Open Source Business Models That Actually Work
Open source business models that actually make money: managed hosting, open-core, and support. The patterns that work, read through SEC filings.
The most misunderstood idea in software economics is that open source is a business model. It is not. Open source is a distribution strategy, and the business model is whatever you charge for around the free code.
That distinction decides who survives. Open source business models that actually work do not monetize the free layer; they stack a paid layer on top of it. Only three patterns generate durable revenue at scale: managed hosting, open-core, and support or subscription. A different escape from commodity competition is to go narrow instead of open, the niche-software argument in vertical SaaS: why niche software wins.
The pattern that wins most often is the one that sells the single thing open source makes hardest, running the code reliably at scale. Give the software away, then charge for the operating burden. That is the thesis this piece reads through public filings, not press releases.
Every company figure below ties to a specific SEC filing or disclosure and fiscal period. The framing is analytical: how the models work, where they break, and what an operator should copy, not what to do about any stock.
Key takeaways
- Open source is distribution, not monetization. The free code wins adoption; the revenue comes from a paid layer stacked on top of it, never from the free layer itself.
- Managed hosting is the dominant winning pattern. MongoDB Atlas reached $1.943B subscription revenue in FY2025 and was 72-75% of total revenue across FY2026 (MongoDB 10-K FY2025, FY2026 releases).
- Open-core works as a funnel, not as the product. GitLab posted $759.2M revenue, up 31%, with 1,229 customers above $100K ARR (GitLab 10-K FY2025).
- The market re-rates these businesses upward. IBM acquired Red Hat for $34B in 2019 and HashiCorp at $6.4B enterprise value in 2024 (IBM/Red Hat July 2019; IBM/HashiCorp April 24, 2024).
- Meta’s open-weight play is not a business model. It is a cost-control and competitive weapon funded by a ~$200B ad engine (Meta FY2025), not by selling the model.
Is open source a business model or a distribution strategy?
Open source is a distribution strategy, not a business model. The business model is whatever you charge for around the free code. The companies that win long-term sell managed hosting, open-core features, or support and subscription, not the open-source software itself.
The confusion is old and expensive. Founders treat “we are open source” as if it answered the revenue question. It does not. It answers the adoption question. Releasing the code is how you get a million developers to try the thing without a sales call. What they pay for later is a separate decision you still have to design.
Think of it as a stack. The bottom layer is free and drives distribution. Revenue stacks vertically on top: hosting, enterprise features, support, compliance. The free layer pulls demand through the funnel; the paid layers convert it. A company that forgets this tries to charge for the bottom layer and watches a fork eat its lunch.
This is the same logic that governs why gross margin is destiny in SaaS: the layer you actually sell, not the layer you give away, decides what you can ever charge and what margin you keep.
The Open-Source Monetization Map
Here is the framework. Call it the Open-Source Monetization Map: a matrix of the five recurring patterns against what stays free, what you pay for, a real company that runs the pattern, and why it works or fails. It is an original analytical asset built so an operator can place their own product on it in one pass.
| Pattern | What is free | What is paid | Real example | Why it works or fails |
|---|---|---|---|---|
| Managed hosting | The full software, self-run | Hosting, scaling, uptime, ops | MongoDB Atlas, Confluent Cloud | Works: sells the operating burden, the hardest thing the free code creates |
| Open-core | Community edition | Enterprise features, security, governance | GitLab, HashiCorp (pre-acquisition) | Works as a funnel; fails if the free tier is good enough for the buyer |
| Support / subscription | The software | Support, certification, lifecycle, indemnity | Red Hat (RHEL) | Works at enterprise scale; needs a large base and procurement trust |
| Dual-license | Code under copyleft | A commercial license to avoid copyleft | Historically MySQL-style | Works narrowly; depends on the license being a real constraint |
| Open-weight + ads | The model weights | Nothing; a separate engine pays | Meta Llama | Not a model: it is cost control funded elsewhere, only viable with a separate profit engine |
The rule the map encodes: run down the “what is paid” column, and if your answer is “the software,” you do not have a business model. If your answer is “the operating, the enterprise layer, or the assurance around the software,” you do. The durable patterns all sell something the free code makes hard, not the free code itself.
The managed hosting pattern: sell the operating burden
Managed hosting is the clearest winner because it sells the one thing open source structurally makes worse: the work of running the software reliably at scale. The code is free. Operating a globally distributed, backed-up, monitored, secure cluster is not.
MongoDB is the textbook case. Its database is open and downloadable. Almost nobody large wants to run it themselves. So MongoDB sells Atlas, the managed cloud version, and that is where the money is. Atlas generated $1.943B in subscription revenue in FY2025 (MongoDB Inc. Form 10-K FY2025), and across FY2026 it climbed to 72-75% of total revenue (Q1 72%, Q2 74%, Q3 75%, per MongoDB FY2026 earnings releases), growing 26% year over year in Q1 FY2026 and 29% for the full FY2026 year.
Confluent runs the same playbook on Apache Kafka. Kafka is free; operating it is a specialist job. Confluent Cloud generated $624M in FY2025, up 27% year over year, and represented 55.7% of subscription revenue (Confluent Inc. Form 10-K FY2025), inside $1.167B of total revenue, up 21%.
Elastic shows the pattern mid-transition. Elastic Cloud reached $157M in Q1 FY2025, up 30% (Elastic investor relations, Q1 FY2025), inside $1.483B of total FY2025 revenue (Elastic N.V. Form 10-K FY2025). The cloud line is the fast-growing half pulling the mix.
| Company | Hosted product | Hosted revenue | Growth | Mix | Source |
|---|---|---|---|---|---|
| MongoDB | Atlas | $1.943B subscription (FY2025) | 26% YoY (Q1 FY2026) | 72-75% of total (FY2026) | MongoDB 10-K FY2025; FY2026 releases |
| Confluent | Confluent Cloud | $624M (FY2025) | 27% YoY | 55.7% of subscription rev | Confluent 10-K FY2025 |
| Elastic | Elastic Cloud | $157M (Q1 FY2025) | 30% YoY | growing share of $1.483B total | Elastic 10-K FY2025; IR Q1 FY2025 |
The shape is identical across all three: the open code is the funnel, the managed service is the revenue, and the revenue grows faster than the company overall because it is where the buyers want to be. The same owning-the-operating-layer dynamic that pressures hyperscaler economics runs underneath, mapped in AWS margin pressure and the cloud reset.
The open-core pattern: the free tier as a funnel
Open-core gives away a capable community edition and charges for the enterprise layer: single sign-on, audit logs, compliance, governance, fine-grained access control. The free tier is the top of the funnel; the enterprise tier is the conversion.
GitLab is the cleanest public example. The community edition is free and widely used; the paid tiers sell the governance and security an enterprise procurement team requires. GitLab posted $759.2M in revenue in FY2025, up 31% year over year, with 1,229 customers contributing more than $100K in ARR (GitLab Inc. Form 10-K FY2025). The free edition did not earn that. It manufactured the pipeline the paid edition closed.
HashiCorp ran open-core across Terraform, Vault, and Consul: open tools with paid enterprise and cloud tiers on top. It reached $583.1M in revenue in FY2024, up 23% (HashiCorp Inc. Form 10-K FY2024). That model proved valuable enough that IBM agreed to acquire the company, which is its own lesson about where open-core value actually lands.
Open-core has one structural failure mode. If the free tier is good enough for the buyer, conversion stalls. The art is drawing the line so the community edition wins adoption while the enterprise edition owns the features a paying organization cannot operate without. Draw it too generously and you have funded distribution with no monetization layer above it.
The support and subscription pattern: Red Hat and the IBM play
The oldest working model sells assurance: support, certification, security backports, lifecycle guarantees, and indemnity around software that is otherwise free. Red Hat built the canonical version on Red Hat Enterprise Linux. Linux is free. A supported, certified, long-lived, someone-to-call version of Linux is what enterprises buy.
That model scaled into a strategic asset. IBM acquired Red Hat for $34B, completed in July 2019 (IBM/Red Hat press release, July 2019). By 2025, Red Hat was generating roughly $6.5B in annual revenue and represented about 45% of IBM Software revenue, growing in the low-to-mid teens (IBM investor relations materials, Q3 2025; IBM 2024 Form 10-K). Inside that, OpenShift reached $1.8B ARR, growing more than 30% (IBM Q3 2025 earnings materials).
The support model needs two things the other patterns can lean on less: a very large installed base and deep procurement trust. It is a slower-growing pattern than managed cloud, but it is sticky, predictable, and exactly the kind of recurring revenue an acquirer pays a premium for. The durability of that recurring base is why it survived a $34B acquisition and still compounds.
Which open-source revenue pattern is winning?
Managed hosting is the dominant winning pattern. MongoDB Atlas ($1.943B subscription FY2025, growing 26% YoY) and Confluent Cloud ($624M FY2025, 27% YoY) exemplify it: they sell the hardest thing open source makes easy, running reliable, scaled infrastructure. The revenue comes from operational burden, not from the software itself.
Open-core and support both work, but they are slower or narrower. Open-core depends on drawing the free line so the buyer still needs the paid tier; support depends on a large installed base and procurement trust. Managed hosting needs neither, because the operating burden is universal: every customer who runs the software at scale would rather pay someone to run it. That is why the hosted line outgrows the parent in every public case, and why it is the pattern to default to.
Why managed hosting wins: the economics of the operating layer
Across the three patterns, managed hosting is the most reliable winner, and the reason is economic, not fashionable. Open source makes the code free, which means the code cannot be the moat. The moat moves to whatever the free code does not solve, and the thing it most conspicuously does not solve is reliable operation at scale.
Running a stateful distributed system in production is hard, ongoing, and high-stakes. It needs on-call staff, upgrade discipline, backup and restore that actually works, security patching, and capacity planning. A managed service absorbs all of that and bills for it monthly. The customer is not paying for the database. They are paying to never get paged about the database.
That is why the hosted line outgrows the parent in every case above: MongoDB Atlas at 72-75% of revenue, Confluent Cloud at 55.7% of subscription, Elastic Cloud as the fast half of the mix. The market is voting with its wallet for the operating layer over the software layer. The principle generalizes into one line: sell the operating, not the software. The software is free and forkable; the operating is sticky and recurring.
This is the same value-capture question that decides where pricing power sits across the AI infrastructure market map: whoever runs the workload, not whoever wrote the code, captures the recurring spend. It is also why the meter you choose matters as much as the model, the fork between usage-based and seat-based pricing.
Meta’s open-weight strategy is not a business model
Meta’s Llama is the most-cited “open source” story in tech right now, and it belongs in a separate row on the map because it is not a business model at all. Meta does not sell Llama. It releases the weights to commoditize a rival’s product, cheapen its own inference cost, and pull ecosystem optimization in for free.
That is only affordable because a separate engine pays for it. Meta’s total revenue was $200.97B in FY2025, up 22%, at roughly 41% operating margin ($83.28B operating income), per Meta Platforms Inc. Form 10-K FY2025. Family of Apps advertising revenue was $58.1B in Q4 2025 alone, up 24% (Meta Q4 2025 results release). The model is a cost line inside an ad business, not a product with a price.
The spend behind it is enormous: FY2025 R&D was roughly $57.37B and capital expenditures were $72.22B including finance-lease principal payments, with 2026 capex guided to $115B-$135B (Meta FY2025 10-K; Meta 2026 guidance). A commercial open-source company cannot copy this. It has no $200B engine to absorb giving the core away. The full mechanics of that strategy sit in Meta’s open-source AI strategy explained, and the mirror-image owned-surface version is Google’s AI strategy as a distribution war.
The transferable rule: open-weight as Meta runs it is a distribution war, not a monetization model. Copy it only if you, too, earn your money on a layer the free release does not touch.
Databricks and the private open-source play
Databricks is the live test of whether the managed-hosting thesis scales into the largest private software company. It is built on open-source foundations (Apache Spark, Delta Lake, MLflow) and sells a managed platform on top, the same stack-the-paid-layer pattern, executed at venture scale.
The run-rate signals are steep. Databricks reported a $5.4B revenue run-rate in February 2026, growing roughly 65% year over year (Databricks press release, February 2026; CNBC). It raised a Series L of $5B in equity at a $134B valuation in December 2025, plus about $2B in additional debt (Databricks press release, December 2025; CNBC).
Some later figures are estimates, not filings, and are labeled as such. A reported $6.9B annualized revenue by June 2026, roughly $1.4B ARR in AI products, and Data Warehousing climbing toward $1.5B ARR are estimates (Sacra company profile, June 2026; not from an audited filing). Treat the $5.4B February run-rate and the $134B December valuation as the disclosed anchors, and the mid-2026 figures as directional.
The signal that matters: even the largest company built on open-source foundations makes its money on the managed platform, not the open projects underneath it. Same map, same paid layer, much bigger numbers.
Methodology: how revenue mix and growth figures were read
When a ”% of revenue” or growth rate is cited, here is the frame keeping it honest.
- Inputs: reported revenue, subscription revenue, and segment lines from each company’s most recent 10-K and earnings releases (MongoDB FY2025/FY2026, Confluent FY2025, Elastic FY2025, GitLab FY2025, HashiCorp FY2024, IBM/Red Hat 2025, Meta FY2025).
- Assumptions: that “Atlas,” “Confluent Cloud,” and “Elastic Cloud” as the companies define them reasonably proxy the managed-hosting line, and that growth rates are reported on a comparable basis period over period.
- Sensitivity: revenue-mix percentages move quarter to quarter (MongoDB Atlas ran 72% to 75% across FY2026 quarters), so any single quarter is a point on a trend, not a fixed property.
- What this misses: these companies rarely break gross margin by hosted versus self-managed line, so the hosted layer’s standalone profitability is inferred, not disclosed. Databricks figures past February 2026 are third-party estimates, not audited filings, and are labeled illustrative.
This is a framework for reading the models, not a model that outputs a target price.
The bear case: what the managed-hosting thesis misses
The strongest counter-argument is not that managed hosting fails. It is that the operating layer commoditizes too, and faster than the database did. State it at full strength.
The bear case runs like this. The thing managed hosting sells, running the software reliably, is itself becoming a commodity. Every major cloud now offers a managed version of every popular open-source project, often the original vendor’s own competitor. AWS, Azure, and Google Cloud can run a managed database next to the vendor’s managed database, frequently cheaper, bundled with the rest of the customer’s cloud spend. When the operating layer converges, the vendor’s pricing power compresses, and the same margin squeeze that hits everyone renting compute starts to bite.
The numbers give the bear teeth. Managed-hosting lines grow fast partly because they are young; mature, the growth rate normalizes and the question becomes what stops a hyperscaler from undercutting the originator on its own software. If the open code is free and the operating is replicable, the durable moat narrows to brand, data gravity, and switching cost, which are real but thinner than “we are the only ones who can run this.”
The honest weighing: the bear is right that the operating layer is not permanently defensible and that hyperscaler competition is the central long-term risk to this model. Where the bear is weakest is the assumption that all operating layers commoditize equally. The vendor that wrote the software ships features first, knows the internals deepest, and accumulates the operational data to run it better, which is a recurring head start, not a one-time one. The disagreement is not about the filings. It is about how fast the operating advantage decays, and that is genuinely unsettled.
What operators should take from this
If you are building on or around open source, the transferable moves are concrete. The map is not just descriptive; it is a checklist.
- Decide what you sell before you open-source anything. Place your product on the Open-Source Monetization Map first. If the only answer to “what is paid” is “the software,” you have a distribution plan and no business model. Pick the operating, the enterprise layer, or the assurance.
- Default to selling the operating burden. Managed hosting is the most reliable winner because it sells what the free code makes hardest. If your software is non-trivial to run at scale, hosting is your strongest paid layer.
- Draw the open-core line at the buyer, not the user. Keep the community edition genuinely great for individuals and small teams; reserve governance, compliance, and security for the org that has a procurement process. If the free tier satisfies the buyer, you have funded adoption with no conversion.
- Treat hyperscaler competition as a when, not an if. Assume a cloud will offer a managed version of your project. Compete on first-party features, depth, data gravity, and multi-cloud neutrality, not on being the only host.
- Do not copy Meta unless you have Meta’s engine. Open-weight-and-give-it-away is a cost-control weapon for a company that earns on a different layer. If you do not have a separate large profit engine, free is not a strategy, it is a hole.
- For analysts: read the mix line, not the headline. The tell of a working open-source business is a fast-growing hosted or enterprise line outgrowing the parent, the way Atlas reached 72-75% of MongoDB revenue. If the paid layer is not outgrowing the whole, the model is not converting.
As an illustrative example (hypothetical numbers, to show the mechanism): a team open-sources a workflow engine, gets 50,000 self-hosted installs, and books no revenue for a year. They add a managed cloud tier and an enterprise SSO-plus-audit tier. Within a few quarters the cloud tier is the fastest-growing line and the enterprise tier closes the large logos. Nothing about the open engine changed. They simply added the two paid layers the map says actually convert, and stopped expecting the free layer to pay them.
Where this is genuinely vulnerable
A credible analysis names the holes. Three stand out.
The operating moat decays. The whole managed-hosting thesis rests on running the software being hard. As tooling, automation, and hyperscaler-managed offerings improve, that difficulty falls, and with it the premium. The model is strongest early and faces compression as the operating layer matures.
Mix can flatter a stalling business. A hosted line growing as a share of revenue can mask a self-managed line in decline. A rising percentage is not always rising health; it can be the numerator holding while the denominator shrinks. Read absolute growth alongside the mix.
Acquisition is not the same as a standalone model proving out. HashiCorp was acquired before the market fully judged its independent trajectory, and Red Hat’s clearest validation is an IBM purchase price, not a decade of standalone public compounding. M&A can reward a model that public markets were repricing, so an acquisition headline is evidence of strategic value, not proof the standalone economics were settled.
None of these is fatal on today’s evidence. They bound the thesis rather than overturn it: managed hosting is the strongest single open-source revenue pattern, and it is not permanently safe.
How the pieces fit together
Open source business models that work all share one structure: free distribution at the bottom, a paid layer stacked vertically on top, and revenue that comes from the paid layer, never the free one.
The three durable patterns are managed hosting (sell the operating burden), open-core (sell the enterprise features), and support or subscription (sell the assurance). Managed hosting wins most often because it sells the thing open source makes hardest, running the code reliably at scale, which is why Atlas, Confluent Cloud, and Elastic Cloud all outgrow their parents.
The companies that confuse the free layer for the business model get forked or undercut. The ones that sell the operating, not the software, build recurring revenue durable enough to compound, to IPO, or to command a strategic premium. That is the whole map. The rest is where you draw the line and how fast you can stay ahead of the cloud running your own code.
Analysis, not investment advice. Figures are drawn from the public SEC filings and disclosures cited inline by company and fiscal period (MongoDB, Confluent, Elastic, GitLab, HashiCorp, IBM/Red Hat, and Meta), with clearly labeled third-party estimates where noted. Frameworks here are for understanding open-source business models and tradeoffs, not for making buy or sell decisions.
Want the full toolkit for reading filings like this, the Open-Source Monetization Map, the revenue-mix scorecard, and the managed-hosting framework used above? It’s in the Tech Business Analysis Playbook.
Sources
- MongoDB Inc. Form 10-K FY2025 (year ended January 31, 2025)
- MongoDB Inc. Q1-Q3 FY2026 earnings releases
- Confluent Inc. Form 10-K FY2025 (twelve months ended December 31, 2025)
- Elastic N.V. Form 10-K FY2025 (fiscal year ended April 30, 2025)
- Elastic investor relations Q1 FY2025 results announcement
- GitLab Inc. Form 10-K FY2025 (fiscal year ended January 31, 2025)
- HashiCorp Inc. Form 10-K FY2024 (fiscal year ended January 31, 2024)
- HashiCorp Inc. / IBM press release, April 24, 2024
- IBM/HashiCorp Form 8-K merger agreement filings, 2024
- IBM earnings and investor relations materials, Q3 2025
- IBM 2024 Form 10-K
- IBM/Red Hat press release, July 2019
- Meta Platforms Inc. Form 10-K FY2025 (year ended December 31, 2025)
- Meta Platforms Inc. Q4 2025 results release
- Meta Platforms Inc. 2026 company guidance
- Databricks press release, December 2025 (Series L funding)
- Databricks press release, February 2026 (revenue run-rate)
- CNBC reporting on Databricks funding (December 2025, February 2026)
- Sacra company profile: Databricks (June 2026 revenue estimate)
Figures are drawn from public filings and primary documents, cited inline by fiscal period. Analysis only, not investment advice.
Frequently asked questions
Is open source a business model or a distribution strategy?
Open source is a distribution strategy, not a business model. The business model is whatever you charge for around the free code. The companies winning long-term sell managed hosting (the operating burden), open-core features (enterprise capabilities), or support and subscription, not the open-source software itself. The model stacks on top of free distribution; it does not arise from it.
Which open-source revenue pattern is winning?
Managed hosting is the dominant winning pattern. MongoDB Atlas ($1.943B subscription FY2025, growing 26% YoY) and Confluent Cloud ($624M FY2025, 27% YoY) exemplify it: they sell the hardest thing open source makes easy, running reliable, scaled infrastructure. The revenue comes from operational burden, not from the software itself.
How much revenue does MongoDB make from Atlas?
MongoDB Atlas generated $1.943B in subscription revenue in FY2025 and represented 72-75% of total MongoDB revenue across FY2026 Q1-Q3. It grew 26% year over year in Q1 FY2026 and 29% for the full FY2026 year (MongoDB Inc. 10-K FY2025, Q1-Q3 FY2026 earnings releases).
What happened to HashiCorp and GitLab as open-source companies?
HashiCorp was acquired by IBM at $6.4B enterprise value ($35 per share, ~$7.7B equity value) announced April 24, 2024, with completion expected Q1 2025. At acquisition it had $583.1M FY2024 revenue (23% YoY). GitLab is a public subscription SaaS business with $759.2M FY2025 revenue (31% YoY) and 1,229 customers above $100K ARR. Neither won by selling open source; both converted to subscription or enterprise sales.
How is Meta's open-source Llama strategy different from commercial open-source companies?
Meta's open-source AI strategy is not a business model; it is a competitive and cost-control strategy funded by a separate ~$200B advertising engine (Meta FY2025). Meta does not sell Llama. It releases the model to commoditize a rival's product, cheapen its own inference, and pull ecosystem work for free. That is only viable for a company with a separate, large profit engine.
Colson Founder & Tech Business Analyst
Colson is the founder of ColsonSuperApps LLC and a multi-product software operator, shipping a consumer SaaS platform, a B2B SaaS product, and a portfolio of mobile apps. He writes siliconcent from the operator's chair — dissecting the same unit economics in public filings that he runs internally: CAC payback, LTV/CAC, net revenue retention, and gross margin.
- Founder, ColsonSuperApps LLC
- Operator of a consumer SaaS platform, a B2B SaaS product, and a mobile app portfolio
- Reads 10-Ks, S-1s, and proxies as primary sources