3 ms·
Just to give a bit of context as to how/where/why that comes from (-apologies for the wall of text. Don't want to skip over anything important in the pursuit of
by rijkvanzanten 2y ago
Just to give a bit of context as to how/where/why that comes from (-apologies for the wall of text. Don't want to skip over anything important in the pursuit of brevity :) ):
Our current license — BSL-1.1 as created by the team at MariaDB) — is as close as we have gotten to being as open source as possible without having the project disappear into thin air.
For the first few years, we were trying to make it work as GPL-3 (eg a "normal" OSS license), but there were simply not enough contributions (time or money) to make that sustainable. We went the donation-ware route first. Make it free and open source to everybody, but entice people to give back in either time (PRs) or money (so we can find a dev to do the same work).
We noticed two things almost right away: Most folks will default to not donating at all, cause why would you pay for something you can get for free, and secondly the people who _did_ contribute where predominantly individuals or small businesses. Generally speaking the more value a group was getting out of the project, the less they were helping to maintain it. At the height of our donation-requesting campaigns (in mid-late 2022, ~15k GH stars) we received about $1k monthly from sponsorships. It took about 4 full time folks at minimum to maintain the project. That obviously wasn't sustainable.
Our next approach was to go with a paid-hosting model. Keep the software itself free, but charge for hosting services around it. This works relatively well, but comes with a catch: you have to make self-hosting as inconvenient as possible, or make a "premium SaaS only" version to differentiate with the free offering. Both of those things are antithetical to what I'd like to see in a project. To me, an open source product shouldn't just be a marketing vessel to get people into a proprietary SaaS (opinion!).
That left us with a choice. Are we going to either A) make it a closed-source SaaS exclusively, B) make it a freemium-style open core, or C) find some other approach. We went with the latter. With an delayed-open-source-license w/ a usage grant that allows all the community members that historically contributed to use it for free, we found a balance between keeping it as open source as possible, while making sure large companies that make a lot of money using it are required to contribute back.
Many bigger open source projects — effectively anything that takes more than ~10h a week to maintain — will run into the open source funding problem. Some projects make it work by being a low-level building block of a bigger paid thing that makes the investment back (think react/facebook and now react/next/vercel), some projects do the hosted route but make/keep self-hosting difficult/expensive (think Discourse), some projects make core features paid so it's more of a freemium model (think Payload), and some projects (like Directus) try a more novel approach to solving the funding problem by finding a way to charge the folks that have the resources and don't otherwise contribute.
There's a lot of movement in the post-open-source world. Companies like N8N are exploring ways to adhere to the open source ideology, but have commercial restrictions in place (https://faircode.io/ https://faircode.io/), Sentry is making great strides in a similar direction with Fair Source (https://fair.io https://fair.io), and other large projects like CockroachDB are adopting similar licensing strategies. While these and our own approaches conflict with rules 5/6 of the open source definition, I strongly feel like this delayed-open strategy w/ a clear funding model is the closest we've gotten to sustainable open source yet. It's definitely not perfect yet, but it's getting somewhere.
No matter what, any body of work that takes a meaningful amount of time eventually needs to generate enough money to be able to keep investing the time. I remain hopeful we as an industry can find a way to keep the good of open source, while removing the burden on the random person in Nebraska.
- lol768 2y agoAppreciate you engaging with people here. I think the key difference between Directus and Sentry is that the restrictions Sentry put in place are directed at folks who want to build and sell their own error reporting service to software companies (and obviously commercially exploit the work they have done). In the same way that Redis went down the route of SSPL with the aim of impacting cloud services with their own Memorystore product that just resold Redis. That meant that most users were unaffected and your 10-person company using Redis as a cache to power their website could continue to do so. We continue to self-host Sentry and we're incredibly grateful that that's something we do have the option to do. I don't have much of an issue with companies taking that approach. I actually genuinely wouldn't have an issue with an AGPL Directus, or SSPL (and releasing all of the plugins we developed internally). But that's not where Directus ended up and so we'll eventually either move to something written internally or an alternative that actually is FOSS. > With an delayed-open-source-license w/ a usage grant that allows all the community members that historically contributed to use it for free, we found a balance between keeping it as open source as possible, while making sure large companies that make a lot of money using it are required to contribute back. I do want to reiterate that a specific "total revenue"/"total funding" figure != "making a lot of money" and I don't think your license captures this nuance at all, today.
- rijkvanzanten 2y agoTotally! I'm also not saying — at least didn't intent to — that we're doing the exact same approach as Sentry here :) I meant that as "Directus is like Sentry in the sense that it moved away from FOSS as it ran into the OSI rules around no-license-discrimination-against-groups-or-use-case. Part of the trickiness for Directus specifically is that it's intended to be self-hosted first software. Going all-in on the SaaS as the moneymaker means divesting in self-hosted and focussing on differentiators for the SaaS offering to make up for the loss in funding of folks who self-host. > I do want to reiterate that a specific "total revenue"/"total funding" figure != "making a lot of money" and I don't think your license captures this nuance at all, today. Agreed! It's been the best I've been able to come up with, but it isn't perfect. Out of curiosity (not snark), what metrics would you have used as a more generic measurement of (large) company?