That is why OpenTF is on its way to CNCF. To ensure it stays OSS forever.
There is a difference between "true OSS" like K8s, OPA, etc and "temporary OSS" (backed by a company) like what Terraform used to be, Pulumi, GitLab ,etc. Those can be changed in the future.
When developers chose OSS, they should consider if it is a CNCF OSS or a vendor backed OSS. What Hashi did is an important example.
(disclaimer - env0 founder here, co-lead the OpenTF initiative)
https://www.pulumi.com/blog/pulumi-hearts-opensource/
Disclaimer: the following is my own opinion as an engineer at Pulumi.
Pulumi is true open source, with a relationship similar to git and the many SaaS services that layer on top of git to provide meaningful value.
To contrast with our competitor, Pulumi relies on open source languages and protocols. We could not, even if we wanted to, change the Python license. Nor could we change our protocols without breaking our users and our growing ecosystem.
That's the value of building on open protocols and standard languages.
But our philosophy at OpenTF is that users would rather participate in an open ecosystem where multiple vendors compete for their business. If you're not happy with one vendor, you can easily switch to another; competition works to make all vendors better.
When we look back at this comment a year from now, I'll wonder how your company will feel about the responsiveness and new features they're getting from Terraform Cloud when the primary incentive to stay is not because you think it's the best product available, but because switching costs are so painful.
Eventually they saw the writing on the wall and moved to Linux systems and replaced all of the hardware, and have an enterprise RHEL subscription that we could call when needed.
I think the story is going to be the same with the current company, mainly "who can we blame if there is a security incident, or get me a Hashicorp person on the phone if we have some kind of Terraform related production issue." Having this in place seems to matter more than everything else honestly.
I would like to see more companies that leverage open-source contribute back to the very community that enables their value creation.
I have come around to the idea that it's good to firmly discourage this kind of late-in-the-game license change.
But I also think that, on net, this episode will lead to fewer businesses choosing the open source model for their software, from the start. It just seems like playing business on hard mode to try to build an open source or source available product, when you can just build a SaaS and charge for it. I think this is really bad (I have a strong preference to not be stuck with opaque SaaSes for most things), and I'm not sure what incentive there is to try to find new business models, when you risk becoming public enemy number one amongst a big chunk of your potential customer base.
Well that's the core problem - what is the product here. Terraform Cloud and Terraform Enterprise are products for sure. They're not open source, though. Is Terraform a product? Well, it doesn't do anything on its own, it requires plugins ("providers") for anything it does. Plugins are developed by or at least with third parties. It's a gatekeeper of an ecosystem that at this point is a common good.
Whether the ecosystem would exist without the permissive license and external contributions - really hard to say. But if your main play is to foster the growth of an ecosystem and then turn it into a product exclusive to your business, then I guess you should look for alternatives.
(Marcin from OpenTF, private opinion)
While I guess that for many vendors they don't care whether it's open or not. For instance AWS. I doubt they truly care about it being open or not.
Even Terraform core remains source available and so 'community' users can still take a look at the source code and identify/report/fix errors.
I was just responding to a comment on how AWS didn't care if the provider was open. IMO there's value for them in it being open.
One would think that the companies thought this through before publishing FOSS code, but seemingly there is a lot that didn't do that.
But unfortunately I think the lesson they will take from this instead is "we should just build a SaaS with no source availability because that's way easier and source-available just makes people mad anyway".
I think that's a shame.
I think that's the general attitude the software companies will have going in the future. Why even bother dealing with negative PR and push back against their ability to make money by going with FOSS? In hindsight, TF should have been released with BSL from the beginning.
I am not a huge fan of Hashicorp changing its licenses for future releases but I am also skeptical of OpenTF's motives since their members have big financial stake in that decision.
Acknowledged, there are always self-serving motives involved. Generally things don't happen without a reason. But we donated the project to a foundation, and will over time build (and fund) a dedicated independent team who will follow their own vision and the community needs, not ours. So please judge us by our actions, not assumed motives.
> their members have big financial stake in that decision
I can't speak on behalf of others but to us at Spacelift it's less about direct financials (we are actually not directly affected by the license change!) and more about being in charge of our own destiny and product roadmap.
It doesn’t mean “everyone does our work for free and then we keep the profit”.
I'd also love to know how much Hashicorp chips in to maintain the projects they build upon. For example, I'd bet the vast majority of Terraform usage is on Linux. Do they support Linux development? Do they support Go language development? It seems like the companies complaining about "leeches" (eyeroll) aren't the ones actually paying people to work on upstream FOSS projects.
At least if the "something else" isn't free software.
I think its the ethical side, rather than the legal side, thats more complicated...the contributions from the community contributed to the Terraform "brand" that got bigger and bigger, and now Terraform is attempting to secure their monopoly on capitalization of the brand when previously there was an implicit understanding that the "brand" was open-source.
However, you might also argue that there was an implicit understanding on Hashicorps side that the community wouldn't build directly competitive projects when they held the lions share of the funding on the contribution/maintenance side...
I think the whole thing is pretty complicated - is Hashicorp leeching off of the contributors or are the competitive contributors leeching off of Hashicorp? Honestly I see both sides.
The beautiful thing is that its totally legal and acceptable for OpenTF to do their own thing and continue Terraform under their own terms...so either way we get to see this play out :)
I'm coming down strongly on the side of the users, though. Hashicorp chose the original license, and the one they picked is perfectly fine with the idea of someone else building off it. I mean, it was written by the Mozilla folks. They want people to build off their projects and make a nicer Internet!
Hashicorp could've used a different license if they wanted to. They deliberately chose one that gives users the rights to build on Hashicorp's work -- and yes, even to profit off it at a competitor. What I don't think HC has is the right to act shocked when others use the software under the terms they were allowed to use it.
Surely, if maintaining it was such a burden, Hashicorp could just stop maintaining it?
Also, when FOSS was created, these concerns were simply non-existing. Times have changed massively in 30 years, "leeching" like this simply didn't exist when those licences were drafted. So no, I don't lack principles, the world simply changed.
FOSS generally allows competitors to use your product to compete against you, and always has (the "free" in FOSS refers to freedom), so either you were never okay with FOSS, or you were okay with it and then abandoned those principles to not be okay with it, but having a "principle" that only holds true until you don't like the result is unprincipled
have times changed in a way that justifies abandoning FOSS principles, which include being okay with your competitor using your FOSS software to compete against you? I don't think so.
and also, the whole ecosystem didn't exist when FOSS was created such as selling your software AND a cloud offering for it. If you created let's say an office suite and made it open, your competitor couldn't sell SaaS based on it 20 years ago because SaaS just didn't exist as a concept.... they could try to sell the same product debranded but that's not a very good business strategy.
hashicorp made a good decision here by being FOSS while it made sense, and when the leeches appeared, they decided to restrict future versions. This kind of leeching is the next m$-like EEE (extend, embrace, extinguish) - steal FOSS, host it and capture all the profits, while not maintaining or improving the software at all.
This kind of rent-seeking was simply unimaginable in the 90s when FOSS became a thing.
Also, hashicorp didn't leech off anyone (they didn't make the licence change retroactive, it's only future versions) because their contributions remain available under the same licence - it only applies to future hashi commits. Why shouldn't hashicorp have the freedom to commit in the fuiture with a different licence?
the "rent seeking" in question is Hashicorp seeking rent, here, now
FOSS generally allows competitors to use your product to compete against you, and always has (the "free" in FOSS refers to freedom)
also, nobody leeched off Hashicorp, they used the software as the license and Hashicorp intended, until Hashicorp changed their mind on being FOSS. Why shouldn't they have the freedom to use software in accordance with the license?
"FOSS generally allows competitors to use your product to compete against you, and always has" Sure, I know, but I don't think that's viable when you are running a business. You have to take some freedoms away if you want to have a viable product.
> I don't think that's viable when you are running a business. You have to take some freedoms away if you want to have a viable product.
I don't agree with this opinion, but even if it were true, it raises the question of why, then, Hashicorp chose that path in the first place, when they knew what FOSS meant?
If they didn't like the freedom part of FOSS, they didn't have to embrace it, but they did, and they did
Just see the latest serde "drama", where everyone disregarded the "no warranty" clause in the licence and loudly demanded changes/wanted to fork the project/etc.
FOSS has a huge problem of expectations from both upstream and downstream. There are very common arguments about "I use this, you broke it/made changes I didn't like, so you are a horrible maintainer and person and you will have zero credibility forever". If anyone uses FOSS dependencies, they also accept the risk of future versions being different. No one breaks versions already released, this is always about future versions. Demanding the maintainers to make specific changes/not to make them for your usecase is extremely entitled.
Not sure what you mean.
I'm all for proprietary companies not pretending to be opensource companies and actually using proprietary licenses.