5 ms·
Could this potentially drive users to the Amazon fork? If I'm a business that may be impacted due to the licensing change, it would seem my safest (legal) optio
by longhairedhippy 6y ago
Could this potentially drive users to the Amazon fork? If I'm a business that may be impacted due to the licensing change, it would seem my safest (legal) option would be to freeze on the last version with a friendly license and then transition to the Amazon fork, since it will probably stay under a more open license. While maybe not the smartest technical decision, from a business standpoint it seems like a reasonable insurance policy, at least until someone else tests the waters in court.
Amazon doesn't have any interest in making their version closed because they want the money from hosting. Even if the product isn't that great, it's super easy if I'm already 100% in on AWS anyway (not necessarily reality, but it is an easy conversation to have and the service should be big enough to warrant investment from AWS).
I applaud the stand they are taking and it will be interesting to see how this plays out.
- znpy 6y ago> Could this potentially drive users to the Amazon fork? If they're dumb, yes. As stated in their blog, changes apply pretty much only if you're either embed or redistribute elasticsearch/kibana. And these are two specific use-cases btw. If you're already a customer, nothing changes.
- paxys 6y agoFind me one lawyer who is going to be convinced by this blog post. There is a blanket no for using SSPL software at every company I know.
- shawnz 6y agoOpen Distro is not a fork but simply a repackaging of ES with some additional modules. However there doesn't seem to be many options left now but for Open Distro to become a complete fork of ES.
- c0l0 6y agoThe notion of Open Distro for ES being "a fork" is, in my opinion and as of last I checked, overblown. Yes, they bundle a bunch of freely licensed stuff to make up for features that Elastic themselves have paywalled off (or sealed behind their free-to-use, but non-libre, custom license where they don't show/include sources either), but they rely on and effectively install the (hitherto) Apache-licensed upstream release of ElasticSearch, as published by Elastic. Also, if you take a closer look at Open Distro, you will quickly come to the conclusion that you really do not want to deploy what drops out of there. The RPM package does CRAZY stuff that made me exhale audibly enough for coworkers to notice - like spawning a postinstall shellscript that `wget`s a .so for/from an optional library that the Open Distro release team put into an S3 bucket, and then `mv`ing that downloaded file (iirc even without any content verification; so the content could be your proxy's captive portal markup, for all they know) into (again, iirc) /usr/lib. That is from WITHIN AN RPM PACKAGE, mind you, where you could and should really just carry that file yourself. That and other minor troubles with the tooling surrounding the actual product (ES) made me abandon Open Distro fairly quickly. Which is a shame, since a really freely licensed spin of ES with "Enterprise" features would indeed be very nice to have.
- ec109685 6y agoHow would the captive portal intercept s3 tls calls successfully?
- c0l0 6y agoTLS in enterprise settings is commonly intercepted by TLS/HTTPS proxies that create trusted (by the OS's local trust store) certificates for proxied peers on the fly. Banks often do this - the one I work for, for instance.
- nijave 6y agoThe proxy should be verifying the cert of the connection it's proxying to so it has to either be malicious or buggy where it corrupts the software. The proxy won't connect to bank.com with an invalid cert unless it's configured incorrectly (but the same is true of the OS anyway)
- c0l0 6y ago"Should" is such a beautiful concept ;) The McAfee-based proxy we have SOMETIMES (I guess it depends on the content-type and the length of the upstream response) renders a kind of "intermediate" HTML document as the response body, where the human user is supposed to click on a link that makes the UA download the originally requested resource from an internal, ad-hoc mirror. I guess that is due to some virus scanning snake oil. At any rate, what the packages at Amazon did there is just right up in "that is crazy"-territory.
- toyg 6y agoIt doesn't have to, can just serve anything - if the client code doesn't check certificates...
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- mintplant 6y ago> Could this potentially drive users to the Amazon fork? Um, about that... > When Amazon announced their Open Distro for Elasticsearch fork, they used code that we believe was copied by a third party from our commercial code and provided it as part of the Open Distro project. We believe this further divided our community and drove additional confusion.
- minhazm 6y agoIt's interesting that they phrased it like that. If they were confident about this, they would easily be able to prove this in court and it would be a very simple case of copyright infringement right?
- TheRealDunkirk 6y agoIf IBM v. SCO taught us anything, it should have taught us that "easily... prove" and "in court" do not belong in the same sentence. The case SHOULD have been thrown out in 5 minutes due to lack of merit, which ANY programmer could see. Instead, it took FOURTEEN YEARS to decide, and is STILL working through appeals. Microsoft funded the litigation, and the scumbag executives of SCO continued to get paid through most of this charade. It all still makes my blood boil.
- paxys 6y agoYeah I'm not sure how much weight this holds, especially considering one paragraph later they transition into accusing Amazon of being "inspired" by their commercial features.
- FireBeyond 6y agoThey have a lawsuit open against the third party. I would presume that "inspired" is covering themselves from libel until they have a judgment that this happened (assuming it appears).
- mintplant 6y agoThey're currently suing the third party mentioned.