Live data from Hacker News

HashiCorp adopts Business Source License

hashicorp.com

371–380 of 760 posts

Re: HashiCorp adopts Business Source License

#371
post #279

Earlier quoted context omitted.

Absurd. Providing a managed instance of open source software that’s complicated to manage is fine. It’s not AWS’s fault that Elastic did a bad job of selling into AWS accounts. They should have worked on their value prop.

> They should have worked on their value prop. AWS customers like that there's one bill and one account. Who wants to deal with multiple vendors if they don't have to? It isn't a level playing field when Amazon offers a service. Amazon could have chosen a cooperative, long-term, strategy and shared some revenue with the authors for some quid-pro-quo, and the world and Amazon, would be better for it. Instead, Amazon c…

The reason historically it hasn’t been a level playing field is because Amazon have:

- The ability to invent new infrastructure to suit a need. For example, multi legged ENIs that provide the EKS control plane are simply not available to others,

- The ability to integrate with IAM natively,

- The ability to build common network architectures without outrageous costs (traffic over peering links being a good example since that is what basically all vendors have to do).

Re: HashiCorp adopts Business Source License

#372
post #230

Earlier quoted context omitted.

> That's pretty disappointing. From the article: “End users can continue to copy, modify, and redistribute the code for all non-commercial and commercial use, except where providing a competitive offering to HashiCorp.” Literally nothing has changed, this isn’t disappointing, it’s smart, they’re protecting themselves against cloud providers that have repeatedly abused the goodwill of the open source community.

> they’re protecting themselves against cloud providers that have repeatedly abused the goodwill of the open source community. e.g. AWS -> Elasticsearch.

Elasticsearch is based off lucene so they are making money off another open source project.

Re: HashiCorp adopts Business Source License

#373

Earlier quoted context omitted.

Spacelift co-founder here - please don’t panic. We will make sure you can continue to use Spacelift :)

You, humanitec, and env0 should start a community fork of pre-BSL Terraform and donate it to the CNCF.

I believe it's a bit too early to make this call but based on the experience of interacting with Terraform the binary it would be absolutely amazing for the community if Terraform could be turned into a library that can become a building block for higher level services.

Re: HashiCorp adopts Business Source License

#374

Earlier quoted context omitted.

If you want people/companies to contribute back, why volunteer your code under a license that doesn't require that?

"Why did I leave Halloween candy on my porch if I wasn't okay with one jerk kid taking all of it for himself?" Because projects believ(ed) that the good will of their users would be enough to sustain their projects and businesses. Now that certain projects see that good will isn't working, they're switching to the legal system.

Sooo much this. I think we are going to see a rise of “wait that’s not cool” defensive measures _in general_.

Re: HashiCorp adopts Business Source License

#375
HashiCorp's CLA page from two months ago (https://web.archive.org/web/20230610041432/https://www.hashi...):

"We require our external contributors to sign a Contributor License Agreement ("CLA") in order to ensure that our projects remain licensed under Free and Open Source licenses such as MPL2 while allowing HashiCorp to build a sustainable business.

HashiCorp is committed to having a true Free and Open Source Software ("FOSS") license for our non-commercial software. A CLA enables HashiCorp to safely commercialize our products while keeping a standard FOSS license with all the rights that license grants to users: the ability to use the project in their own projects or businesses, to republish modified source, or to completely fork the project."

It's disappointing that the non-legal text on the page repeatedly suggested that signing a CLA would help keep HashiCorp projects open source when the actual text of the license agreement made no such claims.

Re: HashiCorp adopts Business Source License

#376

Earlier quoted context omitted.

Yes, check some of the previous HashiConf keynotes to see the types of customers that are paying for it and which products they use. Also HashiCorp's financials are public, although without a per-product breakout. You'll have to connect the dots between some of these things to try and get into the rough ballpark.

I read their s1 and it looked like a lot of the revenue came from professional services. I’m curious how this affects consultants and PSOs that might be competing w Hashi’s services business and running terraform on jenkins or whatever.

previous quarter: https://ir.hashicorp.com/node/8351/pdf

Cloud: $16.5M (+88% YoY) Subscriptions: $133.6M (+35% YoY) ProServ: $4.4M (+75% YoY)

Re: HashiCorp adopts Business Source License

#377
post #327

Earlier quoted context omitted.

Pulumi Founder/CEO here. The blog post is disingenuous. We tried many times to contribute upstream fixes to Terraform providers, but HashiCorp would never accept them. So we've had to maintain forks. They lost their OSS DNA a long time ago, and this move just puts the final nail in the coffin. Thankfully over time, they already pushed responsibility for most Terraform providers back onto their partners, so I'm hopefu…

>We tried many times to contribute upstream fixes to Terraform providers, but HashiCorp would never accept them. So we've had to maintain forks. They lost their OSS DNA a long time ago, and this move just puts the final nail in the coffin. OSS doesn't mean that you have to accept any PRs that showed up in your repo, nor does it mean that you have to let a competitor steer your project simply because you're building i…

I’m sorry, but no. These are usually simple bugs like “forgot to a set a field during refresh”. They almost always correspond to one or more Terraform issues too, often ones that have been open for 4-5 years or have been “marked as stale” by some infuriating bot.

Re: HashiCorp adopts Business Source License

#378
post #375

HashiCorp's CLA page from two months ago ( https://web.archive.org/web/20230610041432/https://www.hashi... ): "We require our external contributors to sign a Contributor License Agreement ("CLA") in order to ensure that our projects remain licensed under Free and Open Source licenses such as MPL2 while allowing HashiCorp to build a sustainable business. HashiCorp is committed to having a true Free and Open Source Sof…

> The CLA does not change the terms of the standard open source license used by our software such as MPL2 or MIT. You are still free to use our projects within your own projects or businesses, republish modified source, and more. Please reference the appropriate license for the project you're contributing to to learn more.

Someone should try challenging the CLA when the pretext of it changes (their contributions being relicensed to non-FOSS). Most CLAs are very dry but HashiCorp may be in trouble with all the proclamations in theirs.

Re: HashiCorp adopts Business Source License

#379

Earlier quoted context omitted.

that's called "Source Available", it's also been a thing for 20+ years (but the limitations are pretty annoying so most people aren't into it)

Are you unable to get out of the hole of vocabulary appropriation and lobbying created by some activist groups? You are perpetrating the mind washing game of zealots that try to convince you they have the right to define what is and is not acceptable to their self defined standards. You keep quoting articles and pages defining what _a specific group_ with a specific agenda has chosen to appropriate as "Open source".…

1999. That's when the first version of this document was published. The original 1999 press release is linked to Wikipedia. There were some conferences and debates that happened before that, and some settling of the OSI in the early 2000s. 20+ years ago.

> I don't know for you, but I was there 20+ years ago, developing and using open source softwares, and that distinction did not exist.

That's really pretty strange ... it was a pretty hot topic back then ... are you sure you used open source software? like linux, freebsd, apache httpd, gcc, bash, samba, mozilla...

The right to use software commercially even if the copyright holder doesn't like you is an important qualification of open source. GPL, LGPL, BSD, MIT, MPL, Apache etc all include this right. It's important. It did take people some time and debate to figure it out ... 20+ years ago.

Re: HashiCorp adopts Business Source License

#380

Earlier quoted context omitted.

I read the rest of your comments on this topic and I’m sorry this happened to you. I have extensive experience with enterprise vault, implementing and managing it across a company infrastructure to manage application secrets, and during the few years we implemented vault and was in negotiations about our contract, I noticed the sales engineers would 1) be dishonest or misleading about features “needed” for our user c…

3 is a confusing one but understandable. You should be using the OIDC login method most of the time for MFA, and not their built-in MFA. I’m unsure if the equivalent software is worth the price when compared to Vault and not sure I can seriously suggest anything else even if I hate this new license.

You can use a mix of secrets manager and certificate manager products in AWS and accomplish essentially the same things Vault promises for much cheaper (and easier to manage).

I’m underselling of course the vast capabilities of vault. but most companies don’t need those advanced features, and they don’t really sell them, they sell and lock you into features that once you implement are going to become an extraodinary hurdle to migrate out of.

On the oidc - yes we were using okta as that. but at some point mid-contract the “okta” management features that connected to it became enterprise only, and we had reasoned that if we didnt need more advanced features (dr, replication) we could go back to OSS when we wanted. In fact that was even told to us, until that was no longer the case.

Post reply on HN