Live data from Hacker News

HashiCorp adopts Business Source License

hashicorp.com

331–340 of 760 posts

Re: HashiCorp adopts Business Source License

#331

Earlier quoted context omitted.

I must not be making myself clear. Projects are free to choose permissive licenses like BSD. Companies are then free to use the code however they like and not contribute back in any way. Projects are then free to be annoyed by this because they hoped that companies would contribute time and/or resouces out their own good will. Finally, projects are free to move to "business source" licenses because good will didn't w…

Here is some software we made. Use it however and for whatever you like. Wait not like that.

Yes, literally this, but without the smug.

Have you ever set lenient guidelines, people took advantage of them in a way you didn't like, so you were forced to tighten your guidelines in a way you didn't originally want to?

eg: a professor establishes a generous late homework policy, which most students use reasonably, except a few who decide to turn in everthing on the last day of the term and make the TA's lives hell. Prof is allowed to be disappointed and then adjust their future terms' policies to be more specific (eg "submit assignments max 5 days late").

Re: HashiCorp adopts Business Source License

#332
I've had this conversation a few times with people today so I may as well have it publicly here now too.

I feel especially privileged to have lead the Heroku Add-ons/Ecosystem team at a pretty pivotal time in devtools history. There was a sudden emergence of people/companies inventing entirely new things (e.g., databases, logging systems, telemetry, etc.) and so much of it was OSS. The overwhelming majority of these companies took the approach of "we'll make this thing free and successful, and we'll build a business off the back of enterprise support contracts and maybe some feature discrimination in a private 'enterprise' version" (e.g., clustering/HA support). I think in part it was because back then the only open source success story anybody had as a reference was RedHat, and cloud adoption wasn't as ubiquitous as it is today. Certainly not in the enterprise segment. So in the vacuum that was left emerged a whole industry of smaller startups that would provide said technology as a managed service. Go check out the Heroku Add-ons Marketplace circa 2012-2015 to see what I mean. Belatedly the creators of these technologies realised the enterprise support contract business was a terrible business to be in, and realised managed services was where they should have been all along. Absolutely none of these companies had any problem muscling in on the ecosystem of managed providers that had contributed to their success in a meaningful way. Some of the startups got acquisition offers on pretty lowball terms, others were essentially forced to accept partner terms that were so onerous it was doubtful they could ever turn what they'd built into a successful high growth business now. Many saw the writing on the wall and found an exit at a larger cloud/platform company that could roll them into their broader product portfolio.

Fast-forward a few years and AWS starts offering some of these technologies as a managed offering (disclaimer: I later worked at AWS for a couple of years). Suddenly these same companies don't like having similar market pressure exerted on them, and so begins the slow trend of license changing away from APL/MIT/whatever towards something that is trying to neutralise a legitimate competitor. Rules for thee, not rules for me.

My time at AWS gave me some new perspective on this whole sorry saga though, some things I'd observed but couldn't quite articulate why it didn't feel right. AWS taught me that at a certain level of scale almost everything ultimately becomes a logistics challenge. Trying to ensure that the infrastructure that's supporting tens of thousands of customers globally is constantly running, highly available, able to support the continued growth, etc.? It's as much a problem of capacity planning and co-ordination as one of software. And the more successful you get the less the problem becomes the specific nuances of running a given OSS product and the more it skews towards just knowing how to coordinate millions of anything.

What this surfaced for me is that in the vast majority of cases that I was personally familiar with, the companies in question barely used their own products. I don't mean in way that suggests they didn't believe in their value. It's just that their day-to-day needs of building said product very rarely intersected with the need to be the most sophisticated user of said product. They had very limited experience at operating it at scale, they all had customers (or managed service partners) who had orders of magnitude more experience about the realities of operating it. And high on their own hubris they'd decided that because they'd invented the technology they were now suddenly expected to be the world leaders at running it. They weren't. And they were never going to be, because the moment you hit that inflection point of success AWS/Microsoft/Google/so many others are better at running software than you are... and a license isn't going to change that reality. The "we'll run this for you" is just a bad business to be in.

A better business is "we'll provide you a UX and workflow and features _on top_ of that thing that makes it even better". There's a whole industry of companies who exist solely to make your AWS bill comprehensible, because AWS are organisationally incapable of providing good UX for most things. In it's most reductive and cynical take Heroku is "just" a UX on top of the core AWS commodities, one that has been largely unchanged for 5-10 years depending on who you want to ask (the slow decline there is a whole separate topic).

Which is why I was excited to take on a product leadership role at HashiCorp to help launch Terraform Cloud a few years ago (I left last year). Here you had an OSS product with a big community, and a set of features and capabilities that extended that to try and make it even better. Especially in situations where you're having to work with other people or across multiple teams. The fact that Spacelift, Scala, Harness, Pulumi, Terrateam, etc. existed didn't bother me much. If they copied what we were doing it was often good validation, if we lost a customer to them it was a good data point for things we were lacking or needed to fix, in some cases they just had wildly different takes on fundamental things which were a great reason for some self-reflection and to question why our conviction on a different way was so strong... were we right? How did we know?

OSS is good for so many reasons, but as a product person one of the things I loved most was the way it could help shape what the product could be in the future. Because of the ecosystem that erupts around it. You've already got such a huge advantage as the steward of the project, the most recognised brand in the ecosystem you created, the brand recognition in an enterprise conversation, and so with all of that head start I felt like we should just win on our merits. And if you can't win given all of that advantage then maybe you don't deserve to.

Re: HashiCorp adopts Business Source License

#333
post #323

Earlier quoted context omitted.

Seems like you missed the part where I literally typed "giving back." Or that I literally contributed part of the hashicorp codebase, specifically vault. And it's been hard continuing to do that at $DAYJOB consistently, so I've hacked on a side project in my spare time (also open sourcing plenty of useful tools during that hacking) as a means to the end of eventually finding ways to keep giving back directly and teac…

with all due respect, unless "giving back" means giving them money, its probably not worth what you think its worth. I maintain some small projects, and most of the people "giving back" contribute such a tiny amount of code that its almost not worth mentioning. that might not be your situation, but I know as a maintainer, in most cases I would much prefer a monetary contribution than a pull request. edit, 2015, ouch:…

> edit, 2015, ouch:

> https://github.com/hashicorp/vault/commits?author=andrewstua...

Not sure what you're getting at with your edit. I'll try to assume positive intent.

I maintain quite a few projects as well, also pretty small. Code to me means a great deal more than a small amount of money. The money is nothing compared to what I've made in my career thanks almost entirely to the code that exists publicly and my ability to run and modify it as needed to learn. I am glad to get code because it tells me something is useful enough for someone else to bother, which to me is what giving back is all about.

Re: HashiCorp adopts Business Source License

#334
post #272
post #87

Earlier quoted context omitted.

Not having competition is not the problem I have seen listed when abuse is talked about. It is not contributing back in ways that are promotional to how much the company is benefiting. Or not going out of their way to acknowledge that they started with someone else's open source project, not even something like an academic citation.

There are open source licenses, such as the AGPL, which explicitly require that those changes being contributed back. There are licenses which require attribution. The fact the companies switching to the BS License is a sign that those aren't the real issues.

AGPL is very explicit/narrow about how and when you give back not everyone will want exactly that. My last example of where I have seen the word abuse used is only about lack of attribution similar to an academic citation.

Re: HashiCorp adopts Business Source License

#335

Earlier quoted context omitted.

I must not be making myself clear. Projects are free to choose permissive licenses like BSD. Companies are then free to use the code however they like and not contribute back in any way. Projects are then free to be annoyed by this because they hoped that companies would contribute time and/or resouces out their own good will. Finally, projects are free to move to "business source" licenses because good will didn't w…

Describing changing to a source-available licenses as "now utilizing the legal system" is strange. Projects choosing a permissive license like BSD is utilizing the legal system. BSD is a contract, a copyright license. It imposes restrictions/limitations/obligations, which can/would be enforced by a court.

Come on, you're unfairly quoting bits of my sentences in order to fuss over something unrelated to my point.

I said:

> so they need to utilize the legal system to ensure that large companies help sustain the project.

No shit they were using the legal system before with the BSD license. I am saying that they are now using the legal system to ensure companies contribute, which is not something the BSD license did.

Re: HashiCorp adopts Business Source License

#336

Earlier quoted context omitted.

There's a pretty good Open Source definition that's over 20 years old: https://en.wikipedia.org/wiki/The_Open_Source_Definition "Business Source License" is not Open Source. You don't have to release your software as Open Source if you don't want to, I certainly write a lot of non-open-source software for a living. But people/companies want to take advantage of the good-will/reputation that comes from calling their s…

It does definitely count as open source. I don't care what a California-based "Open Source Initiative" group try to define as "Open Source Definition". That is all lobbying to me. If I can see the source, then it's open source. The rest is just play on words which only purpose is to entertain sterile debates of zealot groups attempting vocabulary appropriation in a power struggle. I don't want to fuel these groups' d…

that's called "Source Available", it's also been a thing for 20+ years (but the limitations are pretty annoying so most people aren't into it)

Re: HashiCorp adopts Business Source License

#337
post #298

That's pretty disappointing. I personally haven't used much beyond vault (I've used but not enjoyed or built anything on terraform), but this is pretty diametrically opposed to what I appreciated most about hashicorp products. Heck, I've even contributed a chunk of the code I use the most from vault (Cert management) and now I'm going to have to reevaluate whether I can attempt to use that service for customers going…

The huge difference is where the copyright of the code lays. OSS projects that require contributors to assign their copyright away, should not be trusted, and should not receive goodwill contributions to begin with. Otherwise, what today is Apache 2.0, tomorrow can become Commercial, while asking nobody for permission, because the maintainers have ownership of 100% of the code. Not that OSS projects backed by commerc…

It's super frustrating, because I want to assume the best, but I'm starting to agree more and more with this perspective as stuff like this makes me more cautious/cynical. Unless my CLA assigns copyright to a foundation, in which case I am more likely to believe it will be kept in line with the foundation's charter, e.g.

Re: HashiCorp adopts Business Source License

#338

Earlier quoted context omitted.

Maybe you missed my last sentence. I've been hacking on and off for a couple years on a side project I'd like to monetize, to capture some of my value add, while also giving back. (It's sorta "if you build it they will come" at this point tbh so I don't necessarily expect it to work). My project is sort of "OSS platform as a service" only I just deploy it for you and teach you to run it yourself, while jumping on a c…

If so, you can check out Infisical ( https://github.com/Infisical/infisical ) as an open source alternative to Vault. The absolute majority of our codebase is licensed under MIT and we have no intentions to change that. Disclaimer: I'm one of the founders.

> we have no intentions to change that

I suspect that Hashicorp would have said the same thing a couple years ago.

Re: HashiCorp adopts Business Source License

#339

Earlier quoted context omitted.

This anecdote is a lot less interesting, both because of the separation (you know some people vs they run a company with direct exposure) and lack of detail. I'm sure you do know some people who contribute, but you haven't given any details about their experience that would contradict OP's claim that contributing is hard.

Is this enough detail? I work at AWS in Professional Services until tomorrow. I worked with the SA and had meetings with the service team responsible for the AWS Service in question to discuss the API shortcomings that we needed for automations. He contributed to Terraform once the APIs became available from our service team and I wrote the equivalent CloudFormation custom resources for a project (and open sourced on…

(former product lead for Terraform here)

There's probably not much AWS contribution to the core of Terraform from AWS, but there's very little contribution to that from anybody outside of HashiCorp because contributions happen on the providers.

AWS is definitely involved with their provider though. AWS ProServ built out a whole account vending machine thing that was in Terraform (the name escapes me atm), and various other service teams and SAs are regularly involved in contributing to and growing the Terraform ecosystem.

It would be super disingenuous to imply AWS is not contributing to the success and growth of Terraform.

Re: HashiCorp adopts Business Source License

#340
post #288

Earlier quoted context omitted.

Based on multiple previous employers of mine, it seems like software companies start noticeably going downhill about 1.5 years after they go public. Let's check Wikipedia and see how I did: > On 29 November 2021, HashiCorp set terms for its IPO ...I'm starting to think I'm onto something. (I do welcome anecdata that either helps or hurts my hypothesis)

1.5 years? Their stock was down 60% only 3 short months after IPO. I think this is just a struggle to turn what was once technical excellence into something that gives money. I haven't followed HashiCorp lately but was once a fan of some of their products. These days it seems things are slower over there. At least that's what it feels at a distance.

They IPOed at the peak of the ZIRP bubble. There's nowhere to go but down.
Post reply on HN