Phase 6: license-compliance audit and enterprise/ relicensing to AGPLv3

Full dependency inventory across Rust/Go/npm plus Docker base images
and vendored assets (776 rows, 502 unique deps), classified against
AGPLv3 compatibility with real citations rather than assumptions.
enterprise/ relicensed from its commercial-license stub to AGPLv3,
matching core -- the one real flag (Redpanda's BSL 1.1) was evaluated
against primary sources and accepted as-is rather than triggering a
broker swap. CI enforcement wired up (.github/workflows/license-
compliance.yml, this repo's first CI workflow), a root LICENSE file
added, and every doc/comment referencing the old commercial-license
boundary updated to describe it as architectural only.

See /docs/compliance/ for the full report, inventory, and policy.
This commit is contained in:
2026-08-16 18:03:32 -07:00
parent 595d1fe0fd
commit 661568085e
24 changed files with 11409 additions and 73 deletions
+7 -4
View File
@@ -192,10 +192,13 @@ replacement for it. Full middleware/handler wiring is task 5's scope.
## Web UI boundary: a runtime capability check, not a conditional import
Core `web` never bundles enterprise-licensed Svelte components into its
build — that would put commercial-licensed source inside an AGPL
artifact, the UI-layer equivalent of the Go import-boundary problem
`hack/check-tenant-boundary.sh` already guards against. Instead: core
Core `web` never bundles `enterprise/`'s Svelte components into its
build (at the time this was written, that would have put
commercial-licensed source inside an AGPL artifact; as of Phase 6 both
are AGPLv3, but the architectural separation stands on its own merits —
core builds and ships standalone, the UI-layer equivalent of the Go
import-boundary problem `hack/check-tenant-boundary.sh` already guards
against). Instead: core
`web` ships a generic settings/admin route
(`web/src/routes/settings/+page.svelte`, added in task 5) that, on load,
calls `GET {enterprise-auth base URL}/auth/features` and renders