Skip to main content

Open-source strategy

Open foundations. Governed integration. A clear exit path.

CLIP integrates proven open-source capabilities through stable product boundaries, documented interfaces and exact-version security and license review.

CLIP · Supply-chain flow

Illustrative view
  1. 01Source
  2. 02Review
  3. 03Build
  4. 04Attest
  5. 05Sign
  6. 06Internal registry
  7. 07Deploy

Nothing reaches a deployment without passing every stage.

Why open source

Four reasons that survive procurement review.

  • Sovereignty

    Core functions operate without dependency on public Internet or foreign software-as-a-service, which is a hard requirement for disconnected deployments.

  • Transparency

    Source availability lets a security authority inspect what it is accepting rather than trusting a description of it.

  • Interoperability

    Open standards and documented interfaces keep data portable and prevent lock-in to opaque formats.

  • Skills reuse

    Practitioners train on tools they will encounter operationally, so capability transfers out of the classroom.

Capability categories

Candidate components by capability.

This records intended direction, not an approved bill of materials. Neutral text labels only — no partner logos and no implication of endorsement.

  • Structured learning

    Open edX
  • Exercise control

    INJECT MUNI
  • Infrastructure

    OpenStackKubernetesKubeVirt
  • Security analytics

    WazuhOpenSearch
  • Network visibility

    ZeekSuricataArkime
  • Digital forensics

    VelociraptorTimesketchAutopsy
  • Secure development

    ForgejoTektonHarborTrivy
  • Observability

    OpenTelemetryPrometheusGrafana

Not an approved bill of materials

Candidate components are subject to exact-version security and license review. Listing a component does not imply it is integrated, approved or included in a given deployment.

Foundation systems

Two systems CLIP builds on rather than replaces.

Rebuilding what already works well would add cost and risk without adding capability.

Open edX

Structured learning system of record

Remains authoritative for course enrolment, delivery and completion. CLIP integrates identity context, launch, completion and result synchronisation without creating circular authority over those records.

INJECT MUNI

Tabletop and exercise-control foundation

Remains the authoritative source for tabletop scenario and inject state in the MVP. CLIP exchanges exercise, participant, inject and status context while preserving that authority.

CLIP adds the unified experience, identity, policy, competency, range-orchestration, telemetry and evidence layer around these systems.

Adoption gates

Nine gates before a component enters a baseline.

Every gate must be satisfied for the exact version in use. Passing for one release does not carry forward to the next.

  1. 01Exact version and sourceThe specific release and repository, never a floating tag.
  2. 02Licence and distribution modelReviewed against the intended deployment and redistribution model.
  3. 03SBOM and vulnerabilitiesComponent inventory with a known-vulnerability assessment.
  4. 04Maintainer and community healthActivity, governance and end-of-life outlook.
  5. 05Offline installation planReproducible install from an internal mirror, no public-Internet dependency.
  6. 06Security hardeningA documented hardened configuration, not upstream defaults.
  7. 07Backup and recoveryBackup, restore and migration procedures that have been tested.
  8. 08Integration contract and ownershipA named owner and a defined interface boundary.
  9. 09Exit strategyA data-export path and a viable replacement route.

Licence families

Licence obligations shape architecture.

Licence review happens against the exact release used, including transitive dependencies, fonts, icons and copied assets. An SPDX identifier alone is not approval.

Permissive

MIT, Apache-2.0, BSD, ISC. Retain notices; few architectural constraints.

Weak copyleft

MPL-2.0, LGPL. File- or library-level obligations on modification and distribution.

Strong copyleft

GPL, AGPL. Network and distribution obligations require architecture and legal review.

Mixed or component-specific

Distributions bundling many licences. Inventory the exact image or release.

Legal review is required

Strong-copyleft and source-available components undergo architecture and distribution-model review before adoption. Licence information published here is a planning input, not legal advice.

Supply chain

From upstream source to running deployment.

  1. 01SourceExact version, pinned by digest.
  2. 02ReviewSecurity, licence and community health.
  3. 03BuildIsolated, reproducible pipeline.
  4. 04AttestProvenance and SBOM generated.
  5. 05SignArtifact and image signatures.
  6. 06DeployFrom the internal registry only.

In sequence: An upstream source is reviewed, built in an isolated pipeline, attested with provenance, signed, published to an internal registry and only then deployed — with each step producing retained evidence.

Contribution and partnership

Working with the communities we depend on.

Depending on open-source projects creates an obligation toward them. These are the ways that obligation is met in practice.

  • Upstream contribution

    Fixes and improvements developed for CLIP are offered upstream where the project accepts them.

  • Scenario and content sharing

    Approved scenarios and detection content can be shared subject to classification and releasability rules.

  • Research collaboration

    Governed datasets and reproducible environments for academic and institutional research.

  • Integration partnership

    Documented interfaces for organizations building adjacent capability.

Discuss a partnership.

Whether you maintain a component we use, build adjacent capability or want to collaborate on content — we would like to hear from you.

Open-source Ecosystem | CLIP