Strengthening Open Source with Mirantis’s Randy Bias and Shaun O’Meara
Randy Bias, newly appointed vice president for open source strategy and technology for Mirantis, and company CTO Shaun O’Meara, dive into why Mirantis is doubling down on open source software with the opening of a program office.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Randy Bias, who's the newly appointed vice president of Open Source Strategy and technology for Martis.
And we also have Sean Amira, who's CTO from Martis. Gentlemen, welcome the show, Todd. Its We do.
Thanks, it's Mike. All right. You guys have a new, uh, formal program around open source that Randy's gonna lead.
Randy, why don't you walk us through what's going on here? 'cause TIS has been around the open source space for all of its existence, so why do we need a new formal office and program? Uh, that's a great question.
Um, basically, you know, so I've knowns for a long time. We've had a relationship with the co-founders for 15 or so years before they even joined, uh, the OpenStack movement. Uh, and I've seen their evolution as a business, and in the early days they were very, very active, upstream contributor.
Um, they were making some key contributions in areas that were critical that made a difference to the communities. And all of that noise that we were making, uh, generated a lot of inbound customer interest. Um, and then kind of over time, um, we sort of, uh, walked a little bit away from that and became a little bit focused on our downstream products and, um, realized that it would be in our best interest to kind of go back to our original roots to be, um, the best open source community participant that we can be.
Um, and to lead through, uh, to lead in terms of thought leadership in each of these communities to really drive, um, the direction of things like Kubernetes cluster, API, OpenStack and so on. And so we decided to, uh, kind of reinvigorate our processes and open the open source program office and to kind of double down again on our roots. Sean, I think everybody has the same basic struggles when it comes to open source.
Where's the line between that which I contribute back to the project and that which I try to, uh, help customers with some sort of capability that I can monetize. Where is that line from Meranti? How do you guys kind of come to those conclusions?
Yeah, you know, it's always a challenge and, and as Randy mentioned, it's been a challenge for us for a while. Um, the reality is the way SYS is looking at today is to be good citizens of the community. We need to push as much as possible back into that community.
You know, we have a large enterprise customer base that we're, we're learning from. Um, we're helping them solve problems in the real world. So our policy as we move forward is to lean way more heavily into pushing everything into that back into that community, trying to hold absolutely nothing back, but making sure what we are pushing back into the community is stable and ready to go for enterprises.
Finding that balance point is going to be the big challenge that we're having Randy deal with. Um, I think he's, he's starting to realize the, the, the mountain that we're giving to him, but it's really important because we're taking that innovation and we're supporting that innovation that's being created across thousands of organizations that are contributing to open source. Um, and to be good citizens, we have to also provide something that infection back into the community.
It also gives our customers, at the end of the day a sense of safety, I suppose, um, that allows them to say, okay, they have a choice and they don't get locked into a single vendor model. Um, and as we see with some of the, the funny games happening in the market today with organizations changing, um, nevermind licensing models changing, but also large organizations creating lock-ins. We wanna give our customers to peace of mind that that won't happen going forward.
All right, Randy, to Sean's point, what is your assessment currently of the open source community? Because there are all these changes to licenses and acquisitions. What's your sense of where are we?
Well, there's a couple different pieces to that question, right? So there's the open source community as a whole, um, which I'll, I'll kind of respond to in a moment, but I just wanna point out that not all open source communities are the same, right? So, so, you know, OpenStack is different from Kubernetes is different from K Zeros, so it's not monolithic.
Um, but what we have seen is we've seen, um, a lot of businesses come out, um, and use open source as a way, as a business model to basically drive their own products. And then when they realize that, um, those products, um, anybody could take their open source and do something with it, they started to try to put moats and walls kind of around, uh, with using sort of this fancy licensing models that were just trying to be free. Um, even if they weren't open source, um, you know, we saw it with Terraform, uh, we saw it with HashiCorp and you know, basically we've also seen people kind of rebellion against that model and going and forking those projects.
And I think it's pretty clear that what the world wants, what businesses want is a hundred percent pure play open source, and they want companies like TIS to support that open source for One of the things we've heard for a long time now is that the organizations that are consuming open source aren't contributing enough back to those projects. Um, you know, it varies by project. Of course some have huge communities, but others are small and need help.
Sean, is there something that Ranis can be doing to maybe help enterprises make those contributions? 'cause I think part of the issue is just inertia and that they don't know how to contribute and they don't know where to engage. Um, I mean, that's exactly what we're trying to have do as Martis.
Um, this is a big part of what we've tasked Randy Bias moving forward. You know, we see the same challenge as internally for us. We, we have a huge number of changes, fixes, bags, new additions that we make to open source products.
But just finding the time, you know, balancing that need to deliver software to customers, deliver fixes to customers, and negotiate all the challenges of just contributing to community, getting accepted, frankly, the politics, um, sometimes getting code accepted in the community has a political edge to it because we're contributing with our competition in many cases, you know, with, that's who we're collaborating with, you know, from the commercial side of things, the reality is is foundations and the foundations like Open infra, the CNCF are a big part of that, and they have to take on the mantle of ensuring that the politics doesn't get in the way of those contributions. But from us, to answer your specific question, how do we help our customers? We help our customers back, allowing them to contribute through us back into that, into those communities.
They're always legal challenges. We help negotiate those legal challenges. We take on the mantle of, say, if we have a customer who creates code, makes a fix themselves within the base, we can then work with them to balance that, validate that, and make sure there's nothing in that they don't want to share and then contribute on their behalf.
Um, very often giving them credit for it, al always giving them credit for it. So that's how we balance it today, and we've been relatively successful with that. Randy, in your experience, um, the smaller projects, there seems to be the places that we're having the most challenge with these days.
What is your best advice to those people who have a project that others have picked up and used, but you know, there's still a small team and there's more people kind of banging on their door for security patches and whatnot, but is there something you see among the maintainers that, um, you wish that they might, uh, consider? Uh, I, why, I'm curious why you think that there's more of a challenge for the small communities. I I kind of see it the other way around.
I feel like there's more challenges for the larger communities. Well, you could be right, but the, the wrap is that the Linux community, for example, has tons of people contributing and there's tons of peers. And, um, that community is more self-sustaining than what we saw maybe with say Log four J, where it was just a handful of people who were rapidly overwhelmed and probably surprised how many people were actually using their self.
I see. So, uh, the, uh, the downside of sudden success, catastrophic success, right? Um, you know, I, I think for small teams, you're right.
You're, you're just going to have to figure out some way to rate limit things. You're just gonna have to throttle it, and you're gonna have to point out to people who are coming to the community who are consumers only and aren't contributing back, that if they want things to be different, they're gonna have to pony up resources. I think that's sort of just an ongoing challenge for all communities, right?
Everybody who uses open source doesn't contribute back to it. There's, and, and there's no way that that can be true, right? You've got a mix of people who are consumers of the software, people who develop the software, people who are consumers and developers of the software.
And in the case where you suddenly get a lot of consumers and you've got a very small number of developers, you're gonna have a challenge. And I think that you just have to rate limit kind of the request in the community and basically create a forcing function for those consumers to point up resources to help you out. And I would poit you should also probably consider, and, and for example, uh, for Jay, we, we a while back spoke to the, the developers there, you know, somebody who's a fantastic developer, it's not always gonna be a fantastic community manager.
And this is an opportunity for you to partner, um, come, come talk to organizations like, like Marias, come talk to organizations like the C ncf f talk to those organizations that have customers that are using that software, um, using the code, and then ask them to support you. In many cases, we would happily step up and do that. I think that's also another opportunity.
The risk to our customer base of a piece of code, which is core Log four J is a good example where there are two developers globally who are trying to keep up with a huge amount of demand. Don't take that risk on yourself, ask for help. You'll find that the community will step up and, and find ways to help you, whether it's financial help, guidance, governance, um, and that's where we would also like to, you know, have the community look at us that way.
Um, we don't need to own it, we don't even need to the rights to it, but we also need to understand that those things are very important to our customers and we'll find ways to support our customers. Randy, I think a lot of people when they think about contributing to open source, they're like, well, you know, I don't really write code and it's not really my thing, but, um, there are other ways to contribute. Are there not, I mean, it seems like community needs as much help with everything from documentation to managing the politics.
So are people kind of having a narrow focus on what they can contribute? Uh, I mean, in my experience, um, lines of code and development is sort of the least, least of your problems. Um, I took over the Tungsten fabric community and forked it from the Linux Foundation into open SDN uh, last year.
That's a very small community. When it was under Linux Foundation and Juniper, uh, Juniper Networks was, uh, contributing. There was a lot of activity.
Now there's not so much. And, and where I'm hurting running the small community is all documentation, bug fixes and code reviews and all this small stuff around the edges, right? So, um, I'd say that code contributions are the, the lowest priority, usually Sean, everybody and his brother's watching what's going on with AI these days.
How do you think the open source community will evolve around AI and all these LMS that are floating around out there? Because historically, at least, uh, over time, open source will end up being a better driver of innovation, but will that play out in the realm of ai? Absolutely.
I think we're seeing it already. Just look, look at the community of tools around the AI space. You know, investing in, in large language models, which is all the rage right now, is incredibly expensive, you know, and that's not really something open source communities are gonna be that, but the ecosystem around that, everything from the vector stores to a great example is something like the Lang chain community, the tools that support and extend that OpenAI space or what that AI space or what really are making the difference.
That's what's making it accessible to everyday developers. And we're, we're starting to invest there ourselves. We're spending a lot of time there.
We're looking at how we can leverage those tools within our enterprise products to make the operational experience better. And it's all enabled by open source communities. The big ones are smaller companies that are getting, that are fully open source, like from DB or, um, as I said, the Lang chain community, um, and many others, uh, companies like HuggingFace that are, you know, really encouraging that community saint around development and work with right now, lms, I say all the range, but there's a whole world of machine learning out there that's really being accelerated for it by the community today.
Randy, does the community need to rethink how it operates in the age of ai, or is the current structure where we have all these, I don't know, thousands of flowers of projects that are all doing their thing and we all benefit from that because everybody's pursuing their passion, but, um, I can't help but wonder is, is AI evolves when we need more sharing of data and integration if the communities need to maybe work a little more closely together? Yeah, I mean, the opportunity with ai, uh, in open source is, is huge. And I don't just mean the ecosystem like Sean was talking about, but I mean, the leverage we can get from it, the, it's just another tool.
People seem to get wound talking about things like, um, now there was one community, I don't recall who it was, but ba they basically said, you can't contribute back any AI generated code if you played with any of these tools. You see that you can use them to accelerate, you know, your development cycle. I, I've been getting a lot of leverage from them.
So is my code bad because part of it was generated by ai? I don't think so. What about the opportunities to have AI assess security vulnerabilities and tell me about whether it's something I said should patch sooner or later.
What about it helping with code reviews, basic code reviews? Like is this in the correct format? Is it to our coding guidelines?
I mean, there's a bunch of ways that the open source community can get leveraged from AI to actually bring some of this workload down. Um, you know, we're just talking about log four J being overwhelmed. I, I don't know the details of that, but, you know, there are opportunities when we see that happen in smaller open source communities to get leverage from these tools.
And I think the really important thing that you were talking about earlier is, hey, documentation's a pain, especially for develop AI makes it easy. Um, some of the tools that we're using day-to-Day to ride code, accelerate that cap those capabilities. We need to, we need to be, we need to get out of our own way in many ex in many cases, um, we can start arguing and acting a bit like we are in the creatives industry and saying that it's taking our jobs and no, it's making our jobs better, whereas not faster.
Randy, there's not always a lot of trust between the hardcore members of the open source community and the vendors that are in that community. How do you kind of bridge that and get everybody to kind of realize that maybe they are working together towards the same goal? I I mean that's, that's a challenge, but we've already seen some interesting moves there, right?
Red Hat or IBM Run owns Red Hat now, right? They were the 800 pound gorilla. So, um, you know, I, for, for somebody who, you know, led the open source initiatives at two of the big vendors, EMC and and Juniper Networks, um, I can say that there is a large amount of variance across those vendors and how they engage with open source communities.
Some of them have been very good from day one. Um, some of them have to be, Microsoft has learned to be a great open source citizen, right? And, and there was huge tension between Microsoft and open source community in the early days.
So, um, I really don't think it's a, a one size fits all. It's not vendors or open source. It's learning how to work together and it's just a ongoing process and evolution.
Um, and, um, that's the role of people like myself and other OPOs at other, uh, businesses to basically continue to, uh, level up the understanding of why open source is good, how you use it, uh, to make yourself successful, and how you be a good open source citizen as you do that. Sean, is there some paradox at work here? Microsoft is more open and contributing more and more other traditional open source vendors are pulling in their horns and being less open.
So what's going on in ultimately? I think this is the, the, the typical ebb and flow we see in the industry. I mean, everything comes around, uh, you know, companies like Microsoft, I'm very happy to see them being a lot more open.
Um, and frankly, they're in a position to be able to afford it. You know, contributing to open source doesn't come for free. Um, the oldest arguments in the book, we keep going, oh, oh, it's open source.
It must be free. Certainly not the people writing that still have bills to pay. At the end of the day, what it means really in open source is, is open access and sharing the load.
Um, and if companies like Microsoft can take more of that load, um, and smaller companies that have you open source routes, um, are not able to at the moment, that's fine. It'll ebb and flow. Um, we just need to make sure that we're, we'll continue to keep the ethos of what open source is about available to everybody and giving people their ability to choose.
That's really what open source is about. It's about choice, and we need to keep that choice open. Yeah, I think it's critical to remember these are, these are public comments and it's just like any other public comments, right?
Like the more the people kind of work together to make it better, the better it is for everybody. And you know, they're just littering on the ground, so to speak in a park, you know, you're making it worse for everybody. So it's about sort of that collective good and the more collective good there is, the more collective good for all there is.
All right folks, everybody needs to remember that we are all part of a larger community and act accordingly. Gentlemen, thanks for being on the show. Thank you.
Cheers. Thank you. All right.
And back to you guys and the student.