The biggest problem I see is that you can suddenly become non-compliant just because Hashicorp decides to release a new service (i.e.they start competing with you, rather than the other way). It can be a huge risk for companies.
The FAQ covers this:
- If I want to build a product that is competitive with HashiCorp, does that mean I’m now prevented from using any HashiCorp tools under the BSL license?
No. The BSL license does not prevent developers from using our tools to build competing products. For example, if someone built a product competitive with Vault, it would be permissible to deploy that product with Terraform. Similarly, if someone built a competitive product to Terraform, they could use Vault to secure it. What the BSL license would not allow is hosting or embedding Terraform in order to compete with Terraform, or hosting or embedding Vault to compete with Vault.
So if you are selling a product and HashiCorp releases a product which competes with yours, you can still use Valut, Terraform, etc the way you had been. I can’t see a way for your senario to play out based on their FAQ.
So it would seem it’s always a good idea to contact them, get a commercial license or custom licensing terms (they do seem open to that from what I gather here and here) before building a business on top of their software.
Probably works well if you are an established company, but why would e.g. a startup pick licensing headaches over the competition? I imagine bigger companies would also rather just move to e.g. CDK or ARM if they don’t need multiple providers (at least our company started discussing this today).
What kind of “custom licensing” do you anyway think a 5-person startup would get?
I appreciate Grafana going in the opposite direction and relicensing under the AGPL. it largely serves the same purpose but it provides a stronger guarantee for users.
This is the 2nd of such moves this year to my knowledge; first there was #Lightbend and #Akka and now this. What a year for #FOSS 😕
I know for a fact that so many organisations use #hashicorp products for commercial purposes w/o ever contributing back. And I understand how this may feel for hashicorp in these harsh economic times. Though this still is, IMHO, a cheap move: they used an OSS license for a very long time which resulted in a massive user base and a “soft” vendor lock-in, and now they decided to milk that user base.
Looking forwards to solid community-driven forks of their products 💪
was about to include it in my stack, guess i wont be now.
What does this mean?🤔
Given I was recently involved in minimising the impact of Lightbend’s similar move earlier this year, AFAIU it means their products will be conditionally open source. They’ll be free to use for non-commercial use but you’d need to pay for anything else.
There’s no need to AFAIU when their FAQ explains all the detail, which is that commercial production use is fine as long as you’re not using it to build a competitor product to Hashicorp.
There is no such thing as “conditionally open source.” The license terms you describe are just “not open source.”
If they actually gave a shit about commercial entities contributing back, they should’ve gone AGPL3. This is just a money grab and yet another example of how permissive licensing isn’t good enough and everything should be copyleft.
You’re conflating FOSS and open source. This is open source just not FOSS anymore
Its still open source. You can still view the source code. That’s what open source is. The change here is the restriction on providing Terraform as a service in the form of a Terraform Cloud competitor. This seems to be a very direct response to Amazon introducing a service for hosting terraform modules, storing terraform state, and applying changes.
I don’t love this, but they’re also not restricting anyone’s comercial ability to develop products using terraform like a banking app, a link aggregator, or a e-commerce platform. All you’re restricted on is providing an IaC service where you directly profit from running someone else’s terraform for them. This is the same license the MariaDB creators came up with when they felt burned by Oracle but did want people to be able to build closed source products using their database without profiting from providing their db as a service (this is why many self hosted projects use Maria instead of MySQL) which is why AWS can’t offer maria RDS instances.
AGPL wouldn’t help them keep developing terraform the way BSL would because their business problem isn’t that no one is contributing back to the code, their problem is a $1T market disruptor just turned their Sauron eye towards Hashicorp’s $5B shire and offered their own shire for less money behind the black gates. All after for many years directly benefitting from Hashicorp’s existence and giving them white glove treatment as a result. And yes I’m aware that in this analogy Hashicorp is probably one of the Nazghul being corrupted.
Like I said. I don’t love this license change. But like I said. Hashicorp doesn’t have a code contributions to Terraform problem. They have a funding their business and development problem
It basically means you can view the code, which is the literal by-the-word definition of open source. It’s not the common understanding of open source, which would be free-to-use (with some minor restrictions like attribution or publishing derivatives under the same license).