AWS Mesh Generally Available
aws.amazon.com
aws.amazon.com
Yet another Amazon product based on open source software, while still contributing almost nothing to this space.
Permissions: Commercial use, Modification, Distribution, Patent use, Private use
Envoy is indeed open source and freely-available for corporations to use. That is not what I was implying.
Amazon, out of all the big companies (Google, Netflix, Microsoft etc.), is the one with the least contribution to the open source world, despite using many of open source tools to build their AWS products.
This has become a bit of an interesting topic to me because it keeps being brought up by people who sort of just state it as fact without providing any real argument. How much is enough? One full time developer? Ten? What if the project doesn't want to merge their contributions? Amazon just got killed on HN for open sourcing all of their ElasticSearch work in a separate repository.
I feel like they can't win on open source with some of you guys.
On these figures, Amazon is behind other giants and has fewer contributions that a number of midsize tech companies like Red Hat or Pivotal (my employer).
And are github repos and stars the only way to measure open source contribution? The Xen project only has 162 stars, yet I don't think anyone would say it isn't an important project, and it's one Amazon has contributed to - if you're using a PV guest on Xen that's protected against Meltdown, chances are high you're using the Vixen mitigation that Amazon released.
Could Amazon do more? Probably. I'm not trying to say they're perfect. But this idea that they don't contribute back to open source seems pretty flawed, even by the data in your link, which seems incomplete.
But unless Amazon are hiding several hundred contributors and thousands of commits in a repo that's been magically overlooked for years, the figures tend to make them look bad.
For some reason Amazon just doesn’t want to show they had any involvement with that commit and doesn’t care about how it’s seen. From the times I’ve seen it, seems like this might by by design
You're free to set your project's license to whatever you want but why complain when it's used the way you said it can be?
Corporations exist for the benefit of the society that grants them their charter and that charter can--and should--be revoked when the corporation acts against the best interests of that society. We do have that power, but we've forgotten about it.
That's weird ... what do you expect from, say, hammers and blenders ?
I expect people to do nice things and be kind and think of my interests. Simple tools, on the other hand (like screwdrivers and shovels and LLCs and Corporations and family trusts) should just do exactly what they are designed to do - and nothing more.
So it's possible that well-funded consumer/producers like Amazon may at times crush, overtake, or otherwise discourage some of the unpaid labor that they benefit from.
(Not trying to make a moral argument. Personally I'm a bit conflicted on consuming and producing FOSS.)
I don’t see why it is different from asking a small one-man shop to take care of my infrastructure for me?
It's a start. Looking forward to more contributions from the team.
Traefik is not a service mesh, it's a webserver and reverse-proxy and similar to Nginx and HAProxy, although all of them have been trying to get into this space along with Kong and others.
In the other direction there's also Heptio Contour and Datawire Ambassador that use Envoy as a reverse-proxy.
If you're doing any kind of communication between components then that has to be facilitated somehow, and production requirements like security, retries, load-balancing, observability, etc have to live somewhere. A mesh just extracts it all into a single external system.
They're both control planes for envoy proxy. App Mesh is a managed proprietary solution, Istio is open source and self-hosted but there are managed options available. Istio explicitly supports k8s and consul; app mesh doesn't care where the envoy proxies run (great for migrating).
I _think_ Istio is a full knowledge model where everyone knows about everyone else in the mesh, App Mesh is explicit. The configuration pushed to the proxies only have the targets that have been modeled as such in the app mesh model (great for larger organizations).
App Mesh roadmap: https://github.com/aws/aws-app-mesh-roadmap
Traditional licenses forced you to contribute back if you used community's code. SaaS changed everything: you can now "leech" software without giving back.
We need a new model. We need to force contribution, because software corporations won't give back otherwise. I've worked for big corps and the bureaucracy will not allow it, even if developers wish to. If we don't force legal departments to comply we will lose the whole culture of freedom we've built in the past 40 years.
Forcing contribution would actually remove freedom.
I’m interested in your proposed mechanism for that!
EDIT: fixed typo
This is untrue; plenty of permissively-licensed projects are supported by code contributions and dedicated paid support by software companies who use their code. You don't need copyleft, much less something new beyond copyleft, to get that.
What Redis and others want gratis-but-proprietary licensing for is to prevent cloud services companies from competing with their SaaS offerings, not to force anyone to “give back”.
I wonder if moving to something like this would allow us to eliminate the global network and let VPCs run in an isolated context save for services published via mesh.
"You can create your own application in your VPC and configure it as an AWS PrivateLink-powered service (referred to as an endpoint service). Other AWS principals can create a connection from their VPC to your endpoint service using an interface VPC endpoint. You are the service provider, and the AWS principals that create connections to your service are service consumers."
https://docs.aws.amazon.com/vpc/latest/userguide/endpoint-se...
Let's say I have a bunch of services calling each other. Which I already do... Why should I add this?
i.e. using open source under the published license? Look, I'd prefer that everyone using open software supports it with public patches, but if it's not under A/GPL or something, then clearly the authors weren't so worried about it. If you don't like others using your work without publishing their changes, use A/GPL. If you don't like others using your work without paying you, go with shared source (and accept that you're writing proprietary software) or use a noncommercial license or something. But don't publish something and then complain that people used it under the exact terms that you published it!
Always space for one more I guess!