Strategic Playbook

A curated intelligence guide for navigating the Open Source landscape.

โš–๏ธ

License Intelligence

Elastic License 2.0 (ELv2)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ”ด RESTRICTIVE (Source Available) Executive Summary: What is it? The Elastic License 2.0 (ELv2) is a non-copyleft "Source Available" license created

๐Ÿ“– Resource ยท 1 min

Functional Source License (FSL)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ”ด RESTRICTIVE (Source Available) Executive Summary: What is it? The Functional Source License (FSL) is a modern "Source Available" license pioneered by

๐Ÿ“– Resource ยท 1 min

GNU GPL v2

๐Ÿ›ก๏ธ RISK BADGE: ๐ŸŸ  HIGH (For Distribution) Executive Summary: What is it? The GPL v2 is the classic "Copyleft" license (Linux Kernel). It ensures that

๐Ÿ“– Resource ยท 1 min

GNU LGPL v3

๐Ÿ›ก๏ธ RISK BADGE: ๐ŸŸก MEDIUM (Weak Copyleft) Executive Summary: What is it? The LGPL (Lesser General Public License) is a compromise between the permissive Apache/MIT and

๐Ÿ“– Resource ยท 1 min

Business Source License 1.1 (BSL)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ”ด RESTRICTIVE (Source Available) Executive Summary: What is it? The Business Source License (BSL or BUSL) is a "Source Available" license, NOT

๐Ÿ“– Resource ยท 1 min

Sustainable Use License (Fair Code)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ”ด RESTRICTIVE (Source Available) Executive Summary: What is it? The Sustainable Use License (often associated with the "Fair Code" movement) is a

๐Ÿ“– Resource ยท 1 min

BSD 3-Clause License

๐Ÿ›ก๏ธ RISK BADGE: ๐ŸŸข LOW (Permissive) Executive Summary: What is it? The BSD 3-Clause License (also known as "New BSD" or "Modified BSD"

๐Ÿ“– Resource ยท 1 min

Custom License

๐Ÿ›ก๏ธ RISK BADGE: โšช VARIES (Non-Standard) Custom Licenses While the Open Source Initiative (OSI) maintains a list of approved licenses (like MIT, Apache 2.0, GPL), some

๐Ÿ“– Resource ยท 1 min

MIT License

๐Ÿ›ก๏ธ RISK BADGE: ๐ŸŸข LOW (Permissive) Executive Summary: What is it? The MIT License is the most permissive and popular open-source license. It allows you to use,

๐Ÿ“– Resource ยท 1 min

GNU GPL v3

๐Ÿ›ก๏ธ RISK BADGE: ๐ŸŸ  HIGH (For Distribution) Executive Summary: What is it? The GPL v3 is a "Copyleft" license. It guarantees freedom for the end-user,

๐Ÿ“– Resource ยท 1 min

Apache License 2.0

๐Ÿ›ก๏ธ RISK BADGE: ๐ŸŸข LOW (Permissive) Executive Summary: What is it? The Apache 2.0 is a modern permissive license favored by large enterprises (Google, Android, Kubernetes)

๐Ÿ“– Resource ยท 1 min

GNU AGPL v3

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ”ด CRITICAL (For SaaS) Executive Summary: What is it? The Affero GPL (AGPL) is designed to close the "SaaS Loophole." Unlike standard

๐Ÿ“– Resource ยท 1 min

SSPL (Server Side Public License)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ”’ VENDOR LOCK-IN Executive Summary: What is it? The Server Side Public License (SSPL) is not an official Open Source license. Created by MongoDB,

๐Ÿ“– Resource ยท 1 min

Open Software License 3.0 (OSL-3.0)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ”ด HIGH (Network Copyleft) โš–๏ธ The Executive Summary The Open Software License 3.0 (OSL-3.0) is a strong copyleft license, often compared to the

๐Ÿ“– Resource ยท 1 min

Mozilla Public License 2.0 (MPL-2.0)

๐Ÿ›ก๏ธ RISK BADGE: ๐ŸŸก MEDIUM (Weak Copyleft) Executive Summary: What is it? The Mozilla Public License 2.0 (MPL-2.0) is the "middle ground" of

๐Ÿ“– Resource ยท 1 min
๐Ÿ—๏ธ

Deployment Models

Language Runtime (Pip/NPM)

๐Ÿ—๏ธ COMPLEXITY BADGE: โœ… STANDARD (Developer Tool) Executive Summary: What is it? Runtime Deployment means installing the application as a library or package using a language-specific manager

๐Ÿ“– Resource ยท 1 min

Native System (Binary/Linux)

๐Ÿ—๏ธ COMPLEXITY BADGE: โœ… STANDARD (System Package) Executive Summary: What is it? Native Deployment involves running the software directly on the Operating System, either as a Single

๐Ÿ“– Resource ยท 1 min

Mobile Application

๐Ÿ—๏ธ COMPLEXITY BADGE: ๐ŸŸข LOW (App Store) Executive Summary: What is it? Mobile Applications are native software installed on smartphones (iOS/Android). In Open Source, these are

๐Ÿ“– Resource ยท 1 min

Extension / Plugin

๐Ÿ—๏ธ COMPLEXITY BADGE: โšก LOW (One Click) Executive Summary: What is it? Extensions (or Plugins) are small software modules that live inside another host application, most commonly

๐Ÿ“– Resource ยท 1 min

Managed SaaS

๐Ÿ—๏ธ COMPLEXITY BADGE: โšก ZERO (SaaS) Executive Summary: What is it? Managed SaaS means the Open Source creator hosts the software for you. You pay a monthly

๐Ÿ“– Resource ยท 1 min

Kubernetes (K8s)

๐Ÿ—๏ธ COMPLEXITY BADGE: ๐Ÿ”ด HIGH (Enterprise) Executive Summary: What is it? Kubernetes is an orchestration system designed for high availability and massive scale. It manages multiple containers

๐Ÿ“– Resource ยท 1 min

Desktop Application

๐Ÿ—๏ธ COMPLEXITY BADGE: ๐ŸŸข LOW (Installer) ๐Ÿ—๏ธ The Model: Local Native Desktop Applications are installed directly on the user's operating system. In the context of Open

๐Ÿ“– Resource ยท 1 min

LAMP Stack (Linux, Apache, MySQL, PHP)

๐Ÿ—๏ธ COMPLEXITY BADGE: ๐ŸŸ  MEDIUM (SysAdmin Required) Executive Summary: What is it? The LAMP Stack is the grandfather of the modern web. It stands for Linux (OS)

๐Ÿ“– Resource ยท 1 min

Docker Container

๐Ÿ—๏ธ COMPLEXITY BADGE: ๐ŸŸ  MEDIUM (Container Ops) Executive Summary: What is it? Docker Deployment is the industry standard for self-hosting software. The application comes pre-packaged in a

๐Ÿ“– Resource ยท 1 min

Browser-Based / Local-First

๐Ÿ—๏ธ COMPLEXITY BADGE: โšก ZERO (Instant) Executive Summary: What is it? Browser-Based (Local-First) solutions run entirely inside your web browser. There is no server installation, no login,

๐Ÿ“– Resource ยท 1 min
๐Ÿ›ก๏ธ

Security Standards

Single Sign-On (SSO) & SAML

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ”ด CRITICAL (>20 Users) Executive Summary: What is it? Single Sign-On (SSO) allows your employees to log in using their existing company credentials

๐Ÿ“– Resource ยท 1 min

Data Residency (GDPR/CCPA)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ‡ช๐Ÿ‡บ COMPLIANCE Executive Summary: What is it? Data Residency refers to the physical geographic location where your data is stored. Laws like GDPR (Europe)

๐Ÿ“– Resource ยท 1 min

Backup Strategy (3-2-1 Rule)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿš‘ DISASTER RECOVERY Executive Summary: What is it? A Backup Strategy is the protocol for copying and archiving data so it can be restored

๐Ÿ“– Resource ยท 1 min
๐Ÿค

Support Tiers

Enterprise Support (SLA)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ’ผ INSURANCE Executive Summary: What is it? Enterprise Support is a paid contract (SLA - Service Level Agreement) that guarantees a response time. It

๐Ÿ“– Resource ยท 1 min

Community Support

๐Ÿ›ก๏ธ RISK BADGE: ๐ŸŽฒ UNPREDICTABLE Executive Summary: What is it? Community Support means there is no help desk to call. Support is provided by volunteers or other

๐Ÿ“– Resource ยท 1 min
๐Ÿ›๏ธ

Project Governance

Vendor-Backed (Single Vendor)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ’ผ MODERATE RISK Executive Summary: What is it? The project is open source, but the copyright and roadmap are controlled 100% by a single

๐Ÿ“– Resource ยท 1 min

Total Cost of Ownership (TCO)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ’ฐ FINANCIAL REALITY Executive Summary: What is it? Total Cost of Ownership (TCO) is the calculation of the real cost of software, not just

๐Ÿ“– Resource ยท 1 min

Open Core Model

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿข BUSINESS MODEL Executive Summary: What is it? "Open Core" is a business model where the core functionality of the software is

๐Ÿ“– Resource ยท 1 min

Foundation-Backed (CNCF / Apache)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ›๏ธ HIGH STABILITY Executive Summary: What is it? This software is owned by a neutral non-profit organization (like The Linux Foundation, CNCF, or Apache)

๐Ÿ“– Resource ยท 1 min

Data Portability (Exit Strategy)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ”“ FREEDOM METRIC Executive Summary: What is it? Data Portability refers to the ability to easily export your data from a system in a

๐Ÿ“– Resource ยท 1 min

The "Bus Factor" (Project Health)

๐Ÿ›ก๏ธ RISK BADGE: ๐Ÿ“Š SUSTAINABILITY METRIC Executive Summary: What is it? The "Bus Factor" is a risk metric that asks: "If the lead maintainer

๐Ÿ“– Resource ยท 1 min