Licensing
The Go SDK, the CLI and the install surface are Apache-2.0. Everything else is Elastic License 2.0, and this page states both of its restrictions.
Two statements cover it.
The Go SDK, the CLI, the microVM operator and the Helm charts are Apache-2.0. What you write against them is yours. The license puts no obligation back on you.
Everything else is Elastic License 2.0. You may read, run, modify, and self-host it. You may not offer it to third parties as a managed service, and you may not remove the license-key check. Elastic License 2.0 is source-available, not open source.
The map
| Repository | License | What it is |
|---|---|---|
sdk | Apache-2.0 | Go SDK — agent, tool, and plugin contracts, the harness API |
adk | Apache-2.0 | The gibson CLI — scaffold, build, validate, enrol, submit missions |
setec | Apache-2.0 | Kubernetes operator for Firecracker microVMs via Kata. Useful standalone |
ast-checks | Apache-2.0 | Static checks the SDK depends on |
charts | Apache-2.0 | The Helm charts you install the platform with |
gibson | Elastic License 2.0 | The control plane |
dashboard | Elastic License 2.0 | The web interface |
gibson-executor | Elastic License 2.0 | One microVM image, one binary, parsers for common security and ops tools |
sdk-ts | Elastic License 2.0 | TypeScript SDK |
zerocool-plugins | Elastic License 2.0 | opencode plugins for running a coding agent under Gibson's controls |
docs-site | Elastic License 2.0 | This documentation |
zitadel-login | MIT | A fork of the ZITADEL login application. A fork keeps its upstream license |
The License column is generated. pnpm regen:licensing reads the LICENSE
file of each repository and writes what it finds into this page. A build gate
fails if anyone edits the column by hand.
Why this page states the two restrictions
A procurement reviewer stops on Elastic License 2.0. So it is better to say what it forbids than to leave someone to find out:
- You may not provide the software to third parties as a managed service.
- You may not circumvent the license-key functionality, or remove or obscure protected notices.
Neither restricts internal use. You may run the control plane for your own organization, on your own infrastructure, modified as you like.
Elastic License 2.0 is not approved by the Open Source Initiative. GitHub
reports it as NOASSERTION and the repository sidebar says nothing useful. Read
the LICENSE file at the root of the repository.
Components you write
A component you build with the SDK is your code. It links against Apache-2.0 libraries, and the license carries no obligation to publish it or to license it back to us. You may keep it private, sell it, or open it under whatever terms you choose.
What to check
- The
LICENSEfile in each repository matches the table above. - Nothing you build against is Business Source License or source-available with a delayed conversion. The Apache-2.0 rows above are the surface you build against.
- The Elastic restrictions apply to every row the table marks Elastic License 2.0.