6 ms·
OPA maintainers and Styra employees hired by Apple
- slt2021 1y agoGreat job Styra team, great job Apple! OPA is a great project and I am glad they are looking to open-source the Enterprise OPA offerings
- jb1991 1y agoThis is an extremely smart acquisition by Apple, very nice to see.
- ramoz 1y agoCan you explain why
- rossjudson 1y agoAt scale, the larger companies end up needing to be able to make policy decisions (read: authn/authz, most of the time) across a large number of "policies" in an efficient way. Everybody starts with simple representations that can go fast but have limited expression, then moves to various forms of extensions/templating/substitution/rules/etc. OPA and Rego use a datalog variant to bring order to that bespoke mess. Think IAM policy, but you DRY because it's a real programming language with a library full of nice-to-have built-ins. OPA and Rego can basically "become" other types of access control systems (see https://www.openpolicyagent.org/docs/comparison-to-other-systems https://www.openpolicyagent.org/docs/comparison-to-other-sys...).
- ramoz 1y agoThanks. I’m very familiar with opa. My only assumption for this was that Apple’s infrastructure needs have evolved to the point where they need quite a focused effort around policy. Styra either acquired or became available through a different form of change management. And Apple was already a major customer. Just blind guesses. I was hoping for more insight.
- Temporary_31337 1y ago1. Any idea on what should I start next so that I can get acquihired? 2. It looks like Apple didn't get much 'ownership' of OPA in this case, what was the point of purchasing the company as a whole versus simply offering these 3 employees generous sign-on bonuses? 3. Why is it that companies generally tend to pay a lot more per employee in an acquihire scenario?
- xp84 1y ago3. (From zero authority here as I’ve never bought a company:) Perhaps the acquired employees might prefer this for tax reasons. If they stand to profit mainly via capital gains, that is wildly better than receiving ordinary income, like a bonus, would be. Or, a completely different, unverifiable possibility: An acquisition does not set any precedent for compensation of any kind. As a general rule corporations hate paying humans, but don’t mind paying other corporations.
- ergsef 1y ago3. It's very hard to know what kind of compensation employees are actually getting in an acqui-hire. I've been involved in a few of these - money flows through the cap table, so investors and founders get most of it depending on liquidation preference. Retained employees get a typical, levelled offer + some cash/stock (probably more stock) incentive with the usual 1 year cliff and 3-4 year earn-out. Incentives are also usually contingent on specific business goals. In other words, the scenarios I've seen if the acquired company is not doing well the acquirer pays off the investors and gives the employees a small bonus contingent on staying for 1+ years and hitting goals. It's not necessarily a crazy windfall.
- johnnyanmac 1y ago1. probably something with AI in it. You got maybe 2-3 years before the bubble pops. 2. branding. cultural awareness can take years or more, and I'm sure coporate knows by now that their brands aren't the best thing to slap onto every scenario. Disney is well learned in this kind of conduct. 3. Because the last thing you want in an aquihire is for all the talent your poaching to jump ship. Some employees may have even worked there previously and used a company to get away from that corporate culture. So a lot of an aquihire's money tends to go towards golden handcuffs.
- abtinf 1y agoBased on Apple's acquisition of FoundationDB, this seems like it will have negative consequences for public development of OPA. What are the counterexamples, where Apple acquiring a project results in it being more open with sustained development?
- starttoaster 1y agoCUPS?
- diggan 1y agoWas FoundationDB a CNCF project at the time of acquisition, or in some similar incubator/umbrella? Besides, seems FoundationDB was open sourced after Apple acquired it, wouldn't mean FoundationDB get more open after the acquisition? Although development stalled no matter what so maybe doesn't matter.
- halestock 1y agoIt was independent (I think it predates the CNCF actually), but was acquired by Apple in 2015 and disappeared until it was open sourced in 2018.
- limagnolia 1y agoRight, FoundationDB wasn't even open source when Apple acquired them. The FoundationDB story is a prime example of why it is important to use open source technologies for foundational infrastructure.
- aseipp 1y agoFoundationDB development has not stalled; v8 is still on the way. If anything, it's mostly just been stable for a while now, and it has now been developed as open source longer than it existed as closed source.
- convolvatron 1y agoapple reopened foundationdb in 2018
- md3911027514 1y agoIsn't Styra like a company of like 50-100 people? Seems like it'd be a bummer to be an employee at the company that gets left behind.
- eastbound 1y agoIn most acquisitions, the buyer interviews employees and only takes part of them - or only offers bonuses to part of them.
- abuani 1y agoA counter example would be Weaveworks(folks behind Flux/FluxCD and many other widely used oss tools). I'm sure the ex employees would've preferred to get acquihired vs closing up for good. I highly doubt Styra was pulling in enough money to fund their business, and the days of zirp are long gone, so I doubt they would've been able to raise another round to keep the lights on for another few years.
- sublimino 1y agoControlPlane was able to hire (not acqui-) a few of the FluxCD maintainers and other WeaveWorks staff to continue supporting the project — we did what we could, agree this is better for Styra folk than the uncertainty of closing up shop.
- biggestdummy 1y agoThe shop (Styra) did get closed. A few of the most senior maintainers were hired by Apple. Many - including anyone not directly involved in engineering of the OSS product - are now looking for jobs. Capitalism is ruthless.
- MBCook 1y agoThis is a very well written announcement. It immediately defines OPA (for people like me who don’t immediately recognize it). It says what’s not changing for people, and says where things will go. Congratulations to the team.
- ambentzen 1y agoI was left with the somewhat opposite feeling. I still don’t know what OPA actually is or does. It has a nice paragraph describing it without saying anything at all.
- timsneath 1y agoOPA solves the problem of defining and enforcing policies across a system. Some examples: - How do I enforce that inbound API requests come only from trusted sources? - How do I enforce fine-grained access to user records? - How do I enforce a set of naming conventions for a data update? Many such policies may come from regulatory requirements, may be regional in nature, and may change in otherwise stable codebases. And it's even harder when you're applying this to a highly-scalable production internet service. As a result, defining policy at an organizational level with auditing is a challenge for large enterprises. OPA helps enterprises administer and enforce policies. More details on what OPA does here: https://www.openpolicyagent.org/docs/philosophy https://www.openpolicyagent.org/docs/philosophy And you can see some examples of Rego (the policy language) here: https://play.openpolicyagent.org https://play.openpolicyagent.org
- robertlagrant 1y agoThat's still not saying what it is, though. Is it a thing you put in front of your backend to allow/deny requests? Is it an endpoint something like nginx calls with an auth token and the http verb and url that responds with 200/403 that nginx can react to? Is it a library you embed in your application? Is it an agentic AI? It's as though you're describing a car to someone who's never seen a car before by listing all the places you can go in a car.
- biggestdummy 1y agoFrom the post, I'm pretty sure Apple didn't buy Styra. Sounds like Apple hired the maintainers who worked at Styra (including Tim, Teemu and Torin). I'm guessing that Styra is just shutting down.
- bitweis 1y agoWith Both Aserto and Styra gone - there aren't any commerical/enterprise options to get capabilities and support around OPA. Has anyone seen more options?
- ericand 1y agoPermit.io
- gneray 1y agothey don't actually "support" OPA. more like they run/depend on OPA
- gemanor 1y agoGabriel from Permit.io here Actually, Permit does support OPA. In fact, about 15% of our large customers came from StyraDAS and use Permit as their enterprise OPA solution. On top of that, we offer OPAL+, which is already adopted by Fortune 100 companies as a production-grade OPA framework.
- biggestdummy 1y agoNot OPA-based , but Kyverno-based. Kyverno is also CNCF, basically an overlap of OPA functionality (with some give and take.) Nirmata provides commercial/enterprise options around Kyverno.
- meghan 1y agoHere are a few OPA alternatives: https://www.osohq.com/learn/open-policy-agent-authorization-alternatives https://www.osohq.com/learn/open-policy-agent-authorization-...
- davidbrossard 1y ago[dead]
- gneray 1y agoProps to this team for giving it their all
- meghan 1y agoSeems similar to Apple's 2015 acquisition of FoundationDB -- they sunset the commercial offering. But it's unclear if they acquired Styra or just hired the team? I'm maintaining an article about this news (as well as commercial alternatives to OPA) on the Oso blog: https://www.osohq.com/post/opa-maintainers-join-apple-oss-community-to-maintain-styra-products https://www.osohq.com/post/opa-maintainers-join-apple-oss-co... Disclaimer is that I work with Oso :-) but hope it will be helpful regardless.
- jen20 1y agoThis is a more defensible take than some on here, but still a wild comparison. FDB was closed source software that existing customers kept source access to the entire time it was closed, and then opened under a permissive license soon after. So yes, you couldn’t buy it, but if you had, you kept access to new development.
- alexolivier 1y agoCongrats to the team and Apple! It's great to see authorization getting more attention in the mainstream developer conversation. For folks exploring policy-based authorization solutions, we've written up a detailed comparison between Cerbos and OPA that might be helpful: https://www.cerbos.dev/blog/cerbos-vs-opa https://www.cerbos.dev/blog/cerbos-vs-opa The key differences tend to be around developer experience, policy language complexity, and deployment patterns. Both are solid open source options depending on your specific needs. (Disclosure: I'm a cofounder of Cerbos)