第 16 章
Chapter 16 The Cathedral’s New Stewards (circa 2019-2022) (c. 2019)
The boardroom was quiet, save for the hum of the air conditioning and the faint click of a trackpad. The quarterly meeting of the Open Source Initiative’ s directors, convened via video link in the spring of 2021, proceeded through its agenda with practiced efficiency. Item four: ratification of updated trademark usage guidelines for the OSI Approved License mark. Item five: review of corporate membership tier benefits, with a discussion on enhancing platinum-level visibility at industry conferences. Item six: report from the license-review committee on the continued applicability of the Open Source Definition to emerging licenses concerning ethical use and non-discrimination clauses. The conversation was technical, procedural, and calm. The moral fury that had once crackled through every syllable of the movement’s founding documents—the righteous anger against proprietary hoarders, the declaration of a user’s inalienable right to study, change, and share—was now a distant resonance, absorbed into the dry language of compliance, governance, and sustainable funding. The revolution was not over; it was on the calendar, penciled in between subcommittee reports.
“Free software is a matter of liberty, not price. To understand the concept, you should think of ‘free’ as in ‘free speech,’ not as in ‘free beer.’”
The words were Richard Stallman’s, published in the GNU Manifesto of 1985. They were a philosophical lance, aimed at the heart of a commercial software industry built on secrecy and control. They spoke of freedom as a first principle, of communities bound by ethics, of software as an expression of human cooperation rather than a commodity. For decades, this clarion call had animated a global movement, inspiring licenses, projects, and a profound reimagining of how technology could be built. By 2021, those same words read like a scripture preserved under glass—venerated, quoted, yet functionally separate from the operational reality of the world they had helped create. The movement’s foundational ideals had not been repudiated. They had been rendered ambient. They had become the atmosphere in which business was conducted, infrastructure was deployed, and value was extracted. The moral crusade had won by becoming indistinguishable from the landscape it sought to transform.
The outcome of this transformation was a state of profound, normalized integration. The shock of Microsoft’s acquisition of GitHub in 2018, which had sparked waves of protest and existential dread within the community, had faded with astonishing speed. By 2019, the migration of critical projects from GitHub was a fringe activity, pursued by a principled few. The vast majority of developers stayed. The platform’s workflows—the pull request, the issue tracker, the seamless integration of continuous integration tools—had become as fundamental to the craft as the compiler itself. Microsoft, once the archetypal villain of the free software saga, now stewarded the primary civic square of the open source republic, establishing an Open Source Program Office to formalize its strategy. It did so not by dismantling its practices, but by embracing and enhancing them, pouring resources into reliability, features, and developer outreach. The acquisition was not an invasion; it was a change of municipal government, one that kept the streets clean and the water flowing while quietly rewriting the city charter.
The protests subsided not because the concerns were invalid, but because the practical cost of exile—the loss of network effects, the friction of moving years of issues and contributions, the alienation from the de facto standard—outweighed the ideological premium. The sovereignty of the commons had been transferred, and its inhabitants, surveying the sturdy, well-maintained walls, chose to adapt their lives within them. This pattern of corporate stewardship extended far beyond a single platform. The digital economy’s foundational layer was now a patchwork of open source projects managed by, or deeply integrated into, the proprietary empires of Amazon Web Services, Google Cloud, and Microsoft Azure. The Linux operating system, the Kubernetes container orchestration system, the countless databases, programming languages, and frameworks that powered the global internet—these were built in the open, under permissive licenses. Yet their utility was most powerfully harnessed within walled gardens of cloud infrastructure.
A developer could use the Apache-licensed Kafka stream-processing software with perfect freedom, but its most scalable, managed, and economically significant deployments ran on AWS’s MSK, Google’s Pub/Sub, or Azure’s Event Hubs. The open source code was the raw ore; the proprietary cloud service was the refined, branded, billable product. The bazaar produced the ingenious clockwork; the cathedral—now a conglomerate of corporate spires—sold the telling of the time as a subscription service. This was not a betrayal engineered in shadow; it was the logical outcome of a model that had championed openness and pragmatism. The giants had not needed to seize the bazaar; they had simply built the most convenient, reliable, and scalable market stalls around its most popular goods, and the crowds had followed. This was not a failure of the open source model. It was its logical, pragmatic culmination. The inner workings of this new order were managed through a sophisticated apparatus of foundations, licenses, and developer relations programs that transformed collaborative zeal into a stable, governable utility.
The Linux Foundation, along with its subsidiary the Cloud Native Computing Foundation, stood as the paradigmatic institution of this era. Funded by millions in annual dues from corporate members spanning the technology and financial sectors, these foundations provided a neutral ground for collaborative development. They managed trademarks, organized conferences, and provided legal oversight. Their board meetings mirrored the OSI’s: agendas filled with budget reviews, marketing initiatives, and compliance discussions. The revolutionary energy of Linus Torvalds’s early kernel announcements, of the Debian Social Contract, was channeled into working groups and technical steering committees. The foundations were not malevolent; they were profoundly effective. They prevented fragmentation, reduced legal risk, and accelerated standardization. In doing so, they also institutionalized the priorities of their major funders. The roadmap for a project like Kubernetes was not set by the ragged collective will of a mailing list, but through a structured governance process where corporate-backed contributors, often full-time employees with clear strategic mandates, held significant influence. The chaos of the early bazaar was replaced by the efficient, well-lit corridors of a professionalized commons.
The license wars of the previous decades had settled into a stable, corporate-friendly détente. The fierce copyleft of the GNU General Public License, which sought to virally propagate software freedom by requiring derivative works to remain free, had lost ground to the more permissive Apache 2.0 and MIT licenses. This was not merely a technical preference. Permissive licenses enabled corporate adoption without obligation. A company could take open source code, embed it within a proprietary service, monetize that service aggressively, and contribute back only those modifications it chose to—often those that improved the core project in ways that also benefited its own competitive position. The GPLv3, released in 2007 as a response to the rise of hardware restrictions and software-as-a-service, had failed to achieve the dominance of its predecessor. The corporate appetite for a license that could restrict “tivoization” or mandate the release of service code was minimal. The pragmatic, business-friendly approach had won. Freedom, in its most demanding and ideological form, had been prioritized below convenience and scalability.
The choice of license was no longer a political declaration but a strategic calculation about the ease of adoption and the ecosystem one wished to attract. The result was an infrastructure layer that was universally accessible but also universally appropriable, a commons that enriched the public domain while simultaneously fueling proprietary advantage. This prioritization was evident even in projects that had once been flagships of the community-centric ideal. Canonical’s Ubuntu Linux distribution, which had brought free software to a mass audience with the slogan “Linux for human beings,” increasingly exemplified the trade-offs of the new era. By the early 2020s, default installations of Ubuntu included features that reported system metrics and search data back to Canonical for product improvement. Optional “relevant” shopping suggestions were integrated into the desktop search function. The discourse around these features centered not on a violation of user freedom—the code for these systems was often open, and the telemetry could be disabled—but on convenience, privacy settings, and opt-out mechanisms. The community was divided, with some seeing Ubuntu as a milestone of success and others a failure of representation, where convenience was prioritized over freedom.
The philosophical imperative of “free as in freedom” had receded behind the practical concerns of user experience and commercial sustainability. The user was no longer a citizen of the republic; they were a consumer of a product, one built on an open base. This shift mirrored a broader business reality: by 2022, an estimated 78% of companies reported running all or part of their operations on free and open source software. The value was no longer in the ideology itself, but in the operational efficiency and innovation velocity it enabled. The freedom was a means, not the end. Eric Steven Raymond, often referred to as ESR, is an American software developer, open-source software advocate, and author of the 1997 essay and 1999 book The Cathedral and the Bazaar. He wrote a guidebook for the Roguelike game NetHack. His 1997 essay had provided the defining metaphor for two opposed modes of production: the centralized, hierarchical, secretive cathedral of proprietary software, and the chaotic, collaborative, open bazaar of free software.
He coined an aphorism he dubbed Linus’s Law, inspired by Linus Torvalds: “Given enough eyeballs, all bugs are shallow.” It first appeared in his book The Cathedral and the Bazaar. Raymond had promoted this model with a strategy of “making rational, technical, utility-maximization arguments” while explicitly disclaiming any “normative or moralizing agenda.” The metaphor had framed a generation’s understanding of the struggle. Yet by 2022, the dichotomy itself had grown obsolete. The bazaar had not overthrown the cathedral. Instead, the most successful bazaars—the thriving open source ecosystems—had been annexed as vital quarters within the cathedral’s sprawling, corporate-owned citadel. The cathedrals now provided the plumbing, security, and global distribution networks that the bazaars relied upon. The eyeballs inspecting the code were now often employees of Microsoft, Google, or Amazon, paid to contribute during business hours. The law still held; bugs were found and fixed with remarkable speed. But the social and economic context of that scrutiny had fundamentally altered. The bazaar had become a regulated marketplace within a larger economic empire, its vibrant chaos now a managed asset.
The barriers to creating and sharing software had never been lower, thanks to the freely available tools and platforms. A single developer could launch a project on GitHub and attract a global audience overnight. Yet the success of that project increasingly depended on its alignment with the strategic interests of the platform owners and the major cloud providers. The most reliable path to sustainability was not through donations or pure community support, but through corporate patronage—a job at a foundation-backed company, a grant from a big tech firm’s open source program office. The passion economy of open source had been formalized into a career ladder within the very industries it had once opposed. For the corporations, open source was the ultimate strategic layer. It was a risk-mitigation strategy, dispersing the cost of core research and development across a global community. It was a talent-acquisition strategy, allowing companies to identify and recruit the most skilled contributors. It was a market-creating strategy, establishing standards like Kubernetes that locked in demand for complementary proprietary services.
And it was a regulatory and public relations strategy, painting the giants as collaborative stewards of the digital commons. Their internal memoranda from this period, where they exist, do not speak of embracing freedom for its own sake. They analyze metrics of adoption, contributions, and influence. They map ecosystems and identify critical projects for investment or forking. They calculate the return on investment for funding a foundation seat or hiring a key maintainer. The moral language of the GNU Manifesto is absent; the language of portfolio management and ecosystem governance takes its place. The question of ownership, once so central to the free software debate, had morphed into a more elusive problem of control. In open-source communities, the producer traditionally owned the development of the evolving software, making formal intellectual property difficult to assert. By the 2020s, this dynamic had been leveraged not by the community against corporations, but by corporations within the community. Ownership of the code was less important than control over the project’s direction, its integration points, and its official distribution channels.
The future of the open source community, successful yet confused about what it stood for, was now determined by questions of what open source should be and whether it needed protection. The movement’s foundational body, the OSI, held no legal authority over the term ‘open source,’ its definition a matter of social convention that had sparked a decades-long ‘culture war’ within software communities. To some, the OSI’s non-discrimination criteria were an oppressive dogma; to others, they were the last bulwark of principle. This intergenerational conflict played out as the community grappled with its own success, where open source had become the backbone of global digital infrastructure yet its soul seemed up for grabs.
A company could, without owning a single copyright, effectively steer a project through the weight of its engineering contributions, its control over the dominant hosting platform, and its influence within the governing foundation. The future of the software was still open, but the trajectory of its development was increasingly shaped by closed-door strategic planning sessions in Seattle, Mountain View, and Seattle. The ideological aftermath, therefore, was not a clean defeat but a vast, quiet diffusion. The movement’s energy did not vanish; it dissipated into the infrastructure itself. The commitment to collaboration was now embedded in a million automated workflows. The ethic of sharing was operationalized through permissive licenses and public repositories. The crusade was over because its battlefield had been paved over and built upon. The new stewards were not ideologues; they were administrators, product managers, and developer relations specialists. Their mandate was not to propagate freedom but to maintain stability, drive adoption, and ensure interoperability within their commercial ecosystems. This institutionalization reached its apotheosis in the mundane, automated systems of compliance and security that emerged in these years.
This professionalization of contribution was mirrored by a parallel systematization of consumption. The rise of Software Bill of Materials (SBOM) tools and automated license compliance scanners exemplified how the ideals of transparency and sharing were repurposed into risk-management protocols. Corporations, now dependent on thousands of open source dependencies for their own products, required guarantees that this freely available software would not expose them to legal or security vulnerabilities. Open source programs offices within these companies did not merely fund projects; they curated approved lists, mandated the use of specific permissive licenses, and established automated pipelines that rejected contributions or blocked deployments based on license policy violations. The freedom to study the code was thus funneled through corporate legal departments, which studied it primarily for potential liabilities. The shared commons became a supply chain, subject to the same rigorous, auditing gaze as any proprietary component. This was not a rejection of open source principles but their ultimate absorption into standard operating procedure; the revolutionary demand for access had become a checklist item for enterprise procurement.
The transformation of the developer’s relationship to their tools was perhaps the most profound psychological shift. The integrated development environment, the compiler, the version control system—once realms of personal sovereignty and often passionate DIY customization—increasingly arrived as managed services. Microsoft’s Visual Studio Code, an open source editor, achieved dominance not merely through its quality but through its deep, proprietary hooks into Azure and GitHub. Its stewardship under Microsoft changed contribution patterns, with the company’s engineers shaping its roadmap. The act of writing code became subtly but inexorably tied to a specific commercial ecosystem. The programmer’s creativity was facilitated by tools that gently nudged them toward cloud deployment, proprietary extensions, and paid tiers of service. The “bazaar” of tools was now a well-organized department store, where every free sample was designed to lead to a subscription. This environment cultivated a generation of developers for whom the frictionless integration of services was a higher virtue than the ownership of their toolchain. The pragmatic benefits were undeniable; the ideological cost was rendered invisible by the sheer convenience of it all.
Even the act of protest or fork, the ultimate expression of software freedom, was subtly co-opted by the new infrastructure. When a community grew dissatisfied with a project’s corporate steering, the path of least resistance was not to establish a wholly independent new republic, but to create a new fork within the same corporate-hosted platform. The fork would leverage GitHub’s familiar interfaces and social graph, ensuring continuity and minimizing disruption. In doing so, however, it reaffirmed the platform’s centrality and its owner’s role as the indispensable arbiter of collaboration. The rebellious act was hosted on the company’s servers, subject to its terms of service, and analyzed by its metrics teams. The platform captured the dissent, normalized it, and rendered it a data point in its own ecosystem health dashboard. This dynamic demonstrated the final, subtle form of control: the power to contain and manage opposition within a system so comprehensive that exit became a theoretical, rather than a practical, option.
The human cost of this managed ecosystem was often borne by the independent maintainer, the figure who had once been the romantic hero of the bazaar. Faced with the exponential growth of their project’s popularity, driven by corporate adoption, these individuals found themselves crushed between the community’s expectations and the lack of sustainable, ideology-aligned funding. Burnout became a rampant pathology. The solution offered by the new order was, predictably, institutionalization: the maintainer was encouraged to incorporate, to join a foundation, or to accept a corporate sponsorship that would provide a salary in exchange for aligning project priorities with the sponsor’s roadmap. The passionate individualist was thus transformed into a de facto employee, their creative autonomy preserved in name but circumscribed by the implicit requirements of their benefactor. The vibrant, sometimes chaotic autonomy of the bazaar was slowly replaced by the psychological framework of a gig economy, but one where the platform owners also set the terms of engagement and captured most of the derived value.
This pervasive integration reached its logical endpoint in the concept of “Inner Source”—the application of open source methodologies within the private, proprietary codebases of large corporations. Companies like Google and Microsoft mandated internal code reviews, encouraged cross-team collaboration through internal “forking,” and created internal platforms mimicking GitHub. The tools and culture of the bazaar were harvested to improve the efficiency of the cathedral’s own construction projects.
Companies built and released open source tools for scanning software bills of materials, checking for license violations, and patching vulnerabilities. These tools were essential for the safe, professional use of open source at scale. They were also mechanisms of control, defining the boundaries of acceptable use and enforcing a corporation’s interpretation of complex license terms. The freedom to run, study, change, and share was now mediated by automated legal checkpoints and security gates. The infrastructure policed itself, and in doing so, it rendered the original, human-centered ethics of the movement into a set of operational protocols. The quiet, bureaucratic management of the open source commons thus handed off the pressure of its total, ambient ubiquity as mere operation. The consequence was a world where the most radical idea in software history had become too essential to question, too fundamental to disrupt, and too deeply woven into the fabric of power to reclaim.
Its original spirit persisted not as a guiding force, but as a faint harmonic in the hum of the global build process, a historical echo against which every new commit was measured and found, almost invariably, to be compliant.