The Under-the-Radar Pick: Open source software sustaining modern infrastructure
The standard take on open source software powering modern infrastructure misses what’s actually happening underneath. Everyone focuses on the obvious stuff, but there’s a better way to think about this that explains what we’re seeing.
Here’s what’s different this time: Apache, Nginx, and PostgreSQL generate billions in enterprise revenue while their maintainers burn out. That’s not a contradiction—it’s the whole story. Once you look at the actual evidence, the optimistic reading turns out to be the accurate one.
The Recommendation: Setting the Terms
Linux runs over 96 percent of the world’s top 1 million web servers. That’s not just a statistic—it’s the foundation that makes everything else make sense. This didn’t happen overnight. The pieces have been falling into place for years, and now we’re seeing the convergence.
So you have Apache, Nginx, and PostgreSQL generating massive enterprise revenue while maintainer burnout forces companies to start adoption programs and funding pledges. Look at both trends together and you see what the Open Source Initiative has been tracking: this is more stable than it looks, and the implications go way beyond the headlines.
Compare today to three years ago. It’s not just that the numbers got bigger—the whole game changed. Different players, different infrastructure, different incentives. And these changes reinforce each other instead of canceling out.
What makes this worth paying attention to isn’t that it’s new. The underlying forces have been visible for a while. What’s new is that ignoring them now takes real effort. When you have to work to not see something, that’s when you know you’ve crossed a threshold.
GitHub’s sponsors program has paid out over $30 million to maintainers. That’s part of the same picture. These aren’t separate trends—they’re connected pieces of the same shift.
The Under-the-Radar Pick: The Analysis
That $30 million from GitHub sponsors is where things get interesting. The surface reading is fine as far as it goes, but it misses the actual mechanism. And the mechanism is what matters for figuring out what to do next.
Take the EU Cyber Resilience Act putting new liability pressure on open source projects. This isn’t some random policy development—it’s a direct result of structural changes that have been building up. Previous attempts to analyze similar situations failed because they confused symptoms with causes.
The comparison to earlier cycles is useful precisely because it breaks down in specific places. What looked similar before played out differently because the foundation was different. Rust replacing C in safety-critical systems across the Linux kernel and AWS—that’s a foundation change. It doesn’t just move the numbers; it changes how elastic the whole system is.
The skeptical take deserves a real response: similar-looking moments in the past didn’t deliver what seemed logical at the time. That’s true. But this time we have Rust replacing C in safety-critical systems across the Linux kernel and AWS. That’s not a minor detail—it’s the infrastructure change that previous cycles didn’t have. Infrastructure changes stick around in ways that hype cycles don’t. GitHub Open Source tracks this stuff with the rigor it deserves.
There’s also a question that doesn’t get asked enough: who actually benefits from these shifts, and who pays the costs? The big picture can look great while specific people get hammered in ways that really matter. Keeping track of who wins and who loses is part of reading the situation clearly rather than just hopefully.
Implications: What This Means If You Care About Hidden gems
The effects of open source powering modern infrastructure reach beyond the immediate story. Linux running 96 percent of top web servers, combined with everything else I’ve described, creates ripple effects in adjacent fields and communities that aren’t always obvious from the inside. The second-order effects often matter more than the first-order ones.
Here’s where this analysis differs from mainstream coverage: maintainer burnout forcing corporate adoption programs isn’t a reaction to what already happened. It’s a signal of what’s coming next. The people who respond to the signal instead of waiting for confirmation are going to be less surprised by what follows.
What you should do depends entirely on where you sit relative to these dynamics. If you’re close to the core of open source infrastructure, the implications hit immediately. If you’re further out, it’s more strategic—understanding which pressures are building and which stable-looking things are actually fragile.
The question isn’t whether to engage with this stuff. It’s how. The answer depends on your context, your role, and your actual timeline. But step one is the same for everyone: understand what’s actually happening instead of what the most convenient story says is happening.
A few concrete points worth pulling out: First, Apache, Nginx, and PostgreSQL generating billions in enterprise revenue isn’t temporary—it’s the new baseline. Second, the EU Cyber Resilience Act putting liability pressure on open source projects tells us the adjustment period isn’t over. Third, and most important: organizations treating this moment as a new steady state instead of a transition are making a mistake that will cost them later.
The Case Against: What the Critics Get Right
Honesty means engaging with the strongest counterarguments, not just the easy ones. The case against the optimistic reading of open source infrastructure isn’t weak. There are real structural problems that deserve direct engagement.
The most serious objection is about sustainability. Maintainer burnout forcing corporate funding programs can be read not as a foundation but as a ceiling. If we’ve already incorporated most of the early adopters, the remaining growth curve might be structurally shallower than recent trends suggest.
Then there’s the regulatory dimension. Linux powering 96 percent of top web servers describes a condition in a relatively permissive environment. Regulatory responses to this scale aren’t guaranteed, but they’re not impossible either. Organizations planning as though the current regulatory environment is permanent are making an assumption that history doesn’t support.
The response to these concerns isn’t that they’re wrong—it’s that they’re already partially priced in. Rust replacing C in safety-critical systems reflects an environment where participants are already adapting to constraints rather than operating freely. The ecosystem’s ability to adjust is higher than a top-down view of the risks suggests.
Looking Forward
The direction is clearer than the timing. Anyone claiming precision about when specific thresholds will be crossed should be treated with skepticism. But the direction toward greater Linux dominance and continued development of these conditions is supported by evidence that doesn’t depend on a single variable going right.
Rust replacing C in safety-critical systems is the variable to watch as the leading indicator. Historical patterns suggest it moves first, with broader metrics following with some lag. This doesn’t make the outcome certain, but it makes it readable. And being able to read the situation is what you need for good decisions.
Three questions worth holding as this develops: First, are the structural conditions that created the current state durable, or are they cyclical? Second, who benefits from the next phase, and is that different from who benefited in the current phase? Third, what would clean evidence against the optimistic thesis look like, and is there any sign of that emerging? You don’t need answers today, but asking these questions changes what you notice going forward.
The direction is clear even when the pace isn’t. Right now in open source infrastructure, the people who have built an accurate model of what’s actually happening are better positioned than the people relying on the surface story. Building that model takes time, but it’s doable. This analysis is meant as one input into that process.
What’s in your personal toolkit that nobody talks about?