4 ms·
I'm concerned that people who do not have a provable track record for contributing to terraform believe they can fork and be good stewards of the project. Look
by sontek 3y ago
I'm concerned that people who do not have a provable track record for contributing to terraform believe they can fork and be good stewards of the project. Looks like the top contributors to the foundation are:
- https://www.scalr.com/ - https://github.com/Scalr
- https://gruntwork.io/ - https://github.com/gruntwork-io
- https://www.massdriver.cloud/ - https://github.com/massdriver-cloud
- https://spacelift.io/ - https://github.com/spacelift-io
- https://digger.dev/ - https://github.com/diggerhq
Gruntwork and Digger do some decent opensource but the others haven't been great stewards of opensource. Looking at their githubs they don't seem to give much of anything back. So why should we trust them over hashicorp?
- fishnchips 3y agohttps://www.terratag.io/ https://www.terratag.io/ is by env0, one of the OpenTF sponsors. I also encourage you to take a look at the Sponsor badge on our (Spacelift's) profile. Whenever a possibility exists, we give back to the projects we use. We tried the same with Hashi, too. Re: trusting us over Hashi. DON'T. If there are any lessons learned from the great Hashi bait-and-switch trick it's that for-profit companies should not be trusted as the guardians of open source. Trust the foundation that takes over the project. Trust the cash we'll endow it with.
- fishnchips 3y agoAlso worth mentioning that we support our employees working on open source during their Friday projects where they're free to do anything to grow as engineers. Many choose to do open source and we don't require them to do it under our umbrella. In fact the guy from my team who is the acting TL of the OpenTF project is the creator and maintainer of https://github.com/cube2222/octosql https://github.com/cube2222/octosql
- Znafon 3y agoSo the software from your company is fully closed-source, isn't it? The employes can do open-source on Friday but no part of Spacelift is actually open-source?
- fishnchips 3y agoIncorrect. Parts of Spacelift are open source: https://github.com/spacelift-io/celplate https://github.com/spacelift-io/celplate https://github.com/spacelift-io/prometheus-exporter https://github.com/spacelift-io/prometheus-exporter https://github.com/spacelift-io/spacectl https://github.com/spacelift-io/spacectl https://github.com/spacelift-io/spcontext https://github.com/spacelift-io/spcontext https://github.com/spacelift-io/terraform-provider-spacelift https://github.com/spacelift-io/terraform-provider-spacelift https://github.com/spacelift-io/vcs-agent https://github.com/spacelift-io/vcs-agent Whenever we're extending an external library, we're submitting the change upstream. Whenever there's an opportunity to sponsor a project on which we heavily rely, we do that. But yes, we don't maintain any major open source projects as a company. And neither will we with OpenTF, because our active involvement with it is only temporary - we are just helping it get off the ground. Long term we will be primarily a sponsor of a dedicated team (see our pledge), not a core maintainer.
- Znafon 3y agospacectl, vcs-agent and terraform-provider-spacelift are only useful with your proprietary product. prometheus-exporter is a very small exporter to monitor your proprietary product and has no utility beyond that. I'm not sure what spcontext does because it has no documentation but I'm sure I could read the 10 commits to find out. The only none trivial project in the list is celplate which actually looks nice, but even there most of its complexity is in cel-spec. > Whenever there's an opportunity to sponsor a project on which we heavily rely, we do that. Come on, on Spacelift GitHub profile there is one project sponsored, and only since August 24! > we don't maintain any major open source projects as a company So you never had to handle project management of large open-source supports, community support, doing code reviews every day and handling feature requests from the community? Yes, HashiCorp has been slow to respond to PRs and did not always commmunicate clearly, but so does many large open-source project like PostgreSQL, Python, Linux, etc. Managing a large open-source project takes more time than clicking on the merge button on GitHub. Users don't magically come fix all the bugs in the software, and develop complex new features. HashiCorp did contribute a lot, and there is still a lot to learn from their projects, there is Raft, the autopilot, various library that are used a lot in the Go ecosystem, including go-plugin, a programming language with its specific type system and plenty more. After all, the change of license is making noises because we their tools defines part fo the DevOps world and we all use them a lot. I wish HashiCorp would have kept using the MIT license, but using the BUSL is still miles ahead better than companies that are completely closed source. From the outside perspective it looks like you support Free Software as in Free Beer more than in Free Speech. You are supportive when others are actually maintaining the projects for you, and you just want them to merge your contributions quickly. It is a very efficient way to externalize some of your costs, but you only step forward to actually to help manage them when your bottom line is threatened. That's ok, it looks like you love money more than open-source ideas. That's perfectly fine but don't pretend otherwise. Some others companies that signed the pledge have actually been maintaining open-source projects and have a leg to stand on. Spacelift loves having the high moral ground and the extra publicity. Release the core of your product as open-source, like HashiCorp did for 9 years, and it will change my mind.
- sontek 3y agowe support our employees working on open source during their Friday projects This is very different than hashicorps model of paying people to work on the opensource project during their working hours. Making it a core part of their job. If we are to accept that the OpenTF foundation is going to be a better maintainer of terraform we need something better than "Hack on opensource if you want to!" Spacelift doesn't have a good track record of contributing to opensource so the current model isn't working. Also, Jacob started OctoSQL before ever joining Spacelift so its pretty odd to use that as an example of spacelift doing OSS well. Especially since his activity on his has tanked since joining you.
- cube2222 3y ago> If we are to accept that the OpenTF foundation is going to be a better maintainer of terraform we need something better than "Hack on opensource if you want to!" The plan is for the foundation to employ dedicated engineers that we can sponsor. Regarding open source vs closed source, I have nothing against closed source software. I think the outrage about Terraform specifically is caused by people seeing it more as an ecosystem, not a product (like Vault or Consul), and the whole thing looks like a bait-and-switch of reaping the benefits of open source (and others building a provider ecosystem) and then closing that down, once you start getting the cons of open source (healthy competition building inside of that ecosystem). Honestly, I'm grateful for Hashicorp for the contributions they've made over all these years, and the libraries they've built. And as is the beauty of open source, in a situation like this, we can just fork, which we're doing. In a dream scenario, HashiCorp would eventually join us working on OpenTF in the open, with the load much better distributed across companies, and the roadmap better reflecting the community's needs. I don't think, however, that it's fair to call these companies freeloaders who just now decided to contribute, as HashiCorp quite openly didn't encourage community involvement in the development process of their core open source projects. All in all, I hope we'll do a much better job of involving the community in the core development and decision-making process (via public RFCs), while the foundation part means you don't have to trust any of the companies specifically. A healthy open-source ecosystem here is both good for the companies using it (partly due to no vendor lock-in, better competition, more innovation, lower prices), as it is for companies building products that extend tools in that ecosystem, as it is for any individuals involved. It's a win-win-win situation. Disclaimer: Work at Spacelift, and currently temporary Technical Lead of the OpenTF Project, until it's committee-steered.
- sontek 3y agoTrust the foundation that takes over the project But part of the value the foundation is pitching is that it has companies donating engineering time to keep the project well managed. My concern is spacelift and some of the other companies have no track record of being GOOD at opensource. Not as part of the terraform community or opensourcing things they've built in-house.
- ohad1282 3y agoenv0 founder here. Thank you for your note. Important to mention Gruntwork, creators of Terragrunt and Terratest together with us here. Also, the CNCF/LF will assign some external members to the TSC (technical steerring committee). I honestly believe such a balance (external, Gruntwork, and direct competing vendors), all under a well experienced foundation is the ideal situation.
- sanderjd 3y agoI think your pushback here is appropriate and valuable. But I also really like their response to it, essentially: Don't trust us, watch us. This group of people has taken a leap of faith. They aren't asking us to leap with them, they're asking us to pay attention to where they land, and come along if it looks like the water is fine. I applaud their approach.
- fishnchips 3y agoI couldn't express it any better, thank you!
- sorenmartius 3y agoTerramate co-founder/ OpenTF member here All those companies have very decent experience with Terraform. Even if some didn't contribute to the core, they all built decent software on top of or around Terraform. In addition, we at Terramate also plan to contribute as much as possible. We have worked exhaustively with Terraform and related libraries such as HCL and are very well aware of the limitations and shortcomings we need to resolve with OpenTF. I'd love to emphasize that many of us tried to contribute to Terraform in the past, but HashiCorp became somewhat hesitant to review and accept PRs which massively slowed down innovation for Terraform. While I see the reasoning behind HashiCorps decision to switch licenses I strongly believe that closing up the ecosystem further won't do any good to Terraform and other of HashiCorps products, hence our strong buy-in for OpenTF.
- sontek 3y agoBeing good at using terraform is very different than being an opensource maintainer and community builder. I'd love to emphasize that many of us tried to contribute to Terraform in the past, but HashiCorp became somewhat hesitant to review and accept PRs which massively slowed down innovation for Terraform. Do you have links to PRs people from your organization pushed that weren't reviewed/accepted by HashiCorp?
- MysteryVice 3y ago"Due to current low staffing on the Terraform Core team at HashiCorp, we are not routinely reviewing and merging community-submitted pull requests" https://www.theregister.com/2021/09/07/hashicorp_pause/ https://www.theregister.com/2021/09/07/hashicorp_pause/