Live data from Hacker News

Elasticsearch is open source, again

elastic.co

421–430 of 473 posts

Re: Elasticsearch is open source, again

#421

Earlier quoted context omitted.

> To me, it's weird that the AGPL is any more "open source" than the Elastic License. The AGPL requires you to publish all of your source code if you make any changes to the product; the Elastic License just says, "don't use our code to make a direct competitor to Elasticsearch". I find the former to be much more restrictive in most practical ways since the majority of companies don't want to open source their code,…

the four freedoms were not written by God, just a bunch of ideological pedants. it's perfectly valid to have a completely different view of what freedom is for software

But FOSS and OSS are brands/labels of FSF and OSI and sometimes it is good to have such labels. This like arguing that same SmartTV is not smart or that there is other ways making a TV smart. I think it is good to have some innovation in licencing (like ethical licences which are by definition probably not free), but not by redefining stuff.

Re: Elasticsearch is open source, again

#422
post #387

Earlier quoted context omitted.

They all say if you sell the database as a service you can't use AGPL; you have to pay for a commercial license.

no they don't unless, you are using the features like SSO that are behind the license or you are refusing to publish any patches you apply

The point of DBaaS is that you wrap an open source database with a proprietary control plane that you won't release. Cloud vendors say this is compliant with AGPL but database startups say it isn't and thus the cloud vendors need to buy a license.

Re: Elasticsearch is open source, again

#423

Earlier quoted context omitted.

> But I do think it'd be a good look for AWS to proactively help these companies. But how much value does "a good look" have to AWS?

Depends on who sits in the antitrust seat. It's pretty incredible to realize the one who does today wrote this a few years ago: https://www.yalelawjournal.org/pdf/e.710.Khan.805_zuvfyyeh.p...

I'm fairly skeptical that Amazon would seek out a "good look" like the one here, solely in hopes that it will save them from antitrust scrutiny.

Re: Elasticsearch is open source, again

#424
post #149

Earlier quoted context omitted.

> not great for the re-seller If the AGPL is exactly as you say, I don’t see why this would be a problem for a re-seller. For a pure re-seller I don’t think the value add is provided by modifying the software. E.g. take the example that Amazon hosts the service and integrates with their internal services etc for logging, storage, load balancing etc. If they only have to distribute the modified source, then their inte…

> take the example that Amazon hosts the service and integrates with their internal services etc for logging, storage, load balancing etc. If they only have to distribute the modified source, then their internal service APIs will be leaked. No. What URLs the logs are sent to is just a config option - probably not even for the hosted software, probably for the kubernetes pod - not source code. If the logging exporter…

Re: logging URLS

In my example, the URLs are not the issue. What I was trying to say, which you actually ended up agreeing with is that they would have to publish the changes that allowed talking to the internal protocol. All I added to that, is that is perhaps not something that they want to share (logging is just an example, big companies have a lot of internal infrastructure for debugging, tracing, monitoring etc).

Re: distributing modifications

You’ve missed the point in my second example. The API portion is covered by my first example. My second example is about possible virality due to the concept of required dependencies.

If I have a special remote storage backend that requires speaking a custom protocol (which is used widely across my existing infrastructure) and I change AGPL code to require it, it is reasonable that I have to publish the source code for talking to the custom protocol (again, covered in the first example).

What is new about this, is that if my version of the binary requires a backend that uses the custom protocol, then just publishing the version of the AGPL software that speaks the API is not enough to be able to run it (because it won’t work without a backend that speaks that protocol). According the provisions for intimate data transfer and executability, it is possible to interpret the license as requiring the backend, which is NOT a part of the AGPL software that you have pulled in as a dependency to be AGPL as well. I assume this is where the concerns about virality beyond the original project arise.

Distributing modifications is reasonable, possibly needing to distribute everything the binary ends up talking to over the network is the concern.

Re: Elasticsearch is open source, again

#425
post #422

Earlier quoted context omitted.

no they don't unless, you are using the features like SSO that are behind the license or you are refusing to publish any patches you apply

The point of DBaaS is that you wrap an open source database with a proprietary control plane that you won't release. Cloud vendors say this is compliant with AGPL but database startups say it isn't and thus the cloud vendors need to buy a license.

None of those pages you linked say anything like that, you're just making stuff up.

One of them is not the company talking about their license choice but a FUD article crying about AGPL which we've seen a million tired versions of.

The Rethink one says

> * Require users who choose to modify RethinkDB to fit their needs to release the patches to the software development community.

> * Require users who are unwilling to release the patches to the software development community to purchase a commercial license.

note:

> * who choose to modify RethinkDB

and

> * release the patches

none of these say anything about problems with putting control planes in front of it.

I have worked with cloud hosting a database where the only feature behind the enterprise license is a load balancer with some dead simple authz plugins.

You can write put any LB in front of it and host and sell it with the same capabilities without violating the OSS license. Adding a "control plane" that sits in front of the hosted database does not require you to publish any modifications unless you actually are running a modified version of the open source software. You would never have to publish your own LB.

Re: Elasticsearch is open source, again

#426
post #424

Earlier quoted context omitted.

> take the example that Amazon hosts the service and integrates with their internal services etc for logging, storage, load balancing etc. If they only have to distribute the modified source, then their internal service APIs will be leaked. No. What URLs the logs are sent to is just a config option - probably not even for the hosted software, probably for the kubernetes pod - not source code. If the logging exporter…

Re: logging URLS In my example, the URLs are not the issue. What I was trying to say, which you actually ended up agreeing with is that they would have to publish the changes that allowed talking to the internal protocol. All I added to that, is that is perhaps not something that they want to share (logging is just an example, big companies have a lot of internal infrastructure for debugging, tracing, monitoring etc)…

No, you're just willfully misinterpreting these clauses

> Source includes interface definition files associated with source files for the work, and the source code for shared libraries and dynamically linked subprograms that the work is specifically designed to require, such as by intimate data communication

If you don't change the source code and you instead write a shim service for it to talk to a special logging protocol, you haven't dynamically linked anything, you haven't changed source code for shared libraries, and you haven't messed with source files.

And even if you tried to argue that "talking over a network" is "dynamically linking" which would be just a completely made-up definition of dynamic linking that would never stand up, it still would not count as something that the original "work is specifically designed to require".

Re: Elasticsearch is open source, again

#427
post #354

Earlier quoted context omitted.

You speak as if there is a divinely written definition for the words "open source". There is not, there's a group of people who have said, "this is ok, this is not". I'm of the opinion that those people have made a mistake that will work against them, and they should consider revising their definition.

But... there is a definitively written definition for those words. The phrase was invented to refer to a very specific thing. Changing the meaning of the word would accomplish nothing except force existing usages of the word to change. Like, if fair source licenses began to be referred to as "open source", then "open source" will have lost its original meaning. So now when stating that something is "open source", you…

The world changes, and we update definitions. There's nothing magical about a group of people in the 90s defining a thing one way because they disliked the politics of another definition.

It's all just people making the best decisions they could. It's clear to me at least that there are existential threats presented by tech megacorps that aren't present awhile ago. Maybe it's time to rethink our definitions.

Re: Elasticsearch is open source, again

#428
post #421

Earlier quoted context omitted.

the four freedoms were not written by God, just a bunch of ideological pedants. it's perfectly valid to have a completely different view of what freedom is for software

But FOSS and OSS are brands/labels of FSF and OSI and sometimes it is good to have such labels. This like arguing that same SmartTV is not smart or that there is other ways making a TV smart. I think it is good to have some innovation in licencing (like ethical licences which are by definition probably not free), but not by redefining stuff.

sure then people should stop crying and pooping their pants when someone tries to introduce a license that's not technically OSS but tries to address ethical concerns.

"It's not OSS" is a not a value judgement unless you think that the four freedoms were written by god. But it is treated exactly as religiously.

Re: Elasticsearch is open source, again

#429
post #336

I'm increasingly of the opinion that the definition of "open source" that narrowly defines open source is going to be the thing that contributes to the reduction of open source software. Open source communities are essentially anarchist syndicates, collectively working towards common good. Groups like Amazon coming in and taking their work and selling it, profiting to the tune of millions, and contributing nothing ba…

> GPL flavors get close, but not sufficient What do you think makes it insufficient?

Amazon has the market power, legal strength, and willingness to run at a loss indefinitely, as well as the regulatory capture and connections to ensure they cannot be fairly investigated.

So if I want to ensure my software is used maximally, by the people who need or want it most, I need to ensure there isn't a "gravity distorting player" taking my project and white labeling it to push out all the other people.

The AGPL gets closer, but still doesn't go far enough in defining "modifications to the software" or linking, IMO.

Re: Elasticsearch is open source, again

#430
post #222

Earlier quoted context omitted.

Your link specifically says Amazon didn’t steal the code, some German company did. I get it, Amazon is bad, I agree they are too, but not because they’re malicious, Amazon is bad because they’re too large to compete on level ground with anyone other than Google or Microsoft in the cloud. My peeve is with the companies like elastic that claim they are for open source but they try to prevent the open source from being…

> Your link specifically says Amazon didn’t steal the code, some German company did. Yeah it's not that Amazon stole the code, it's that they were distributing stolen code. It's not as bad but it's still problematic unless Amazon immediately pulled said code when they were notified. > My peeve is with the companies like elastic that claim they are for open source but they try to prevent the open source from being use…

> it's a dick move and against the spirit of FOSS

I disagree with this. Most people use FOSS and do not give anything back, individuals included. The spirit of FOSS is creating things that others will use without compensation. If I release anything open source, it's because I'm donating it as a whole to humanity, including big corps and individuals. I understand that, because I've thought long and hard about what it means to release something with, say, an MIT license. It means you lose having full control of your creation. If I wanted to limit who can use my software, I'll sell it or license it accordingly. Complaining later that your FOSS software was "stolen" or "exploited" or whatever is just sour grapes.

Post reply on HN