Live data from Hacker News

HashiCorp adopts Business Source License

hashicorp.com

351–360 of 760 posts

Re: HashiCorp adopts Business Source License

#351

Earlier quoted context omitted.

Spacelift co-founder here - please don’t panic. We will make sure you can continue to use Spacelift :)

You, humanitec, and env0 should start a community fork of pre-BSL Terraform and donate it to the CNCF.

Massdriver would contribute here.

Re: HashiCorp adopts Business Source License

#352
post #298

That's pretty disappointing. I personally haven't used much beyond vault (I've used but not enjoyed or built anything on terraform), but this is pretty diametrically opposed to what I appreciated most about hashicorp products. Heck, I've even contributed a chunk of the code I use the most from vault (Cert management) and now I'm going to have to reevaluate whether I can attempt to use that service for customers going…

The huge difference is where the copyright of the code lays. OSS projects that require contributors to assign their copyright away, should not be trusted, and should not receive goodwill contributions to begin with. Otherwise, what today is Apache 2.0, tomorrow can become Commercial, while asking nobody for permission, because the maintainers have ownership of 100% of the code. Not that OSS projects backed by commerc…

Does assigning copyright with a CLA mean that I would not be free to, say, submit the same PR to more permissive fork as well as Hashicorp's vault?

Re: HashiCorp adopts Business Source License

#353
The so-called "Business Source License" always seemed like a huge crock of shit. What criteria is used to determine if another project is competitive with Hashicorp? Ansible modules exist to create cloud resources, and they exist in an actually open ecosystem without being built on terrible DSLs.

To be honest I'm not a huge fan of the wringing about the OSI definition, but it exists for a reason. This whole article is just another example of corporate gaslighting. If you don't define this and prevent that definition from being acquired, you're going to keep having CEOs define open source on how they 'feel', and you won't have the 'spirit' of open source at all.

I mean it's literally the BS License. You really can't even make that up.

Re: HashiCorp adopts Business Source License

#355
post #323

Earlier quoted context omitted.

with all due respect, unless "giving back" means giving them money, its probably not worth what you think its worth. I maintain some small projects, and most of the people "giving back" contribute such a tiny amount of code that its almost not worth mentioning. that might not be your situation, but I know as a maintainer, in most cases I would much prefer a monetary contribution than a pull request. edit, 2015, ouch:…

> edit, 2015, ouch: > https://github.com/hashicorp/vault/commits?author=andrewstua... Not sure what you're getting at with your edit. I'll try to assume positive intent. I maintain quite a few projects as well, also pretty small. Code to me means a great deal more than a small amount of money. The money is nothing compared to what I've made in my career thanks almost entirely to the code that exists publicly and my a…

> The money is nothing compared to what I've made in my career

right, but thats not the case for everyone. you have been fortunate, but for many they cant even pay their bills with the tiny donations that come in. hence why the need arises for a license like this. to force people to either go away, or pay up.

as you've noticed, its not ideal. in a perfect world I would license my code without restriction, but I need to pay rent like everyone else.

Re: HashiCorp adopts Business Source License

#356

Earlier quoted context omitted.

> This is purely a way for HashiCorp to ensure they are the only ones who can commercialize these formerly open source projects. Which is fine. But just go closed source, then, and own that, instead of trying to have it both ways. Pragmatically I would rather bsl than closed source and I am more likely to use a product that is bsl, with reasonable transfer time and license, than a 100% closed source product.

I'd rather have proprietary than "almost open source". Both aren't useful, but only one attempts to damage the common understanding of what "Open Source" means.

Why? To me, the BSL comes off as a good faith attempt at a compromise between the letter of "Open Source" and the realities of not wanting to give free labor to your competition.

The actual text of the BSL mandates - under threat of infringing on BSL's trademark - that in at most four years the code will be available under a GPL 2.0 compatible license. In practice, the BSL license is usually a traditional open source one with caveats. The BSL FAQ also states and restates many, MANY times that it is not an open source license according to the OSI's definition.

I can't help but feel like the outcry over this is just a tempest in a teapot. I have a hunch that "Open Source" will do just fine without us having to carry water for it. After all, the list of OSI's corporate sponsors is quite illustrious: https://opensource.org/sponsors/

Re: HashiCorp adopts Business Source License

#357
post #305

Earlier quoted context omitted.

> I've been hacking on and off for a couple years on a side project I'd like to monetize OK so you want to use their software, make money off it, and give nothing back. if thats the case, you cant do that any more. you can either stick to personal use, or purchase a commercial license from them.

Seems like you missed the part where I literally typed "giving back." Or that I literally contributed part of the hashicorp codebase, specifically vault. And it's been hard continuing to do that at $DAYJOB consistently, so I've hacked on a side project in my spare time (also open sourcing plenty of useful tools during that hacking) as a means to the end of eventually finding ways to keep giving back directly and teac…

Imagine that someone see your open-source code and creates a competitor product by assimilating it... Imagine that this entity is much bigger than you even...

I don't think you'd be happy, would you?

I know I wouldn't be... :-)

Re: HashiCorp adopts Business Source License

#358
post #298

Earlier quoted context omitted.

The huge difference is where the copyright of the code lays. OSS projects that require contributors to assign their copyright away, should not be trusted, and should not receive goodwill contributions to begin with. Otherwise, what today is Apache 2.0, tomorrow can become Commercial, while asking nobody for permission, because the maintainers have ownership of 100% of the code. Not that OSS projects backed by commerc…

Does assigning copyright with a CLA mean that I would not be free to, say, submit the same PR to more permissive fork as well as Hashicorp's vault?

It depends on the CLA, and there is often very little similarity between one CLA and another. On a technical note, CLAs don't usually assign copyright, they only grant a licence, but one which permits the recipient of the CLA to relicense the contribution whenever they choose to.

Re: HashiCorp adopts Business Source License

#359

That's pretty disappointing. I personally haven't used much beyond vault (I've used but not enjoyed or built anything on terraform), but this is pretty diametrically opposed to what I appreciated most about hashicorp products. Heck, I've even contributed a chunk of the code I use the most from vault (Cert management) and now I'm going to have to reevaluate whether I can attempt to use that service for customers going…

I read the rest of your comments on this topic and I’m sorry this happened to you. I have extensive experience with enterprise vault, implementing and managing it across a company infrastructure to manage application secrets, and during the few years we implemented vault and was in negotiations about our contract, I noticed the sales engineers would 1) be dishonest or misleading about features “needed” for our user c…

3 is a confusing one but understandable.

You should be using the OIDC login method most of the time for MFA, and not their built-in MFA.

I’m unsure if the equivalent software is worth the price when compared to Vault and not sure I can seriously suggest anything else even if I hate this new license.

Re: HashiCorp adopts Business Source License

#360
This happens because our companies basically want vendors with open code, not open source.

Open source implies a model of collaboration between different organizations. A single vendor, even with an OSI license, does not an open source project make. And we have only ourselves to blame. Most companies can’t spare their developers for open source development - it’s time consuming and frankly open source is the outlier in how we think about code ownership and development. It’s hard to be a good steward. It’s hard to pitch the upside of such an abstract investment. In the end, actually want vendors, strongly opinionated solutions, managed by a single entity, but vendors we hire to let us treat their code as open and extensible.

I wonder if this era of single-vendor “open source” will be looked at not because it redefined open source but because it changes how we think about vendors, expecting certain types of code access and transparency.

Post reply on HN