Sustainable Practices in Open Source Software with Brian Fox | Open Source Summit NA 2025
Brian Fox discusses the responsible use of open source software is essential for sustainability. The reliance on cloud infrastructure incurs costs that many users overlook, leading to irresponsible consumption. Organizations are encouraged to manage repositories effectively and support open source projects. Awareness of infrastructure costs is vital, and best practices include reviewing pipelines and optimizing resource usage to promote responsible consumption.
Transcript
Hey, everybody. Welcome back to the Open Source Summit in Denver. We're here with Brian Fox, who's CTO for Sonatype, and we're talking about well responsible use of open source software and responsible consumption, because after all, gluttony is still a sin.
Brian, welcome to Show. Yeah, thanks for having me. So, it's clear there are lots of folks using more open source software than ever, and a lot of that resides on infrastructure that somebody has to support, but that's not free.
So how do we kind of come up with an economic model that works in a way that, um, enables people to enjoy the fruits of the labor, but not take advantage of all the kindness? Yeah, I, if I had the answer to that question, I, I, I would certainly solve it for everybody, but I, I think, you know, part of it starts with just responsible consumption of, of what's out there. And I think, you know, if, if we, if we go back quite a ways to, when I first got into open source, you know, the, the, the thing that needed to be donated was your time because you were largely using computers.
You already had, you're already paying your power and internet bill. They weren't really incremental costs for you to contribute to open source other than just your time. Right?
But fast forward to 2025, and, you know, it's generally frowned upon if you release an important project from your own personal computer because it might be, might be hacked, right? You, you don't know the trust it. So we've, we've modernized our practices to the point where all of these open source projects, everything is dependent upon, you know, CICD in the cloud, right?
And GitHub actions, GitHub, you know, sponsors lots and lots of machine and compute time for, for GitHub projects to run their builds. And lots of other companies do it too. You know, Sonotype, we run the Maven Central repository.
We, we pay for the bandwidth and all these things, but I think people have, they don't recognize the underlying cost because all these companies are bearing that, that burden, right? And so it, it's led to this sort of sort of, uh, mentality, you know, the gluttony mentality of it's all free. And so I'm just gonna run my build as many times as I possibly can, every commit I'm gonna run a, a pretend release.
And, and so what I'm, what I'm seeing when I really look at this is I'm seeing really just frankly irresponsible consumption by, by, uh, individuals and, and companies, big trillion dollar companies that really should know better, right? And are just eating up all of the resources that are causing every company that has to donate this stuff, um, to have to put in more till, you know, I'm worried that eventually it, it all comes coming, uh, comes crashing down because the, the cost become prohibitive. Don't those costs kind of like an insurance company eventually get passed on to the end customer anyway somehow?
It's just not, it's an in an indirect cost that we all pay for. I I mean, in, in theory to the, to the extent that those companies are carrying that burden on their balance sheet, yes. Ultimately, um, everybody's paying it, but the people that are consuming it may not be the ones that are paying it.
Right. You know, if, if, um, if an organization is out there, I mean, I've been doing a lot of work understanding why, uh, why the consumption around Maven Central has just been going through the roof lately. And what I'm finding is, you know, trillion dollar companies downloading 10,000 different components 500,000 times each every month when those components don't change.
And it's been an accepted best practice for decades that you have a caching proxy repository manager. And so because it's free, there's no cost for these companies to do it. They may not be customers of sonotype, they may not be customers of GitHub.
And so the, the costs are being passed on to a different set of people. Right. So the, it's, it's not well aligned for sure.
And, and that certainly leads to the problem, but I'm seeing, I'm at least taking the tack for the moment, that awareness is part of the challenge that most of these organizations, they might have a repository manager in place, they just don't realize that all their builds are bypassing it. Right? Now, if you actually pull that thread a little bit more, I mean, we've talked about this before with malicious open source components.
Like if your developers and all your builds are bypassing your, your repository manager, you're wide open to accidentally grabbing malicious components, right? That's, that's something you should be aware of. But also your builds are taking longer.
Like if you downloaded it from something on the same network, it's gonna be infinitely faster than fetching those same things over the internet. Um, and so you're paying for that CI machine time somewhere somehow, um, your developers are waiting for it, right? So it's sort of this weird situation where the, it's gotten so easy to consume things somewhat irresponsibly, the costs are piling up in other areas.
And I think I'm, I'm trying to get people to understand that better. Back in the battle days of it, I seem to remember there was a concept called chargebacks, and that's evolved into show backs. Mm-hmm.
Show backs, you don't really charge back. You just give people the information that say, this is how much this service that you're consuming costs. So maybe it's time to apply showback as a concept to customers.
So at least they are the users of these things so that yeah, they're at least aware of what's, what the cost is. I mean, I've been looking at some of those things, frankly, to try to try to see it. It's, it's very difficult because in the open source world, everybody's used to everything being free.
And so, you know, if there's a repository of things to download, you know, who are you to tell me I can't download it over and over and over again. Right. You know, and, and, and, and that's the thing that has to change because the, the cost of the all of this is just gonna keep growing, you know, geometrically to the point where it becomes really unsustainable.
Um, but I think it doesn't have to be that way. If people can think, uh, better about it. I was, I was engaging with one person who was a publisher to Maven Central and, um, you know, they had a problem with a release once years ago.
And so they set their entire pipeline up to basically do a mock release, every single commit just because it was easy for him to do and it didn't have any downside. And I looked at that and I was like, listen, you're wasting bandwidth. You're wasting my bandwidth.
You're wasting a whole bunch of my machine time doing validations on your stuff, which is computationally expensive, and then you're gonna throw it away. You're gonna do that a thousand times for each release. And I said like, listen, if, if you don't care about wasting GitHub's money and sonatype's money, at least be a better carbon burner, like you're wasting energy, you're wasting resources for all of us if you don't care about my money.
At least care about that. It turns out this person was a professor and he was like, wow, that's really interesting. Can I quote you back to my students to help educate them around, uh, being better, you know, uh, consumers of this, which is kind of what got me thinking about maybe, maybe this is the message that needs to be spread a little bit.
We talk about a lot about who contributes to the community and whatever, and we've kind of beat that horse to death, but a lot of the enterprises, they don't have people who necessarily gonna contribute code, but maybe they can contribute money to support the infrastructure to the project. They certainly could. And, and trying to get that conversation going can be very difficult.
Yeah. Um, but that would go a long ways to solving the problem when you've got huge organizations where, you know, sponsoring this as a rounding error. Um, you know, the, the challenge is when we reach out to these organizations and try to point out, um, you know, the, the behavioral changes, um, many of those, those folks are lower level in the organization.
They don't have the power to decide to say, you know what, maybe we should sponsor it. Right? And so there's a, there's a big disconnect in, in the people that have the control over what's actually happening versus the people with the budget, you know?
So that's why I said at the beginning, if I had the answer to this, I would certainly be doing it. But I, I'm, I'm just now scratching at the, the problem at the moment. Do you think that the various open source consortiums might wanna take a more active role in this conversation because they are encouraging the adoption of open source, but there is this hidden infrastructure cost?
Yeah, I mean, to to, to the extent that they can help raise awareness, of course. You know, um, a a lot of the focus has been on how consumers consuming organizations can adopt best practices to make themselves more secure. I think the thing I'm pushing on is can those same people maybe tweak their practices to be more aware of the pressure they're putting on the rest of the ecosystem?
And that, that's, that's not something that we've really pushed on, uh, very much. A lot of these organizations also have their own internal systems that they're using, and they would be more cognizant of those costs. And we hear conversations about finops and we hear conversations about, um, we need to be more responsible about the consumption of that infrastructure.
Why do you think it only kind of sits internally, but they don't look outside their organization and apply the same philosophy and the same best practices that they're kind of using to control costs internally? Yeah. Um, because they don't get the bill.
It, it's, it's the same reason as like, why is it, why, why do organizations, you know, do things that, you know, burn so much carbon? Because there's no, there's no cost to doing that. That's the whole, uh, concept behind cap and tax, right?
Cap your expense until you, until you actually see the money value of what you're actually consuming in this, this other dimension, you're not gonna do anything about it. So I do think some of these resources, there's a lot of analogies to like the carbon carbon trading stuff and thinking about that clean energy and because it's the same problem. These are finite resources.
Companies are not gonna pour infinite money into infrastructure to allow other large companies to just abuse the heck out of it. That that is going to come to an end at some point. So the more we recognize that and the more we adapt, the easier it will be.
Does this wind up being an exercise in shaming people into the right behavior? Or is there some more altruistic way of doing this? I mean, I would say at this point, all things are on the table.
That wouldn't be my first move. But, um, but, uh, but yeah, I think, I think raising the awareness, starting the conversation like I'm trying to do here, I think that's part of it. It's just, it's a missing dimension from the sustainability.
When we, we talk about making open source sustainable, where we tend to think only about supporting the people writing the code, but the missing part of that is all of the infrastructure that goes behind it. I think we take that for granted because it's just, you know, every big company gives away services for free, for open source projects and, and largely for open source consumers. Um, but that free part and that disconnected part is, is a challenge here.
There are other maintainers of various open source projects. Are they having the same conversation? Are you starting to talk to them about the same issues?
Um, it's, it's, I'm seeing it pop up in a lot of different places. I don't think it's a cohesive conversation yet. You know, um, to the extent that, that the donations keep coming, I think it's easy for them to ignore.
Um, but you know, the tin cup, as we all know with the foundations, you know, it doesn't last forever, right? And, and that's kind of the point that I'm trying to make. If we can make the amount of investment we're getting already able to support more and do more, then we're already better.
We don't have to keep going out and trying to raise more mon money, infinitely. Some people would say, well, won't the infrastructure get better and we'll just, you know, be able to do more with less? Or is that kinda, you know, the end of the day we're just, the amount of data is out weighing the volume, even the advances in the infrastructure.
I mean, uh, all of those things can be true. And if, if big companies stop downloading the same thing half a million times a month, we could do more with what we had. We could make it even even better.
We could put more of that resource into, into, you know, making the infrastructure better instead of just sending the money to telecom providers or to machine providers, right? Mm-hmm. They're the only ones that win in this, too.
The, the people that are actually getting paid underneath the hood to, to actually burn the carbon. They're, they're the ones that are, that are winning with all of this abuse And among some of the most ardent advocates of open source software. 'cause they see the consumption model, right?
Right. That's right. Um, so last question.
What is, you know, if, if you had to give somebody a, a to-do list or a set of best practices to become a more responsible consumer of open source, what would you tell 'em to do? Well, I would, I would take a close look at my pipelines. I mean, clear, uh, you know, close to my heart is looking at, you know, the Maven consumption.
Um, you know, and I would, I would say that you should look at all of the repos, not just Maven, but you know, if you don't have a caching proxy or repository manager in place, why not? Like why, why these files don't change. It's gonna make your builds faster, more, more secure, and um, more, you're more productive and you're gonna lower your impact on the rest of the ecosystem.
So I would start there, um, you know, make sure those things are configured properly so that they do things intelligently, like hit the internal repository before you go to the ones outside, because the cost of doing that is basically null before you go and hit e external one. So think intelligently about how you're sequencing. This is just best practice around how you optimize network.
Like you're doing this for other parts of your business already. Pay attention to it as you're doing it for the o uh, the open source side of it. I would also further take that and think about, you know, we've been pushing continuous everything for like a decade at this point.
Maybe it's time to start thinking about that. Do we really have to run everything on every single commit? Do we have to pretend we're gonna do a release if we don't, if we know we're not actually going to do it?
What is the sensible trade off between running these things often enough to give feedback and versus just running them for the sake of running them and wasting the resources? Right? And I, and I think those two big things, if people took a closer look at that, um, I think it would make more sense.
And I was just talking to, um, you know, a friend of mine at another big company who said the same thing. He said, I see it, it shows up in their cloud bill where some, some project had one problem one time, and the way they fixed it is they run this test, they run this really expensive ping test basically every 12 hours and it shows up as a $50,000 cloud bill at the end of the month, right? So it's like, yeah, it was great.
You made this whole thing continuous. Awesome. Now you just cost a company a whole bunch of money.
They fixed that because they got the bill, but people are doing the same damn thing with all these other ones and, and, uh, you know, hammering these public repos, right? So, um, so that's what I would say start with that. Look at, look at how you're using it and how often you're running these things and, and, and rationalize it a little bit better.
Alright folks, I think you're hurting here. The truth of the matter is we just all got a little lazy and it's time to be a better open source citizen. Hey brother, thanks for coming by.
Thank you. Thanks for having me. All right.
And we'll be back in a minute.