Commons cause: IBM, Oracle, CNCF protest over Google's handling of Istio governance

Deep upset at what is perceived as broken commitments

Google's creation of an Open Usage Commons organisation to manage trademarks including those of Kubernetes service mesh Istio has drawn harsh criticism from other tech giants unhappy with the new approach.

IBM’s veep and and CTO of Cloud Platform Jason McGee said Google’s initiative “doesn’t live up to the community’s expectation for open governance… without this vendor-neutral approach to project governance, there will be friction within the community of Kubernetes-related projects.”

Projects like Istio, which manages network traffic and security, are not mandatory components in a Kubernetes deployment, though they can be jolly useful for building successful large-scale projects. There are alternatives to Istio, such as Linkerd, though Istio is the best known and most feature-rich service mesh for Kubernetes.

IBM, along with Google and Lyft, founded the Istio project in 2017, with IBM contributing code from its earlier Amalgam8 project. “At the project’s inception, there was an agreement that the project would be contributed to the CNCF [Cloud Native Computing Foundation, already the home of Kubernetes] when it was mature,” said McGee.

Google has not done this, and the Open Usage Commons (OUC) is not an open-source foundation – it is a trademark management organisation.

Trademark ignorance...

What of reports citing Google Cloud CEO Thomas Kurian as saying in April this year that Istio would be donated to a foundation? When we asked Google’s director of open source Chris DiBona, he said the formation of the OUC had no direct bearing on the matter. “This doesn’t change any of that,” said DiBona, “for good or for bad. If your perception is that [Istio stewardship] needs to be fixed, then it still needs to be fixed.”

It appears, though, that it is related. A post yesterday from Google’s Sean Suchter, lead engineer and director of Istio, was headed “Open and neutral”, and stated it was an update on “trademarks and project governance.”

Google, photo by lightpoet via Shutterstock

Google forges Open Usage Commons to manage open-source project trademarks, lobs hot-potato Istio at it


Suchter described the transfer of trademarks, but also wrote about “the next evolution of Istio’s governance” – which is nothing more than tweaks to the steering committee and a new appointment to the project's technical oversight committee. There is nothing about transfer to an independent foundation, on top of which it would be odd to have a foundation oversee the code without also having the trademark.

We asked DiBona to comment again in the light of the response to the OUC, and he said "what I can tell you is that work towards updating Istio’s governance is being done right now via a new steering committee charter, being discussed in the open with the community."

Further confusing the issue, Google’s application to register the Istio trademark has been suspended by the US Patent and Trademark Office (USPTO) because of “likelihood of confusion” with the already-registered SAIL. Istio is a Greek word meaning sail. DiBona told us “Google is in the process of seeking USPTO registration for Istio, but this is not required for ownership.”

It is reasonable to conclude that the OUC is in fact Google’s attempt to satisfy the demand for Istio to be under neutral governance. It seems to have satisfied one important customer. US Air Force Chief Software Officer Nicholas Chaillan, who previously expressed concern about Istio's status, said he was “excited to see the Istio community and Google listen to my call to make Istio truly open and address the trademark issue. Now the steering committee must be addressed as currently discussed.”

The Linux Foundation, on the other hand, has implied the rationale behind the formation of the OUC is flawed. “There has been concern that open source hasn’t addressed issues of trademarks as it relates to major OSS projects. This is not the case,” said the foundation, explaining that it already registers and manages trademarks for some projects it hosts. “We have successfully done this for the most important open source projects in the world.”

CTO of CNCF Chris Aniszczyk said: “Google set up an organization with no details claiming to be solving a "trademark issue" in open source that doesn't exist given the 100+ open source foundations... using a trademark (Istio) that was rejected by the USPTO in 2019... just bonkers sorry, nothing novel here.”

Oracle’s Jon Mittelhauser, veep of Developer Services and on the CNCF board, said: “IBM comes out against Google; says Istio should be part of CNCF (I agree strongly). My team is in the process of reevaluating (and likely moving away from) the use of Istio as we build new cloud native services and technologies. Without open governance, we can’t support it.”

The OUC seems to be completely controlled by Google

If OUC is intended to be neutral, Google could have done a better job. The board has six members: two from Google, one ex-Google, and three working in academic research. No large company invested in Istio or Kubernetes is represented, other than Google. VMWare principal engineer Joe Beda observed “the OUC seems to be completely controlled by Google or Google aligned people/entities.”

Rancher Labs CTO and co-founder Darren Shepherd observed that the “Istio trademark going to this weird new foundation shows a complete misunderstanding of why people wanted Istio to go to a foundation. People were not like, 'I will only use Istio if the trademark is owned by a proxy foundation.'

Note that Istio is open source under the Apache License 2.0, and that there is representation from other companies on its committees. The steering committee has six people from Google, three from IBM, and one from Red Hat. The technical oversight committee has three from Google, two from IBM, one from Tetrate, and one from Aspen Mesh. Istio could potentially be forked, as has happened to projects such as MySQL, which was split to create MariaDB, and OpenOffice, forked to create LibreOffice, in both cases because of governance concerns.

The CNCF was co-founded by Google, and Google remains a platinum member. Unlike the new OUC, though, the CNCF represents a breadth of members and may be more "open and neutral" than the web giant would like.

If Google’s aim with the OUC was to convince its partners that Istio is now in neutral hands, it has more work to do. It appears instead that it has created greater friction. The implication is that it sees commercial advantage in not handing Istio over to the CNCF or another well-known foundation, and must figure that this advantage more than outweighs the cost in terms of worsening relationships with its Kubernetes partners. ®

Similar topics

Broader topics

Other stories you might like

  • Lonestar plans to put datacenters in the Moon's lava tubes
    How? Founder tells The Register 'Robots… lots of robots'

    Imagine a future where racks of computer servers hum quietly in darkness below the surface of the Moon.

    Here is where some of the most important data is stored, to be left untouched for as long as can be. The idea sounds like something from science-fiction, but one startup that recently emerged from stealth is trying to turn it into a reality. Lonestar Data Holdings has a unique mission unlike any other cloud provider: to build datacenters on the Moon backing up the world's data.

    "It's inconceivable to me that we are keeping our most precious assets, our knowledge and our data, on Earth, where we're setting off bombs and burning things," Christopher Stott, founder and CEO of Lonestar, told The Register. "We need to put our assets in place off our planet, where we can keep it safe."

    Continue reading
  • Conti: Russian-backed rulers of Costa Rican hacktocracy?
    Also, Chinese IT admin jailed for deleting database, and the NSA promises no more backdoors

    In brief The notorious Russian-aligned Conti ransomware gang has upped the ante in its attack against Costa Rica, threatening to overthrow the government if it doesn't pay a $20 million ransom. 

    Costa Rican president Rodrigo Chaves said that the country is effectively at war with the gang, who in April infiltrated the government's computer systems, gaining a foothold in 27 agencies at various government levels. The US State Department has offered a $15 million reward leading to the capture of Conti's leaders, who it said have made more than $150 million from 1,000+ victims.

    Conti claimed this week that it has insiders in the Costa Rican government, the AP reported, warning that "We are determined to overthrow the government by means of a cyber attack, we have already shown you all the strength and power, you have introduced an emergency." 

    Continue reading
  • China-linked Twisted Panda caught spying on Russian defense R&D
    Because Beijing isn't above covert ops to accomplish its five-year goals

    Chinese cyberspies targeted two Russian defense institutes and possibly another research facility in Belarus, according to Check Point Research.

    The new campaign, dubbed Twisted Panda, is part of a larger, state-sponsored espionage operation that has been ongoing for several months, if not nearly a year, according to the security shop.

    In a technical analysis, the researchers detail the various malicious stages and payloads of the campaign that used sanctions-related phishing emails to attack Russian entities, which are part of the state-owned defense conglomerate Rostec Corporation.

    Continue reading
  • FTC signals crackdown on ed-tech harvesting kid's data
    Trade watchdog, and President, reminds that COPPA can ban ya

    The US Federal Trade Commission on Thursday said it intends to take action against educational technology companies that unlawfully collect data from children using online educational services.

    In a policy statement, the agency said, "Children should not have to needlessly hand over their data and forfeit their privacy in order to do their schoolwork or participate in remote learning, especially given the wide and increasing adoption of ed tech tools."

    The agency says it will scrutinize educational service providers to ensure that they are meeting their legal obligations under COPPA, the Children's Online Privacy Protection Act.

    Continue reading
  • Mysterious firm seeks to buy majority stake in Arm China
    Chinese joint venture's ousted CEO tries to hang on - who will get control?

    The saga surrounding Arm's joint venture in China just took another intriguing turn: a mysterious firm named Lotcap Group claims it has signed a letter of intent to buy a 51 percent stake in Arm China from existing investors in the country.

    In a Chinese-language press release posted Wednesday, Lotcap said it has formed a subsidiary, Lotcap Fund, to buy a majority stake in the joint venture. However, reporting by one newspaper suggested that the investment firm still needs the approval of one significant investor to gain 51 percent control of Arm China.

    The development comes a couple of weeks after Arm China said that its former CEO, Allen Wu, was refusing once again to step down from his position, despite the company's board voting in late April to replace Wu with two co-chief executives. SoftBank Group, which owns 49 percent of the Chinese venture, has been trying to unentangle Arm China from Wu as the Japanese tech investment giant plans for an initial public offering of the British parent company.

    Continue reading
  • SmartNICs power the cloud, are enterprise datacenters next?
    High pricing, lack of software make smartNICs a tough sell, despite offload potential

    SmartNICs have the potential to accelerate enterprise workloads, but don't expect to see them bring hyperscale-class efficiency to most datacenters anytime soon, ZK Research's Zeus Kerravala told The Register.

    SmartNICs are widely deployed in cloud and hyperscale datacenters as a means to offload input/output (I/O) intensive network, security, and storage operations from the CPU, freeing it up to run revenue generating tenant workloads. Some more advanced chips even offload the hypervisor to further separate the infrastructure management layer from the rest of the server.

    Despite relative success in the cloud and a flurry of innovation from the still-limited vendor SmartNIC ecosystem, including Mellanox (Nvidia), Intel, Marvell, and Xilinx (AMD), Kerravala argues that the use cases for enterprise datacenters are unlikely to resemble those of the major hyperscalers, at least in the near term.

    Continue reading

Biting the hand that feeds IT © 1998–2022