26 ms·
The OpenTF Manifesto
- Sparkyte 3y agoNot sure what sort of thought process went into Hashicorp thinking that going BSL was a good idea. I am exagerating but almost all of their code is community driven. So the biggest issue is that this will likely kill all of their profit. Perhaps if they went down the certification strategy it would've been a safer gamble. Certified Hashicorp Terraform Practioner. 650 a cert, probably would've saved their arse.
- mkl95 3y ago> This is similar to how Linux and Kubernetes are managed by foundations (the Linux Foundation and the Cloud Native Computing Foundation, respectively), which are run by multiple companies, ensuring the tool stays truly open source and neutral, and not at the whim of any one company. > We strongly prefer joining an existing reputable foundation over creating a new one. Stay tuned for additional details in the coming week. Joining an existing foundation sounds like the right move to me. Many organizations need this fork to take off very quickly, since they are facing legal uncertainty. Make sure it is clear how to support the project, and those organizations will be happy to do so.
- stavrus 3y agoI don't think the license change is unwarranted. At a previous employer we used Terraform but the pricing on the cloud/enterprise offerings was prohibitive enough that we instead had a dev create simple wrapper scripts in our CI/CD system to run the deploy jobs. Significantly cheaper, but I spent years pushing for us to eventually move to the paid offerings as the developer experience was significantly lacking (and to support Hashicorp), up until I left the company. I think they're still using those wrappers today despite how awful they were to use. There was definitely room for improvement around using Terraform to do actual deployments. From better UX around doing PR's -- showing not only the commit diff but the output of a "tf plan" as well to see what it might actually do -- to actually running the deployments on isolated build machines that could hold the sensitive cloud API keys and provide a deployment audit trail, these were all features that teams absolutely needed to use Terraform sanely. As a solo developer you don't really need those features, but if you're on a team you definitely did, and were almost certainly willing to pay for it. Hashicorp recognized that need and created the cloud/enterprise offerings to provide that. At some point the thought even crossed my mind of creating some open-source tool that could provide a nice enough web interface for dealing with Terraform for teams, building on what we had and providing the features I listed above, but the main reason I didn't was because it would be biting the hand that feeds. Such a tool would take away people's incentives from using Hashicorp's paid offerings and ultimately reduce their investment in Terraform and their other fantastic tools, and in my opinion, be disrespecting the tremendous work Hashicorp had done up to that point. I've been a user of their stuff since they only had Vagrant, and of course have loved them seeing them succeed. It seems others, however, had different opinions and saw a business opportunity thanks to the permissive licensing and the high costs of Hashicorp's paid offerings. Plenty of money to be made from making it easy to use TF in teams, especially when you're not obligated to contribute back or maintain the underlying software [1]. Any time I saw a "Launch/Show HN" post from a company that was offering such TF wrapper web interfaces, I kept being surprised that Hashicorp hadn't yet clamped down on preventing lower-cost offerings of their paid services. It was only a matter of time. [1]: I realize this reads as overly harsh to some of these companies, especially as some of them are in here replying and pledging to give back, so let me try to explain my reasoning here. When I use a product, I like it when the source is available from me to learn from and understand how it works [2] and to contribute back to for needed features or bugfixes [3]. When a company makes a product open-source, that's great! But if that product is the core of that company's business model [4], and another company starts competing with that company using the same open-source product, then I see a problem down the line. While you can make the argument that the competition is good and motivates the two companies to compete on the value they bring to their customers, which is a net-benefit to the open-source ecosystem as a whole as the open-source product is improved, it eventually turns into a race to the bottom. Pricing will be used as a core differentiator, reducing the overall R&D spending on the open-source product because ultimately the two companies have to maintain non-R&D staff like sales, finance, and support. If the Total Addressable Market is fixed (obviously not, but work with me), then that's two or more companies with the same fixed non-R&D costs diverting revenue that could be spent instead on improving the open-source product. Sure, the reality is that a lot of that revenue isn't going back to the open-source product, as a lot of people are complaining about in the comments, but that diversion is probably going to happen anyway whether there's 1 company or 20, so I'd accept it as a cost of doing business. If instead the competition were on providing a better but different open-source product in the same space (e.g. Pulumi), rather than working off the same base, that would be a different story. But if developers keep seeing businesses take open-source projects and directly compete with their creators, then I think we're going to see a net harm to the open-source community as it creates a sort of chilling effect as it'll demotivate them from going the open-source route so that they can find a viable way to sustain their efforts. I think licenses such as the BSL and SSPL are valid enough compromises, considering that even mentioning the AGPL inside of a lot of companies seems to be like someone saying Voldemort's name. We can't rely on large corporations sponsoring open-source projects, either with money or developer time, if we want them to succeed. We grant inventors 20 years of exclusive-use on an invention, provided they explain how to reproduce it through the publishing of a patent. What's the difference between that and the BSL? I see a lot of complaints about bait-and-switches, but I don't really see the issue. If you contributed to the project under the old license, it's still available under the old license! You just don't get any of the new changes starting from the license change. If you decided to use Terraform in a non-competing way [5] solely because of the old license, and are concerned about the new one, then you have to recognize that Hashicorp is now another addition to a long-line of "open-core" companies trying to deal with the reality that companies will make money any way they legally can. This is where the industry is currently headed, and whatever replacement you find will probably be next. If you believe different, then make an open-source offering, and don't just make a public statement saying it'll be open-source forever. Public statements are great and all, up until there's doubts about meeting payroll. Find a way to make the statement legally binding and then we're talking. Which is I guess why there's so much consternation, since the way to do it is through the license, but the OSI doesn't recognize any of these other licenses as "open-source" and the AGPL is a non-starter at most companies. [2]: Reading the source code for libraries I use has been incredibly valuable in my understanding of how to use the libraries properly, much better than any documentation could. And of course, makes me a better programmer in the process. [3]: At one point, Terraform was missing a feature that I badly needed. With the source available, I could easily get a new version of it running locally with that feature to unblock me, and then everyone benefited when I contributed it back to the project. It's also been invaluable having these locally modifiable builds to understand the quirks of products from cloud vendors, and to work around them. Ever had multiple deployment pipelines fail because Azure decided to one day change the format of the timestamps they returned in API calls, without publishing a new API version? I have. [4]: As opposed to supplementing their business model. Google open-sourcing K8s was great for them because it drove adoption of their cloud VMs. Their cloud business makes money off the VMs, not GKE, so sponsoring K8s is essentially a marketing expense. But for Hashicorp, their core business model is paid offerings of their products. [5]: Yes, I get that the license currently is un-clear, for all their products. But let's simply say that you're not trying to directly sell a wrapper around running Terraform.
- berniedurfee 3y agoTerrafork?
- WaterSponge 3y agoWhat if Microsoft buys it for there devtools business like NPM, Github, VSCode + Terraform,Consul,Vault.. all just more gateways into azure but like all the others they own allow you to use it how you want opensource.
- kitanata 3y ago[flagged]
- xyzzy_plugh 3y agoThis was inevitable after Hashicorp's move. After thinking about it for a few days, I think Hashicorp's move is actually net great for everyone. The products that matter will be forked and maintained in the open. Hashicorp would choose wisely to merge mature forks back into their product, if they can, and now you have a pretty standard model of up selling enterprise features on an open product that's developed in the actual open. It frees Hashicorp up to focus on the enterprise, which they have already been doing, but they've been neglecting their OSS, like Terraform (what the actual fuck is going on with the development of Terraform over the last two years?) This is great. I'm really looking forward to using freed forks that pop up in the months ahead. This is Hashicorp's sink or swim moment. If you asked me when they announced the license change, I'd say bet the horse on Pulumi and move on. But now I actually think this could really rejuvenate the TF ecosystem.
- garfieldnate 3y agoI'm looking forward to seeing the creation of the foundation. Honestly, given the huge number of people that use it, the open source activity, etc., closing the source is a huge deal and Hashicorp could not really expect anything other than a big response to keep the open source version going. Am I wrong here?
- jhoelzel 3y agoWhile this wont affect 99.9% of us, I am very happy what this will mean for further kubernetes adoption. VMS are a concept of older times and should be replaced by containers. YES; there is still use for VM's but everyone and their mother migration to k8s will mean wonders for portability of applications and more.
- luckystrike99 3y agoopentf.org - the "tf" part Isn't "Terraform" a copyrighted / owned word by Hashicorp? Is it somehow itself part of the MPL - the name itself? Would then whatever opentf.org would become need a new "tf" name? Just don't know the ins and outs on that.
- thrwawayhashi 3y agoFrom Hasicorp’s perspective this license change is less about Terraform and mostly about Vault. Terraform Enterprise isn’t very successful. Their cloud offering for Terraform isn’t competitive with a basic GitHub actions workflow. They’ve learned this the hard way. With Vault they’ve just recently launched their new cloud secrets service. Most of their revenue comes from Vault. Nearly all of their future revenue growth is vault. Any competitor could relatively easily provide the same service with vault FOSS today. Vault is feature complete. The only moat they have is their license. Best for the ecosystem if both Vault and Terraform are maintained by a foundation. Not best for Hashicorp, but best for the industry for sure.
- ohad1282 3y agoOhad here, co-founder of env0, one of the main supporters of opentf I think Gruntwork's blog explains this the best - https://blog.gruntwork.io/the-future-of-terraform-must-be-open-ab0b9ba65bca https://blog.gruntwork.io/the-future-of-terraform-must-be-op...
- ovuruska 3y agoHey folks, so Terraform did a thing. They changed their license type, and a lot of people aren't too happy about it. There's this OpenTF Manifesto now where people are speaking up about wanting Terraform to be truly open-source again. Some are even thinking of making a new version if HashiCorp doesn't switch back. Just a heads up for anyone using or thinking of using Terraform
- onedr0p 3y agoThere is zero chance of Hashicorp donating Terraform to an open source foundation. If there was they would have never even considered this change in license. Honestly it's not a bad thing, maybe the maintainers of the Terraform fork will actually listen to feedback from the community of people who use it instead of ignoring them.
- deleted 3y ago[deleted]
- datadrivenangel 3y agoHopefully the schism this causes will result in more competition and improvement in the infrastructure as code space.
- SebastianStadil 3y agoScalr cofounder here. Hope so too, we're a fractured community splits resources and forces every organization to have a discussion on what to use. That affects all of us.
- jsiepkes 3y agoPart of me hopes a fork comes out of this. I mean maybe features like this PR[1] for local state file encryption can then finally get merged. [1] https://github.com/hashicorp/terraform/pull/28603 https://github.com/hashicorp/terraform/pull/28603
- LVB 3y agoI did see https://github.com/diggerhq/open-terraform https://github.com/diggerhq/open-terraform but have no idea if it is related. And I’m sure there are others. What I’ll be interested to see with the forks is how they will practically be maintained. All the bug and security fixes that HashiCorp is writing can’t just be cherry-picked into these forks (I think?), so what exactly are they supposed to do? Update: and in the past hour this repo is gone.
- yellowapple 3y ago> Update: and in the past hour this repo is gone. Which is interesting, since Digger (the company that created that fork) is one of the OpenTF Manifesto signatories. Maybe they're recreating it under a different name / without the Hashicorp/Terraform branding all over the place?
- pawelpiwosz 3y agoHi! OpenTF is not connected with a single company. This is an united, community-driven effort. You can check on the manifesto side who is behind. And we welcome all support! The fork you mentioned is no longer existing.
- JeremyNT 3y ago> All the bug and security fixes that HashiCorp is writing can’t just be cherry-picked into these forks (I think?), so what exactly are they supposed to do? Indeed, any fork will need to implement their own bug fixes. Ideally they should do this "clean room" and not even look at the BSL'd code, to help defend against any accusations of copyright infringement.
- fishnchips 3y ago
- lijok 3y agoI love it. The list of "pledged companies" is literally just a list of all the offenders that Hashicorp are trying to shake off.
- tedivm 3y agoThese people have seriously contributed back to the Terraform community. Terraform doesn't have a test suite- Grunt made Terratest, as well as many other tools. These people have seriously contributed back to the ecosystem, in many ways beyond what Hashicorp has done. Beyond that, I know some of these companies tried to be contributors to Terraform itself but were ghosted by Hashicorp. At the same time there's only a handful of regular contributors to Terraform[1]. It would not be hard for these companies to provide more resources to Terraform than Hashicorp is. https://github.com/hashicorp/terraform/pulse/monthly https://github.com/hashicorp/terraform/pulse/monthly
- DrRobinson 3y ago> Terraform doesn't have a test suite- Grunt made Terratest They have experimental support: https://developer.hashicorp.com/terraform/language/modules/testing-experiment#current-experimental-features https://developer.hashicorp.com/terraform/language/modules/t...
- rjbwork 3y agoProbably not difficult for these competitor organizations to fund an OpenTF team to hire some of these people away from HashiCorp and continue it on as FOSS either. I can't imagine Liam turning down .5M/year to do so.
- fishnchips 3y agoMarcin here, co-founder at Spacelift. We are open to fund 5 FTEs, feel free to reach out to us via the pledge page if you're interested in OpenTF becoming your full-time job.
- 3y ago
- cube2222 3y agoAlso, update from Spacelift, we believe that we are not in violation of the new license, you can find more details in our today's announcement[0]. We nevertheless support this initiative, though, as written in the article itself. [0]: https://spacelift.io/blog/spacelift-latest-statement-on-hashicorp-bsl https://spacelift.io/blog/spacelift-latest-statement-on-hash... Disclaimer: Work at Spacelift
- empressplay 3y agoYou guys effectively sell cloud-based TF instances though, don't you? Pretty sure that's a no-no...?
- cube2222 3y ago> cloud-based TF instances Not sure what specifically you mean with this. Anyway, the devil’s in the details, of both the license as well as the internal architecture of our system. I can’t share more here, but if you’d like to learn more please reach out via our chat or email. You can also expect more updates on our blog.
- miah_ 3y agoI think this is awesome. I highly doubt Hashicorp will do the right thing, so I look forward to the new OpenTF foundation and their fork of Terraform.
- SebastianStadil 3y agoThanks for your support! Please consider helping us by: - starring the Manifesto - spreading the word - pledging your organization if you can
- sausagefeet 3y agoWe, Terrateam, do not believe we violate the new license but we support Terraform being open due to how important it is to the ecosystem. Unlike Vault or Waypoint, Terraform is closer to a language compiler like Go or Java and benefits from a robust community that can build on top of a stable ecosystem. As such, we have announced our support of the OpenTF Manifest[0] [0] https://terrateam.io/blog/opentf-pledge https://terrateam.io/blog/opentf-pledge
- igorzij 3y agoDigger here Our statement: https://medium.com/@DiggerHQ/diggers-statement-on-the-hashicorp-license-change-to-bsl-983bf184e7d7 https://medium.com/@DiggerHQ/diggers-statement-on-the-hashic...
- yellowapple 3y agoY'all had previously forked Terraform in response; what happened to that repo? https://github.com/diggerhq/open-terraform https://github.com/diggerhq/open-terraform
- ddon 3y agoImpossible to read, behind a paywall... why people post stuff to Medium is a big mystery to me :) Here is how your post looks like: https://postimg.cc/Pvwdw8D3 https://postimg.cc/Pvwdw8D3
- yellowapple 3y agoYou can click the X on that modal to close it. (But yes, I agree that this is annoying, and this kind of sign-up-nagging is what prevents me from having any interest in using Medium or Substack.)
- mdaniel 3y agoLet me introduce you to my go-to for that bullshit: https://scribe.rip/@DiggerHQ/diggers-statement-on-the-hashicorp-license-change-to-bsl-983bf184e7d7 https://scribe.rip/@DiggerHQ/diggers-statement-on-the-hashic... courtesy of: https://news.ycombinator.com/item?id=28838053 https://news.ycombinator.com/item?id=28838053
- oars 3y agoThanks for sharing Scribe which can help me read Medium articles with an alternative front end that bypasses the paywall.
- Coryodaniel 3y agoMassdriver was designed to be infrastructure-as-code agnostic from day 1. Our goal has been to help companies get great operations, compliance, and security posture from day one. While Massdriver is not a competitor to HashiCorp, the license language is extremely vague and leaves any infrastructure company running containers for their customers wondering if HashiCorp will consider them a competitor tomorrow. We are proud to be providing development and community support for this initiative. Read our statement here: https://blog.massdriver.cloud/posts/2023-08-14-opentf-commitment/ https://blog.massdriver.cloud/posts/2023-08-14-opentf-commit...
- pjmlp 3y ago[flagged]
- aftbit 3y ago>Imagine if the creators of Linux [] suddenly switched to a non-open-source license that only permitted non-competitive usage. Linux cannot even successfully switch from GPL2 to GPL3 because of the sheer number of contributors and the fact that not all of them have transferred their copyright ownership to any given organization. This patchwork of different copyright owners has historically been seen as a potential weakness for Linux, but it seems like perhaps license inflexibility is a strength for open source.
- cies 3y agoI thought Linus and other believed GPLv2 was fine and the improvements of GPLv3 did not outweigh the potential problems introduced by it. It never came to a point where all authors were asked to agree, or sign away their ownership.
- nabakin 3y agoYes, I believe I saw a video of Linus stating exactly this
- aftbit 3y agoMy understanding was that some people in the community believed that GPLv3 was better, and one of Linus's criticisms was that it was essentially impossible to switch even if it were better. I also believe Linus was opposed to the switch, which would make it unlikely anyway, but even if he had approved, I still think it would be practically impossible.
- tux2bsd 3y ago[dead]
- kmeisthax 3y agoTorvalds considered the anti-TiVo clause to be changing the deal and he didn't want to do that, and there's no way in GPLv3 to opt-out of the clause[0]. This is less "locking down devices is a human right" and more him being angry that the FSF was trying to butt into his project's affairs. He's also similarly angry about "GNU/Linux" as it sounds an awful lot like Stallman just demanding everyone stick "GNU" onto the name of Linus's kernel project. Anyway all of this is going to seem really quaint in 2027 when Broadcom gets sued under DMCA 1201 by a rogue kernel contributor for evading the Linux linker's license checks[1] and they have to hurriedly rewrite them out of the kernel and relicense anyway. [0] Granting a blanket exception doesn't work because others can just remove the exception. "No further restrictions" is an ironclad law of copyleft. [1] The Linux kernel checks the declared license of loaded modules and refuses to link non-GPL-compatible code against any kernel symbol not marked as a user-space equivalent. The reason why this works this way is because Linux ships under GPLv2 plus an exception that says user-space APIs don't trip copyleft, so you can legally load code built to those APIs into the kernel, but anything else might violate GPL. Since this is enforcing an interpretation of the GPL, this is a DMCA 1201 technical protection measure. You absolutely could make a DMCA 1201 anticircumvention claim in court against a proprietary driver developer that tried to evade the checks. Though Linus usually just bans their modules in the next kernel revision since he's mainly worried about keeping proprietary modules from generating spurious bug reports in Linux. But the lawsuit is still possible, since they're on GPLv2. If they had relicensed to GPLv3, this wouldn't be an issue.
- brikis98 3y agoGruntwork here. You can find our statement here: The Future of Terraform must be open—our plan and pledge to keep Terraform open source. https://blog.gruntwork.io/the-future-of-terraform-must-be-open-ab0b9ba65bca https://blog.gruntwork.io/the-future-of-terraform-must-be-op... If you want to help us keep Terraform open source, please show your support at https://opentf.org/ https://opentf.org/!
- DrRobinson 3y agoGreat to see your commitment but I'm also curious why you, unlike some other companies, have chosen not to support with any full time employees? It seems your business is largely based on Terraform and saying pretty much "we'll contribute code" doesn't signal too much commitment. I realize my comment might sound like an accusation but that's not my intention, I want to hear your reasoning about it!
- moulick 3y agoYep, I wonder the same
- ms4720 3y agoI think the problem is that if hashicorp thinks you are a competitor you and your clients now have legal/operational issues. Ie you are now a competitor because we are releasing a product just like yours, here is a letter from a lawyer telling you to stop using terraform.
- brikis98 3y ago> if hashicorp thinks you are a competitor This is precisely the problem with the new BSL license. Whether your usage of Terraform complies with the license isn’t determined by the legal terms, but instead is entirely at the whim of HashiCorp. And they can change their mind at any time. It makes it impossible to build anything on top of Terraform. I talk about that more here: https://blog.gruntwork.io/the-future-of-terraform-must-be-open-ab0b9ba65bca https://blog.gruntwork.io/the-future-of-terraform-must-be-op...
- unethical_ban 3y agoI worked at a financial institution that heavily utilized terraform. Their business is banking and they do not offer automation, orchestration or IaC as a service. They're fine. This seems to affect only those places that attempt to build a business off terraform. I am not saying those businesses can't be mad at the rug getting pulled out from under them, but it's important to be accurate that this doesn't affect end users of TF directly.
- ig1 3y agoIs the financial institution made up of separate legal entities which bill each other for services, and does one of those entities provide tech infra for the other legal entities?
- unethical_ban 3y agoGood point, but no. Also I think they pay Hashicorp for support.
- punnerud 3y agoIsn’t all agreements to limit competition illegal in EU/Europe? Even collaboration between competitors agains a 3. part is illegal. The rest of the agreement is still valid, just the completion part is nullified
- fishnchips 3y agoSpacelift co-founder here. Not going to comment on the legal aspect, but I'm actually curious when it did become acceptable in polite society to say that "we just want to kill the competition".
- dbingham 3y agoI appreciate the letter and trying to work with Hashicorp -- I used to have a ton of respect for Hashicorp. But honestly... at this point... ...just fork it into a foundation. Don't wait for Hashicorp's response. I get wanting to have the appearance of working with Hashicorp, but we've been shown again, and again, and again, and a-fucking-gain that private corporations cannot be trusted to maintain public goods. Only community governed non-profit foundations can do that. Private corporations will put the bottom line first every single time. And in the case of investor funded enterprises, the bottom line is never ending exponential growth or bust.
- VectorLock 3y agoI don't think you can just "fork it." Hashicorp already owns all that code because they make contributors sign it away to them.
- pxc 3y agoThey can't retroactively take source code away from people who they already granted access to it under the MPL. The old code is still available under the MPL forever- even if they take down all of their own public copies of it, anyone with the old Terraform code is still free to upload their copy for the creation of a new fork. That's kinda the whole idea with these open-source licenses :)
- VectorLock 3y agoI've heard some people discuss that the contribution agreement that Hashicorp makes people sign gives them the right to change the license for existing contributions, but I'm not a lawyer so I really couldn't say for certain either way.
- linuxandrew 3y agoHashiCorp makes its external contributors sign a CLA to basically hand over the copyright. However the MPL and licensing in general is irrevocable. They have irrevocably licensed Terraform 1.5.5 under the MPL and an enterprise license (dual license). Anyone can use, modify and distribute version 1.5.5 under the terms of the MPL. Since HashiCorp retains full copyright they can release the next version under the BSL. Note that many free software projects (like Linux) don't have a CLA which makes relicensing impractical since every contributor would have to agree to it.
- notswayze 3y agoWhat's the cleanest way to pledge support as an individual, but without pledging as part of my company?
- brikis98 3y agoWe just moved the signatures to a table format, so you individuals can now add themselves to the table: just set the "type" column to "Individual." Thank you! https://opentf.org/ https://opentf.org/
- yabones 3y agoTurns out the proliferation of open source was never because of "collaboration" or "community", it was actually just a result of zero interest rates and "growth".
- yjftsjthsd-h 3y agoThat's a possibility, but a collection of companies trying to drive FOSS even after the original company stops is a great argument that it is in fact a collaborative thing
- busterarm 3y agoFOSS predates the zero-interest rate era by almost 20 years.
- jen20 3y agoHow exactly do the companies involved plan to fund a fork? It would require at minimum 3-4 full time engineers, and no one is going to do that work for free. It’s also telling that this manifesto blithely suggests TF could become Apache 2, which is wholly untrue.
- yjftsjthsd-h 3y ago> It’s also telling that this manifesto blithely suggests TF could become Apache 2, which is wholly untrue. Why is it untrue? If Hashicorp has the ability to relicense to BSL, what would prevent them relicensing to anything else?
- jen20 3y agoThey can make their own contributions going forwards BSL licensed. They can also make their own contributions Apache 2 _going forward_. They could only make my contributions to Terraform Apache 2 with permission, so at best it could be MPLv2 with Apache 2 files interspersed.
- igorzij 3y agoAn earlier version of the manifesto contained pledged resources from each company (you can still find it in commit history). It totalled to ~10 full-time engineers just from founding orgs. It was removed to simplify adding their entries for new pledgees
- jen20 3y agoDo the founding orgs have public disclosure of their finances? It seems the vast majority of them are VC backed companies that probably don't even have two years worth of runway, let alone be in a position to meaningfully commit to funding engineers for five years.
- myroon5 3y agoOmitting commitment details may simplify pledges, but it also makes pledges almost meaningless. I'd take pledges much more seriously if they still had details
- marcinzm 3y agoAs I see it Hashicorp has failed to create a viable business model in an environment where there isn't unlimited perpetual VC money. Now they're at the stage of giving up and simply trying to shake down those who have managed to make better business models. It's usually not a good idea to be near a company flailing like this since who knows what their next rent seeking approach will be. A company with nothing to lose is a dangerous partner to have.
- zzbn00 3y agoA company that loses money is a dangerous long-term partner, full stop.
- tedivm 3y agoThe worst part is they did create a viable business model. They were profitable when they had their IPO. They then pretended that the IPO was just another Series X investment, blew all the money, and went negative on their cashflow. Hashicorps problem isn't that their business model doesn't work, it's that they are really bad at their jobs. They ignore customer feedback, laid off support people, and then jacked their prices up. It's a self inflicted wound, and instead of trying to fix it they just keep making it worse.
- glenngillen 3y agoBlew all that money? They still had about $1B in the bank at the last earnings, and they only raised $1.2B in the IPO iirc
- marcinzm 3y agoDefinitely, the fact they're rent seeking against similar small companies clearly shows that. Sad that rather than looking inward to improve themselves they've decided to just attack others.
- jen20 3y agoHave you actually read the financial statements? None of what you just wrote is remotely true.
- theowawayhs 3y agoOnce a prolific commentator, Mitchell Hashimoto has gone quiet here for over 50 days now. His GitHub activity seem to indicate he is now focused on the Zig programming language.
- tedivm 3y agoHe doesn't work at Hashicorp anymore, and even quit the board. Since the company is public he could have just completely cashed out at this point (and I wouldn't blame him for it).
- throwaway1101z 3y agoOnly Hashicorp employees are allowed to comment here? How about the person that actually built it? Maybe he has interesting things to say. Also, he's been silent on HN as a whole, not just Hashicorp-related threads. Maybe he signed a gag order and cashed out. We may never know.
- pxc 3y ago> Maybe he signed a gag order and cashed out. We may never know. Regardless, this is likely a painful moment for him. Maybe he just doesn't want to talk about it, and won't for some time.
- i4k 3y agoyes, I really hope he says something about it.
- Brian_K_White 3y agoWe need a new word for this. We say OpenTF is (or will be) a fork, and forks are bad, nuclear option, etc, but really, Hashicorp are the ones who made a breaking change, and the "fork" merely maintains that which already was, but for reasons, are not allowed to continue using their own name. We need for the shortest sound-bite 3-word sentence to the non-technical to somehow use terminology that says that the entity that caused the problem is the one who did some action. OpenTF did not (or is not prepareing to) fork this project, Hashicorp did. If it was me and I wasn't legally prevented by something actually binding in writing with signatures, I'd even keep using the original name and duke that out.
- dijit 3y agoThe issue with that is the ownership of the name. Name is identity, and thus the canonical representation of "Terraform" is now BSL. However, if you don't have an identifier such as the trademarked name and you look at the project itself then I think you're right.
- PeterZaitsev 3y agoDo not mix source code license with Trademark. Trademark use is focused by Trademark policy which is here for Hashicorp https://www.hashicorp.com/trademark-policy https://www.hashicorp.com/trademark-policy
- hadlock 3y agoIt can be rebranded, that's pretty straightforward for something that's such an industry standard. "Oh yeah? Earthworks? That's the open source fork of Terraform" pretty simple. If it were a lesser known technology it would be an issue but most of the (modern) internet runs on it, whatever they name the fork will be well known pretty much instantly
- Brian_K_White 3y agoNo one asked "How does one rebrand?" The whole point of this thread is the premise that it's not a fork. Hashicorp's copy is the fork, and it's backwards that the fork gets to keep the name and the original must rename itself.
- PeterZaitsev 3y agoOne thing I particularly hate about license change is lack of notice - If you operate in good faith you probably would want to give time to community to make arrangement, whenever it is negotiating agreement with you or looking for alternatives. Lack of notice this means everyone who embedded Terraform put their customers at risk immediately as in case any discovered CVEs they will not be able to ship security fixes to their customers.
- cube2222 3y agoTheir FAQ states they'll backport security fixes under the old license until the end of 2023. Disclaimer: Work at Spacelift
- PeterZaitsev 3y agoAh, this is great when. MongoDB did not do it in their switch to SSPL
- moulick 3y agoElastic also did not during the Log4J debacle.
- PeterZaitsev 3y agoInteresting to see Twitter (X) poll was right on this one https://twitter.com/PeterZaitsev/status/1691173820122443776 https://twitter.com/PeterZaitsev/status/1691173820122443776
- cyberax 3y agoTerraform core is kinda crappy. The language is awful, and the module infrastructure sucks. I would support (with my own money) a fork that would re-use the Terraform providers, and reimplement the language as something not so insane.
- jen20 3y agoWell, if that's something you _actually_ want, take a look at Pulumi, which does precisely what you ask.
- sevagh 3y agoWhat's preventing Pulumi from making a license change in the future?
- cyberax 3y agoPulumi looks great. Why aren't they more popular?!? They still need the state (boo!), but otherwise they're great.
- aequitas 3y agoYou can’t implement this kind of tooling with the features is provides without the state.
- cyberax 3y agoYou can, for most of the cases. You just need a way to tag resources as belonging to the tool. This can be done via prefixed (or suffixed) names, tags, etc.
- jen20 3y agoThat… is state, just stored elsewhere. It’s also not usable for lots of important parts of AWS, which does not have consistent tagging support and would leave you running very much foul of API rate limits. Terraform having state wasn’t some easy button decision, it was absolutely required and carefully considered.
- bastardoperator 3y agoAsk Roblox employees how they feel about Hashicorp products. Terraform is probably the most solid product they have seconded by vault, but after hearing the consul and nomad horror stories, I don't think I could take their products seriously ever, not when kubernetes is setting right there.
- vilkkala 3y agoCould you elaborate on these horror stories?
- CaptArmchair 3y agoWell, here's the link to the post-mortem of said "horror" story on the Roblox blog: https://blog.roblox.com/2022/01/roblox-return-to-service-10-28-10-31-2021/ https://blog.roblox.com/2022/01/roblox-return-to-service-10-... TL;DR The outage was caused by (a) they enabled a new streaming feature in Consul under unusualy high read-and-write load, (b) the load conditions triggered a pathological issue in the third-party BoltDB system upon which Consul relies and (c) all of that was exacerbated by having one consul cluster supporting multiple workloads. I'd use quotes to catalog this as a "horror" story, because this was clearly a very specific issue triggered by a specific and complex set of circumstances. The blogpost also mentions that Roblox worked closely with Hashicorp engineers to mitigate the issue, and work towards structural solutions; the post also affirms their choice to manage their infra themselves rather then moving into a public cloud solution. Sure, Kubernetes covers loads of territory. But there definitely are niches where products like Consul & Nomad do add value.
- throwaway2023rb 3y agoHashicorp enterprise support is rock solid for Nomad, Consul, Vault. If there is a P0 problem, they will root cause, and usually have a fix identified in < 48 hours. All three of those products are taken very seriously - running 10,000+ servers in a single cluster.
- busterarm 3y ago> not when kubernetes is setting right there. Enjoy spending the rest of your life trying to get etcd to cooperate. If you think operating Kubernetes at scale is a cakewalk, you don't have the scale problems you think you do. I'll take consul over etcd ten million times out of ten.
- sberens 3y agoI created a prediction market to estimate the success of this manifesto (along with other efforts): https://manifold.markets/SimonBerens/will-terraform-be-mpl-licensed-by-e https://manifold.markets/SimonBerens/will-terraform-be-mpl-l...
- bcantrill 3y agoWe at Oxide were honored to be asked to add our name to OpenTF Manifesto. Our statement: At Oxide, our vision has been that on-premises infrastructure is deserving of a system consisting of both hardware and software, at once integrated and open. Ensuring Terraform users can easily deploy to Oxide has been essential for realizing this vision: we want customers of an Oxide rack to be able to use the tools that they know and love! And while HashiCorp's move to the BSL does not immediately affect Oxide (our Terraform provider is and remains MPLv2), we recognize that the ambiguity in both the license and HashCorp's language has created widespread concern that gives customers pause. We support the OpenTF efforts to assure an open source Terraform. It is our preference to see an MPLv2 Terraform as led by HashiCorp, and we join the call from the OpenTF signatories for HashiCorp to renew its social contract with the community by reverting the change of Terraform to the BSL. That said, we also agree with OpenTF's fallback position: a BSL-licensed Terraform is not in fact tenable; if Terraform must be forked into a foundation to assure its future, we will support these efforts. Open source comprises the foundation of the modern Internet, and is bigger than one company: it is the power of us all together to determine our fate. But we cannot take that foundation for granted -- and we must be willing to work to exercise that power to assure an open source future. Thank you to the consortium here that is coming together to guide Hashi to see the wisdom in an open source Terraform!
- sausagefeet 3y agoAs a huge Oxide fan, thank you for the support!
- lawnchair 3y agoThanks Bryan!
- diarrhea 3y agoJust scrolled through your open job postings, and the Control Plane opening is jaw-droppingly interesting. Sounds like a marvelous mission you're on. I'm wishing you all the best and will make sure to check back in with Oxide's progress!
- hbogert 3y ago
- kemitchell 3y ago> When any company releases their tool as open source, the contract with the community is always the same... There is no contract. Try to enforce it. Even non-binding expectations differ widely among projects. > We believe that HashiCorp should earn a return by leveraging its unique position in the Terraform ecosystem to build a better product, not by outright preventing others from competing in the first place. Nobody at Hashi cares how their competitors think they should make money. As for competition, Hashi just blew the whistle for an all-comers product pace-race against its formerly free-riding rivals. The old code remains MPLv2-licesed. That's the starting line. Their new BSL automatically releases new code under MPLv2 four years after it's published. That's Hashi committing to a minimum pace. They clearly foresaw a fork. They are betting their maintenance commitment, expertise, new development pace, and existing book of business will make their new, less than four-year-old versions the versions users want, despite the license. Hashi's announcement and FAQs try to minimize perceived cost of the license change by emphasizing they intend no change for users, customers, and contributors, as distinct from product-service competitors. This new fork announcement tries to maximize uncertainty about the license and throw shade on future development prospects. It's all in the game. Customers can watch the runners run. Eat popcorn. I think it's highly unlikely Hashi's rivals will make enough marketing pain on this to force them to reverse the change. The database companies made far bigger moves, with more complexity and fewer marketing lessons learned. They held out. So the war's on the product dev and product marketing fronts. The real test will come in January, after Hashi says it will stop backporting fixes to the current MPL release. At that point, the rivals are under their own power only. Will any MPL-today-licensed fork be so competitive with Hashi's version at that point that customers bet on it over Hashi's long-term? It will have to bear its own development and maintenance costs for whatever differentiates it. I'm familiar with the products, but not an active user. My main question is whether there's substantial new development still to be done on the most popular projects, or whether it's really a maintenance war. I'd be looking for whether Hashi's new versions break compat, either tactically or as a consequence of new development.
- slikrick 3y ago> there is no contract There are social contracts
- flash0777 3y agoLong time YC reader here. Created an account just to make this comment: maybe this idea of a fork is a good thing. We maybe able to potentially explore developing HCL further. Develop further abstractions that are provider agnostic. At least for most common resources like instances, security groups etc. Obviously there would be tradeoffs involved. But if we can cover the 80% situation, that would be a good start.
- losvedir 3y agoI don't get the argument that there's legal ambiguity. It was Mozilla licensed through some version; as long as you use that version it will be fine, right? Obviously, there's the argument that Hashicorp might sue you even for that, but it feels like the reductio ad absurdum that any company can sue you for anything, and not remotely plausible.
- fidotron 3y agoThe weaponisation of open source by the cloud vendors combined with devops culture encouraging only paying for operations and commoditising development is going to lead to constant pointless migrations of this kind (such as Docker/podman etc.) Devops people need to find a viable way to reward the developers of the tools they make a living from operating. Failing that they will wake up finding no one is willing to make them or that those that do have an ulterior motive.
- rank0 3y agoI actually love the weaponization of OSS. It eats away at the technical gap between proprietary systems and their FOSS equivalents. See elasticsearch + openAI (although open models are still quite far behind)
- jupp0r 3y agoiojs comes to mind. This is the beauty of open source in action. Long living forks and fragmentation sucks, but now HashiCorp has to react to this and provide compelling benefits if they don't want to loose the whole project alltogether.
- ragona 3y agoThe CDK and Pulumi teams must be truly delighted by this move.
- fuddle 3y agoThis reminds me of how the MapLibre project was created after Mapbox changed their license. https://wptavern.com/maplibre-launches-as-official-open-source-successor-to-mapbox-gl-js https://wptavern.com/maplibre-launches-as-official-open-sour... https://maplibre.org/ https://maplibre.org/
- deleted 3y ago[deleted]
- bloopernova 3y agoIf any Hashicorp people are reading, can you please tell your middle and senior management that this decision has deeply soured my entire DevOps cohort on continuing to use Terraform in the future. We're already exploring alternatives. Future client projects may not use Terraform at all. Languages and frameworks must remain open or they will wither and die.
- thdn 3y agoWould you mind to share, those alternatives?
- johnbellone 3y agoJust stop using their products. Stop giving them free advertisements. Stop integrating your software and services with them. It is harsh, but they’re a public company now, not Mitchell.
- bshacklett 3y agoFar easier said than done.
- AtNightWeCode 3y agoThe fantastic cost of running TF in the cloud is painful. Several years ago it was very clear that it would be difficult for HC to survive once they became a company registered at stock markets.
- jen20 3y ago> The fantastic cost of running TF in the cloud is painful. Citation needed. I don't think it costs very much at all.
- WhyNotHugo 3y ago> We're already exploring alternatives. Future client projects may not use Terraform at all. I'd wait and see what happens with OpenTerraform. If the fork gains some good momentum, it would be the easier choice. Usually, you should be okay with using the latest FLOSS version for a few weeks/months until things settle anyway.
- mousetree 3y agoAs a regular end-user of Terraform, what difference does BSL vs MPL make to me? From reading this article it seems not very much? Perhaps I'm misreading this.
- LinXitoW 3y agoSomeone correct me if I'm wrong, but if I use TF in a Petstore-as-a-Service to provision new machines for my users, does that not count as embedding TF? So if HashiCorp decides to do Petstore-as-a-Service tomorrow, no matter how shitty the offering, no matter how insincere, even if it's just a single intern working on it, I would have to, overnight, rip TF out of my entire offering, no?
- yellowapple 3y agoCorrect. That, or "negotiate" with HashiCorp for a commercial license.
- brikis98 3y agoIt means that whether you can use Terraform at any future company you work for will be determined... by HashiCorp. That's because the BSL license is intentionally vague. What does "competing" mean? What does "hosting or embedding" mean? Who decides? In order to really know if you're a competitor, you have to reach out to HashiCorp (as the FAQ tells you to do). So whether your usage is valid is not controlled by the license terms, but is instead entirely at the whim of HashiCorp. So they switched from a permissive open source license to a HashiCorp decides license: they get to decide on a case by case basis now—and they can change their mind at any time. That is very shaky footing on which to build anything. And the legal team at every company you work for will have to take that into account before deciding you can or can't use Terraform. See https://blog.gruntwork.io/the-future-of-terraform-must-be-open-ab0b9ba65bca https://blog.gruntwork.io/the-future-of-terraform-must-be-op... for more info.
- robbintt 3y agoIt will affect categories of business users (programmers) who currently embrace terraform: amazon, google, microsoft, oracle, alibaba cloud. Like it or not, cohorts of engineering organizations like the above (cloud providers) have a very outsized weight and already have contender products they can choose to vigorously fund tomorrow. From the article: The license does not allow you to use Terraform if you meet both of the following conditions: You are building a product that is competitive with HashiCorp. You embed or host Terraform in your product. My $0.02: the management of hashicorp is following a stupid trend and should have thought about their customers more. It will come out to what lawyers think, I guess. Lawyers usually say no to things with poorly established precedent.
- 0xbadcafebee 3y agoActually, can we just kill Terraform? Please? Terraform has a bad design. It's a configuration management tool, first and foremost, and configuration management tools need to do one thing well: fix things. Not just "change state", but functionally, actually fix some software to make it work again. Terraform is really bad at this. It's difficult to configure, difficult to operate, and it likes to find any reason at all to just blow up and force you to figure out how to make the software work again. Configuration management tools should make your life easier, not harder. You shouldn't have to hire a "Terraform Admin with 3 yrs experience" just to learn all the bizarre quirks of this one tool just to get your S3 bucket to have the correct policy again. You shouldn't have to write Go tests just to change said policy. It's like it was invented to be a jobs program for sysadmins. I have a laundry list of all the stupid design decisions that went into the damn thing. And because the entire god damn industry is stuck on this one tool, no other tool will ever replace it. Its providers are so large and there are so many modules created that it would take years of constant development to replace it. So it doesn't get changed or improved, and it can never be replaced. It is the incumbent that blocks progress. A technological quagmire we can't extricate ourselves from. The essential purpose of this tool is really to be a general interface to random APIs, track dependencies in a DAG, pass values into resources when it has them, attempt to submit a request to the API, and then die if it doesn't get a 200 back. We can accomplish this in a simpler way that is less proprietary and more useful. And we can ramp up on specific functionality to give the solution actual intelligence, like default behaviors for specific resources in specific providers, hints on how to name a resource, more examples, canned modules that are easier to discover or publish, ability to use different languages or executables, etc. But we need to put forward those alternatives now, or we won't get the chance again for a long time.
- snom380 3y agoI have a hard time thinking of how terraform as a piece of software can do to much more than it already does to fix things? When terraform fails, it's typically because of a an API error or a configuration issue that is beyond its control? Not handling state rollback is a design decision that, having dealt with the fun of CloudFormation, I'm pretty happy that they made.
- sredevops01 3y agoTerraform is terrible as it is. Good riddance. We need real tools instead of messing around with text files with ridiculous formatting.
- latchkey 3y agoWhile I agree with you about TF having a lot of issues, the comment isn't helpful. What would you suggest otherwise? Kind of a moot point now that the license is fubar'd, but what could be improved to make it better? If you could have a do-over, what would that look like?
- zapnuk 3y agoRight now there is pulumi as a alternative that supports different clouds. Otherwise AWS CDK or Azure Bicep come to mind. If i could to a do-over I'd want the solution to look and feel like AWS CDK but without the cloudformation in the background, and support for GCP and Azure. I've worked with CDK for 2 years now and being able to define your code in Typescript is quite handy and drastically reduces the effort it takes for new people to learn how our deployment work. It's also quite nice to be able to directly bundle and deploy the application together with the infrascructure with very little effort.
- latchkey 3y agoThe mind boggles why Pulumi doesn't do ssh. I have a whole bunch of bare metal sitting in data centers all over the world, how am I expected to manage it? Ansible/Salt/Chef is obviously one type of solution, but like you said, being able to code things in TS is really nice. One thing TF does well, is bare metal.
- yjftsjthsd-h 3y ago> One thing TF does well, is bare metal. How? I've always viewed TF as good at anything except metal; the best I would know to do is remote-exec but at that point you might as well drop to raw shell.
- thdn 3y agoAny reliable alternative at the moment?
- deleted 3y ago[deleted]
- robbintt 3y agoFor now you can pin your version and cache your sources.
- time0ut 3y agoAs a long time Gruntwork customer, contributor, and fan, it is really nice to see them stepping up as thought leaders here. They run a great open source community already. Our DevOps team has been buzzing all day with what we are going to do. For now, we are staying pinned to the last open source version of Terraform and will likely follow Gruntwork's lead when the time comes.
- linuxdude314 3y agoIf your company isn't building a product based on terraform, why are you doing anything?
- time0ut 3y agoWe use Terragrunt to manage thousands of Terraform configurations. If it and Terraform drift apart, we will have to go one way or the other eventually. Separately, a new license for Terraform means its gotta go back through legal and compliance so we will be paused for months anyway.
- Halan 3y agoThanks Hashicorp for providing me with an excuse to convince my management to give Crossplane a try
- new23d 3y agoAs an end-user, not competing with HashiCorp, this change doesn't worry me. According to their FAQ [1]: 10. What are the usage limitations for HashiCorp’s products under BSL? All non-production uses are permitted. All production uses are allowed other than hosting or embedding the software in an offering competitive with HashiCorp commercial products, hosted or self-managed. 24. Can I host the HashiCorp products as a service internal to my organization? Yes. The terms of the BSL allow for all non-production and production usage, except for providing competitive offerings to third parties that embed or host our software. Hosting the products for your internal use of your organization is permitted. [1] https://www.hashicorp.com/license-faq https://www.hashicorp.com/license-faq
- ryanisnan 3y agoI think it should, to some extent. A really quick example comes to mind. Some of the best documentation on how to use Terraform properly comes from folks who provide competitive offerings. I could also see someome like Amazon eventually launching a CloudFormation like tool that works natively with Terraform, but now that's off the table and I think a net negative. It also sounds like projects like Atlantis also would be against the BSL, including self-managed installations of the tool.
- diarrhea 3y agoIt’s not about individual usage but the ecosystem around and on top of Terraform, whose foundation just got a lot more shaky.
- deleted 3y ago[deleted]
- nikolay 3y agoIt should worry you - it hurts the ecosystem. Terraform is just a tool. The providers, modules, not supported by HashiCorp, is what makes Terraform useful. Ige the ecosystem dies, Terraform becomes useless.
- jen20 3y ago
- cattown 3y agoI like Terraform and will continue to use it. I'm just an end user that isn't involved in building other product offerings on it or a user of other derivative products. Even though this really doesn't affect my use case it does feel like kind of a dirty bait and switch. I do hope for a future where there's a version (and Terraform provider module versions) that are actively maintained under a true open source license. I'll favor using those over the official BSL version as much as possible. I guess it's the CLA that all of the contributors signed that allows this to happen? I wonder if there's a way for open source licenses to address this, and disallow the use of CLAs, or require some CLA clause that doesn't allow sudden switches to non-permissive licenses?