License
OpenTremor uses two open source licences: the GNU AGPL v3 for the server, and Apache-2.0 for everything that plugs into it. Both are approved by the Open Source Initiative. Here is what that means in practice.
The short version
Section titled “The short version”- Use it — yes, and you owe nothing. Self-host it for your team or your whole company, commercially, forever. Every analyzer, unlimited.
- Change it — yes, share your changes. Patch the server however you like; if other people use your modified version over a network, offer them its source.
- Extend it — yes, under any licence. Write analyzers, fork the Terraform provider or the Helm chart — proprietary included.
Which licence covers what
Section titled “Which licence covers what”| Modules | What they are | Licence | In practice |
|---|---|---|---|
core · platform · dashboard · task-scheduler | The server: the API, the analysis engine, the web UI and the scheduler | AGPL-3.0-or-later + analyzer plugin exception | Free to use and modify. Changes to it stay open for the people who use them. |
analyzer-* · terraform-provider · deployments · monitoring · docs | Everything that plugs into the server: analyzers, the Terraform provider, the Helm chart, Grafana dashboards, docs | Apache-2.0 | Permissive. Fork it, embed it, close it — keep the LICENSE and NOTICE files. |
Can I…?
Section titled “Can I…?”| I want to… | Allowed? | What I owe |
|---|---|---|
| Self-host OpenTremor for my team or company, as it ships | Yes | Nothing. Commercial use included — every analyzer, unlimited. |
| Call it from my own scripts, CI jobs or MCP agents | Yes | Nothing. Code that talks to OpenTremor over its API is a separate program; the AGPL covers OpenTremor, not your code. |
| Write my own analyzer and keep it closed-source | Yes | Nothing, as long as it uses core only through the analyzer plugin API. |
| Fork an analyzer, the Terraform provider, the Helm chart or the Grafana dashboards | Yes | Keep the LICENSE and NOTICE files and mark the files you changed. A closed-source fork is fine. |
| Modify the server and run it for my own company | Yes — share your changes | Offer your modified source to the people who use that instance — here, your colleagues. An internal Git repo does it. Nothing has to go public. |
| Run OpenTremor as a hosted service for my own customers | Yes — share your changes | Unmodified: nothing beyond keeping the notices. Modified: offer your customers the modified source under the AGPL. Neither licence gives you the OpenTremor name. |
| Ship the server inside my own product — an image, an appliance, an installer | AGPL, or a commercial licence | Your customers receive the source of the server, and of whatever you built into it, under the AGPL. |
| Copy parts of core’s source code into my own product | AGPL, or a commercial licence | Your product becomes a work based on an AGPL program, and the AGPL applies to it in full. |
Examples
Section titled “Examples”| Who | Situation | Outcome |
|---|---|---|
| A platform team | Runs OpenTremor on its own Kubernetes cluster for 200 engineers, every analyzer on | Free, unlimited, forever. Nothing to publish, no one to ask. |
| A consultancy | Builds a paid analyzer for a client’s in-house configuration language | Covered by the plugin exception; it can ship under whatever licence the contract says. |
| An SRE | Forks the Helm chart for an unusual cluster setup and keeps it private | Apache-2.0: keep the NOTICE file and they’re done. |
| A fintech | Patches core to plug in an internal approval system | Fine. Their engineers — the people using that instance — can get the patched source. The rest of the world doesn’t. |
| A startup | Adds features and sells it as its own hosted review service | Allowed. Its customers are entitled to the modified source under the AGPL — and it needs its own name. |
| A security vendor | Wants to bundle the server in a closed-source on-premise appliance | Either the appliance’s server code ships under the AGPL, or the vendor takes a commercial licence. |
Questions
Section titled “Questions”Is OpenTremor really open source? Yes. Both the GNU AGPL v3 and Apache-2.0 are OSI-approved, and every module carries one of them. There is no “source-available” tier and no time-delayed licence.
Will the AGPL spread to my own code? Only to code that becomes part of the server itself — a modified core, or core’s source copied into your product. Scripts, CI jobs and agents that call the API are separate programs, and analyzers that use the plugin API are explicitly carved out.
Do I have to publish my changes on GitHub? No. The AGPL asks you to offer the source to the people who use your modified version — not to the whole world.
Why not one licence for everything? Because the pieces do different jobs. Copyleft on the server keeps improvements to it open. Copyleft on analyzers would force every third-party analyzer to be AGPL too, so the plugin boundary gets a permissive licence and an explicit exception instead.
What does “or later” mean? You may follow the terms of AGPL version 3, or of any later version the Free Software Foundation publishes — your choice.
The AGPL doesn’t suit my use. Now what? A separate commercial licence, which replaces the
AGPL’s obligations for your use, is available from the copyright holder — see the contact in any
module’s NOTICE file.