OpenTerraform – an MPL fork of Terraform after HashiCorp's license change
github.com
github.com
The GPL has a specific exception for GCC that prevents it from polluting the licensing conditions of compiled programs.
Seems to stand for "Terraform Automation and COlaboration Software"
Yeah so basically TACOS are ci-like tools / control planes for Terraform. The OG one being Terraform Cloud.
The term TACOS was coined by Piotr Zaniewski here: https://itnext.io/spice-up-your-infrastructure-as-code-with-...
(December 2020)
The TF bridge is interacting. If they really want to remove liability they'd just leave TF out of the repo and shift all liability to the end user where the first step runs a package install that brings in terraform.
Has an attorney who practices in this area reviewed this sentence in their capacity as an attorney (e.g. to a client of theirs, and not as free legal advice on Twitter et. al.)?
Personally, speaking figuratively, I think they just pulled a shotgun and decided to shoot both of their feet off. As someone doing devops consultancy since well before terraform became a thing I'd have no problem at all going back to custom python code with configuration in yaml if the clients decide its better for them.
So, if you were AWS, you can't create "Elastic Terraform Service" using the TF source code as the base of your product.
It looks like it boils down to being no longer able to "incorporate the source code or embed or distribute newer versions of Terraform." (From Spacelift's blog). For a piece of software that doesn't even have a server, this seems extremely restrictive. I wouldn't be surprised if Hashicorp takes a few steps back on this / provides clarifications for specific use cases
Or for that matter, custom Python code with Pulumi - which AFAICT ain't pulling these sorts of shenanigans (yet).
Plenty of companies (including my employer) have been building fully monetized software using Consul and Vault under the hood and not paying them a dime. We're a company that's valued/market capped in the Billions btw and I know plenty of other large software companies doing the same thing.
Why? If software authors don't understand that releasing their code under an open source license means someone else other than them may potentially benefit from it, that's really on them.
Predatory unethical open source freeloaders don’t.
Amazon has never offered a database service based on the MongoDB server software. Not when it was AGPLv3 nor when it was SSPLv1.
It implemented a wire protocol for interoperability purposes, similar to functionality in IBM DB2, Azure CosmosDB, FerretDB, and other databases.
If you're using Terraform to manage deployments in test and development it's still business as usual, but if you're actively using them in production or making a company that sells a wrapper around Terraform then you'd have to pay Hashicorp.
Honestly it's pretty fair. I can continue to make my own personal, test, or development apps using vault, consul, and terraform.
And this move was done because plenty of large companies (not naming names because this is starting to touch a legal gray area) are using Vault and Consul in production to generate hundreds of millions to billions a year in revenue.
> All non-production uses are permitted. All production uses are allowed other than hosting or embedding the software in an offering competitive with HashiCorp products or services.
Competition is healthy. Everyone should be reluctant to lock himself in with a vendor seeking a monopoly.
The idea that every credit card transaction or any form of dollar based transaction works on software directly built on Consul is patently false.
Open Source software quickly becomes a tragedy of the commons because most organizations are unscrupulous. Look at how AWS destroyed the entire Elastic, MongoDB, PostgreSQL, Kafka, etc ecosystems by abusing overly permissive licenses.
The problem lies with OSS, not with people using it.
Oh you mean the unwritten, unenforceable, undefined, romanticized spirit of the license?
It's a major reason why I'd never release a core revenue generating feature of mine under a permissive Open Source License.
Unsrupulous implies some form of an ethical code, whereby you are judged by intent, not by action - which is an idealized view of the world but an unrealistic one at that.
On the matter, Grafana has relicensed most of its software to AGPLv3 (eg: https://github.com/grafana/grafana/blob/main/LICENSE)
There is a huuuuge difference between OP and your examples.
Err, I think you need better examples, as the PostgreSQL ecosystem is doing just fine, and RDS doesn't threaten anyone's IPO price. Since Kafka is not only Apache licensed but is an Apache project, I gravely doubt that the Apache Foundation is going to IPO anytime soon either
If you want to pick on two other ecosystem casualties by the Big Bad AWS Gonna Steal Our Shit fearmongering, use Sentry and Sourcegraph as examples of "we want the community until we don't" rug pulls
Following your example, Alphabet should open source all the weights they use in their current search algorithm as well as the algorithm itself.
And extending that principle, they should also open source the machine translation model and weights Robert DeNero made for them when at Google Translate.
Both of these are dumb hypotheticals but serve to point out the fact that there are loss leaders and revenue generators at each company.
Hashicorp doesn't generate revenue from Terraform.
(They do generate revenue from Terraform Cloud, but that's a backend for Terraform, not Terraform itself)
I guess it is up to Google to decide how to monetize Go, or who knows, maybe some day they will put it into a foundation of sorts that should find a way to keep sponsoring its development.
The only advantage was static binaries, which not many other languages in a usable state supported at the time. It’s not even like there was an ecosystem at the time - HC had to maintain an AWS client for Go for several years, and similarly for Azure.
Side note: I’m not defending the license change and generally think most of HashiCorp’s products are not that great.
Plenty of companies are using Vault and Consul in this manner.
Review the FAQ here: https://www.hashicorp.com/license-faq
The problem is that "competing offering" is poorly defined.
if so, that's similar to proprietary programming languages. Not a thing. The community can just agree on a similar but open alternative and the original company is left behind. That's why all languages and frameworks are open-source with permissive licenses.
and if not, if it's just about the hosted / managed parts - then what exactly is it that I can use wrongly? Terraform Cloud / Enterprise was never open source. There's nothing I can self-host and charge users for...
I think they want to make it difficult for SaaS products that embed terraform (or an altered version of terraform I would assume where they have built APIs) in their product. That said, customers can install terraform so you can still hypothetically have an "integration" with Terraform where you call the raw binary (like Atlantis). So basically, they want terraform cloud to have a "privileged" user experience is my guess.
Clearly Terraform was also in mind, since Terraform is now under the BUSL: https://github.com/hashicorp/terraform/blob/main/LICENSE
I still think that the best way to compete is by having a more appealing product, thought, rather than changing licence. And I mean this for Hashicorp, Elastic, etc.
If you need to do this move is because you don't really succeed at having a better product, else you would just benefit from FOSS rather than it being a liability.
https://github.com/diggerhq/digger
Anyways, fully agree that if you have a great product, you don't need to make such moves. We designed our product the way we did purely out of technical considerations - it didn't seem to make any sense to duplicate the CI stack. But it looks like this whole idea behind Terraform Cloud of having an "infra-specific CI" was driven exclusively by commercial interest. You can charge per minute! You can charge even more per resource! Now it's catching up with Hashi; so they have to make such defensive moves. If the product made sense technically, if it was designed the way someone would design it with no commercial considerations whatsoever, they wouldn't have to make such moves.
> Funny enough, our own product (Digger, an open-source CI runner for Terraform) is not using Terraform (or any other Hashicorp's code) under the hood.
Oh yes you are:
https://github.com/diggerhq/digger/blob/develop/pkg/core/ter...
You're on thin ice if you want to argue whether forking a terraform process constitutes "hosting" or "embedding" terraform.
This will shake the sandbox. I personally hope that the community will step up with a fork.
I've spent a fair amount of time digging around the terraform codebase and hacking on providers. I'm not too worried about the license change tbh, almost all the important IP is locked up in the provider codebases and no matter what direction hashicorp goes those providers will remain open.
The question will be, how are those providers executed? Most likely an open terraform fork will fill that role for the foreseeable future. But long-term I think hashicorp just handed IaC to crossplane and pulumi.
I think ACK from AWS and k8s-config-connector from GCP probably represent the future of IaC. Crossplane is neat and all and pioneered the architecture but using the cloud provider native operators directly will always be a better experience. The question will be what the next generation of TACOS frontend tools look like.
Rewriting a provider into a kubernetes reconciler isn't an impossible undertaking and the tools for doing so are improving at a rapid rate. I recently finished up on a major project writing a kubernetes controller for a private cloud platform.
They're burning $50M loss last quarter which is mind blowing considering they had a monopoly originally. Michael raised too much money and let everything go to his head and his leadership. The internal chatter I hear is pure technical folks know this is a terrible choice, but "leadership" is so pressured and desperate given the economic headwinds they're trying to cut out any competitors building on top of their success. They refuse to believe their paid offers are just not good enough.
Hashicorp had lost nearly all it's value in the space.
Terraform, terra..what? Pulumi is starting to gain momentum as the long term winner in the space.
Nomad, K8s is mostly destroyed their future outside of some very specific cases around smaller deployments and frequent disconnects with the control plane.
Vagrant, docker RIP.
Consul, coredns and the main reason to use it for service discovery is gone with any of the cloud providers versions like ECS or K8s.
Vault, Pulumi chipping away at the main reason why people buy it which is dealing with TFs lack of encrypting each value in the state file. There are still spots where Vault wins (but open source is all that is needed) such as issuing out temp credentials off of a "root credential".
Packer, lack of overall community adoption even though in automation with hardware it is incredibly needed. Piss poor documentation and experience when getting started with it.
Rest of the services I've never looked at because there hasn't been a gap with a lack of a winner already. License change just means company is dead in my future choices anyways.
This is the most important sentence, as I see it.
The size of a usable nomad cluster can absolutely dwarf the (pathetic) scaling capabilities of Kubernetes, largely thanks to the poor etcd API which simply cannot be fixed.
Their finances are pretty insane. In 2023 on sales of $475M their operating loss was $297M. And everything is going the wrong direction. They had $163M increase in operational expenses and increased revenue by only $155M. The last quarter they didn't increase revenue at all.
I don't see how the stock is worth $5.6B and any more than the $1.2B current liquidation value of the cash that they've got. How did they manage to go public at all?
Spacelift and Env0 need architecture licenses. People on TF cloud essentially are licensing their IP cores. Their terraform cloud service is being run very poorly. When outsiders moved to provide an alternative for this thing which is broken inside of Hashicorp, the lawyers have been sic'd on them! That is not adult behavior. It shows a great naivety in business affairs ...
Can the patch / new code be copied to this version without violating anything or does it have to be some sort of “clean room” patch where you only read the bug report and not the actual fix
That's why they are saying it's not an "open source" license anymore – because it's not. Source available means just that. You can read it (say for the purpose of figuring out some annoying bug so you can contribute the fix upstream) and you can probably build and run it, so long as your use is according to the terms granted in the license. But you can't redistribute it, any copy you take probably isn't yours, and it's only usable according to the terms of the license.
Perhaps 'derivative works' isn't the right term. I know there's some exceptions for copyright when there's 'one way' to do something, or something that substantially is not a creative work, such as a function that adds two numbers.
There being one right way to solve a problem, doesn't really change whether a bit is copied or not. If you have a bug and there's one right way to solve the issue, then you don't need to copy the original. You can reproduce the bug and solve the issue, and any similarity between the independent solutions is coincidental.
If you take the source code and accept the new license terms, I think you'll be bound by the terms. I am not a lawyer and I haven't read the full text of the BUSL-1.1 but I will now, since that's probably the best way to understand what the license does or does not do.
https://www.reddit.com/r/Terraform/comments/15p2p32/impact_o...
For instance, I have one stack that sets up a bunch of Hetzner Cloud vm instances and creates an RKE cluster on top of 'em, and another stack that uses the k8s provider and creates k8s resources based on the cloud instances, like a MetalLB load balancer.
It would be ideal if it was built in to the language.
Not a single vendor should own it all or even the majority.
Having this delay makes me now more concerned that they're going to "catch" more of the MPL ones and relicense them, too
Yes we are competing in the same market; customers using Spacelift probably wont be using Digger and vice versa. But we feel like having a community-friendly fork would benefit everyone, without harming anyone.
Clearly, based on my downvotes, I'm mistaken and should be ashamed.
[1]: https://www.pulumi.com/docs/using-pulumi/adopting-pulumi/mig...
Downvotes are nothing more than an indicator of how many people clicked the downvote button.
That was several years ago, though; might be stale.
There is an unfortunate meme that this makes it a “Terraform wrapper” like CDK for TF, which it does not.
I'll probably use this for my personal projects instead of Hashi's official stuff.
I don't think that OpenTerraform will be able to pull the Terraform code and relicense it under the MPL.
Either this fork lives on and becomes its own thing (better or worse than the original terraform? only time will tell!) or it dies very quickly.