8 ms·
IMHO Hashi TF is the fork since they changed the license to a non-open source one. OpenTF is the same MPL license under a different name.
by SebastianStadil 3y ago
IMHO Hashi TF is the fork since they changed the license to a non-open source one.
OpenTF is the same MPL license under a different name.
- igorzij 3y ago[flagged]
- bornfreddy 3y agoYes. Worse than that, they changed to a license that prevents companies to use their product freely - if they chose some "cloud protection license" that simply handicaps possible competitors to their commercial offwrings, this fork would probably not happen, or at least it wouldn't have such momentum.
- saxonww 3y agoThey really didn't. They changed it to prevent companies from building commercial products around terraform, which is what you've suggested as a cloud protection license. Companies that use terraform to manage their infrastructure are not practically impacted in any way, except by this OpenTF effort (which I don't personally oppose either!) which will create a schism and leave us with competing tools that are not quite interoperable over time (thinking about ZFS/OpenZFS, MySQL/MariaDB, etc.). https://www.hashicorp.com/license-faq#usage-limitations https://www.hashicorp.com/license-faq#usage-limitations It isn't the AGPL, but I am just sort of stunned at the uproar around this. Is Hashicorp supposed to just shrug and clap while a competitor takes (primarily) their work and competes with them using it? That's what the MPL allows, and they don't want to do that anymore, so they... changed the license to protect their interests. What do you expect them to do?
- SebastianStadil 3y agoWhat we expect them to do? How about making better commercial products to start?
- swozey 3y agoI just went through about 20-30 SRE interviews while hiring an SRE II for my team. Every single one of them that had state management at all used terraform cloud. I found that really interesting because I've never heard positives about it vs the others (spacelift, env0, terrateam, brainboard etc). Not a single one of them had anything other than tfc. Not even atlantis.
- technics256 3y agoThat's funny, I've only ever used Atlantis with a smattering of tfc
- swozey 3y agoI've only used Atlantis as well! We actually need to decide on a service next month. I haven't demoed it yet but I'm really aiming to use brainboard.co if it actually does what it says. It's priced per user, not some weird deployments a month price and it honestly looks amazing. Gives you a gui to move resources around, imports your current state, etc.
- notnmeyer 3y agosame. love atlantis. was happy to read that atlantis isn’t impacted by these changes.
- jxjfkff 3y agoI've helped companies evaluate TF Cloud few times and not a single time they could be convinced to adopt it. I've also interviewed dozens of SREs and zero had experience with TF Cloud.
- ohad1282 3y agoenv0 founder here. What were the main reasons that they used TFC? was it the ability for Hashi to fix things in Terraform CLI/providers? was it their size / "nobody gets fired for buying IBM"? something better in the product? something else? would love your insights here
- 3y ago
- Hrun0 3y ago> It isn't the AGPL, but I am just sort of stunned at the uproar around this. Thought the same. I think the uproar is partly manufactured by competitors and freeloaders who are affected by this license change, eg. Spacelift.
- saxonww 3y agoAlso, I haven't read a lot about this, but I would be very surprised if the Spacelifts of the world could not work out a licensing arrangement. The actual license at https://www.hashicorp.com/bsl https://www.hashicorp.com/bsl says "provided such use does not include offering the Licensed Work to third parties on a hosted or embedded basis which is competitive with HashiCorp's products." To me this sounds like a self-hosted version of something could still work with terraform, and you just have to provide the binary yourself vs. it being pre-packaged. IANAL; it would be pretty shitty if they started going after products that support terraform as a tool that way.
- joshpadnick 3y agoGruntwork co-founder/OpenTF core member here. Hashi went out of their way to clarify that you couldn't do this. https://www.hashicorp.com/license-faq#what-does-embedded-mean https://www.hashicorp.com/license-faq#what-does-embedded-mea...
- saxonww 3y agoWell that does suck. I would also wonder if that's a legal battle they would win. I've never used Spacelift, etc. so I may be off base with the comparison. But I think about them like specialized CD tools that do nice things with/for terraform. Their value is that you don't have to implement these nice integrations yourself in e.g. Jenkins. So replace Spacelift with Jenkins. There are some community plugins that idk, facilitate reporting plan impact from code changes. Is Cloudbees now in violation of Hashicorp's license? Regardless, good luck.
- bornfreddy 3y agoIt would kind of make sense though? When part of the product you are selling is made and supported by someone else, don't they deserve a part of your income? I know that FOSS works differently, but that's also the reason why a lot of open source software is of questionable quality. When the development becomes a burden (is not fun anymore) and nobody is compensated, why would someone waste their time on it? Good will only goes that far. Not suggesting that proprietary software is without faults, but maybe such licenses are a good comprise?
- klooney 3y agoI have a dumb BUSL question- if you don't compete with Terraform, but you do with something else, like Boundary, can you still use TF? If Hashi releases a new product that competes with you do you have to stop/license TF?
- jxjfkff 3y agoWho knows? No answer given today is future proof. Best advice I can give is not to use Hashicorp products as the basis of any offering ever. Simply don't even consider them.
- bornfreddy 3y agoIANAL, but I would say yes, and yes. https://www.hashicorp.com/license-faq#usage-limitations https://www.hashicorp.com/license-faq#usage-limitations > 11. What are the usage limitations for HashiCorp’s products under BSL? > All non-production uses are permitted. All production uses are allowed other than hosting or embedding the software in an offering competitive with HashiCorp commercial products, hosted or self-managed.
- softveda 3y agoNo. Read FAQ #26 and 27 https://www.hashicorp.com/license-faq#usage-limitations https://www.hashicorp.com/license-faq#usage-limitations
- bornfreddy 3y agoThank you for correcting me! Two sources (mariadb and fossa.com) claim that by BSL any production use requires a different (commercial) licence, while HashiCorp's explanation [0] indeed tells that there is no change except for those providing competitive offerings (I'll take their word for it). Which seems... more than fair? Not sure what the uproar is about either, if anything, I understand (and support) HashiCorp. Too bad about the split though. [0] https://www.hashicorp.com/license-faq https://www.hashicorp.com/license-faq
- BarryMilo 3y agoThe uproar is that people and coompanies contributed to the project without compensation, and are just now being told Hashicorp has altered the deal... unilaterally. I for one would not have built my infra on non-free software, and I will certainly avoid it now.
- znpy 3y agoAre you sure the MPL is free software? Last time I checked, debian had to provide a forked version of firefox and thunderbird because their license (the MPL) wasn’t free enough.
- eitland 3y agoThat was not about the license of the code I think. The code for IceWeasel is still MPL, only they have changed the artworks and names that are trademarked or otherwise protected by Mozilla.
- xorcist 3y agoYes, the MPL is free software. The FSF explicitly says so on https://www.gnu.org/licenses/license-list.html https://www.gnu.org/licenses/license-list.html and the Mozilla project developed the license with the intent of it being used in other free software projects. The important difference is in its limited grant on patents. The reason Debian avoids distributing Firefox is not because of copyright licenses but because Mozilla vigorously protects their trademarks, including "Firefox" and the various logotypes. You are not allowed to distribute them without permission, which Debian largely wants to avoid to have in order to not set a precedent which would impact further distribution of Debian and its derivatives. Mozilla does this to avoid the risk of third parties offering Firefox with spyware-like modifications. One might ask why Debian itself do not seem to suffer the same problems. It seems like a problem mostly on proprietary software distribution platforms in practice, but it's certainly a possibility.
- kpgalligan2 3y agoI'm amazed and a bit dismayed by the general vibe in the comments. I'll preface this with I don't know anything about Terraform, OpenTF, HashiCorp, etc. I couldn't even guess what Terraform is. I'm in mobile dev. However, I work on open source a lot and think about sustainability and revenue streams quite a bit. I read the manifesto. I saw the "revert the license or we'll fork". What I didn't see is any form of trying to work with HashiCorp on their goals. It seems like very considerable resources have been pulled together to fork, but I didn't see the part where anything remotely like that level of effort and resources was on offer to HashiCorp to rethink the plan and come up with a better answer. As I understand it (which is based off of some comments. See above about not knowing anything about this), a good chunk of the resources are actually from competitors. If true, it takes a lot of the sting out of the "HashiCorp are jerks" argument. I mean, I'm not saying they're not, but it's more like, "HashiCorp changed the license so they could push back on competition, so the competition forked the code". I don't really expect "right and wrong" from companies, or open source for that matter. But the spin and vibe feel a little misdirected. I mean, don't get me wrong. Building up a community who contributes, then doing a rug pull, sucks. However, the "company does a risky thing and builds this awesome tool, then a bunch of others fast follow and exploit it" has become very common, and it is going to be a bad thing in the long run. You can say "We believe that the essential building blocks of the modern Internet, such as Linux, Kubernetes, and Terraform need to be truly open source", but to be fair, Terraform was not an essential building block until somebody built it. As much as license rug-pulls damage user/community investment, fast-follow competition and the threat of forking will ensure far less investment in the very kind of open source everybody wants. There is a financial sustainability problem involved in "big open source", and we are seeing the changes. In many ways, it simply has to happen. Going forward, I do hope new products like this start with a license that works rather than changing, as that is obviously not appreciated, but many devs reflexively avoid that kind of arrangement, even if it costs nothing to use. Anyway, just thinking out loud. Hashicorp might be run psychopaths. I have no idea. In a general sense, though, the whole industry is going to need some new models. If it's just "fully open source or nothing!", there's a whole class of tools that won't exist. Building things is risky and expensive. I don't want to go back to when everything was closed source and needed a license, but open source without a reasonably protectable revenue model will definitely limit what gets built and why. And as we like to say, "if you're not the customer, maybe you're the product", or something like that :)
- mcfedr 3y agoThere is no such thing as an open source license that prevents others from doing something specific with the software, that's basically the point of open source.