ONEHUNDRED

Free whitepaper

Open source for operations: why independence must be measurable.

Independence is not a statement of belief but a measurable property. Seven pages by Andreas Hankel, CTO onehundred, for IT decision-makers and CTOs.

Andreas Hankel, CTO onehundred

Andreas Hankel

CTO onehundred · Former CTO idealo · CIO of the Year 2014

„Independence cannot be claimed, only tested. Whoever knows how long, and at what cost, they could replace a core component has something they can show in an emergency. Everything else is a hope.“

Andreas Hankel, Autor des Whitepapers
  • Former CTO idealo: Nearly nine years, 2016 to 2025.
  • CIO of the Year 2014: Mid-market category, awarded by IDG, CIO-Magazin and Computerwoche. As VP Technology at ImmobilienScout24 he brought server operations back in-house, built a private cloud and switched the virtualisation platform while in live operation.
  • Over 30 years in IT: Since 1990, including 18 years at Fiducia IT, then ImmobilienScout24 and idealo.

„What has been created is exemplary and shows the way for designing the systems of the future.“

Manfred Broy, jury CIO of the Year 2014

Request the whitepaper

You will receive the PDF by email at your business address.

Why now

In your inbox within minutes. With the nine questions you will know today whether your lock-in risk sits in the risk register or only shows up at the next renewal.

The situation

800 to 1,500 % more expensive: why lock-in belongs in the risk register.

The VMware/Broadcom case put a number on the lock-in question. After the licensing experiences of the last two years, this is above all a question of risk, not values.

800 to 1,500 %

Price increase on contract renewals in the VMware/Broadcom case, documented by the European cloud association CISPE. For many organisations the first occasion to treat lock-in as a risk that shows up on the balance sheet, not a theoretical one.

Quelle: CISPE

March 2026

CISPE filed a competition complaint against Broadcom with the European Commission. The German IT user association VOICE has also complained about abuse of market power.

Quelle: CISPE, VOICE, reported by Computerwoche

NIS2 Art. 21(2)(c)

Documented configuration and reproducible recovery are required for organisations under NIS2 in any case, and both are precisely the properties that make up the ability to exit.

Quelle: NIS2 Directive, § 30(2) no. 3 BSIG

What's inside

How many components of your operations could change their terms unilaterally?

The whitepaper covers three propositions: why lock-in belongs in the risk register rather than the technology debate, why open source shifts cost rather than removing it, and how independence can be tested through the ability to exit. Each proposition comes with three questions to place your own position within minutes.

01

Lock-in belongs in the risk register, not in the technology debate

A supplier able to set the terms unilaterally is a risk position in the same way a single-source supplier is in manufacturing. In IT that risk is rarely managed as such: it is not in the risk register, it has no owner and no assessment, until the renewal date arrives.

02

Open source shifts cost, it does not remove it

The licence line disappears, the operations line does not. An open toolchain, monitoring, automation, CI/CD, virtualisation, databases, demands version maintenance, security updates, documented configuration and people who know the components. Booking the licence saving as a pure saving is doing half the sum.

03

Independence can be tested: through your ability to exit

"Independent" is worthless as a self-description because it cannot be disproved. It becomes testable through a single question: how long would it take, and what would it cost, to replace a core component? A test of that kind, even only on paper, for one component, produces more clarity in a few days than a debate of principle.

Further chapters

  • Technical detail: portability per component
  • Benefits and economics
  • What happens if you do nothing
  • What onehundred takes on here
  • Frequently asked questions
  • Conclusion: where do you stand?
  • Sources

What onehundred takes on

Consulting, transition, operation.

onehundred builds IT operations consistently on an open source basis, monitoring, automation, CI/CD, virtualisation, databases, and takes on running them.

Consulting

Open source readiness and lock-in analysis, assessment of exit capability per core component

Transition

Migration to an open toolchain with documented, reproducible configuration

Operation

Running the open source stack, including version and security maintenance

One limitation, stated openly: in project practice, open source for operations is usually a building block of larger undertakings, a sovereignty roadmap, building your own cloud platform, or a virtualisation migration, rather than a separately commissioned project. We treat the lock-in question independently here because it has its own decision logic and should be answered independently of any undertaking currently under way.

Questions

Frequently asked questions.

Is open source as stable in operations as proprietary solutions?
For the relevant areas, monitoring, automation, CI/CD, virtualisation, databases, there are established projects in production use worldwide. What matters is not the software alone but the operational competence behind it.
Does moving to open source mean giving up support?
No. In the operation phase onehundred takes on running the stack in full, including support, patch management and further development. The difference is that this support rests on our own operational experience with the tools.
Is this a standalone product we can commission separately?
No, and we say so openly. Open source for operations is not an isolated purchasable service but the technical basis of larger undertakings: a sovereignty roadmap, building your own cloud platform, or a virtualisation migration. You can commission the lock-in analysis on its own; the implementation then follows within the respective undertaking.
What does the Broadcom/VMware case have to do with us if we do not use VMware?
The case is an example, not an isolated topic. The pattern, dependency on a vendor with market power in a critical area, transfers to many proprietary tools in monitoring, CI/CD or databases. The lock-in analysis shows where it applies in your environment.

Conclusion

Where do you stand?

Independence does not arise from choosing open software but from the operational discipline it presupposes, and it only becomes reliable once it has been tested. The nine questions in the whitepaper lead to three points: do you know your dependencies, have you planned for operations, and is your ability to exit more than an assumption?

  1. Do you know your dependencies
  2. Have you planned for operations
  3. Is your ability to exit more than an assumption
Get the whitepaper

Why now

A test of exit capability, even only on paper, produces more clarity in a few days than a debate of principle you will have to have at the next renewal anyway.