
Avoiding vendor lock-in through open source: a developer's perspective
An analysis published on The New Stack with SUSE's support explains why vendor lock-in rarely starts with one bad decision, and how open licences, neutral governance and portable foundations lower the price of leaving a platform.
How tightly a company depends on its technology vendors left the architecture debate and entered the budget and compliance agenda. In an analysis published on The New Stack with the support of SUSE, the authors argue that vendor lock-in rarely starts with one bad decision, it accumulates from many reasonable ones.
What vendor lock-in actually costs
The issue is not the use of third-party products, since every production system relies on vendors. The problem is a dependency that has become too expensive or impractical to unwind, and on a platform team it builds up across APIs, contracts, roadmaps, identity patterns and data models.
The dangerous part is what nobody examined. A managed database picks up proprietary extensions that application code begins to assume, and a Kubernetes environment binds to one cloud's IAM, networking and load-balancer model. Together they raise the price of leaving, which arrives later as rushed migrations, service disruptions and retraining.
Open licences and who can change the rules
Open source performs well against this test because it keeps systems inspectable, portable and replaceable, though the authors stress it is no guarantee: tight coupling can be built on open foundations too. Licensing does change one thing, namely who may rewrite the terms. The Linux kernel requires no copyright assignment, so merged code keeps its original owner and the kernel has thousands of owners. Kubernetes is licensed under Apache 2.0 and governed by the Cloud Native Computing Foundation, so no vendor can retroactively withdraw open-source rights.
The fork from Terraform to OpenTofu shows the practical value. In 2023 HashiCorp changed Terraform's licence from the Mozilla Public License 2.0 to the Business Source License 1.1, and the community forked the last open-source codebase into OpenTofu, today a Linux Foundation project under MPL 2.0.
Digital sovereignty and the 52% gap
Digital sovereignty, the degree of control an organisation holds over its infrastructure, data and technology choices, makes the same questions urgent. SUSE research cited in the article found that almost all enterprises treat it as a priority, yet only 52% take real steps towards it.
The authors present sovereignty as a property of the architecture rather than a separate compliance workstream: portable workloads, clean interfaces, reproducible deployment and auditable behaviour are worth investing in anyway. Sovereignty does not create new work, it sets a deadline for work already worth doing.
Four capabilities worth testing
Reversibility comes down to four abilities: real control over every layer of the stack, the ability to audit independently what the software does, exit velocity that only means something when tested on a schedule, and the capacity to change direction when a regulation or a vendor's plans shift.
The conclusion is direct: "The true cost of any platform includes the cost of leaving it, and teams should understand that cost before they commit."
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.