Skip to content
Stribog

§02/OSS-AS-DISCIPLINE

Open source as method

Writing on open source as a discipline — inspectable tooling, supply-chain integrity, contribution fluency, and independence from any single vendor.

This is the smallest collection here and the most opinionated. It treats open source as an operating discipline rather than a procurement category: the question is never whether a licence file says Apache, it is whether your team can read the code, rebuild it, patch it under pressure, and keep running if the upstream company changes its mind.

A recurring subject is what happens when it does change its mind. Several of these articles were written because a widely deployed project was gutted, put into maintenance mode, or archived outright — and teams discovered that their exit plan was a slide. The rest are about tooling whose internals you can actually inspect when something breaks at 3am.

Start here

Replacing MinIO: Ceph vs SeaweedFS vs Garage

A default component archived by its vendor under an unchanged licence — proof that AGPL is not a governance guarantee — and the migration paths that were actually available.

When the vendor changes its mind

Four dependencies that stopped being safe to stand on — one archived by the single vendor that controlled it, three rented services whose pricing or operating model stopped making sense. Read these before assuming any of yours is permanent.

Inspectable by design

Tooling whose value comes from being readable at the layer where it operates — kernel-level networking and detection, and attestation you can verify rather than take on trust.

A supply chain you verify yourself

Consuming open source at scale means proving what you shipped. Signing and admission control, secrets handling that survives review, and resilience you demonstrate instead of assert.

Replacing the rented layer

Straight substitutions for services most teams pay for by the seat or the gigabyte: CI and the registry, mesh VPN, bare-metal ingress, and the retrieval tier under a RAG system.

All 25 articles expressing this pillar

Executive Briefing

Thirty minutes to clarify your infrastructure risk

Walk us through your vendor footprint and regulatory constraints. We will tell you honestly where sovereignty creates leverage — and where it does not. No pitch deck. No obligation.