An open source operating system publishes its source code under a license letting anybody read, change and redistribute it. Linux is a kernel and a distribution is the operating system. The license is free; the skills, support and patching are not.
- The license grants three rights: read, change, redistribute
- Linux is a kernel. A distribution is the operating system
- Copyleft requires published changes; permissive licenses do not
- Choose a distribution on release model and support lifetime
- The firewall and the NAS are already running one
On this page
- What open source actually means
- The two open source license families, and why it matters
- Linux is a kernel, and a distribution is the operating system
- The lineages, and which of the rest are real
- Where these systems actually run in a business
- On the desktop, which is a different question
- What it actually costs
- Where people go wrong
- Comparison
- FAQ
What it meansWhat open source actually means
The phrase describes a license rather than a price, and three permissions define an open source operating system.
Read the source code. Any user or developer can obtain and inspect it. That is what makes independent security review possible, and it is why a serious vulnerability in an open source component is usually found and fixed in public rather than disclosed by a vendor on a schedule that suits them.
Change it. Users may modify the source code for their own purposes. Most organizations never will, and the permission still matters, because it means the software cannot be discontinued out from under you.
Redistribute it. Users may pass on the original or a modified version, under the terms of the license. This is where the two license families diverge and where the practical difference lies.
Free of charge is a common consequence and not part of the definition. Several open source operating systems are sold with support, and buying that support is normal in a business. Closed source software is the opposite arrangement on every count: the source code is not published, users cannot change it, and the vendor decides when it ends.
The licensesThe two open source license families, and why it matters
Copyleft, such as the GPL. A developer who distributes a modified version must publish the changes under the same license. The Linux kernel uses this, which is a large part of why Linux has one shared kernel rather than a dozen incompatible commercial forks. Improvements from every developer have to come back.
Permissive, such as BSD, MIT and Apache. A developer may take the source code, modify it and ship the result as a closed source product with no obligation to publish anything. This is why BSD code turns up inside commercial products constantly, including network appliances, storage systems and consumer devices whose vendors never mention it.
For an organization that runs open source software rather than shipping it, neither obligation is usually triggered, because these terms apply to distribution rather than to use.
The exception is worth knowing: an appliance or a product sold to customers containing modified copyleft code does carry obligations, and that catches people who did not realize their vendor had built on it.
Kernel and distroLinux is a kernel, and a distribution is the operating system
This distinction causes more confusion than any other in the subject.
Linux is the kernel: the part that manages memory, schedules processes and drives the hardware. On its own it does nothing a user can do anything with. A distribution combines that kernel with system tools, a package manager, an installer, default configuration and a release policy, and the result is a complete operating system.
Distributions of this operating system differ in decisions rather than in capability, and three of those decisions matter to an IT operation.
Release model. A fixed-release distribution ships a version, supports it for years and changes little. A rolling release updates continuously. Servers want the first, and choosing the second for a production estate is a decision people make once.
Package management and repositories. The tooling and the software available through it. This determines whether the thing you need to install is one command or an afternoon.
Support lifetime and vendor. How long security updates are provided and whether a commercial support contract exists. This is the whole argument for the enterprise distributions, and the reason a business pays for a system whose source code is free.
| Family | Examples | Typical use |
|---|---|---|
| Enterprise, commercially supported | Red Hat Enterprise Linux, SUSE | Production servers with a support contract |
| Community, long-term support | Debian, Ubuntu LTS, Rocky, Alma | Servers where support is internal |
| Rolling release | Arch, openSUSE Tumbleweed | Workstations, and rarely servers |
| Purpose built | pfSense, TrueNAS, Proxmox | Firewalls, storage, virtualization |
| BSD lineage | FreeBSD, OpenBSD, NetBSD | Network appliances, and security-critical roles |
The lineagesThe lineages, and which of the rest are real
Search the phrase and most of what comes back is a list. The list is longer than the set of systems a business should consider, so it helps to sort it by lineage instead of by rank.
Almost everything on it is Unix or Unix-like, which is why an administrator moves between them with a week of friction rather than a year. The shell, the file layout, the permissions and the process model are recognizable across all of them, whatever the kernel underneath is called.
Windows is the exception that makes the point, because it shares none of that ancestry, which is why moving an application to or from it is a different size of job.
The BSD family is separate code from Linux rather than a distribution of it. FreeBSD's own about page says it is derived from BSD, the version of UNIX developed at the University of California, Berkeley.
OpenBSD describes itself as a 4.4BSD-based UNIX-like operating system emphasizing correctness and proactive security, and its front page notes that OpenSSH came from it.
DragonFly BSD is the fourth name in that family. Its own history page says it was forked from FreeBSD 4.x, and its published feature list is led by HAMMER, the filesystem the project wrote for itself.
It is a much smaller project than the other three, and the reason to know it is the ideas rather than any deployment count.
A third lineage came out of Solaris. The illumos project describes itself as a Unix operating system providing next generation features for downstream distributions, including advanced system debugging, a next generation filesystem, networking and virtualization. ZFS and DTrace reached the rest of the industry from that lineage.
After those three, the list turns to projects with a different purpose. Haiku says it is an open source operating system that targets personal computing, inspired by BeOS. ReactOS states its mission as running Windows applications and drivers in an open source environment. Both are worth reading about.
FreeDOS is the one name on the list that earns a place in a toolkit. Its own site says it is a DOS-compatible operating system, and that any program which works on MS-DOS should also run on it.
That is what you install on a USB stick when a firmware update tool, or the controller on a twenty year old machine, exists only for DOS. It is not a server operating system and it was never trying to be.
GNU Hurd is the clearest case of what that means. Its own project page says the Hurd is under active development and that because of this there is no stable version, and it gives GNU Hurd 0.9 as the latest release. A system that has not declared itself stable is not a server operating system.
The practical limit on the smaller projects is drivers. A project with a small developer base writes a driver for the hardware its own developers have, and an office full of standard laptops and standard server hardware is not that hardware. Driver coverage rather than licensing is what keeps these systems off a shortlist.
Install one in a virtual machine for an hour if you are curious. That is the honest way to look at a project like this, and it costs nothing except the hour.
So the sort is short. Linux distributions and FreeBSD are systems a business can staff, patch, install and buy support for. Everything else on the list is a project, and a project is not the same thing as a platform.
Where it runsWhere these systems actually run in a business
Most organizations run more open source software than they realize, because a great deal of it arrives inside something else.
Servers and cloud instances. The majority of server workloads and almost every cloud instance run this operating system. That is the visible case and it is the smaller half.
Network and security appliances. Firewalls, load balancers, wireless controllers and routers are very often an open source operating system with a closed source vendor interface on top. The appliance is a product; the system underneath it is not proprietary.
Storage and virtualization. NAS products, storage arrays and several hypervisors are built on open source in the same way, which is why a storage appliance sometimes has a shell that looks familiar.
Containers. Every container image is a piece of a Linux userland, and container hosts run this operating system by definition. An organization running containers is running open source at scale whether or not anybody described it that way.
Embedded devices. Access points, cameras, printers and the rest. This is where update discipline goes wrong, because the vendor controls the update and often stops providing them long before the hardware leaves service.
On the desktopOn the desktop, which is a different question
Every list of open source operating systems is dominated by desktop distributions, and a business asking about them is asking something the server case does not answer.
The open source operating system is not the obstacle. A modern desktop Linux distribution installs cleanly, detects the hardware on most computers, performs at least as well as the alternatives on the same machine, and is free. None of that is the problem.
The applications are. One line-of-business application that runs only on Windows decides the whole question, and most organizations have at least one. A web application changes the calculation entirely, which is why desktop Linux is more viable now than it has ever been.
Management tooling is the second obstacle. Group policy, imaging, patching and endpoint protection all exist for Linux desktops and none of them are the tools the team already runs. Supporting two desktop platforms costs more than the licenses saved on either.
The honest position for most businesses is servers and appliances yes, desktops only where the applications genuinely allow it and somebody has costed the support.
What it costsWhat it actually costs
The license fee for an open source operating system is zero and the total cost of ownership is not, and being clear about where the money goes is more useful than an argument about philosophy.
Technical knowledge. Somebody has to know the operating system. That is a hiring or a training cost, and it is the largest one. An organization whose users and administrators all know Windows will spend real money becoming competent on Linux, and pretending otherwise is how these projects go wrong.
Support. Community support means a forum and the goodwill of other users and developers. Production systems want a contract with a response time, which is what the enterprise distributions sell, and the price is normally well below the equivalent closed source license plus support.
Update discipline. Nobody sends an invoice for missing patches. An open source operating system is patched quickly and publicly, and that visibility cuts both ways, because a published fix tells everybody exactly what to attack on systems that have not applied it. Patch management is the same security job here as anywhere.
Integration. Directory integration, backup agents, monitoring and management tooling all exist for these systems and all need configuring. Where an environment is heavily built around one vendor ecosystem, the friction is real and worth costing honestly.
PitfallsWhere people go wrong
Treating free of charge as free. There is no license fee, and the skills and the support are the actual cost. Budget for them, or the project fails on the day something breaks.
Choosing a distribution on preference. Release model and support lifetime are the criteria for a server operating system. What somebody used on a home desktop is not.
Running a rolling release in production. Continuous updates on a server estate produce continuous change. Use a fixed release with a long support window.
Assuming published source code means audited source code. Any developer can read an open source project and that does not mean any developer has. Widely used projects get real security scrutiny, and obscure dependencies with one part-time maintainer frequently get none.
Missing the open source software already in the building. The firewall, the NAS and the access points are running it. Their update policies belong to the vendor, and that is the part worth asking about.
Ignoring open source license obligations when shipping a product. Using the software imposes almost nothing. Distributing something built on copyleft code does, and that is a legal question rather than a technical one.
ComparisonTwo models, and the row about discontinuation
| Criterion | Open source | Closed source |
|---|---|---|
| License cost | None | Per server, per socket, or per user |
| Source code available | Yes | No |
| Support | Community, or a paid contract | Included in the license |
| Users who know it | Widely available | Widely available |
| Can be discontinued | No, the code survives | Yes, at the vendor's discretion |
| Vulnerability disclosure | Public and fast | On the vendor's schedule |
| Integration with one ecosystem | Varies | Excellent inside that ecosystem |
| Right for a server estate | Usually | Where the application requires it |
| Right on the desktop | Where the applications allow | Usually, for the tooling |
The row worth pausing on is discontinuation. A closed source system reaching end of life gives you a migration deadline set by somebody else, and an open source operating system can be maintained by any community willing to do it.
That is not a theoretical benefit, and several long-lived enterprise distributions exist precisely because a community continued a product after its vendor changed direction.
FAQFrequently asked questions
What is an open source operating system?
An operating system whose source code is published under a license permitting any user to read, modify and redistribute it. Linux and the BSD family are the significant examples.
What are examples of open source operating systems?
Linux in its many distributions, including Debian, Ubuntu, Red Hat Enterprise Linux and Rocky, and the BSD family of FreeBSD, OpenBSD and NetBSD. Android is an open source operating system too, on very different hardware.
Is Linux an operating system?
Strictly it is a kernel. A distribution combines that kernel with tools, a package manager and a release policy, and the distribution is the operating system.
Is an open source operating system free?
Free to license, not free to run. Skills, support contracts and patching are the real costs, and they are comparable to any closed source platform.
Is open source software less secure?
No, and the transparency cuts both ways. Security flaws are found and fixed in public and quickly, and the published fix also tells attackers exactly what to try on systems that have not applied it.
What is the difference between GPL and BSD licenses?
The GPL requires you to publish changes if you distribute a modified version. BSD and similar permissive licenses do not, which is why BSD code appears inside closed commercial products.
Do license obligations apply if I only use the software?
Almost never. These terms are triggered by distribution. Running it internally, however heavily modified, generally imposes nothing.
Which Linux distribution should a business use?
One with a long support lifetime and a fixed release model, and a commercial support contract if the systems are production. The specific name matters less than those two properties.
Can we move our desktops to an open source operating system?
The operating system is rarely the obstacle: hardware support and performance are fine. Applications are, because one Windows-only line-of-business application decides it, and so is the cost of running a second set of management tooling.
Should I use a rolling release on a server?
No. Continuous updates mean continuous change on systems whose value is being predictable. Rolling releases belong on workstations.
Is BSD better than Linux?
For a general server estate, Linux has broader hardware support, more software and far more people who know it. BSD is strong in network appliances and in security-critical roles, and OpenBSD in particular has a reputation earned by auditing rather than claimed.
Am I already running an open source operating system?
Almost certainly. Firewalls, NAS units, access points, load balancers and every container image are built on one, whatever the badge on the front of the hardware says.
Can I get commercial support?
Yes, from the enterprise distributions and from third parties. For production this is worth buying, and it is usually cheaper than the proprietary equivalent.
What happens when an open source project is abandoned?
The source code remains and any developer or community can continue its development. Several current enterprise distributions exist because a community did exactly that after a vendor changed direction.
What does GPL licensing require?
GPL licensing lets anyone use, study, change and share the software. If you distribute a changed version, you must release its source code under the same license. The Linux kernel uses GPL version 2. Running GPL software inside a company, without distributing it, triggers no obligation.
Keep readingRelated concepts
Read next · Containers What Is Docker? Every container image is a piece of this, which is how most organizations ended up running it at scale. Open this next14 min- Hypervisors · 10 min Type 1 vs Type 2 Hypervisor Several hypervisors are built the same way, which is why the shell on a storage appliance looks familiar.
- Operations · 13 min Patch Management, and Why the Hard Part Is Not the Patching The cost in the right-hand column that nobody invoices for, and the one that decides how a breach goes.
- Platforms · 10 min What a Kernel Is, and Why a Driver Can Take Down the Machine The kernels you can read for yourself.