Open source as strategic autonomy

Control you can inspect, not a black box you must trust.

Sovereignty and open source are often treated as separate preferences that happen to travel together. They are not separate. Open source is the mechanism that makes sovereignty verifiable and durable. A closed “sovereign” platform is a contradiction: you are asked to trust a claim you cannot check.

What open source actually buys you

Auditability

You — or a national security agency, or an independent auditor — can read exactly what the software does. There is no telemetry you cannot see, no backdoor you cannot find, no dependency you cannot trace. For high-assurance environments this is the difference between assurance and assertion.

No kill switch

Closed platforms can be disabled remotely, geofenced, sanctioned, or degraded by the vendor. Open source you self-host has no call-home and no licence server that can refuse to answer. The capability keeps working when the relationship doesn’t.

Freedom to fork and rebuild

If a vendor is acquired, changes its licence, or exits the market, open source lets you continue: rebuild from source, maintain it yourself, or move to another supporter. Your continuity does not depend on the vendor’s business decisions.

The relicensing risk is now concrete

This is not hypothetical. Recent years have made the closed-source dependency risk tangible:

  • HashiCorp relicensed Terraform and Vault away from open source (to the BSL), prompting community forks (OpenTofu, OpenBao).
  • Broadcom’s acquisition of VMware brought repricing and packaging changes that turned stable infrastructure budgets into a live cost shock.
  • Red Hat moved RHEL source access behind subscription terms.

Each was a business decision that changed the terms under organizations that had built on those products. Open source, self-hosted, does not remove commercial relationships — but it removes their ability to hold your infrastructure hostage.

“Open core” and honest labelling

Not everything marketed as open source is. Watch for:

  • Open core — an open kernel with the features you actually need locked in a proprietary layer.
  • Source-available — readable but not freely runnable or forkable (e.g. BSL).
  • Open-washing — an open logo over a closed operational reality.

The honest question is the same as the sovereignty-washing test: can you run it, audit it, and rebuild it without the vendor’s permission?

Where we stand

The platform is built on CNCF open source — Kubernetes and the surrounding ecosystem — and is self-hostable end to end, including air-gapped. That is a deliberate architectural choice in service of the definition: open code + self-hosted + no foreign root access.

← All sovereignty articles Talk to an expert