Live data from Hacker News

Elasticsearch is open source, again

elastic.co

451–460 of 473 posts

Re: Elasticsearch is open source, again

#451

Earlier quoted context omitted.

That gives you more rights than it gives me. I was always free to release my patch under the AGPL, why would I need you to do it? (well, if you do it I wouldn't have to maintain a fork, which is something I will admit). It would allow you to maintain a proprietary product with proprietary features that you don't release under the AGPL and use my code within that product. I like reciprical licenses, if I get code from…

Totally fair, thanks for responding! > It would allow you to maintain a proprietary product with proprietary features that you don't release under the AGPL and use my code within that product. As much as I can say "everything in my version is AGPL; this is just for _other_ companies" I don't know that there's a way to _legally_ guarantee it that wouldn't be easily circumventable, at least not without rendering the id…

Yeah, I thought about that, and unless you form a nonprofit with explicit governance requiring the release to all code, and the CLA is to the nonprofit, it would be difficult to guarantee. Even the nonprofit route isn't a guarantee, which is why I would evaluate each organization separately for their history and governance. It would likely take some time for a new organization to develop the reputation.

Re: Elasticsearch is open source, again

#452
post #376

Earlier quoted context omitted.

I'm saying that companies that opensource their products tend to distinguish "enterprise" and non-enterprise based on things like RBAC and audit mechanisms, neither of which is "security" as much as "compliance". The original license owner, if a commercial enterprise trying to sell the product alongside the "open" version, has less incentive to accept those features from the community as it would reduce their sales o…

RBAC is absolutely a practical security control, even for non-commercial users. Least necessary privilege is not a checkbox, it will 100% save your butt in a breach by limiting blast radius.

Sure. But for smaller users it's easier to breathe the accounts by hand rather than manage an entire active directory installation.

Re: Elasticsearch is open source, again

#453

Earlier quoted context omitted.

Or worse, "SSO" as an Enterprise feature. You're a 2-3 person startup, you set up GSuite, you want to set things up right, oh, "$Call us" for a tier with SSO. Nope, I guess disparate users for now. Not the worst in the world to be clear, but an entirely arbitrary gate, in my experience.

Yeah, the SSO gates are common and borderline criminal. "The only way you can use our software is insecurely"

I have long held that view also, although the post below about the cost of supporting SSO was interesting. Unlike withholding SOC2 reports which cost nothing to incremental to give to your lowest tier, SSO may increase the cost of support. I wonder how it would go offering SSO as an addon to entry level tiers that covers the incremental support cost.

https://news.ycombinator.com/item?id=41304228

This SSO cost post is also interesting:

https://news.ycombinator.com/item?id=40752518

Re: Elasticsearch is open source, again

#454

Earlier quoted context omitted.

Out of curiosity, did you pursue a rev share model with Elastic (Co) for your Elastic managed service? I guess that's not something thay can be discussed openly but recognizing you probably had 10x their revenue in the managed service and another 10x their revenue in compute behind the OSS, I wonder if there could have been a proactive happy middle ground found years ago. I suppose that they might not have accepted s…

Why? Does Amazon rev share with Red Hat? Does Google rev share with Linux? Or is it the other way around, should perhaps Linux instead pay Android for putting their product in front of billions of eyeballs? I'm sure there's a way of monetizing a billion users even for a kernel. The answer is no, because Linux is open source. It is a multi stakeholder model where no single actor is allowed to control other actors use…

This is why Amazon, Red Hat and Google all can justify to employ hundreds of engineers all contributing to a common product. Amazon can work on security functionality with no risk that Red Hat will veto it because it threatens its revenue stream. And while none of the top kernel developers have made billions from their important work, they still earn well, and all the mentioned companies have grown to become billion dollar companies.

This can't be stressed enough. OSS does monetarily work for the developers too. FAANGs love paying top dollar for OSS maintainers.

Re: Elasticsearch is open source, again

#455

It's an interesting move for sure but I don't think it's enough. A move back to the Apache license would open up the landscape for a reunification with the now dominant fork, which is Opensearch. But that's not going to happen with AGPL + copyright transfers. AGPL + copyright transfers vs. SSPL is a choice between getting stabbed or shot from a legal point of view. It's a hard no either way for a lot of corporate leg…

I was scared away as a plugin developer when Elastic changed to closed source, because the plugin that I assembled was based on third-party code and can only licensed under AGPL. Fun fact is, I could now resume my plugin development, and provide the code in the open with future Elasticsearch versions. But will I do it? I am also frustrated and my trust was violated.

The point is, having Opensearch as an alternative is finding answers to my question to resume Elasticsearch development not easier than before. All the positive aspects are still counting for Opensearch. It is true that AGPL is not enough.

While I do not think there will ever be an effort by the Elastic company to join Opensearch or embrace the Opensearch community, it seems to me the license switch to AGPL was driven by the analysis that Elastic's product offering can not be copied any more by hyperscalers. It was a mere question of the exclusiveness of the cloud service offering. That collided with the Apache license once. But now, it is clear that Amazon will never switch back to the Elastic stack as their primary cloud service search product.

Re: Elasticsearch is open source, again

#456

Earlier quoted context omitted.

Out of curiosity, did you pursue a rev share model with Elastic (Co) for your Elastic managed service? I guess that's not something thay can be discussed openly but recognizing you probably had 10x their revenue in the managed service and another 10x their revenue in compute behind the OSS, I wonder if there could have been a proactive happy middle ground found years ago. I suppose that they might not have accepted s…

Why? Does Amazon rev share with Red Hat? Does Google rev share with Linux? Or is it the other way around, should perhaps Linux instead pay Android for putting their product in front of billions of eyeballs? I'm sure there's a way of monetizing a billion users even for a kernel. The answer is no, because Linux is open source. It is a multi stakeholder model where no single actor is allowed to control other actors use…

As a matter of fact, yes, AWS rev shares with Red Hat, SUSE, Canonical and the likes.

Re: Elasticsearch is open source, again

#457

Earlier quoted context omitted.

RBAC is absolutely a practical security control, even for non-commercial users. Least necessary privilege is not a checkbox, it will 100% save your butt in a breach by limiting blast radius.

Sure. But for smaller users it's easier to breathe the accounts by hand rather than manage an entire active directory installation.

RBAC and Active Directory are different things.

Re: Elasticsearch is open source, again

#458
post #231
post #13

Earlier quoted context omitted.

To be honest, the OpenSearch brand has more value now than Elastic.

I think it's nuanced. I'm currently managing an engineering team on an interim basis. During standup I noticed that most engineers were talking about 'elastic' or 'elasticsearch' but one was talking about opensearch. I asked them to clarify that for me and they told me that they transitioned to AWS opensearch but still use the old name for the product often - that might point to the strength of the Elastic brand.

"Elasticsearch" seems to be often referred to as a technology, as in ELK stack, rather than as in "Elastic" the company.

Re: Elasticsearch is open source, again

#459
post #347
post #5

Earlier quoted context omitted.

what is preventing AWS from dropping OpenSearch and going back to just selling Elastic ?

Recently tried OpenSearch, it has good momentum but tbf the tooling / documentation and support are not that great. Contrary to what other people are saying in this thread, I would not say it has better branding than ElasticSearch and that ES has lost its battle. Outside AWS OpenSearch is still not a big contender

You're right about documentation and tooling. There's some good momentum in the OpenSearch community around it though, and I am really excited by things like https://github.com/opensearch-project/documentation-website/....

Re: Elasticsearch is open source, again

#460
post #171

Earlier quoted context omitted.

Plus they lost all trust now. Who's to say they won't pull the same thing again if developers were to come back? It's not like they stopped requiring a CLA...

To be fair, though, every project of a certain size requires you to sign away your rights via CLA, so I don't think that can be held against them. (Though I admit, dispensing with a CLA would be an amazing gesture of good will.)

OpenSearch only requires DCO.

https://github.com/opensearch-project/.github/blob/main/CONT...

Post reply on HN