Skip to content
Notifications
Clear all

Unpopular opinion: Vault's response to the license change was a betrayal

1 Posts
1 Users
0 Reactions
42 Views
(@karina23)
Estimable Member
Joined: 3 months ago
Posts: 50
Topic starter   [#5928]

I’ll start by saying I’m relatively new to the enterprise secret management space, but I’ve been deep in vendor evaluation and contract negotiation for years. The recent license change from HashiCorp, and specifically Vault’s position within it, has fundamentally altered my team’s procurement strategy, and not in a good way. I’m calling it a betrayal because it feels like a breach of the implicit trust and community partnership that was a huge part of their sales pitch to us.

When we originally evaluated Vault, a massive part of its appeal was the open core model. We invested significant time and resources building internal expertise, writing automation, and integrating it into our stack with the understanding that the core project would remain under a permissive license. This wasn't just a technical decision; it was a strategic one based on long-term TCO and avoiding vendor lock-in. The BSL 1.1 move, especially applying it retroactively to core products like Vault, feels like a bait-and-switch.

My concerns are very practical and are now central to our ongoing review:

* **Total Cost of Ownership Recalculation:** Our initial TCO model is now obsolete. We must factor in the new license's restrictions, the potential future costs if our usage hits the new boundary lines, and the legal overhead of ensuring compliance. This is a nightmare for procurement.
* **Implementation Timeline & Future Roadmaps:** We were midway through a multi-phase rollout. Do we pause? The uncertainty around what features remain in the community "bit" versus what gets pushed to the "enterprise" tier makes future planning incredibly risky. Our project timelines are now in jeopardy.
* **Exit Strategy Necessity:** This move forces us to develop a formal exit strategy for Vault, which was previously unthinkable at this stage. We're now actively evaluating alternatives, not because Vault is technically inferior, but because the foundational trust in the vendor is broken. What’s to stop another, more restrictive change in 18 months?
* **Vendor Evaluation Criteria Updated:** "License stability" has now jumped to the top of our checklist, above even feature parity. This event has shown us that a vendor's governance and license philosophy are as critical as the product itself.

I’m genuinely curious how others are handling this from an operations and procurement standpoint. Are teams absorbing the risk and continuing? Has anyone managed to negotiate special terms with HashiCorp post-change? Most importantly, for those who have started exploring alternatives, what has been the most painful part of the migration assessment?



   
Quote