Open Source Software Licensing – Dotan Horovits, Logz.io
Dotan Horovits, principal developer advocate for Logz.io, shines a light on the dark side of open source software licensing.
Transcript
This is texturung TV. Hey guys. Thanks for the throw.
io. And we're going to be talking about the Dark Side of Open Source software. Don't welcome the show.
Thank you. Glad to be here Michael. All right.
So what is the dark side? Because everybody in his brother thinks, you know open source software is the gift that keeps on giving so what are the things we should be on the lookout for? Yeah, so for all I'm a big believer at an open source and advocate of Open Source software and Open Standards.
And so I'm definitely all in favor of using open source, but my point is that many people treat open sources just a license and are unaware of other aspects of what open source means so they find some tool that is of Open Source license Apache MIT BSD. 0 for instance open source license so fine and will suddenly and no open source license database and then what exactly are you supposed to be doing and the database is a Example because it typically is in the heart of your system. It's critical Mission critical component.
So definitely not a convenient situation to be in so these are sorts of situations that I'm trying to make sure that people are aware of this seems to be happening more frequently because there's tension between the developers of the open source software and people who provide cloud services using it. So there's a lot of folks changing the licensing terms right now to make sure that all the money doesn't quite flow to the cloud service providers. So do you think we'll see more of this?
Yeah, so I definitely we see more of that and when you say people unfortunately oftentimes it's vendors. So it's commercial entities that decided to go down the open source path, but then at some point couldn't I guess build a sustainable business model and came to situation they perceive as as a competitive with obviously with their commercial competitors, utilizing the same open source. So definitely we've seen several of those in the past year or two by very prominent open-source projects such as a elastics grafana Loki and others and yeah, these are because of the great Community around each and every one of these obviously this makes the circle of impact of such decisions to realize or otherwise modify the project very impactful for many of the community members.
Do I need a tool to help me do the financial analysis of that impact or am I just looking to discover the instances of where I have this software and then I can figure out what the impact is from there. So I would say that it's very important to understand how when you choose the let's say you vet a new tool or even if you use already if you're already making use of some tools or platforms. It's also valid to make this assessment first understand the licenses because even within the open source realm all not all licenses are born equal some licenses are for example, the GPL licenses are copy left licenses that have infectious nature and in there as I said the categories a lot like elastic search and and Mongo DB and others that are not open source at all, but they sometimes get confused because it's a folks been Source license.
It's what people some some people call it Source available eyes. And so because people see the source code they assume it's also open source, but Source available is not open source by any means so it's very important for people. First understand the types of licenses and make the distinction and then find the right license to them and then understand also as I mentioned who's behind the open source license, but as I mentioned it could be a vendor that is close to a conflict with a cloud vendor or something like that that distention May roll into some decision to relicense or otherwise modify the access or something like that.
So I would say these are the prominent steps to to understand and the what's the license really about who's behind the open source or maybe the last pieces what's the governance policy behind that so who can actually impact who can grab control obviously ultimately who can make a decision such as a relicensing or other in material decisions. This is in the evaluation stage and then maybe we can touch upon when utilizing open source what you can do to keep safe as possible in that. Who is in charge?
Of tracking these licenses. Is it really the developers or is it somebody else in these organizations in the finance team? Who should be responsible?
Where does the onus for figuring all this out? Really lie? So on the licensing front definitely you need to consult with your legal department understand the fine print in the in the licenses.
I'm not a lawyer myself and even though I know quite a bit about open source licensing I go myself and consult with with the legal department. But then as I said, there's also the aspect of how to manage that in a day to day and usually This falls under the Realms of what typically is known as the dev and devops practices and when software is being updated for instance oftentimes developers want to do as much automation as possible because the stocks are being more elaborate working in Cloud native environment and so on but automation has a price and if you don't put the right gating within the process when you upgrade to check that maybe the license has changed and while upgrading you may find yourself in in awkward situation with new license. This is something that needs to be taken under advice.
So with all due respect to the automation the what is going the cicd pipelines continuous delivery continuous integration. You need to put the propagate in just as you do with for a security and cyber concerns same for let's say licensing exposure being very clear in making sure that you get the right licensing and if licensing changes this needs to be addressed stop the process of upgrade and take the right consultation and also manage the third party licensed exposure because sometimes even a small component within your system may have a license that these infectious in nature that is copy left license that may impact your broader system without you intentionally planning on doing that. Good.
Do you think that people will wind up swapping out open source software components because of these licensing issues and that becomes something of a major devops headache when that occurs. I think that it's definitely a concern to many many organizations for example in the case of elasticsearch that used to be very very popular and database and many have turned to different alternative paths to remain in the open source path. And actually that was the story behind the open search a new project that came about started as a fork of open search of elastic search in Cabana and now is an independent project under Apache Toto open source license and people migrated to from elastic just to remain within the open search around and I think the awareness will grow I know I'm not saying that people will stop using open source definitely not people like open source developers, like open source the trust open source, but we need to mature up in the way that we look at open soul and open those tools and Frameworks beyond the license and understand the complexity and make more intelligent choice.
Vetting and also more intelligent use of that making sure that we manage our licensed compliance checks manage the licensing exposure and and so on and by the way, it's important to say it's not just material for vendors. It's also material for other open source projects, for example, the cncf the cloud native Computing Foundation as issued at the directive to all of its It open source projects not to use for example a GPL a licensed open source, because that contradicts the licensing directives of the cloud native Computing foundation. So even another open source tool may be impacted by Being imposed by licensing that it did not intend to utilize so it's definitely a concern both for vendors and for other open source projects.
There are only licensing models sustainable or do we need like a summit where we all come together and say let's sort this out once and for all I think there's enough of a variety of Licensing for vendors to choose the right path for them some more and let's say least restrictive like Apache to the Toto and MIT or some more restrictive, but I think the more important concern on the vendor side is to understand that open source is not a business model. If a vendor decides to go down and open source path the vendor needs to understand open source means that others can utilize that can can modify can take it to their own needs. It could also be competitors.
So the model needs to be sustainable in a way that the open source can have its own community and its own value where the commercial part. Has its own independent value independent of the open source, it could be a managed version of the open source as a SAS. It could be additional Enterprise Edition with additional guarantees or many other models that exist out there, but the the business model needs to be well constructed not to drive this conflict between the competitive side in the business and the community side of the open source.
Do you think there needs to be some sort of gate in the devops process to evaluate the licensing before developers just start making something part of a build. I mean, how do I go about managing this on a practical level? Definitely.
I I that's this exactly what I'm trying to advocate for people when choosing when vetting a tool or framework. It's not just about something being shiny and sexy and I've heard the the other startup next door using it. It needs to undergo a very meticulous evaluation, obviously for the technology the technical feature side aspect that is taking for granted but also for the licensing aspect and there we need to look in the financing.
We need to look in the the legal as I said and also on the devops side to understand if this is something sustainable as part of the ongoing continuous integration continuous delivery flows, if it's something that they can actually integrate easily and the licensing model supports the licensing scheme of the software that is being hosted whether it's another open sources, I mentioned or a close source and understanding the broader picture Behind it which by the way not only vendors let's let's be honest it could you know open source can go Australia. So with an individual contributor behind it. js Frameworks colors and Faker that went astray with the Rogue commits that broke the libraries because of financial constraints on the side of the the maintainer behind this project.
So having a single maintenance a single point of say, yeah, and this is also something that is less desirable. So understanding there is a diverse set of maintainers that can sustain it that is not held by a single entity a single vendor for example that the governance policy and make sure that no single entity takes ownership and is very clear and transparent way to make a material decisions in the project such as relation thing, but obviously about also other decisions such as promoting maintain. Winners and who has access to to a review PRS and other aspects.
So governance policy is a material part of Open Source. Not just the license itself. All right.
So I think what you're kind of saying is that open source software is like that proverbial free puppy, right? So there's nothing quite free about it. You gotta maintain it and pay for it as we go along.
So do you think people understand that that's the level of commitment that they're making? I think that what's what's confusing about free is that the free is not free in the sense of doesn't cost anything freezing the sense that you have the freedom to take it and make use of that as you see fit and this is what gets people confusing because they said okay I get a free free softener. It's not free you need to invest you need to invest in in the skillset within your company you need to invest in your ci/cd pipelines to integrate it in an intelligent manner.
But if it's true open source, then you can take it and you adapt it to your needs you can invest in in what we've done for example in my company it logsdot IO to just to exactly customize it to our needs to our customers to our workflows. And that's the beauty you have the the open source at your availability to modify not just to see that's the source available that actually take it to your own use cases. And that's the magic when you have that in the hands of skilled software Engineers.
You can do wonders. All right. Hey, don't thanks for being on the show.
Thank you very much. Michael Pleasant. All right back to you in the studio boats.