Mr.PlanB Logo

    Newsletter

    Subscribe our newsletter

    Get new infrastructure guides, comparison reports, and migration notes in your inbox.

    Infrastructure notes, guides, and new tools. Unsubscribe anytime.

    Back to Blog
    Open Source
    CNCF
    Kubernetes
    Infrastructure
    Cloud Native

    Open Source Is Free Until It's Not: CNCF and the Cost of Free

    August 7, 2025
    8 min read

    If you've ever spun up a Kubernetes cluster, deployed a container, or even touched a modern cloud-native stack, chances are you've benefitted from a sprawling web of free tools maintained by the Cloud Native Computing Foundation (CNCF). The code is there, the documentation is often excellent, and projects like Prometheus, Envoy, Fluentd, and Helm are stable, battle-tested, and trusted by some of the world's biggest tech players.

    The whole thing still sits on a knife's edge. One comment summed it up perfectly: "Imaging all the free tools in the CNCF community, all the free work, and a lot of companies turning on them. What if one day we need to buy everything?" That hits hard. The worry is more than hypothetical, and it hums along under the surface of the open source world.

    The beautiful illusion of "free"

    Open source is often celebrated like a utopia of free tools, global collaboration, and decentralized power. Under the hood it's a little messier.

    Many of these projects are maintained by a handful of individuals, sometimes by just one. They might be getting by on sponsorships, side gigs, or personal dedication. The infrastructure of the internet is being held together by volunteers who could burn out or walk away at any time.

    Take the xz compression library. As someone pointed out, it had a single full-time maintainer, and when a backdoor exploit hit that project it sparked chaos. That's how brittle some of this stuff really is.

    Then there's the classic XKCD comic, with a massive tower of modern software balanced precariously on one tiny component maintained by "a random person in Nebraska." It's funny until you realize it's real.

    CNCF: where the best tools live, but don't always thrive

    The CNCF acts as a sort of home base for many of these tools. It brings structure, marketing, and visibility, but that doesn't always add up to sustainability.

    Kubernetes itself has serious backing, with top contributors often employed by Google, Red Hat, and VMware. The same can't always be said for its dependencies. Think of Kubernetes as the well-funded, shiny skyscraper... sitting on an aging subway system that no one's maintaining.

    As one commenter put it, "What about all the libraries, frameworks, and other dependencies they use, huh?" Nobody has a comfortable answer to that.

    Some argued the narrative is overly romanticized, since a lot of open source contributions come from big corporate engineers who are paid well for their time. That doesn't change the underlying problem, though. Big tech funds what serves its own business interests, and everything else is left to community goodwill.

    The freemium model creeps in

    One sharp comment made a comparison that feels more accurate the longer you think about it: "A lot of CNCF is more freemium than free. Like mobile gaming: the entire industry is fueled by whales so the rest of us can grind for free."

    That stings a little, and it's not wrong. You can use many of these tools for free, but more and more companies are building paid layers on top, and enterprise support, advanced features, and integrations all get monetized. That isn't inherently bad. Developers need to eat, and startups need revenue.

    It becomes a problem when open source is the bait instead of the core mission, and users and maintainers alike end up fueling a freemium business model when they thought they were building public digital infrastructure.

    Companies turn on their roots

    What's even more disheartening is when companies that built themselves on open source tools later lock things down.

    We've seen open core projects shift licenses. MongoDB, Redis, and others changed their terms to avoid being exploited by cloud providers. Again, the rationale makes sense, because nobody wants to be AWS's unpaid R&D department.

    From the outside, though, it feels like betrayal, a promise of freedom rewritten with little warning. Users are left stuck: they build a business on something labeled "free" and find themselves in licensing trouble a year later.

    The cost of not paying

    The twist is that treating open source as something that should always be free sets us up for disaster.

    Free tools with no funding can't scale, can't offer security guarantees, can't respond quickly to threats, and can't take feature requests seriously. You get what you pay for, and in many cases we're paying nothing and expecting everything.

    We forget that software doesn't build or maintain itself. Someone has to fix bugs at 2 a.m., answer GitHub issues, and keep reading RFCs and rewriting code after their day job. What follows is burnout, neglect, or, worst of all, compromise.

    So, what's the solution?

    There's no single fix, but a few ideas come up again and again in the community.

    Corporate sponsorships could be done right, funding the infrastructure, documentation, and lesser-known dependencies that make everything run, instead of throwing money only at the biggest name in the project.

    Public recognition helps too. Celebrating the unsung heroes of the open source world gives them visibility, and visibility can lead to opportunity.

    Freemium models could be more transparent. If a company builds on open source and offers premium tiers, it should be honest about that, support the base, and contribute back instead of just extracting.

    Finally, there's government and institutional funding. Open source is public infrastructure, and maybe it's time we treated it like one.

    The human side of code

    It's easy to get lost in licenses, governance models, and business logic, but this is about people. People who build tools for free because they believe in something. People who wake up to news of a zero-day vulnerability in the thing they maintain on nights and weekends. People who could've cashed out and chose to stick around.

    As one commenter said, "There's always an option to cash out if your project gets big… if that's a concern." Maybe that's the point. Open source is powerful because it offers freedom, and it also needs protection, from exploitation and from our own unrealistic expectations.

    The day we have to buy everything might not be far off, and when it comes, we'll realize how much we took for granted.