This is the first post in a three-part series about the impact of the AWS Open Source Credits program on the Drupal community. Part one covers our testing infrastructure. Part two will cover the community programs we host beyond code. Part three will cover what the AI era is doing to open source infrastructure, and what we're building next.
Drupal is one of the open web's longest-running content management projects, in continuous development since 2001, and a recognized Digital Public Good. It runs a large share of the public web: government portals, universities, hospitals, cultural institutions, and international organizations, including the European Commission and agencies across the UN system. The Drupal Association is the small non-profit that keeps the project's home online. We build the tools that enable our community to build Drupal.
Since 2025, the AWS Open Source Credits program has supported the infrastructure behind that work. This series is our thank you, and impact report about what that support has made possible.
The scale
Drupal's collaboration happens on git.drupalcode.org, our self-hosted GitLab instance and one of the largest in open source. It hosts 42,382 contributed projects: 39,003 modules, 2,400 themes, and 979 distributions, alongside Drupal core itself.
The Drupal community opens more than 5,300 merge requests every month, about 65,000 a year, from 8,000 unique contributors annually. Drupal core alone has 15,256 issue forks.
Every one of those merge requests runs through continuous integration (CI) before it can ship. Our GitLab CI runners autoscale on AWS, accounting for roughly a third of our entire cloud footprint. In the last year they executed ~4.1 million jobs, consuming ~159.8 thousand compute hours. That's 438 hours of compute per day. (Data from Aug 26, 2025 – Aug 26, 2026).
Velocity is a contributor experience challenge
Here's what autoscaling CI means for a community like ours. A contributor in Singapore, Mumbai, or Rotterdam pushes a change and gets test results back in minutes. There is no fixed pool of test machines, no queue where contributors wait on each other, no rationing of who gets to test what.
If elastic capacity, funded by credits, means those contributors have never had to deal with longer queues, capped concurrency, or asking volunteers to test less..
We care about this because contributor velocity is essential to the success of Drupal. The Drupal Association engineering team is small, just 4 people. We don't build Drupal; thousands of people do that. Our job is to make sure the tools are available and fast when they need them.
Velocity and safety are the same system
It would be easy to frame fast CI as a developer-happiness story and stop there. But for a project with Drupal's footprint, that same infrastructure is a safety system.
In the last twelve months, the Drupal Security Team has coordinated 163 security advisories across core and contributed projects. Every fix behind those advisories was developed, tested, and released through the same AWS-powered pipeline as any other change. The sites that depend on those fixes find out through us too: about 667,000 Drupal sites check in with our update infrastructure every week to learn whether they need to act. That's a conservative floor, since it only counts sites that phone home.
We also operate Drupal Steward, a protective service that shields sites during the most dangerous window in security response: the hours between a public advisory and a site's own patching. AWS powers that too.
Drupal powers governments, public utilities, and health systems worldwide, making our testing pipeline critical public infrastructure. Every automated test directly protects the security and stability of the websites people rely on daily.
A smooth transition
For two decades, much of Drupal's infrastructure ran on donated hosting at the Oregon State University Open Source Lab, which has been a quiet hero to dozens of open source projects. As the lab restructures, we have been migrating essential services to AWS. Credit support meant that migration happened without cutting contributor capacity, and without asking a small non-profit engineering team to do more with less at the worst possible moment.
Our thanks to the OSU Open Source Lab for twenty years of partnership, and to AWS for making this next chapter possible.
What's next in this series
While compute numbers show our scale, the human impact matters just as much., In our next post: the community programs we host that have nothing to do with code, and why we think that infrastructure matters just as much.
The Drupal Association is a 501(c)(3) non-profit. If your organization depends on Drupal, or on the health of open source infrastructure generally, you can support our work.
A required part of this site couldn’t load. This may be due to a browser extension, network issues, or browser settings. Please check your connection, disable any ad blockers, or try using a different browser.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Drupal.org blog: Migrating issues from security.drupal.org to git.drupalcode.org | 5 | 7 | 17-07-2026 |
| 2 | LakeDrops Drupal Consulting, Development and Hosting: Eight Posts on the Fun Part. One on the Bill. | 0 | 10.09 | 23-09-2026 |
| 3 | Why DrupalCon | 0 | 6.14 | 20-02-2018 |
| 4 | Très Bien Blog: Drupack: Drupal infrastructure in a single binary | 0 | 10.53 | 22-09-2026 |
| 5 | Talking Drupal: Talking Drupal #571 - GovHub | 0 | 7.9 | 24-09-2026 |
| 6 | Tag1 Insights: A New Direction for Authentication in Drupal Core | 0 | 5 | 15-07-2026 |
| 7 | The AWS AI-DLC: Why AI Coding Still Needs Human Accountability | 0 | 11.4 | 04-08-2026 |
| 8 | Going full-time as an open source developer | 0 | 7.42 | 16-04-2025 |
| 9 | Dries Buytaert: Tiffany Farriss to lead the Drupal Association | 0 | 5 | 15-07-2026 |
| 10 | BloomIdea: Mautic Audiences for Drupal: personalisation built on the segments you already maintain | 0 | 5.9 | 21-09-2026 |