License Compatibility Analysis

Document Version: 1.1.0 Last Updated: 2026-01-20 StellaOps License: BUSL-1.1

This document analyzes the compatibility of third-party licenses with StellaOps’ BUSL-1.1 license and Additional Use Grant.


1. BUSL-1.1 Overview

The Business Source License 1.1 (BUSL-1.1) is a source-available license that:

  1. Allows non-production use, modification, and redistribution of the Licensed Work
  2. Allows limited production use only as granted in the Additional Use Grant
  3. Requires preservation of the license text and attribution notices
  4. Provides a Change License (Apache-2.0) that becomes effective on the Change Date
  5. Restricts SaaS/hosted service use beyond the Additional Use Grant

Key Compatibility Principle

Permissive-licensed code (MIT, BSD, Apache) can be incorporated into BUSL-1.1 projects without changing the overall license. Strong copyleft or service-restriction licenses (GPL/AGPL/SSPL) impose obligations that conflict with BUSL-1.1 distribution terms or Additional Use Grant restrictions.


2. License Compatibility Matrix

2.1 Fully Compatible (Inbound)

These licenses are fully compatible with BUSL-1.1. Code under these licenses can be incorporated into StellaOps.

LicenseSPDXCompatibilityRationale
MITMITYesPermissive, no copyleft restrictions
Apache-2.0Apache-2.0YesSame license, patent grant included
BSD-2-ClauseBSD-2-ClauseYesPermissive, minimal restrictions
BSD-3-ClauseBSD-3-ClauseYesPermissive, no-endorsement clause only
ISCISCYesFunctionally equivalent to MIT
0BSD0BSDYesPublic domain equivalent
CC0-1.0CC0-1.0YesPublic domain dedication
UnlicenseUnlicenseYesPublic domain dedication
PostgreSQLPostgreSQLYesPermissive, similar to MIT/BSD
ZlibZlibYesPermissive
BlueOak-1.0.0BlueOak-1.0.0YesPermissive
Python-2.0Python-2.0YesPermissive

2.2 Compatible with Conditions

LicenseSPDXCompatibilityConditions
LGPL-2.1-or-laterLGPL-2.1-or-laterYesMust allow relinking; library boundary required
LGPL-3.0-or-laterLGPL-3.0-or-laterYesMust allow relinking; library boundary required
MPL-2.0MPL-2.0YesFile-level copyleft; MPL files remain isolated

2.3 Incompatible

These licenses are NOT compatible with keeping StellaOps under BUSL-1.1:

LicenseSPDXIssue
GPL-2.0-onlyGPL-2.0-onlyRequires GPL relicensing; incompatible with BUSL distribution
GPL-2.0-or-laterGPL-2.0-or-laterRequires GPL relicensing; incompatible with BUSL distribution
GPL-3.0-onlyGPL-3.0-onlyRequires GPL distribution for combined work
GPL-3.0-or-laterGPL-3.0-or-laterRequires GPL distribution for combined work
AGPL-3.0-onlyAGPL-3.0-onlyNetwork copyleft conflicts with BUSL restrictions
AGPL-3.0-or-laterAGPL-3.0-or-laterNetwork copyleft conflicts with BUSL restrictions
SSPL-1.0SSPL-1.0Service source disclosure conflicts with BUSL restrictions
Commons ClauseLicenseRef-Commons-ClauseCommercial use restrictions conflict with BUSL grant
ProprietaryLicenseRef-ProprietaryNo redistribution rights

3. Distribution Models

3.1 Source Distribution (BUSL-1.1 Compliant)

When distributing StellaOps source code:

StellaOps (BUSL-1.1)
+-- StellaOps code (BUSL-1.1)
+-- MIT/BSD deps (retain notices)
+-- Apache-2.0 deps (retain NOTICE files)
+-- MPL/LGPL deps (retain file/library boundaries)

Requirements:

3.2 Binary Distribution (BUSL-1.1 Compliant)

When distributing StellaOps binaries (containers, packages):

StellaOps Binary
+-- LICENSE (BUSL-1.1)
+-- NOTICE.md (all attributions)
+-- third-party-licenses/ (full license texts)
+-- Source link (optional, transparency only)

Requirements:

3.3 Network Service (No Copyleft Clause)

BUSL-1.1 restricts SaaS/hosted service use beyond the Additional Use Grant. Operating StellaOps as a service is permitted only within the grant limits or under a commercial license; see LICENSE for details.

3.4 Aggregation (Not Derivation)

The following are considered aggregation, not derivation:

ScenarioClassificationBUSL-1.1 Impact
PostgreSQL databaseAggregationPostgreSQL stays PostgreSQL-licensed
RabbitMQ message brokerAggregationRabbitMQ stays MPL-2.0
Docker containersAggregationBase image licenses unaffected
Kubernetes orchestrationAggregationK8s stays Apache-2.0
Hardware (HSM)Interface onlyHSM license unaffected

Rationale: These components communicate via network protocols, APIs, or standard interfaces and are not linked into StellaOps binaries.

3.5 Plugin Distribution (Community Plugin Grant)

The Community Plugin Grant Addendum (LICENSE-ADDENDUM-COMMUNITY-PLUGIN-GRANT.md) provides additional terms for plugin development and distribution.

When distributing StellaOps Plugins:

Plugin Distribution
+-- Plugin code (your license)
+-- Attribution to StellaOps
+-- If derivative work:
    +-- LICENSE (BUSL-1.1)
    +-- LICENSE-ADDENDUM-COMMUNITY-PLUGIN-GRANT.md
    +-- NOTICE.md

Requirements by Plugin Type:

Plugin TypeLicenseAttributionInclude LICENSEInclude Addendum
API-only (no StellaOps code)Your choiceRecommendedNoNo
Includes StellaOps codeBUSL-1.1RequiredYesYes
Bundled with StellaOpsBUSL-1.1RequiredYesYes
Competing managed serviceCommercialN/AN/AN/A

Not Allowed Without Commercial License:

See Also:


4. Specific Dependency Analysis

4.1 BouncyCastle Cryptography (MIT)

AspectStatus
LicenseMIT
CompatibilityFull
UsageLinked into binaries
RequirementInclude copyright notice in NOTICE.md

4.2 Npgsql/PostgreSQL (PostgreSQL License)

AspectStatus
LicensePostgreSQL (permissive)
CompatibilityFull
UsageNuGet package (linked)
RequirementInclude copyright notice in NOTICE.md

4.3 Polly (BSD-3-Clause)

AspectStatus
LicenseBSD-3-Clause
CompatibilityFull
UsageNuGet package (linked)
RequirementInclude copyright notice; no endorsement claims

4.4 RxJS (Apache-2.0)

AspectStatus
LicenseApache-2.0
CompatibilityFull
Usagenpm package (bundled in frontend)
RequirementPreserve NOTICE file

4.5 CryptoPro CSP (Commercial)

AspectStatus
LicenseCommercial (LicenseRef-CryptoPro)
CompatibilityN/A - Not distributed
UsagePKCS#11 interface only
RequirementCustomer obtains own license

Analysis: StellaOps provides only the integration code (BUSL-1.1). CryptoPro CSP binaries are never distributed by StellaOps.

StellaOps Ships:
+-- PKCS#11 interface code (BUSL-1.1)
+-- Configuration documentation
+-- Integration tests (mock only)

Customer Provides:
+-- CryptoPro CSP license
+-- CryptoPro CSP binaries
+-- Hardware tokens (optional)

4.6 AlexMAS.GostCryptography (MIT)

AspectStatus
LicenseMIT
CompatibilityFull
UsageSource vendored
RequirementInclude copyright notice; license file preserved

Analysis: The fork is MIT-licensed and compatible with BUSL-1.1. The combined work remains BUSL-1.1 with MIT attribution preserved.

4.7 axe-core/Playwright (@axe-core/playwright - MPL-2.0)

AspectStatus
LicenseMPL-2.0
CompatibilityYes (with conditions)
UsageDev dependency only
RequirementMPL files remain in separate files

Analysis: MPL-2.0 is file-level copyleft. Since this is a dev dependency used only for accessibility testing (not distributed in production), there are no special requirements for end-user distribution.


5. Outbound Licensing

5.1 StellaOps Core

All StellaOps-authored code is licensed under BUSL-1.1:

SPDX-License-Identifier: BUSL-1.1
Copyright (C) 2026 stella-ops.org

5.2 Documentation

Documentation is licensed under:

5.3 Configuration Samples

Sample configuration files (etc/*.yaml.sample) are:


6. Compliance Checklist

6.1 For StellaOps Maintainers

6.2 For StellaOps Operators (Self-Hosted)

6.3 For Contributors


7. FAQ

Q: Can I use StellaOps commercially?

A: Yes, within the Additional Use Grant limits or under a commercial license. SaaS/hosted third-party use requires a commercial license.

Q: Can I modify StellaOps for internal use?

A: Yes. Non-production use is permitted, and production use is allowed within the Additional Use Grant or with a commercial license.

Q: Does using StellaOps make my data BUSL-licensed?

A: No. BUSL-1.1 applies to software, not data processed by the software. Your SBOMs, vulnerability data, and configurations remain yours.

Q: Can I integrate StellaOps with proprietary systems?

A: Yes, via API/network interfaces. This is aggregation, not derivation. Your proprietary systems retain their licenses.

Q: Do I need to disclose my CryptoPro CSP license?

A: CryptoPro CSP is customer-provided. StellaOps only ships integration code. Your CSP license is between you and CryptoPro.


8. References



Document maintained by: Legal + Security Guild Last review: 2026-01-25