Licensing
Bloodraven is source-available, not open source. The full source is public, you can read it, build it, modify it, and contribute to it. Running it in production at a commercial company requires a one-time license.
We are deliberate about that wording. Bloodraven is licensed under the Business Source License 1.1, which is not an OSI-approved open source license, so we do not call it one.
Do I need to pay?
Not if you are an individual, a student, a researcher, an educator, a non-profit, or a company under $1M annual revenue. Not for dev, test, staging, CI, or evaluation — those are free at any scale, forever, whoever you are. A company over $1M annual revenue running Bloodraven in production needs a license.
Pricing carries the full eligibility table, the price of every edition, renewal prices, and the checkout links. It is the only page on this site that states a price, so there is nothing to reconcile.
Licensing is counted in failover groups. A failover group is one
MySQLFailoverGroup resource, however many sites, replicas, or read-only
instances it contains. Two sites is still one failover group.
If you are not sure which side of the line you are on, email licensing@shipstream.io and ask. The answer is free and we will put it in writing.
What you are actually buying
Bloodraven is not a support contract with software attached. It is the reverse.
What is included, for everyone, free:
- Every page of these docs, including the runbooks, the failure mode matrix, and the known limitations we publish up front.
- The playground, which reproduces the full two-site topology and every chaos scenario locally.
- Published results from the deterministic simulation and chaos suites.
- Bug reports on GitHub, from licensees and non-licensees alike.
What a license buys is the right to run Bloodraven in production, perpetually, plus 12 months of updates. Your license never expires. If you stop renewing updates you keep the perpetual right to run every version published while your update period was active.
What is not included at any price except Priority Triage: technical support, an SLA, on-call coverage, emergency incident response, installation help, consulting, or guaranteed feature delivery. See commercial terms §6.
We would rather write documentation once than answer the same question fifty times, and we price accordingly. If you need a vendor to call at 3am, buy a managed database service instead — that is a legitimate choice and Bloodraven is not trying to replace it.
The license key
Licenses are sold through Polar, which is the merchant of record. Pricing covers checkout, invoicing, VAT and refunds.
Fetch a license key at /license with the Polar order ID from your receipt and the email you used at checkout. You can fetch it again if you lose it. You do not need it to run Bloodraven. There is no activation, no license server, no feature gating, and no phone-home. The software is fully functional without a key and always will be. Your receipt is the license, and compliance is on the honor system.
The key exists only so you have something concrete to file: an artifact for your own procurement records, expense report, and internal software inventory.
Recording the license in the cluster
The token is an Ed25519-signed JWT. It is a public assertion, not a credential. You can paste it into the cluster so the operator can verify it offline — no network calls, no phone-home — and log your organization, edition, and update-period end, plus expose them as Prometheus metric labels. This is for your own compliance auditing. It never gates functionality or changes operator behavior. An invalid token, a missing token, and a token whose update period has ended all leave failover, reconcile, and MySQL behavior unchanged. Offline verification shipped in 1.1.0.
An Organization license usually lives on the operator and covers every group:
# Helm values
license: "eyJhbGciOiJFZERTQSIsImtpZCI6ImJyLTEiLCJ0eXAiOiJKV1QifQ...."
That sets BLOODRAVEN_LICENSE (or you can pass --license on the operator
command line). A Production license for one group goes on the group and
overrides the operator default:
apiVersion: shipstream.io/v1alpha1
kind: MysqlFailoverGroup
metadata:
name: orders
spec:
license: "eyJhbGciOiJFZERTQSIsImtpZCI6ImJyLTEiLCJ0eXAiOiJKV1QifQ...."
# ...
Resolution per group: spec.license if set, else the operator default, else
Community. If spec.license is set and fails verification, the operator does
not fall through to the operator default — it reports the field as invalid
and continues as Community.
A license whose update period has ended is still valid. That is the documented
perpetual state. The operator logs it at Info, keeps valid="true", and keeps
running every version published while the update period was active.
Metrics:
bloodraven_license_info{namespace="orders",group="orders",organization="Acme Corp",edition="organization",valid="true"} 1
bloodraven_license_updates_expiry_timestamp_seconds{namespace="orders",group="orders",organization="Acme Corp",edition="organization"} 1786752000
With no license configured the info series is still emitted, with
edition="community" and valid="true", so dashboards do not break on the
free tier. Alert on a paid update period ending in the next 30 days with:
(bloodraven_license_updates_expiry_timestamp_seconds - time()) / 86400 < 30
That alert is a renewal reminder. It is not an outage. The operator does not change behavior when the timestamp is in the past.
The signer contract — header, claims, updatesUntil, and a worked example —
is on License token contract. Your receipt remains the
license even if you never paste the token anywhere.
Why source-available and not Apache 2.0
Two reasons, and we would rather state them plainly than let you guess.
We want you to be able to audit this. Bloodraven automatically promotes production databases and fences nodes it believes are unsafe. You should not run software like that on trust. Every promotion decision, every fencing path, and every split-brain guard is in the repository for you to read before you deploy it.
We want it to still exist in five years. Bloodraven is maintained by ShipStream, which runs it in production for its own warehouse management system. Licensing revenue is what justifies the maintenance time. A free-with-paid-support model would push us toward selling support, which we do not want to sell and you probably do not want to buy.
What happens if ShipStream stops maintaining Bloodraven
Every version converts to the Apache License 2.0 two years after it is published. This is written into the license as the Change Date — it is automatic and we cannot revoke it.
In practice: the version you are running today becomes fully open source, forever, in two years, no matter what happens to us. If ShipStream disappears, the project does not become unusable and you are not locked out of code you depend on.
Two years is shorter than the four-year maximum the license allows, and shorter than what most BSL projects choose. That is intentional.
Contributing
Pull requests are welcome from everyone, licensed or not. First-time contributors sign a CLA, which is a license grant rather than a copyright assignment — you keep the copyright in your own work. See CONTRIBUTING.md.
Common questions
Where do I buy it?Pricing — prices, the eligibility table, and the checkout links for every edition and renewal.
Can I fork it? Yes. The license permits copying, modification, and derivative works. What it does not permit is offering Bloodraven, or a substantially similar derivative, to third parties as a hosted or managed service.
Can I run it for my own SaaS product's databases? Yes, with a license. That is ordinary internal production use. What you cannot do is resell Bloodraven itself, or offer managed MySQL to third parties with it.
Do staging and DR sites need separate licenses? Staging, dev, test, CI, and evaluation are free at any scale. A standby or DR site within a production failover group is already covered by that group's license — a two-site production group is one license, not two.
We are over $1M revenue but only use it for internal tooling. That is still production use if it serves a live system. It is one failover group, so one Production license — see pricing.
What if we grow past $1M mid-year? Buy a license when you cross the threshold. We are not going to audit you.
Do you offer volume, multi-year, or PO billing? Yes. Email licensing@shipstream.io.
Can we get a signed agreement, a W-9, or a security questionnaire completed? Yes, for Organization purchases. Email licensing@shipstream.io before buying.
Is there a trial? The free tier is the trial and it has no time limit. Run it in staging as long as you want. There is also a 30-day refund on any purchase.
Questions this page does not answer: licensing@shipstream.io

