I think would be useful so far:
More Q&A time for what Hummingbird is.
Updates on the bootable image artifact and general artifact updates
Possibly contributor paths?
???
Consider this thread a chance to add topics to the agenda. What would you like to talk about with regard to Hummingbird? (If you suggest a topic and can’t be there to talk about it, please add enough information so I know what to ask for you!)
We had 13 people in total at the peak of the meeting today! Here is a summary generated with Gemini of the meeting, lightly edited by me:
Host and Housekeeping: The meeting was hosted by @nimbinatus. She noted that the session was under the Fedora Code of Conduct.
The Gorget Project: @rsturla introduced Gorget, a source tarball generator tool. It uses YAML pointing to upstreams and features built-in primitives for Hummingbird. This allows maintainers to easily bump dependencies (such as in Go, yarn, or npm projects) with a single line of YAML rather than maintaining patches across different versions. The project is designed to help maintain close to zero CVEs in RPMs that vendor many dependencies. The long-term goal is to automate Gorget in pipelines so contributors do not need write access to a lookaside cache.
Fedora Atomic Initiative Infrastructure: @nimbinatus opened this topic by highlighting updates from the Atomic Initiative meeting held the previous day.
Expanding Konflux Access: The major infrastructure push within the Atomic Initiative currently is making the managed Konflux infrastructure available outside of Red Hat. The goal is to allow external community members to acquire their own tenants and build parts of the pipeline together.
First External Branching: @nimbinatus noted that the very first branching for the Atomics that is not driven by a Red Hatter is currently underway to test the Konflux infrastructure.
Konflux and Access: @cverna chimed in to clarify how access works. He noted that on the Fedora Konflux instance, they have the capability to grant tenant access to anyone who possesses a standard Fedora account. He explained that because a large portion of the Konflux configuration work is stored in Git repositories, a lot of community contribution (such as branching) simply involves updating YAML manifests. While having direct access to Konflux is highly useful for checking if things are working, @cverna emphasized that contributors can easily start right away just by pushing changes and opening merge or pull requests.
Shared Pipelines: @cverna also mentioned a medium-term goal to share more pipelines across all the different atomic variants—including CoreOS, Atomic Desktops, and the Hummingbird bootable host—with the interesting potential to share disk images between the variants in the future.
Bootable Host Update: @bsherman1 shared that a bootable host from the Hummingbird side is in progress. It is dropping the name “bootc” for trademark reasons. The project has onboarded most necessary packages and are currently blocked on trying to repackage and reuse the Fedora shim, grub, and kernel to maintain secure boot capability. @bsherman1 also noted that someone requested a Hummingbird spin of Universal Blue on their issue tracker.
Blogging and Awareness: @fatherlinux started a discussion around blogging to drive awareness and adoption. @nimbinatus suggested that the Fedora discussions forum is a great, informal place to start posting thoughts, and anyone interested in blogging can also work with the Fedora Magazine team for more formal articles.
Hummingbird Metrics: @fatherlinux shared the repository is up to 3,100 packages. @nimbinatus shared a graph derived from the GitHub API showing that the total number of people using Hummingbird images across public GitHub recently crossed 500.
Contributor Pathways and Trust Discussion: Influenced by a question from @dustymabe regarding how the community can feel involved in decisions, a deep discussion ensued regarding contributor pathways, what it means to build a proper contributor ladder, and how to establish trust within an automated environment.
The Traditional Ladder: @nimbinatus noted that a proper contributor ladder typically moves an individual from an initial contributor up to a maintainer, and eventually off the ladder to emeritus status. However, the core question she raised was: How do you build trust—and who are you building trust with—in a heavily automated system?
The Automation/Security Paradox: Because Hummingbird operates as a secure build factory with strict compliance requirements (such as SLSA compliance), @fatherlinux noted it presents unique security constraints. @fatherlinux questioned whether a contributor would be willing to go through rigorous steps—such as a background check—just to become a core maintainer with write access to the factory infrastructure.
The Clash with Fedora Philosophy: @dustymabe pointed out that restricting access or keeping the inner workings private fundamentally clashes with the open philosophy of the Fedora community whose name was used to launch the project. Even if write access is traditionally hard to get in Fedora, there is always a clear, transparent pathway to achieve it.
Visibility as a Barrier: @dustymabe noted the primary barrier was a lack of public visibility. Currently, the Konflux pipelines and build logs are hidden behind a private Red Hat login. Because external community members cannot see why a build failed or inspect the logs to debug an issue, they are prevented from troubleshooting the system and building up the necessary trust to climb a contributor ladder.
Teasing Apart the Pathway: The group realized that a contributor ladder for Hummingbird actually needs to be broken down into three distinct areas of interest, as different people will want to contribute in different ways:
Contributing to the core infrastructure code that builds the factory.
Getting inside the factory to muck around with the build system itself.
Contributing content (like spec files and container files) to create the images that come out the other side of the factory.
Closing:@nimbinatus closed the meeting by stating she would post the meeting notes to the discussions forum and that they would meet again in about a month.
We’re working on the YouTube channel uploads, so I hope to get the backlog of meeting recordings up soon! Please feel free to chime in on this thread to correct anything in case I missed something in editing the notes, or to keep the conversation going!
Hey Scott, my inbox* is full because Linux is amazing. This was going to give a gift for all of you at DevConf but we’re out of time.
Bluefin built on Hummingbird is basically finished. It will a full peer to Dakotaraptor. You will be competing against a reference architecture that is a combination of Apache Buildstream and everything in the CNCF.
Red Hat’s aquihire of Universal Blue is complete - full support from me. Someone will push at some point. This will be a fully supported variant with my full support. Full commitment.
Someone will push to this soon. As you know, making these is trivial now so a bunch of us had individual spikes. Kubernetes needed OpenShift. Maybe we can make a cooler one. Hummingzitte? No, too obvious. Oh I know. Bazzibirdhum. Have Jef name this one I’m going back to cook. See you on the objective!
(* My Discourse inbox not my email one, because the people who will build this for you don’t use email - and the people who do read email understand that we’re building for the future)