Phase 6: license-compliance audit and enterprise/ relicensing to AGPLv3
Full dependency inventory across Rust/Go/npm plus Docker base images and vendored assets (776 rows, 502 unique deps), classified against AGPLv3 compatibility with real citations rather than assumptions. enterprise/ relicensed from its commercial-license stub to AGPLv3, matching core -- the one real flag (Redpanda's BSL 1.1) was evaluated against primary sources and accepted as-is rather than triggering a broker swap. CI enforcement wired up (.github/workflows/license- compliance.yml, this repo's first CI workflow), a root LICENSE file added, and every doc/comment referencing the old commercial-license boundary updated to describe it as architectural only. See /docs/compliance/ for the full report, inventory, and policy.
This commit is contained in:
@@ -42,8 +42,11 @@ boundary text names multi-tenancy as enterprise-gated, and a
|
||||
"mechanism in core, feature in enterprise" split would have let a
|
||||
sufficiently motivated self-hosting AGPL user wire up real isolation
|
||||
without ever touching `enterprise/` — undermining that boundary in
|
||||
substance even while technically respecting the AGPL/commercial import
|
||||
graph. Confirmed: enterprise-only.
|
||||
substance even while technically respecting the import graph (at the
|
||||
time, an AGPL/commercial split; as of Phase 6, `enterprise/` is AGPLv3
|
||||
too, so the import graph is now the whole reason this boundary exists,
|
||||
not a proxy for a licensing one — see
|
||||
`/docs/compliance/license-audit-report.md`). Confirmed: enterprise-only.
|
||||
|
||||
Mechanically, this works because `api/internal/querylang/executor`
|
||||
already defines the seam Phase 2 needs regardless of tenancy:
|
||||
|
||||
Reference in New Issue
Block a user