LIGHT

❯ Free Software Isn't Gratis

Why companies should treat
Open Source as part of their infrastructure

Christopher Tineo SRE @ Palantir Technologies

DevOpsDays Philadelphia 2026 DevOpsDays Philadelphia 2026

❯ whoami

Christopher Tineo

SRE · Palantir Technologies

CNCF Ambassador 2026–2028 CNCF Ambassador
CNCF Kubestronaut Kubestronaut
Google Cloud Professional Cloud Architect Google Cloud Professional Cloud Architect GCP Cloud Architect
Google Cloud Professional Cloud DevOps Engineer Google Cloud Professional Cloud DevOps Engineer GCP Cloud DevOps
Certified Kubernetes Security Specialist CKS
Model Context Protocol Associate MCPA
Community
Cloud Native Community Groups NYC
Cloud Native Community Groups Santo Domingo
Organizer
KCD New York 2026
Upstream Kubernetes SIG Contributor Experience · Member

The five acts

01

Problem

The "free" in free software has a price someone pays.

02

Examples

What it looks like when the bill comes due.

03

Cost

To companies, to maintainers, to the ecosystem.

04

Solution

Treat open source like the infrastructure it is.

05

Action

What you do on Monday morning.

Act 01

The Problem

"Free" has a price. Someone always pays it.

Open source is everywhere

98%

of the 947 commercial codebases Black Duck audited contain open source.

Sources: Black Duck OSSRA 2026, Feb 25 2026

Billions to write. Trillions to use.

$4.15B

to write it
once

$8.8T

for companies to replace
the open source they use

Areas to scale: the dot is ~2,100× smaller.
OSS developers 5% of developers… …create 96% of the value Value to companies ($8.8T)

Source: Hoffmann, Nagle & Zhou, "The Value of Open Source Software", HBS WP 24-038, Jan 2024

❯ clarification

Free software ≠ Open source

Two overlapping but distinct philosophies. Same code, different why.

Free software

A movement

  • User freedom as the goal
  • FSF · 1985 · Richard Stallman
  • Four freedoms (run, study, modify, share)
  • License ethos: copyleft
≠

Open source

A methodology

  • Practical benefits as the goal
  • OSI · 1998 · Raymond & Perens
  • 10 Open Source Definition criteria
  • License ethos: copyright

Most projects are both. The difference is the why, not the what.

Sources: FSF, "What is Free Software?" · OSI, The Open Source Definition

"Free" as in beer vs "free" as in speech

Portrait of Richard Stallman, founder of the GNU Project and the Free Software Foundation
Richard Stallman, founder of the GNU Project and the Free Software Foundation. His framing of "free software" — meaning freedom, not price — gave us this wordplay. Photo: Ruben Rodriguez, LibrePlanet 2019 · CC BY 4.0 · Wikimedia Commons

Stallman chose "free" to mean freedom (speech), not price (beer).

The English language has only one word for both, causing 40 years of etymological confusion.

This talk is about the gap between them — and who pays for it.

Act 02

The Examples

What it looks like when the bill comes due.

What is ingress-nginx?

NGINX logo

The front door to your Kubernetes cluster.

Routes external traffic into your services.
Not built in: Kubernetes ships no default Ingress controller. You pick one.
Maintained by a handful of SIG Network volunteers.

~60% of CERN's Kubernetes deployments relied on ingress-nginx as their ingress controller at the end of 2025.

Project kubernetes/ingress-nginx  ·  Steward Kubernetes SIG Network

Sources: CNCF End User TAB, "Ingress NGINX retirement: Experience from end users", Apr 2 2026 (CERN: "As of the end of 2025 ~60% of deployments rely on ingress-nginx") · kubernetes.io, "Ingress Controllers", checked Sep 30 2026

Critical infrastructure, growing CVE list

~50% of cloud native environments depend on it (Steering, Jan 2026)
41%+ of internet-facing clusters ran it (Wiz, Mar 2025)
6,500+ clusters exposed its admission controller to the internet (Wiz, Mar 2025)
1 critical CVE-2025-1974, CVSS 9.8: remote code execution through the admission controller.
10 high of 17 CVEs in total. 10 of the 17 landed in 2025–2026, then it was archived.

Sources: GitHub Advisory Database, k8s.io/ingress-nginx, queried Sep 27 2026 · Kubernetes Steering statement, Jan 29 2026 · Wiz Research, IngressNightmare, Mar 24 2025

Every feature became someone's upkeep

Issues and pull requests opened per year on kubernetes/ingress-nginx

0 500 1,000 1,500 2016* 2017 2018 2019 2020 2021 2022 2023 2024 2025 2026* Lua dynamic config feature pause no new features
issues pull requests * 2016 starts Nov 4 (repo created) · 2026 ends at the March archive

Features came in as PRs; the upkeep stayed. 9 of 10 PRs in 2025 came from one maintainer or a bot.

Sources: GitHub search API, repo:kubernetes/ingress-nginx created:<year>, queried Sep 26 2026 (2025 authors: first 1,000 of 1,414 PRs, queried Sep 30 2026) · PR #2794, Jul 27 2018 · kubernetes dev list, Jun 23 2022 · issue #13002, Mar 20 2025

The humans behind the controller

"We do this in our spare time, and it's becoming hard for us to keep this pace. … we now have to split our time between issues, bug fixing, new feature reviews, and the bugs that may arise from this feature."

James Strong (@strongjz) · ingress-nginx maintainer · kubernetes dev list · Jun 23, 2022

Sources: James Strong, kubernetes dev list, Jun 23 2022 · kubernetes/org#5305, Dec 15 2024

Act 03

The Cost

To companies. To maintainers. And now, the AI flood.

Cost to companies

0

direct drop-in replacements
for ingress-nginx.

"None of the available alternatives are direct drop-in replacements. This will require planning and engineering time. Half of you will be affected."

Kubernetes Steering + Security Response Committee · Jan 29, 2026

Sources: Kubernetes Steering + Security Response Committee statement, Jan 29 2026

Cost to maintainers

60%

of open source maintainers
are unpaid for their work

"Nobody has been paying anyone to work on this software for some time, it has been entirely volunteer driven and they've been overwhelmed."

@BenTheElder · Kubernetes Steering Committee · Jan 21, 2026

The cost is the most expensive line item in this talk: time, health, and career impact.

The CVE cascade turned volunteer contributions into a second job with constant security liability.

Sources: Tidelift, 2024 State of the Open Source Maintainer Report · @BenTheElder, kubernetes/ingress-nginx#14178

AI didn't shrink the work. It multiplied the inbox.

GitHub activity per month, as reported by GitHub (each panel has its own scale)

Commits pushed 65M 2024 avg 82M 2025 avg ~1.2B Apr 2026* PRs opened 39.5M 2024 avg 47.5M 2025 avg PRs merged 25M Jan 2023 35M 2024 avg 43.2M 2025 avg 90M+ mid-2026

Merged PRs: 25M → 90M+ a month since Jan 2023, about 3.6×.

Sources: GitHub Octoverse 2025, Oct 28 2025 (2024/2025 monthly averages, public repos) · GitHub Blog, Jun 18 2026 (merged PRs, Jan 2023 and 2026) · * Kyle Daigle (GitHub COO), quoted in Latent Space, Jun 2 2026: 275M commits/week in Apr 2026

AI finds bugs faster than volunteers can fix them

Screenshot of Anthropic's Project Glasswing initial update
anthropic.com · "Project Glasswing: An initial update" · May 22, 2026

Anthropic · Project Glasswing

"…some have even asked us to slow down our rate of our disclosures because they need more time to design patches."
75 of the 530 high/critical bugs reported to OSS projects patched at the time of writing

Black Duck OSSRA 2026

Mean vulnerabilities per codebase up 107% to 581. 87% of codebases contain at least one.

Mozilla · with a paid team

423 Firefox security bugs fixed in April 2026, 271 of them found by an AI pipeline.

Patch the Planet · Jun 22

"a firehose of security findings, and already-stretched maintainers must sift through all of it"

Sources: Anthropic, Glasswing update, May 22 2026 · Black Duck OSSRA 2026 · Mozilla Hacks, May 7 2026 · Trail of Bits, Jun 22 2026

One maintainer's token is your production

2026's biggest open-source attacks went through people, not code.

axios MAR 31, 2026

~100Mdownloads a week, backdoored

Social engineering put a RAT on the lead maintainer's PC. It stole the npm login.

trivy-action MAR 19, 2026

76 of 77release tags hijacked

A stolen CI token turned a security scanner into malware.

GitHub MAY 20, 2026

~3,800internal repos accessed

One employee installed a poisoned VS Code extension (Nx Console).

ChainDrop worm AUG 4, 2026

400+npm packages infected

Stolen tokens republished keyv, cache-manager and more.

Sources: axios post-mortem, axios/axios#10636, Apr 2 2026 · Wiz, Mar 31 2026 · GHSA-69fq-xp46-6x23 · GitHub Blog, May 20 2026 · Microsoft Security Blog, Aug 4 2026

Act 04

The Solution

Stop calling it free. Start treating it like infrastructure.

Open source is critical infrastructure

Dependencies are your infrastructure. Run them like it.

Monitor

OpenSSF Scorecard report for github.com/kubernetes/ingress-nginx: 6.9 overall, generated 2026-03-20, Maintained check 10
scorecard.dev · ingress-nginx
  • An SBOM per service (Syft) plus Scorecard and OSV-Scanner in CI.
  • Also alert on archived and EOL: the last scan still says Maintained 10/10.

Set SLOs

endoflife.date page for Kubernetes showing active and maintenance support end dates per release
endoflife.date · Kubernetes
  • Critical CVE in a dependency: patched in 7 days.
  • Nothing past EOL in production. Alert 90 days before.

Staff it

Linux Foundation

hosts CNCF and AAIF

CNCF

Kubernetes, OpenTelemetry

AAIF Agentic AI Foundation

MCP, goose, AGENTS.md

  • An owner for every tier-1 dependency, with 2 h/week upstream.
  • Join the foundation behind what you run. These are examples.

Sources: OpenSSF Scorecard, ingress-nginx · endoflife.date, Kubernetes · Linux Foundation, AAIF launch, Dec 9 2025 · CNCF projects · SLO targets are examples

❯ new since June

The industry just said it out loud

OpenSSF graphic: We're In: Enterprise Commitment to Sustainable Package Registries, signed by Arm, Datadog, Dell Technologies, Ericsson, GitHub, Google, IBM, Kusari, Microsoft, Red Hat, Rust Foundation and Sonatype
openssf.org · "We're In: Enterprise Commitment to Sustainable Package Registries" · Sep 16, 2026

12 signers commit to pay registry fees based on enterprise use, as a business investment, while keeping access free for individuals and small orgs. Covers PyPI, npm, Maven Central, crates.io, RubyGems, NuGet, Open VSX, Packagist.

OpenSSF · Sep 16, 2026

"…the heroic efforts of small teams, often just two or three people."
1.8 million malicious packages needing human takedown "so far in 2026"

Brian Fox · Sonatype / Maven Central · Jun 16, 2026

"But open does not mean infinite. And free does not mean costless."
Publishing limits + paid "Publisher Pro" tier for commercial scale · enforced Oct 1, 2026

Sources: OpenSSF, Sep 16 2026 · Sonatype, "Sustaining Open Publishing at Commercial Scale", Jun 16 2026

Small money, measurable results

What 2026's funding programs actually bought.

GitHub Secure OSS Fund

533 CVEs

found and disclosed by 188 funded projects, for $1.88M in total.

OpenSSF Alpha-Omega · OpenSSF

$12.5M

in grants for maintainers hit by AI-found bugs.

Linux Foundation

2–5× ROI

for companies that contribute instead of only consuming.

EU Cyber Resilience Act, since Sep 11 2026: report exploited vulnerabilities within 24 hours. The duty sits with whoever ships the open source.

Sources: GitHub, Aug 13 2026 · OpenSSF, Mar 17 2026 · Linux Foundation, Feb 24 2026 · EU CRA reporting

Start where your budget is

Two of the four cost nothing but time. Each has a company already doing it.

01 · Know

Know what you run

Cost: $0, a few hours

An SBOM for every service, plus the forks and patches you carry.

45% of organizations keep private forks (LF, 2026).

02 · Upstream

Upstream your fixes

Cost: $0, your time

Send the patch instead of carrying it.

66% say maintainers respond faster to contributors.

03 · Fund

Fund what you use

Cost: any amount

Small, regular grants to the projects you rely on.

Bloomberg FOSS Fund: $10K grants, ~$320K paid out, e.g. to Let's Encrypt.

04 · Join

Join the foundation

Cost: from $2K a year

A seat where the roadmap is decided.

CNCF Silver from $2K a year. Membership returns 4.8×.

Sources: Linux Foundation, "ROI for Open Source Software Contribution", Feb 2026 · Bloomberg FOSS Contributor Fund, Open Collective, Sep 30 2026 · CNCF membership

❯ the new reality

The build-vs-buy equation has flipped

AI is driving down development costs, flipping the build-vs-buy equation. Traditional SaaS margins are eroding.

~$1T software market value lost in seven days (Feb 2026)
+10% projected US software developer jobs, 2025–35 (BLS)

OSS is the Engine

We build on open source, and now we must pay our share by contributing fixes upstream.

Case study · previous role at Game Plan Tech

Added GCS Workload Identity support to Percona MongoDB Operator for a federal compliance workload.

Rather than maintaining a private fork, contributing upstream solved it for us and the community.

Sources: "Build vs. Buy Is Dead" (YouTube) · Fortune / Bloomberg, Feb 5 2026 · BLS OOH · percona-server-mongodb-operator#2315

Act 05

The Action

What you do on Monday morning.

The fork tax

Carrying private forks

5,160 h

of rework every release cycle, just to keep forks building.

86 forks × 60 h each · ≈ $258K at $50/h

At Android scale

18 months from an upstream kernel release to phones.
90% of kernel security bugs were already fixed upstream.

The fix: Upstream First. The patch lands upstream before it ships.

Sources: Linux Foundation, "ROI for Open Source Software Contribution", Feb 2026 (fork questions n=238) · Android GKI docs · ChromeOS, Upstream First

❯ what it looks like in practice

Two hours a week

Bloomberg × OpenTelemetry · 2026

70 PRs

merged in 10 weeks by 48 engineers, at 2 hours a week each. Most were first-timers.

94% of participants felt more confident contributing.
up to 2× productivity for firms that pay staff to contribute (Nagle, 2018).

Sources: CNCF blog, Jul 23 2026 · CNCF blog, Mar 31 2026 · Nagle, "Learning by Contributing", Organization Science 2018 (HBS Working Knowledge)

❯ git log --author=me

A practical example

GitHub pull request percona/percona-server-mongodb-operator #2315, K8SPSMDB-1602: support Workload Identity for GCS backup storage, merged Jun 22, 2026
github.com · percona/percona-server-mongodb-operator #2315 · merged Jun 22, 2026
67 daysissue to merge

The gap: backups needed a key file that IL4/FedRAMP forbids.

Sources: percona/percona-server-mongodb-operator issue #2314, Apr 16 2026 · PR #2315, merged Jun 22 2026 · screenshot cropped, Sep 30 2026

What you do on Monday

Leaders & SRE teams

  • Count your forks and carried patches. Put the hours next to each one.
  • Budget 2 hours a week of upstream time, like Bloomberg did.
  • Pick one foundation or fund for what you run in production.

Individual contributors

  • Carrying a patch? Open the upstream issue this week.
  • Turn the fix into a PR. One merged patch is one less fork.
  • Review someone else's PR. Reviewers are the scarcest resource.

Sources: Linux Foundation, "ROI for Open Source Software Contribution", Feb 2026 · Bloomberg OSPO, CNCF blog, Mar 31 2026

Nadia Eghbal speaking at Strange Loop 2017 in front of her slide: 2017, two-thirds of popular projects have just 1-2 maintainers
Nadia Eghbal at Strange Loop 2017 · Photo: Chris Koerner, CC BY-SA 2.0, Wikimedia Commons · cropped

"In order to maintain our pace of progress, we need to invest back into the tools that help us build bigger and better things."

Nadia Eghbal · Roads and Bridges, Ford Foundation, 2016

  Thank you · Christopher Tineo

Find me · take the slides

Let's keep in touch

QR code to linkedin.com/in/christopher-tineo LinkedIn linkedin.com/in/christopher‑tineo
QR code to tineoc.github.io/talks/devopsdays-philly-2026 Slides tineoc.github.io/talks/devopsdays-philly-2026
QR code to k8s.dev/docs/orientation, the Kubernetes New Contributor Orientation Contribute k8s.dev/docs/orientation

Links: linkedin.com/in/christopher-tineo · tineoc.github.io/talks/devopsdays-philly-2026 · Kubernetes New Contributor Orientation · github.com/TineoC/talks