Code Is Free, the Moat Is Private
Open source began as a shared industrial commons, but through license wars, it has solidified into a new moat of trust and operations. Is Korea a country that borrows this infrastructure, or one that builds it?
AI Summary
While Korean developers excel at assembling open source infrastructure stacks, the country remains largely absent from the governance of core projects like PostgreSQL, Kafka, and Kubernetes. As license wars shift value from code to trust and operational responsibility, Korea's short-term performance culture and pursuit model leave it as a consumer rather than a designer of critical infrastructure. The path forward requires securing maintainer positions in foundational projects and transforming domain knowledge from local industries into shared infrastructure with sustained institutional commitment.
Picture a startup server room in Pangyo. The database runs on PostgreSQL, search on Elasticsearch, containers on Kubernetes, and observability on Grafana. All open source. We didn't build a single line, and initially paid nothing. Korean developers are skilled at assembling this stack. The problem begins when we mistake that proficiency for self-reliance.
We assemble well. But did we design even one of those components? If license terms change one day, what can we do? Before this question, the distinctive confidence of Korean industry becomes oddly thin.
What the License Wars Changed Was Not Code, but the Location of Ownership
The commercial open source model, or COSS, was once simple. Release code to gather a community, then sell hosting and support to enterprises too burdened to operate it themselves. Red Hat paved that path with Linux. But the landscape shifted from 2018. MongoDB introduced a new license called SSPL, and when Elastic changed Elasticsearch's license, AWS forked the entire codebase into OpenSearch. When HashiCorp switched Terraform to BSL in 2023, the community split into OpenTofu. In 2024, even Redis closed its license, and in the space left by original author Salvatore Sanfilippo's departure, a fork called Valkey emerged under the Linux Foundation.
On the surface, it's a turf war between cloud giants and open source companies. But beneath that, a deeper transformation occurred. Code remains free, but the point where money is made has moved outside the code. Trust, operational responsibility, the speed of security patches, who answers the phone when an outage hits. This intangible layer has become the new billing target. It's a structure that releases code as a commons while privatizing the moat of trust built atop it.
Fast Following Only Takes You as Far as Assembly
Korea's software industry excelled at following. It learned frameworks built by others quickly, transplanted proven architectures, and localized global standards well. It resembles how we caught up in semiconductors and displays in manufacturing. The ability to find the fastest path to an answer when that answer already exists.
But Korean names are rare in the open source infrastructure layer. In the governance of any core infrastructure project—PostgreSQL, Kafka, Kubernetes—Korean companies have almost no seat. We have been consumers and skilled users of this infrastructure, rarely its designers or stewards.
Here the limits of the pursuit model are revealed. Open source infrastructure is not merely a bundle of code. It's a sedimentary layer of trial and error accumulated over decades by thousands of contributors encountering bugs, reviewing outages, and reversing design decisions. This sediment doesn't replicate quickly. Code can be cloned from GitHub, but the judgment of why that code looks that way cannot be cloned. Pursuit reaches only to the final assembly stage. The authority of design is not caught up to.
Advanced Nations Laid Standards While Pretending to Lend Infrastructure
We must not misunderstand why U.S. cloud companies pour enormous personnel into open source. It's not charity. When one company becomes the top contributor to a core project, that company effectively determines the project's future direction. They lay the standard, then sell operational services atop that standard. The hand cultivating the commons and the hand digging the moat above it are the same hand.
Foundations like CNCF appear as neutral ground, but influence within them is proportional to contributed personnel and time. Ultimately, who has accumulated longer and deeper determines voice. It's a game where long-term investment becomes sovereignty.
Korea's short-term performance orientation is particularly disadvantageous in this game. Organizations bound to quarterly results and within-year launches find it difficult to bury engineers' time for years in external projects that don't immediately show up as revenue. Contributions remain side projects for recruiting publicity, and the continuity needed to rise to maintainer of core modules is not secured. Failures scatter as individual career records rather than accumulating as organizational experience.
A counterargument is possible. Do we really need to build infrastructure ourselves? Isn't using well-made things cheaply rational? It's correct, in peacetime. But the moment licenses change, core dependencies are pulled into a specific company's moat, and geopolitics turns supply chains into weapons, the rationality of borrowing returns as an invoice of dependency. We already know what price the side without alternatives accepts in cloud cost negotiations.
What Korea Must Accumulate Is Not Code, but the Authority of Maintenance
Then what should be built? Not launching new open source projects like mushrooms after rain. The key lies in securing maintainer positions in infrastructure projects already laid at the industry's foundation. We need a structure where Korean companies cultivate engineers with commit rights to the databases, message queues, and observability tools they depend on, and where companies guarantee that time in multi-year terms.
Industrial data from Busan and other regions, domain knowledge emerging from logistics, ports, and manufacturing sites can itself become infrastructure. Not stopping at adopting others' general-purpose infrastructure, but releasing tools built while solving our field's problems as commons and gripping that governance. The moat of trust ultimately comes from who has been responsible the longest.
A system where failures remain as experience must accompany this. OpenTofu and Valkey rose quickly from the license wars because the split communities did not lose the operational knowledge they had accumulated. The fork was not a copy of code but an inheritance of accumulation. What Korea needs is not a single success story, but a sedimentary structure where even failures and splits are inherited by the next generation.
In the era of pursuit, nations that found answers quickly won. Open source infrastructure looked like a textbook with answers already written, and we were skilled at reading that textbook rapidly. But the frontier era is different. In a world where code is released for free, value has moved to the layer of trust and responsibility, and that layer opens only to those who have been buried in it long. Not nations that solve answers quickly, but nations that first ask which problems we will directly take responsibility for solving will hold ownership of the next infrastructure.
This article was automatically translated from the Korean original by AI. For the authoritative version, read it in Korean.
한국어 원문 읽기 →