Earlier quoted context omitted.
What's wrong with monetization? You understand that OSS's significant problem is a lack of funding, where authors don't want or don't know how to monetize their product? Sentry looks like a good model for OSS, and it's proof that you can make a living from OSS. I also don't have anything against "enterprise features" for which you need a license, while most features are available in OSS version.
There's nothing wrong with monetization. There's just something wrong with making parts of the code proprietary. There'd be nothing wrong with monetizing by picking a copyleft license and selling exceptions, selling hosting, or selling support, for example.
Infisical – open-source HashiCorp Vault alternative
31–40 of 109 posts
Re: Infisical – open-source HashiCorp Vault alternative
#32Earlier quoted context omitted.
What's wrong with monetization? You understand that OSS's significant problem is a lack of funding, where authors don't want or don't know how to monetize their product? Sentry looks like a good model for OSS, and it's proof that you can make a living from OSS. I also don't have anything against "enterprise features" for which you need a license, while most features are available in OSS version.
Open Source is not a business model. It's marketing, for sure, but you can't make money solely by giving away your product. Every single open source company eventually learns this when they have a strong competitor. Eventually you are forced to stop being open source, because no business wants to compete solely on the strength of their service quality. Moreover: a community is antithetical to a corporation's interest…
Many of the open source companies are their own strongest competitor, see HashiCorp.
Re: Infisical – open-source HashiCorp Vault alternative
#33EnvKey ( https://www.envkey.com/ ) is another OSS alternative to Vault with a bit more focus on security (disclaimer: I'm the founder). We have a comparison with Vault here: https://www.envkey.com/compare/hashicorp-vault/ We'll probably write up a comparison with Infisical soon as well but I'd say the main thing is that our end-to-end encryption has no opt-outs (as Infisical does for many of its integrations), and we…
In my opinion, "having no opt-outs" is not a benefit. It's by definition having less functionality. Infisical offers native SDKs, API, and CLI too + many other features (such as native integrations, webhooks, dashboard, etc).
I'd also note that we are able to offer all the features you list without requiring users to opt-out of end-to-end encryption.
Re: Infisical – open-source HashiCorp Vault alternative
#34EnvKey ( https://www.envkey.com/ ) is another OSS alternative to Vault with a bit more focus on security (disclaimer: I'm the founder). We have a comparison with Vault here: https://www.envkey.com/compare/hashicorp-vault/ We'll probably write up a comparison with Infisical soon as well but I'd say the main thing is that our end-to-end encryption has no opt-outs (as Infisical does for many of its integrations), and we…
In my opinion, "having no opt-outs" is not a benefit. It's by definition having less functionality. Infisical offers native SDKs, API, and CLI too + many other features (such as native integrations, webhooks, dashboard, etc).
But, of course, too few features can be just impractical.
Re: Infisical – open-source HashiCorp Vault alternative
#35Backed by another corporation trying to monetize it. This will go well. This repo available under the MIT expat license, with the exception of the ee directory which will contain premium enterprise features requiring a Infisical license. I just sprained my eye sockets from rolling my eyes too hard.
What's wrong with monetization? You understand that OSS's significant problem is a lack of funding, where authors don't want or don't know how to monetize their product? Sentry looks like a good model for OSS, and it's proof that you can make a living from OSS. I also don't have anything against "enterprise features" for which you need a license, while most features are available in OSS version.
Re: Infisical – open-source HashiCorp Vault alternative
#36Earlier quoted context omitted.
In my opinion, "having no opt-outs" is not a benefit. It's by definition having less functionality. Infisical offers native SDKs, API, and CLI too + many other features (such as native integrations, webhooks, dashboard, etc).
There's an inherent tradeoff for sure. In my opinion, I wouldn't say that any added functionality a secrets management service can offer is worth trusting all that service's servers, all its backend dependencies, all its employees and contractors, all its third party sub-processors, etc. with plaintext secrets. I'd also note that we are able to offer all the features you list without requiring users to opt-out of end…
Curious how you are able to create a native integration with, let's say, Vercel without requiring users to opt-out of end-to-end encryption?
Re: Infisical – open-source HashiCorp Vault alternative
#37Earlier quoted context omitted.
What's wrong with monetization? You understand that OSS's significant problem is a lack of funding, where authors don't want or don't know how to monetize their product? Sentry looks like a good model for OSS, and it's proof that you can make a living from OSS. I also don't have anything against "enterprise features" for which you need a license, while most features are available in OSS version.
Sentry isn't OSS...
Re: Infisical – open-source HashiCorp Vault alternative
#38Earlier quoted context omitted.
There's nothing wrong with monetization. There's just something wrong with making parts of the code proprietary. There'd be nothing wrong with monetizing by picking a copyleft license and selling exceptions, selling hosting, or selling support, for example.
Curious why you think it's the wrong way to do it?
Re: Infisical – open-source HashiCorp Vault alternative
#39Earlier quoted context omitted.
What's wrong with monetization? You understand that OSS's significant problem is a lack of funding, where authors don't want or don't know how to monetize their product? Sentry looks like a good model for OSS, and it's proof that you can make a living from OSS. I also don't have anything against "enterprise features" for which you need a license, while most features are available in OSS version.
There's nothing wrong with monetization. There's just something wrong with making parts of the code proprietary. There'd be nothing wrong with monetizing by picking a copyleft license and selling exceptions, selling hosting, or selling support, for example.
Open Core is also a thing, and I think it's better than BSL because at least the core part is truly open.
Re: Infisical – open-source HashiCorp Vault alternative
#40Earlier quoted context omitted.
Sentry isn't OSS...
This is what Sentry says: https://open.sentry.io/
> The Business Source License (this document, or the “License”) is not an Open Source license. However, the Licensed Work will eventually be made available under an Open Source License, as stated in this License.