6 ms·
This shall serve as a great example for why no reasonable company would ever use a permissive license for their main product again.
by andersa 3y ago
This shall serve as a great example for why no reasonable company would ever use a permissive license for their main product again.
- hotstickyballs 3y agoIt should serve as a warning for companies who want to leverage the open source community but then do a rugpull
- ohad1282 3y agoI think it is reasonable for a company to start OSS and then change its license. But it indeed feels like a rugpull for all the contributors. That is why OpenTF is on its way to CNCF. To ensure it stays OSS forever. There is a difference between "true OSS" like K8s, OPA, etc and "temporary OSS" (backed by a company) like what Terraform used to be, Pulumi, GitLab ,etc. Those can be changed in the future. When developers chose OSS, they should consider if it is a CNCF OSS or a vendor backed OSS. What Hashi did is an important example. (disclaimer - env0 founder here, co-lead the OpenTF initiative)
- AaronFriel 3y ago> Pulumi is true open source, uses the Apache 2.0 license, and does not and never will depend on BSL-licensed software in any way, HashiCorp owned or otherwise. https://www.pulumi.com/blog/pulumi-hearts-opensource/ https://www.pulumi.com/blog/pulumi-hearts-opensource/ Disclaimer: the following is my own opinion as an engineer at Pulumi. Pulumi is true open source, with a relationship similar to git and the many SaaS services that layer on top of git to provide meaningful value. To contrast with our competitor, Pulumi relies on open source languages and protocols. We could not, even if we wanted to, change the Python license. Nor could we change our protocols without breaking our users and our growing ecosystem. That's the value of building on open protocols and standard languages.
- ohad1282 3y agofair point. makes sense.
- res0nat0r 3y agoI suspect this project is going to consist of a very loud minority of folks. I'm working for a very large company right now and they've been mandating us to move all of our TF code to Terraform Cloud for the last year, and I've not heard a peep about this licensing issue. I'm assuming they're going full steam ahead and don't care about this issue. As long as the TF Cloud service is easy to use, still a SaaS so it's TF's problem vs the companies, and they allow a robust login / access pattern via OAuth / SAML, all is well.
- joshpadnick 3y agoOpenTF core member here. If you're comfortable opting into an ecosystem where most of the key products are offered and supported by a single vendor (in this case, Hashicorp), then yes, there are no licensing issues to worry about and basically nothing needs to change for now. But our philosophy at OpenTF is that users would rather participate in an open ecosystem where multiple vendors compete for their business. If you're not happy with one vendor, you can easily switch to another; competition works to make all vendors better. When we look back at this comment a year from now, I'll wonder how your company will feel about the responsiveness and new features they're getting from Terraform Cloud when the primary incentive to stay is not because you think it's the best product available, but because switching costs are so painful.
- res0nat0r 3y agoHonestly, I think when it comes to the large companies I've worked for, they care more than anything else revolves around "support". 15+ years ago the my previous company was all Sun Microsystems based, owned millions of dollars in 880s, 6800s and even an E10K. They said Linux was off limits because they couldn't blame/call anyone when they needed "support", even when Redhat was already around. Eventually they saw the writing on the wall and moved to Linux systems and replaced all of the hardware, and have an enterprise RHEL subscription that we could call when needed. I think the story is going to be the same with the current company, mainly "who can we blame if there is a security incident, or get me a Hashicorp person on the phone if we have some kind of Terraform related production issue." Having this in place seems to matter more than everything else honestly.
- sanderjd 3y agoI think you're both right? I have come around to the idea that it's good to firmly discourage this kind of late-in-the-game license change. But I also think that, on net, this episode will lead to fewer businesses choosing the open source model for their software, from the start. It just seems like playing business on hard mode to try to build an open source or source available product, when you can just build a SaaS and charge for it. I think this is really bad (I have a strong preference to not be stuck with opaque SaaSes for most things), and I'm not sure what incentive there is to try to find new business models, when you risk becoming public enemy number one amongst a big chunk of your potential customer base.
- erinnh 3y agoWould a non-permissible open source license somehow changed this? Not sure what you mean.
- Pannoniae 3y agoAlthough we are not there yet, but if we don't do something to change it, there will be a moment where it will be true that "no reasonable person releases anything under a permissive licence", sadly. Just see the latest serde "drama", where everyone disregarded the "no warranty" clause in the licence and loudly demanded changes/wanted to fork the project/etc. FOSS has a huge problem of expectations from both upstream and downstream. There are very common arguments about "I use this, you broke it/made changes I didn't like, so you are a horrible maintainer and person and you will have zero credibility forever". If anyone uses FOSS dependencies, they also accept the risk of future versions being different. No one breaks versions already released, this is always about future versions. Demanding the maintainers to make specific changes/not to make them for your usecase is extremely entitled.
- fishnchips 3y ago> main product Well that's the core problem - what is the product here. Terraform Cloud and Terraform Enterprise are products for sure. They're not open source, though. Is Terraform a product? Well, it doesn't do anything on its own, it requires plugins ("providers") for anything it does. Plugins are developed by or at least with third parties. It's a gatekeeper of an ecosystem that at this point is a common good. Whether the ecosystem would exist without the permissive license and external contributions - really hard to say. But if your main play is to foster the growth of an ecosystem and then turn it into a product exclusive to your business, then I guess you should look for alternatives. (Marcin from OpenTF, private opinion)
- johannes1234321 3y ago> Plugins are developed by or at least with third parties. It's a gatekeeper of an ecosystem that at this point is a common good. While I guess that for many vendors they don't care whether it's open or not. For instance AWS. I doubt they truly care about it being open or not.
- fishnchips 3y agoAWS probably doesn't care much for it being closed either. But the benefit of being open is that folks can investigate, report and fix bugs. For example, at Spacelift we found a fascinating corner case where an RDS DB could be dropped if the call to get its details resulted in a transient API error. We wouldn't be able to do it if the code wasn't open. I also believe that the AWS provider in particular gets quite a bit of attention from the community outside Hashi and AWS.
- t-az-f 3y agoAll the providers are still MPL licensed, however. Maybe I'm missing something, but what part of the license change for Terraform core prevents someone from investigating and fixing a bug in the AWS provider in a similar manner going forward? Even Terraform core remains source available and so 'community' users can still take a look at the source code and identify/report/fix errors.
- capableweb 3y agoIf a company isn't ready to compete against someone/something that is using the code the company has written and published as FOSS, then yes, please do not use FOSS licenses for your "Open Source" product. One would think that the companies thought this through before publishing FOSS code, but seemingly there is a lot that didn't do that.
- sanderjd 3y agoThis is essentially where I have landed. I think these companies should have just used a license like BSL from the get-go, and I hope that the next generation of product companies will learn that lesson. But unfortunately I think the lesson they will take from this instead is "we should just build a SaaS with no source availability because that's way easier and source-available just makes people mad anyway". I think that's a shame.
- pknomad 3y ago> I think these companies should have just used a license like BSL from the get-go I think that's the general attitude the software companies will have going in the future. Why even bother dealing with negative PR and push back against their ability to make money by going with FOSS? In hindsight, TF should have been released with BSL from the beginning. I am not a huge fan of Hashicorp changing its licenses for future releases but I am also skeptical of OpenTF's motives since their members have big financial stake in that decision.
- fishnchips 3y ago> skeptical of OpenTF's motives Acknowledged, there are always self-serving motives involved. Generally things don't happen without a reason. But we donated the project to a foundation, and will over time build (and fund) a dedicated independent team who will follow their own vision and the community needs, not ours. So please judge us by our actions, not assumed motives. > their members have big financial stake in that decision I can't speak on behalf of others but to us at Spacelift it's less about direct financials (we are actually not directly affected by the license change!) and more about being in charge of our own destiny and product roadmap.
- deleted 3y ago[deleted]
- kstrauser 3y agoIt serves as a better example of why it’s important to learn what FOSS means and implies before using those licenses. It doesn’t mean “everyone does our work for free and then we keep the profit”.
- Pannoniae 3y agoIt also shouldn't mean "everyone leeches off our software for free, they get the profit while we get the maintenance burden"
- kstrauser 3y agoExcept you can't say they're "leeching" when they're using the software on the terms you offered it to them. I'd also love to know how much Hashicorp chips in to maintain the projects they build upon. For example, I'd bet the vast majority of Terraform usage is on Linux. Do they support Linux development? Do they support Go language development? It seems like the companies complaining about "leeches" (eyeroll) aren't the ones actually paying people to work on upstream FOSS projects.
- Pannoniae 3y agoThe major difference here is that they are not making a directly competing product to Go, Linux, etc. I find the word "leeching" appropriate because here, it's not simply someone building on Terraform to sell something else, they are selling a direct competitor to hashicorp's products.
- dralley 3y agoIn another era "building on X to sell something else" would be still considered "embrace, extend, extinguish" (in the actual, originally intended sense), depending on the market power of the players involved. At least if the "something else" isn't free software.
- galenmarchetti 3y agoI get what you're saying, but on a strictly legal standpoint, everything Hashicorp is doing is by the books...all previous versions of Terraform will remain under the old license and everyone can still use Terraform without fearing a future lawsuit, as long as they stick to those version. So no one made any legal missteps here, neither the users nor Hashicorp. I think its the ethical side, rather than the legal side, thats more complicated...the contributions from the community contributed to the Terraform "brand" that got bigger and bigger, and now Terraform is attempting to secure their monopoly on capitalization of the brand when previously there was an implicit understanding that the "brand" was open-source. However, you might also argue that there was an implicit understanding on Hashicorps side that the community wouldn't build directly competitive projects when they held the lions share of the funding on the contribution/maintenance side... I think the whole thing is pretty complicated - is Hashicorp leeching off of the contributors or are the competitive contributors leeching off of Hashicorp? Honestly I see both sides. The beautiful thing is that its totally legal and acceptable for OpenTF to do their own thing and continue Terraform under their own terms...so either way we get to see this play out :)
- JimDabell 3y agoThe whole point of permissive licenses is to permit this kind of thing. It sounds like you think every company out there choosing permissive licenses doesn’t actually want to be permissive. Has it not occurred to you that people choosing permissive licenses usually want to be permissive?
- paxys 3y agoThat's a good thing. Either launch a closed proprietary product from the get go or commit to maintaining a real open source project. You can't have all the monetary advantages of the first while enjoying the goodwill and community support of the second.
- sanderjd 3y agoThis attitude will just lead to pretty much every product being closed and proprietary. Which sucks for me, because I like to be able to read the source and run modified versions of tools I use, and have no interest in creating competitive derivations of them. So I think it's a shame that people who try to make software like that get pilloried for being neither proprietary enough (which is apparently fine...) nor open enough.
- managingahhs 3y agoI assume that by reasonable you mean not one that will bait and switch their userbase. I'm all for proprietary companies not pretending to be opensource companies and actually using proprietary licenses.