The Functional Source License (FSL) is a source-available licence written by Sentry and published with an announcement on 2023-11-17. Sentry describes it as an evolution of the Business Source License (BSL) and as “eventually open source”, because every version converts to a permissive Apache 2.0 licence after two years.[2][1] Sentry applies it to the main Sentry web application. The licence is not on the Open Source Initiative’s list of approved licences, and Sentry says so itself.[1] For asset managers the practical effect is that Sentry can be installed and used internally at no licence cost, subject to a restriction on commercial competing use.
Editions and licences
Sentry states four goals for its licensing: anyone should be able to run Sentry for themselves or their business; there should be no feature difference between its SaaS and self-hosted offerings and no open-core model; there should be minimal limitations on use of the code; and there should be protection from other companies selling Sentry’s work without giving back.[1] It uses three licences.[1]
| Licence | Where Sentry uses it | Notes |
|---|---|---|
| Apache License 2.0 | Sentry’s default for new projects | OSI-approved; attribution and patent protection; used unless there is a concern about GPL-2.0 compatibility |
| MIT | All SDKs, as a fallback for the Apache-2.0 licence | Some SDKs include third-party dependencies not under MIT, with additional terms in the SDK repository |
| FSL-1.1-Apache-2.0 | All components powering the main Sentry web app | Limits use in a commercial Sentry-like offering |
Sentry’s history explains the choice. According to its announcement, Sentry started in 2008 as an unlicensed 71-line Django plugin, was published under BSD-3 from the following year, and moved to the Business Source License about ten years later. It then relicensed both Sentry and Codecov under the FSL.[2] The licence file in Sentry’s repositories carries the abbreviation FSL-1.1-Apache-2.0 and a copyright notice for Functional Software, Inc. dba Sentry (2008-2024 in the main repository and 2016-2024 in the self-hosted repository).[3][5]
The SDKs are governed separately from the hosted service. The Terms of Service state that use of reference SDKs is subject to the licence terms provided with them and not the Terms, and that the Service excludes SDKs.[6]
Permitted and competing use
The licence text grants the right to use, copy, modify, create derivative works, publicly perform, publicly display and redistribute the software for any Permitted Purpose, subject to its patent, redistribution and trademark clauses.[3] A Permitted Purpose is any purpose other than a Competing Use.[3] Sentry’s announcement says the FSL has no additional use grant, which is the variable that made each BSL licence different.[2]
A Competing Use means making the software available to others in a commercial product or service that does one of three things: substitutes for the software; substitutes for any other product or service Sentry offers using the software that exists when the software is made available; or offers the same or substantially similar functionality as the software.[3]
The licence lists examples of Permitted Purposes: internal use and access, non-commercial education, non-commercial research, and use in connection with professional services the customer provides to a licensee using the software in accordance with the terms.[3]
Other conditions:
- Patents. The grant includes a licence under Sentry’s patents to the extent that a Permitted Purpose would necessarily infringe them. If the licensee claims against any party that the software infringes a patent, its patent licence ends immediately.[3]
- Redistribution. The terms apply to all copies, modifications and derivatives. Anyone redistributing must include a copy of or link to the terms and not remove copyright notices.[3]
- Trademarks. Other than displaying licence details and identifying Sentry as the origin, no right to use Sentry’s trademarks, trade names, service marks or product names is granted.[3]
- Disclaimer. The software is provided as is, without warranties, and Sentry disclaims liability for indirect, special, incidental or consequential damages.[3]
In Sentry’s self-hosting documentation the same position is summarized for operators: users can deploy Sentry anywhere, even inside an enterprise ecosystem, but may not sell deployed self-hosted Sentry as any kind of offering, and may not be a direct competitor of Sentry by using its FSL-licensed code.[4] The documentation also says the software is “practically open source before that except when you are a Sentry competitor”.[4]
The two-year change
The change to Apache 2.0 is an irrevocable additional licence, effective on the second anniversary of the date Sentry makes the software available.[3] The licence defines “the Software” as each version made available, so the clock runs separately for every release.[3] A user may then use the version under Apache 2.0 instead of the FSL terms.[3] Sentry’s announcement presents the two-year period as half the BSL default, and as meaningful protection for the community if the driving company stops maintaining the software.[2]
For an asset manager this has a concrete consequence. A Sentry release more than two years old can be used under Apache 2.0 with no competing-use restriction, while a current release is under the FSL. A compliance review of an internal Sentry installation should therefore record the release version and date as well as the licence name.
Self-hosted Sentry
Sentry offers and maintains a minimal setup that works out of the box for simple use cases, described as a way to run all of Sentry on one’s own server without paying anything.[4] It is built on Docker and Docker Compose with a bash install and upgrade script, and is installed by cloning the self-hosted repository at the latest release and running the installer.[4] See Self-hosted Sentry.
Support
The self-hosted version “comes with no guarantees or dedicated support”. Sentry engineers will do their best to answer questions, and users are expected to rely on the community on Discord for anything else.[4] The documentation adds that Sentry does not offer recommendations on scaling up, since installations are very custom, and that it provides no further help for air-gapped installations.[4] Where a customer later wants to move to the hosted service, the documentation points to relocation tooling.[4]
Features and limits
Sentry says self-hosted should be considered the Business plan without any software limitations and no paid tier.[4] The following are not available on self-hosted:[4]
- Pricing tiers and the billing system.
- Spike Protection, because it is tightly coupled with billing quotas, and Spend Allocation for the same reason.
- Seer and other AI and machine learning features, which are currently closed source.
- Data Storage Location, because the customer owns the data.
- Some mobile and gaming capabilities: iOS symbolication, because Apple does not provide a public symbol server; Android system symbols, which cannot be redistributed; and PlayStation support, which uses components under a partnership with Sony that cannot be redistributed. Nintendo Switch support is limited.
Because these are the features hosted customers pay for in Sentry plans, reserved volume and pay-as-you-go, comparing the two models requires matching features, not just price. Spike Protection, Seer and regional storage are listed as unavailable on self-hosted,[4] while the hosted plans price Seer and the quota categories.[7]
Resources and data
The documented minimum is Docker 19.03.6 and Docker Compose 2.32.2, 4 CPU cores, 16 GB RAM plus 16 GB swap and 20 GB of free disk, and Sentry recommends 32 GB of RAM. The setup relies heavily on disk I/O.[4] Debian and Ubuntu-based distributions are preferred, RHEL-based distributions have known installation issues and Alpine Linux is unsupported.[4] The installer asks the operator to opt in or out of Sentry’s own monitoring of the self-hosted install, which may collect the operating system username, IP address, install log, runtime errors and performance data with thirty-day retention. Anonymous usage statistics are sent to Sentry by default and can be disabled with a configuration setting.[4]
Practical points for asset managers
- Inventory every self-hosted Sentry installation, with release version and date. Treat each as an FSL-licensed item with no licence fee but also no vendor support commitment.[4]
- Confirm that no internal installation is made available to third parties as a commercial service. An external-facing monitoring product built on Sentry code would be the sort of use the Competing Use definition describes.[3]
- Keep the licence file with any copy or fork, since the terms bind all copies, modifications and derivatives.[3]
- For SDKs embedded in applications, record the SDK repository’s own licence, because Sentry notes that some SDKs include third-party dependencies not under MIT.[1]
- Sentry’s licensing page names an address for questions on the licences, and a full internal licensing policy that employees can review.[1]
Out of scope
This article does not give legal advice on whether a particular use is a Competing Use. The licence text is the authority, and Sentry’s page invites questions to its open source contact.[1] It does not cover the Codecov product, which Sentry says it relicensed under the FSL at the same time.[2]