Live data from Hacker News

HashiCorp adopts Business Source License

hashicorp.com

341–350 of 760 posts

Re: HashiCorp adopts Business Source License

#341
While I do understand the reasoning in their FAQ on the subject (https://www.hashicorp.com/license-faq). I however failed to noticed those intentions in their license text (https://github.com/hashicorp/nomad/commit/b3e30b1dfa185d9437...).

Specifically the part in FAQ which says "internal production use is fine", but then license says that "non-production use only" and then "You may make production use of the Licensed Work, provided such use does not include offering the Licensed Work to third parties on a hosted or embedded basis which is competitive with HashiCorp's products.".

IANAL, but even to me this statement is full loopholes. WHO do we consider 3rd party? WHAT do we consider "hosted or embedded basis"? WHEN do we consider it "competitive with Hashicorps products"?

Re: HashiCorp adopts Business Source License

#342

All that I get from this is that HashiCorp is no longer an open source company. > However, there are other vendors who take advantage of pure OSS models, and the community work on OSS projects, for their own commercial goals, without providing material contributions back. We don’t believe this is in the spirit of open source. This is 100% in the spirit of open source. If this is a problem for them, why not adopt an o…

>like the AGPL? As I explained in an earlier thread, MongoDB tried using AGPL. AGPL is not a barrier for Amazon, they still will resell your product without contributing. MongoDB ended up using a variant of AGPL that is even stricter (requiring the entire tech stack to be under the same license) but is no longer considered FOSS. Until the attitude changes around what FOSS is, this will keep happening.

AGPL is not a barrier for Amazon, they still will resell your product without contributing.

I don't think this is true.

Re: HashiCorp adopts Business Source License

#343
post #301

Funny how @mitchellh has decided not to join the conversation. Pretty sure he had the ultimate input on this decision, and historically he's engaged with HN directly. Hmm. Overall it seems like a loser move. Look what happened to Elasticsearch - to me and most others, ES no longer exists. I've happily moved on to OpenSearch and not looked back at poor kimchi. Due to their own actions, Elasticsearch is no longer relev…

Does anybody even pay for terraform? Outside the “workspace” hosted product, it’s all free as in beer for all the providers.

Yes, check some of the previous HashiConf keynotes to see the types of customers that are paying for it and which products they use. Also HashiCorp's financials are public, although without a per-product breakout. You'll have to connect the dots between some of these things to try and get into the rough ballpark.

Re: HashiCorp adopts Business Source License

#344

Earlier quoted context omitted.

By any chance are you familiar with Little Free Library ( https://littlefreelibrary.org/ ), those public boxes for people to take or leave books? How would you feel if someone took ALL the books, repeatedly, and then sold them? Would you just shrug and say "well that's totally fine, why is it free in the first place?" This behavior is antisocial, and completely destroys the offering/concept for everyone. I have a boo…

Given the lengths you say you went to to actively stop and sabotage licenced (by you) usage I have to question why you even picked an open source license in the first place?

When I started developing my main product, I didn't know if it would be successful, especially since it involved a paradigm shift in how most people thought of the workflow involved (database schema changes / migrations). So I made it open source to encourage adoption and experimentation.

Meanwhile I put some of the core logic (database schema introspection and diff'ing) in a separate library and repo, since it could be re-used for other applications in case my original product didn't get traction.

Fast forward many years, and the product has been fairly successful. The open source edition of the product has been used by many hundreds of companies and has been downloaded 1.2 million times. And in terms of the paradigm shift, the push/pull schema change semantics that I invented have been copied by several much larger projects, such as Prisma.

The separate library was used by a few companies too (e.g. by Canonical for one notable case), but mostly for internal use-cases, not things that directly competed with my product. I think most folks had enough moral fiber or common sense to understand that using the library in a competitive way would result in the library being killed off. What other choice did I have? I wasn't going to let my business be killed by a hostile fork of my own library.

Re: HashiCorp adopts Business Source License

#345
Meh.

Sure, it's hard to make money in open source. I spent 20 years doing it. It ain't easy.

But here's the thing: open source also helps you accelerate a business you might not otherwise be able to build. You get market validation by giving away a free thing, and then you hope to be able to collect some revenue on the backend once you've got a large enough user base, a proven product, and maybe even some contributors. Maybe even a whole ecosystem. You think VCs would have thrown all that money at a thing with no users?

Want to throw it all out? Fine. That's your right. But it's not gonna stop companies from forking the last open source licensed codebase and taking your cookies.

Open core is a thing. You can be good at it, and users understand and respect it. You would think that Mitchell would have learned after his failure to monetize Packer that he needed an actual proprietary value prop to build around before he built Hashi. Guess not.

You can't have it both ways.

Re: HashiCorp adopts Business Source License

#346

Earlier quoted context omitted.

I argue the window is moving as to what “open source” means out of survival. Source available is the new open source, and what young technologists will grow up grinding on. You’ll have folks complain about it during the transition (as happens with any Overton window sort of event), but they’ll move on eventually and a new crop of tech industry will grow up with this as the new normal. Change is inevitable, broadly sp…

> I argue the window is moving as to what “open source” means Only if we let it, and stop shouting about it and finding alternatives every time a company does this. This isn't a new thing; companies have been trying to play "almost open source" games for decades, and they'll continue playing those games as long as it either works or doesn't have sufficiently large penalties for trying. (Much as companies will continu…

> The best possible response to a company doing this is that someone forks the code, starts or expands a competitor, and the original company's revenue drops massively as a deterrent.

Example of the last time this worked?

Re: HashiCorp adopts Business Source License

#347

That's pretty disappointing. I personally haven't used much beyond vault (I've used but not enjoyed or built anything on terraform), but this is pretty diametrically opposed to what I appreciated most about hashicorp products. Heck, I've even contributed a chunk of the code I use the most from vault (Cert management) and now I'm going to have to reevaluate whether I can attempt to use that service for customers going…

> That's pretty disappointing. From the article: “End users can continue to copy, modify, and redistribute the code for all non-commercial and commercial use, except where providing a competitive offering to HashiCorp.” Literally nothing has changed, this isn’t disappointing, it’s smart, they’re protecting themselves against cloud providers that have repeatedly abused the goodwill of the open source community.

> they’re protecting themselves against cloud providers that have repeatedly abused the goodwill of the open source community

This seems a lot more likely to be targeting other startups that build on terraform like spacelift, env0, maybe pulumi (although I think they interface with providers directly, so this might not affect them as much), etc. And maybe there are similar companies for their other offerings, although I'm less familiar with those.

Re: HashiCorp adopts Business Source License

#348

Earlier quoted context omitted.

It does definitely count as open source. I don't care what a California-based "Open Source Initiative" group try to define as "Open Source Definition". That is all lobbying to me. If I can see the source, then it's open source. The rest is just play on words which only purpose is to entertain sterile debates of zealot groups attempting vocabulary appropriation in a power struggle. I don't want to fuel these groups' d…

that's called "Source Available", it's also been a thing for 20+ years (but the limitations are pretty annoying so most people aren't into it)

Are you unable to get out of the hole of vocabulary appropriation and lobbying created by some activist groups?

You are perpetrating the mind washing game of zealots that try to convince you they have the right to define what is and is not acceptable to their self defined standards.

You keep quoting articles and pages defining what _a specific group_ with a specific agenda has chosen to appropriate as "Open source".

All your sources and Wikipedia pages are ultimately linked to GNU publications. Read the references.

"an open source software license must also meet the GNU Free Software Definition"

That is plain ridiculous.

> it's also been a thing for 20+ years

No, it has never been "a thing". Especially not 20 years ago. Not even the sources you quote date back more than 5 years.

I don't know for you, but I was there 20+ years ago, developing and using open source softwares, and that distinction did not exist. If you had the source, it was open source, whatever the limitations of the license.

You are being indoctrinated.

Re: HashiCorp adopts Business Source License

#349

That's pretty disappointing. I personally haven't used much beyond vault (I've used but not enjoyed or built anything on terraform), but this is pretty diametrically opposed to what I appreciated most about hashicorp products. Heck, I've even contributed a chunk of the code I use the most from vault (Cert management) and now I'm going to have to reevaluate whether I can attempt to use that service for customers going…

I read the rest of your comments on this topic and I’m sorry this happened to you.

I have extensive experience with enterprise vault, implementing and managing it across a company infrastructure to manage application secrets, and during the few years we implemented vault and was in negotiations about our contract, I noticed the sales engineers would

1) be dishonest or misleading about features “needed” for our user case or make long-term promises they couldn’t possibly keep about features. standard salesmanship stuff but was very aggressive.

2) encouraged an integration style that would make migrating out of vault practically impossible, if not outrightly dangerous

3) continually rug pulled features we thought would be free forever (okta/mfa login being the biggest one I can think of). You can’t pass any serious compliance without that, and they realized anyone heavily relying on vault for secrets management would absolutely have to pay for this feature.

Basically it just seemed like hard core vendor lock in and every year our bill would be a lot higher for essentially the same or fewer features. Not to mention nonsensical pricing that even their own engineers can’t explain and changes constantly and arbitrarily.

So all this to say sorry this happened to you and for Vault specifically I am not surprised and would personally not rely on it for anything serious, even though I personally consider it fantastic software - I simply lost trust in hashicorp.

Re: HashiCorp adopts Business Source License

#350
post #298

That's pretty disappointing. I personally haven't used much beyond vault (I've used but not enjoyed or built anything on terraform), but this is pretty diametrically opposed to what I appreciated most about hashicorp products. Heck, I've even contributed a chunk of the code I use the most from vault (Cert management) and now I'm going to have to reevaluate whether I can attempt to use that service for customers going…

The huge difference is where the copyright of the code lays. OSS projects that require contributors to assign their copyright away, should not be trusted, and should not receive goodwill contributions to begin with. Otherwise, what today is Apache 2.0, tomorrow can become Commercial, while asking nobody for permission, because the maintainers have ownership of 100% of the code. Not that OSS projects backed by commerc…

This is incorrect, this can happen with any permissive license (BSD, Apache 2...) regardless of copyright assignments.
Post reply on HN