Articles | Callibrity IT Consulting | Custom Software Development

The Forward Slash /AI Slop: Writing Got Cheap, Reviewing Didn't

Written by Callibrity | Aug 26, 2026, 9:24:41 PM

Who is actually reviewing the open source code your business runs on? Rich Bowen has been with the Apache Software Foundation since the late 1990s, served six terms on its board, and now works as an open source strategist at AWS. He tells host James Carman that maintainers are drowning in AI-generated pull requests that fix problems nobody has, and that when it comes to the new AI foundations, governance matters more than the money pouring in.

Prefer another app? Listen on Spotify, Amazon, Overcast, Pocket Casts, YouTube Music, and more.

At a glance

Guest: Rich Bowen, Open Source Strategist, AWS

Episode: /ai slop: writing got cheap, reviewing didn't

Published: August 26, 2026 · 1 hr 14 min

Rich got into open source in 1997 by complaining that the Apache web server's documentation was terrible, and being told he could fix it himself. He did, for the next two decades. He has served six terms on the Apache Software Foundation board, spent over twenty years as its VP of Conferences, put in nine years at Red Hat, and now works at AWS convincing teams inside a hyperscaler to sustain the upstream projects they depend on rather than drain them. His argument on this episode: AI made writing code cheap, but it did nothing to make reviewing it cheap, and the people absorbing that gap are unpaid volunteers holding up most of the software on the planet.

Key takeaways

  • The bottleneck moved from writing to reviewing. Maintainers are receiving a flood of AI-generated patches that are invalid, low quality, or patching imaginary problems. Some triage them with AI tooling. Some just delete them. Rich's line for those: "These are pizzas I didn't order, and I'm just going to throw them away."
  • The slop is causing real burnout, not just annoyance. These are passion projects run by volunteers, and the review load is new unpaid work that arrived without warning. Rich says it is driving developer burnout across the open source ecosystem, not only at Apache.
  • The same wave is bringing in genuinely good contributions. Rich draws the parallel to PHP, which brought a generation of junior developers into web programming who would never have gotten there through C. AI removes a similar gate: you can have an idea, work it out with a model, and hand the community something to nitpick.
  • You are running this code whether you know it or not. "If you have ever used a computing device, including your phone or your microwave, you are using Apache software and it's completely invisible to you." Iceberg, Kafka, Flink, Log4j, and the Hadoop lineage sit underneath most of today's AI tooling.
  • Log4Shell was a three-day fix and a multi-year regulatory event. The bug was patched within three days of being reported. The lasting consequence was governments discovering that their national infrastructure ran on code written by volunteers with no project manager and no accountability, which set off legislation in the EU, the United States, and Brazil, plus funding programs like the EU's Sovereign Tech Fund.
  • Judge a foundation by its governance, not its funding. Rich's test for the new AI foundations is two questions: who makes the decisions, and how can I become that person? "Putting all of the decision making power in the hands of the people who stand to profit tends to produce solutions that benefit the people who have all the money and stand to profit."
  • There has to be a ladder, and you cannot buy a seat at the top of it. In open source you climb into governance by doing the work and earning trust. When a seat is purchasable, that step gets skipped. Rich's benchmark is that a college student in Dubai should be able to reach a governing board without putting in a million dollars.
  • Consuming without sustaining is a self-interest problem, not just an etiquette one. The Apache license does not require you to give anything back. Rich's day job is arguing that you should anyway, because a dependency nobody invests in eventually stops being maintained and you are left on a dead end fork.

Host and guest

James Carman

Host, The Forward Slash · Chief Technology Officer, Callibrity

James Carman is the host of The Forward Slash podcast and Chief Technology Officer at Callibrity, where he champions building software that empowers people and drives meaningful outcomes. With a passion for modern architecture and a human-first mindset, he helps organizations scale smartly, without the red tape. An active mentor, speaker, and open-source contributor, James is dedicated to growing leaders and using tech as a force for good.

Rich Bowen

Open Source Strategist, AWS

Rich Bowen has been doing open source since before it was called open source. He joined the Apache web server project in 1997 as its documentation writer, has served six terms on the Apache Software Foundation board, and spent over twenty years as its VP of Conferences. He spent nine years at Red Hat before joining AWS, where he helps teams participate in the upstream communities they consume. He grew up in Kenya and still points at digital sovereignty as the reason open source matters. rcbowen.com

Frequently asked questions

What is AI slop in open source?
Rich uses it for the influx of AI-generated patches arriving at open source projects that are invalid, poor quality, or fixing problems that do not exist. The cost is not the patches themselves but the human review time they consume, which comes out of volunteer maintainers who were already stretched.
Is any of this actually in my company's stack?
Almost certainly. Rich's position is that if you have ever used a computing device, you are running Apache software without seeing it. He points to the Commons libraries, the logging libraries, and the data processing layer, and notes that current AI tooling sits on Iceberg, Kafka, Flink, Log4j, and Hadoop.
What did Log4Shell actually change?
The bug itself was fixed within three days. What changed was political. Governments realized their infrastructure depended on volunteers with no accountability, which produced supply chain legislation in the EU, the United States, and Brazil, and funding programs such as the EU's Sovereign Tech Fund. Rich also flags the other direction of travel: the defunding of CISA, which handles CVE reporting in the United States.
How do I tell whether an AI foundation's governance is real or pay-to-play?
Ask who makes the decisions and how you would become one of those people. Rich looks for governance that is documented and open, with a path to leadership that runs through doing the work rather than through writing a check. If a board seat has a price, the ladder has been bypassed.
Does the Apache license require me to contribute back?
No. Rich describes the Apache and BSD style licenses as focused on the rights of the user, with no field of use restriction, so you can build a business on the code without obligation. Copyleft licenses like the GPL work differently: you are obliged to release your changes. He argues the social contract applies either way.
What are the working business models around open source?
Rich names three. Selling services and custom solutions on top of free software, which is the Red Hat model. Open core, where the base is free and the premium features are not, which he thinks is fine as long as the free version is genuinely usable and the company is not squashing community plugins that compete with its paid features. And hosting, which is what his own employer does with things like managed Apache Kafka.

Full transcript

Read the full transcript (lightly edited for clarity)

Growing up in Kenya

James Carman: You grew up in Kenya. I have not met a lot of people who have grown up in Kenya. Tell me a little bit about that. What was that like?

Rich Bowen: My parents were missionaries and I was born at a mission hospital down on the Tanzania border, in Tenwek. I grew up in Kenya and I left Kenya to come to the US for college. We visited the US on and off over the years, but I then did not go back until about three years ago, and after thirty-five years, the country had changed significantly. Behind my passion about open source is giving nations the ability to escape from the technology hegemony, or whatever word you want to use, of the United States and Europe, and create their own sovereignty. This whole notion of digital sovereignty that has been so prevalent in the international technology conversation the last four or five years has really struck a chord with me, because watching open source in Africa is just super exciting.

James Carman: How was the education there?

Rich Bowen: Kenya was a British colony and so the education is very much British flavored. But of course it has been independent for about fifty years now, and it has got its own culturally relevant education system. I went to a British boarding school, but they do have free mandatory education through the end of high school. It is a very well educated country. It has got like ninety eight percent literacy, and a lot of stereotypes that folks have about Africa are simply not true.

A complaint that turned into two decades of work

James Carman: One thing you mentioned during the prep call that I did not know about you. You said you were responsible for the documentation. You were a writer by trade?

Rich Bowen: Well, no. I have always been a bit of a writer, but when I got involved in the Apache web server project, I was using it for work. This is all the way back in ninety-seven when the web was still just coming into the public consciousness. My employer wanted this fancy new thing called a website, and I knew nothing about that, but it sounded like an interesting project. I downloaded and installed the very first release of the Apache web server and tried to get it running, and the documentation was just awful. It was written by programmers for programmers and it was not written for content designers, which was still a very new field at the time. I got on the mailing list, and at that time it was not even the mailing list, it was NNTP. It was Usenet. And I said the documentation is terrible. And one of the prominent, and this was exciting at the time, this was a name that I had seen and venerated from afar, Jim Jagielski said, well, you can fix it yourself. So here I was being given permission by somebody whose name I had seen prominently, and him telling me you can fix it yourself was one of my very first introductions to the concept that everybody is a peer, is an equal, in this open source thing.

Rich Bowen: I started working on the documentation. Over the years I have written large portions of it and helped other people write other portions of it. I have not been terribly involved in it in the last five or six years, but that was very formative in my open source experience, and also in my career. My work on the Apache web server documentation, and then subsequently my books and my public speaking, have led very directly to every job I have ever had. I was a writer in open source long before I was a programmer.

James Carman: If the uninitiated hear somebody say "well, you can fix it yourself," you could hear that as a nasty thing. But if you know Jim, that is by no means the way he meant it. He meant it as an empowering thing. You are welcomed in to help take ownership of that product and make it better in any way you can. So a complaint got you in there, huh?

Rich Bowen: That is right. And it empowered me to do so many things. I tend to think that the most important concept in open source is ownership. It is not me doing something to help those people over there. It is me solving my own problem and owning it. The Apache Foundation is my foundation. It is something that I own and take very personally. And so I want to fix the things that are broken.

Why conferences matter more than the code

James Carman: How did you get involved with organizing the Apache conference?

Rich Bowen: Let me lead with a slight correction. I am no longer running the conference. I have turned that over to somebody else. But I am still very involved in it, and I am running the hackathon at this year's conference, which is going to be in Glasgow in October. Everyone should come. I got involved with ApacheCon, which has since been renamed to Community Over Code, all the way back in 99, because I was working on the Apache Web Server project and I was responsible for the documentation. Someone said, you should submit a talk. And I thought, I really am not the expert here, I do not have anything to say. But I submitted some talks and ended up giving four or five or sometimes six talks at ApacheCon from 2000 through probably 2015. I got involved very early on, probably 2001, on the planning committee, and ended up being VP Conferences for over 20 years running that event.

Rich Bowen: One of the things that I learned early on in open source is that the text that you see on your screen is not the human that you meet at a conference. There is a case to be made that online conferences are more ecologically responsible, and that is certainly true. But there is just something about having a meal with someone that makes them more human to you, and that makes your software based interactions more meaningful. Because software is about humans solving problems primarily, and so knowing the humans behind it has always been a great motivator for me in open source community building.

The software you are already running

James Carman: A lot of people are probably using some form of an Apache product in some shape or form and do not even know it. Would you find that to be true?

Rich Bowen: I would go so far as to say that if you have ever used a computing device, including your phone or your microwave, you are using Apache software and it is completely invisible to you. If you play Minecraft and you watch the startup screen, you will see Apache scrolling by many times because it is the underlying libraries. It is the Commons libraries, it is the logging libraries, it is the data processing. If you are using any of the AI tools, they have got Iceberg and Kafka and Flink and Log4j, and Hadoop is part of the data processing there. And you will never see that as an end user. I also have software that I have written running on Mars. Every computer on Mars has my code on it. That is pretty exciting. Apache software is absolutely everywhere. You simply cannot get away from it. And the same can be said about something like Linux. Open source is just ubiquitous and we do not even notice it.

When Log4Shell woke up the governments

Rich Bowen: For those not familiar, there was a security exploit codenamed Log4Shell in the Log4j library. I do not remember the dates of this, I am feeling like it was three or four years ago. It was a very significant bug that allowed an attacker to do arbitrary execution of code on your device. That sounds very boring if you have never heard of Log4j, but it turns out that Java code is ubiquitous, and every piece of Java code written in the last decade uses Log4j as its logging mechanism. So this code is again on most of the computing devices on the planet, and we are just unaware of it because it is six layers deep in your dependencies.

Rich Bowen: What happened with Log4Shell was that suddenly the governments of the world woke up to the fact that every computer in their country was running this code that was written by volunteers. And these volunteers had no accountability. Different nations around the world suddenly started to want to regulate this thing called open source software. My manager at the time, David Nalley, ended up sitting in front of the Senate of the United States of America and trying to explain to them that this software was written by volunteers who had no project manager. They had no company that they were responsible to. They were doing it for fun. He did not know what citizenship they held, and did not care, and the Apache Software Foundation has a policy of not asking. And the Senate of the United States was horrified by this.

Rich Bowen: That has led directly to a lot of legislation in the EU and in the United States and in Brazil and in nations all over the world who very suddenly woke up to this fact that their entire technological infrastructure was dependent on volunteers who were doing this for fun. The EU in particular has come around to understand that this is a very good thing and they should incentivize it. So you will see programs like the Sovereign Tech Fund out of the EU, and largely in Germany, that are funding people full-time to work on open source software.

Rich Bowen: The Log4Shell story is actually a big success, because as soon as the problem was reported, within three days it was fixed. Now, there is the whole supply chain problem that some folks are still today running the exploitable version of this because, hey, it was fixed, I do not need to care about it. But the fact is that you do have to keep up to date on your upgrades. That has led to this international focus on supply chains and being aware of what your dependencies are, on funding distribution networks like the Yum update network, DNF, apt-get, but also the language specific things like PyPI, that help you keep your software up to date. That is seeing a lot more funding now. So this has been a huge boon for open source, but it has also caused a lot of regulation that probably should have been in place already. We should have been self-regulating a lot of this and we were not. And then you see the other side of it where the United States government has defunded things like CISA that does the CVE reporting. That is very alarming, because now that is unfunded. There are organizations in Europe that are picking that up, and that is a whole other conversation. But mostly it is the awareness that Log4Shell brought to this problem that has been a real benefit to software development as a whole.

James Carman: Having to sit in front of Congress because you volunteered to work.

Rich Bowen: David is able to explain these concepts to people with absolutely no backing in technology, and I think he did a fantastic job of explaining it in terms that they could grasp, not because they are dumb, but because that is just not their area of expertise. He explained how this is an international grassroots effort to produce software, and that it is in fact backed by a lot of big companies and small companies, but that it is primarily these self-driven, self-managed individuals that are doing it because it is a passion work. And that was hard for a lot of these politicians to get their head around.

Pizzas nobody ordered

James Carman: There has been some AI stuff going on around supply chain attacks, and it is not just the distribution networks, but inserting themselves into the build process. Has that been an issue at Apache?

Rich Bowen: There are several layers at which AI is changing how open source looks and works. One of the most prominent is that we are seeing a lot of AI-generated patches, and a lot of them are invalid or not good patches, or patching imaginary problems. Having to sort through all of these unwanted contributions has a number of side effects. These individuals that are running these projects as a passion project are finding that this is a huge additional workload. Some of them are using the AI tooling itself to help triage this influx, and some of them are just ignoring it. They are like, these are pizzas I did not order, and I am just going to throw them away.

James Carman: Love that analogy.

Rich Bowen: There are some tools that are doing a really great job of security analysis of open source, providing projects with real high-quality security scanning that is resulting in actual fixes. But the majority of this influx that folks are calling AI slop patches are unwanted and unhelpful and not real security problems and just noise. This is leading to a lot of developer burnout, not just at Apache, but across the open source ecosystem. But it is also leading to a lot of new valid contributions. And this is the part of it that is exciting to me, that AI is allowing people with ideas to solve problems without the gating of you must know how to program in C.

Rich Bowen: There are definitely growing pains here, because it is resulting in a lot of terrible code. But I see a lot of parallels to the early days of PHP, that brought a lot of junior developers into the realm of web programming that would not have had access to it if they did not have an interpreted, easy to learn language. I see a lot of analogies to what is happening in AI, so that somebody like myself who is not a professional programmer can say, I have an idea for a solution to one of my problems, and work with an AI agent to craft that solution and then present that to the community, who can nitpick the technical details that I got wrong. But now I have a solution to problems that even a year ago I would not have been able to come up with a solution for, or would have had to pay a vendor thousands of dollars to produce something for me.

A skeptic who wrote a book anyway

James Carman: Your journey has been interesting around this AI assisted engineering stuff. You were somewhat suspicious of it. Tell us about that journey.

Rich Bowen: I was very skeptical about it because I am a writer and everyone in my family is artists. My vision from reading Asimov as a kid was that computers would do the drudgery so that we can focus on the beautiful, on the art, on the creativity. And instead what we are seeing is a lot of AI being used to produce poor quality artwork to displace real artists, and poor quality writing to displace real writers. That was my mindset going in.

Rich Bowen: This summer I wrote a book that I had been putting off for over a decade, because AI allowed me to do research. Now I did the writing, but it allowed me to pull together a body of research that would have taken me years, which is why I had been putting it off for years. So there is this tension. I think both things at the same time, and the cognitive dissonance is sometimes difficult to deal with. My kids who are artists, and my wife, who is an artist, can look at AI in a very different light. And of course, we put a lot of things under this nebulous heading of AI. AI solving medical problems that were intractable a decade ago is super exciting. AI drawing poor quality Van Goghs is not as exciting to me, and I feel like it is a misuse of the technology. But it has allowed me to solve some data problems, some research problems, that were simply intractable even a year ago. So it is both. It is constant tension between these two things in my mind as the tools continue to get better.

It was never about the code

Rich Bowen: I have a conference presentation called It Was Never About the Code, because open source was never about the code. We have always been bad about explaining the purpose of open source. The purpose of open source is collaboration. It is a melding of minds, it is reaching out to people with different ideas and coming to a collaborative solution to a problem. And the code is the thing that is the output. That was always a gating factor, because somebody had to write the code. Now that nobody has to write the code, in theory, then you can focus on the collaboration. You can focus on picking the minds of experts who are not programmers. You can find a solution to a problem from an electrical engineer that understands the problem deeply but cannot write code, and come up with a software solution. That part of it is super exciting to me.

Eight people scratching their own itch

James Carman: When the OG Apache folks got together, was their mindset very much what you are saying, this community aspect? Or was there a grandiose and broader vision from the get-go?

Rich Bowen: There was not a grand vision. Most of the people on that original eight that I have spoken to were folks that were running their own personal businesses using the NCSA web server, which was a student project out of the University of Illinois Urbana-Champaign. When Rob graduated from NCSA and decided to form a company with his software, he kind of took it off the public market. And all of these individuals that were running businesses on the web said, this is unacceptable. We need to figure out a way to continue maintaining this. Several of the people on that original eight were not even really programmers. They were just consumers of this software that had taught themselves to maintain it. That is where we started, with borrowed code that was freeware. And then we came up with the notion of an actual legal license around that. We were not the first to come up with that, that came out of MIT and BSD, and we borrowed from that. But yeah, it started with solving your own problems. And a lot of those people were surprised and even a little bit disgruntled that it had become this international thing that now you have to maintain like it is a real thing. Most of those folks are no longer involved in the effort. It was always about scratching their own itch.

Two families of licenses

James Carman: When I look for open source stuff, I tend to look for that Apache license badge. What makes the Apache license so free?

Rich Bowen: I would say that MIT and BSD have fewer restrictions. The Apache license has some patent language in there. I am not a licensed lawyer, but the high level view is that there are two classes of licenses. There is the MIT style and the copyleft style, like GPL. The Apache style ones focus on the rights of the user to use the software for anything that they choose, so there is this notion of no field of use restriction. You can use it for whatever you want, even to the extent of making money with it. And then there is the copyleft style, which focuses on the notion that software itself should be free and that closing it up is the wrong thing to do. So it focuses on the freedom of the software as opposed to the freedom of the consumer.

Rich Bowen: What I like about the Apache license in particular is the ability for somebody to take it and build a business around it without any sort of restrictions on what they do from that point going forward. The reason I find that so valuable is that it has enabled entrepreneurs around the world, especially in developing nations, to not have to start from zero. They can take something and monetize it and build a business around it. Now, I do think that if you are building value using free software, you have something of an obligation to contribute back to keeping that alive, not just because of altruism but also because of self-interest. If you want that thing to continue persisting, to continue being sustainable going forward, then you should invest in that and make sure that it is sustainable and you are not just working off a dead end fork. That is the conversation that I have most of the time at work, trying to convince businesses to invest in the thing that they are depending on and not just consume it.

Rich Bowen: With copyleft you have to release your changes. Whether the upstream project is going to accept those changes back is irrelevant, you are obligated to release your code. So when you buy a television and it has GPL code in it, they are obliged to provide you with that source code. There have been a number of successful lawsuits against hardware manufacturers that include GPL code in their product, and they have been forced to release that code on GitHub or in a code dump or in some format. My car has GPL code in it and I can go to Jeep.com and download that code. That is because the Free Software Foundation and the Software Freedom Conservancy pushed that all the way through the courts, and good for them, because that is an important part of sustaining our ecosystem.

When a company closes the license

James Carman: There were prominent stories about projects that were Apache licensed, and then folks stood on the shoulders of those giants and started to make real money, and the original projects flipped the switch on the licensing. How do you think that has impacted the open source world?

Rich Bowen: There are a number of flavors of that. There are software projects who have observed companies making a huge profit and not contributing anything back, and they have attempted to put licenses in place that say this is free for everyone's use, but not you. That is not in line with the OSI, the Open Source Initiative's definition of what open source is, because field of use is one of the clauses. You cannot restrict field of use. So some of those projects have opted to go non-open source in order to prevent the strip mining, not a favorite term of mine, but an effective one. These people consuming without contributing back, not sustaining the ecosystem.

Rich Bowen: Another flavor of this is when a business releases something as open source, and then another larger business builds a bigger business around that than the originator of the software was able to do. Full disclosure here, I work for Amazon, and there have been instances where a small company has released something as open source, making a tidy profit on it, and Amazon or Google or Microsoft has made a much larger fortune on that thing. And the smaller companies cry foul. They say, no fair, you are consuming without helping us in any way. Which of course the license allows, but like I said, there is a social contract there. And then that smaller company says, all right, never mind, this is not open anymore. And it forces a crisis in that project. How that crisis is resolved, it might be a fork, it might be that we choose to use something else.

Rich Bowen: My department at Amazon was created to help the company be better team players, be better community participants. So what I do in my day job is work with departments within my company that consume open source and help them understand how to participate in the upstream community in a sustaining way rather than in a draining way. That is my whole day job and I love it. But it is fair to say that hyperscalers, so big cloud companies like Google or Microsoft and Amazon, are frequently frowned upon for their consumption without contributing back. It is just kind of a thing that we get chastised for.

In favor of the ninety percent that is crap

James Carman: There are a lot of stranded projects out there that nobody is listening to. Is it better for the community to have all of that going on, or is it watering it down and making it harder for the jewels to shine?

Rich Bowen: I think it has always been the case in human history that ninety percent of everything is crap. If people were not publishing their stuff, all the way back to the Gutenberg press, we would not have those gems. So I think that having individuals publish their idea for public view, even though most of it is going to be garbage and most of it is going to be ignored, is how we lead to these great ideas. When I am trying to solve a problem, the first thing I ask is, surely someone else has solved this problem before. Let us go look. And nine times out of ten I will find a thing out there which has an interesting solution that is not done yet, and I will either try to participate in that community or I will take it as inspiration and move on. A lot of these are just individuals with single developer projects that they threw out there and abandoned. But that can be the gem that leads to something. SourceForge and Google Code and today GitHub have led to a richness of experimentation that leads to those few gems.

Rich Bowen: One of the things that we do in open source is we tend to think only I can save the world, and we do not look at other folks and we do not look outside of software. One of the things that I try to do in my community development work is always look at other fields of study. When I was doing ApacheCon, and now that I am doing Community Over Code, I try to invite keynote speakers that are from outside technology. They come in and they provide interesting insight that can spark a conversation that can spark solutions. So I always like to invite science fiction authors. Last year we invited a carpenter who unfortunately was unable to come due to a personal tragedy, but he used to run a carpentry show on PBS, and in our conversations he was talking about using tools that are handed down over generations to solve problems. That sounds like open source. I always like to go outside of our expertise to find insights.

Ship It or Skip It: getting on a plane

James Carman: We live in a very remote world, especially since COVID. What is it like getting on a plane and going and meeting other people around the world these days? Is that something you recommend?

Rich Bowen: I definitely recommend it. I think that sitting down and having a meal with somebody is the most important thing in conflict resolution. Conflicts happen all the time in open source, where we are extremely opinionated people, and I am right and you are wrong, and that can lead to unnecessary personal conflicts. Showing up at an event, sitting across the table from somebody, having a meal, understanding that they are more than just their code, that they also have weird hobbies like emotional support kale, just like you do, can be really formative.

Rich Bowen: But I will also say that this is an enormous privilege that I have. I have a job that allows me to go to exotic places around the world and covers my expenses, and I am very cognizant that that is a huge privilege that not everyone shares. So I am also a strong believer in local tech communities that have these same sort of meetups, and inviting those people that have the privilege of traveling to come in.

Rich Bowen: What you lack on remote events is the social aspect. Some conferences have done a really good job of building in a social hour tacked onto the end of the conference. But the hallway track at a conference, and for those of you that do not go to a lot of conferences, the hallway track just means the fortuitous conversation with that person that you bump into in the hallway about whatever comes to mind. That is such an important aspect that you simply do not get in an online conference where there is a set topic. We are going to talk about this for an hour and everything else is out of bounds. When I go to a conference, we invariably end up talking about crafts and art and cooking and all of these things that are off topic in the formal session online.

Vibe coding, minus the term

James Carman: What is your definition of vibe coding, and your take on it?

Rich Bowen: I think that the term vibe coding itself sounds kind of pejorative to me. It sounds like I am going to code without really understanding the concept. I think that what it has evolved into, at least for me, is that I do not just sit down and chat with the computer. I think about the overall structure and I define what I want a thing to do. That is more than a vibe. That is planning. It reminds me of the old days of documentation driven development and test-driven development, where before you wrote the first line of code you would write a document that described the project. We have come back around to that, I think. You do not just sit down and start writing 10 GOTO 20. You think about the overall structure. And to me, that is what vibe coding has become.

Rich Bowen: I think that it is the future of open source, because it allows you to bring in the subject matter experts who are not coders to describe the problem. And describing the problem is the first step to solving the problem. As technologists, we like to jump to the solution and we like to jump to the specific technology that we are going to use. Vibe coding, although I hate the term, allows you to take a step back and describe the problem. To me that has always been a critical part of software engineering. To use Amazon phraseology, it is being customer obsessed. It is talking to the actual person who has the problem and solving it. So again, do not like the term, but big fan of the process.

The Red Hat model, and the other ways to make money

James Carman: You were at Red Hat. People always talk about the Red Hat model. Is that dead? Can it still work today?

Rich Bowen: I was at Red Hat for nine years. I think it is still a relevant model. I know that there are folks that say you can never reproduce what Red Hat did, and maybe that is true in that particular niche. But the Red Hat model is that Red Hat does not sell software. It sells solutions around the software. That might mean documentation and help you set it up and packaging. The big Red Hat product is Red Hat Enterprise Linux, where they take a free thing and they give it to you for free, but they wrap it in a container that makes it easier to consume and use and puts all the bits together. Linux is not useful as just the operating system. There are hundreds of thousands of tools that come along with it, from your editor to your web server to your DNS server. Red Hat produces that useful package and then gives you advice and services and help in making that work for your environment. But the software itself is always free. You can always obtain the source code and you can always decide that you are not interested in Red Hat's support model and go your own way.

Rich Bowen: I have never started an open source business directly. I did web development for a while, and everything that I produced was free. What I was charging for was my custom solutions. So that is one model in open source, producing custom solutions on top of open source products and selling your labor. Another model is what we call open core, where the core of your thing is free and open source, but if you want it to do this extra shiny special thing, you have got to pay me extra for it. To me, even within that, there are two flavors. There are companies that make the free thing useless by itself. Crippleware is one of the rather unfortunate terms for that. You can download and install the free thing, but if you actually want to use it for real work, you have to pay me extra. To me that is a little unpalatable. I think that the free thing, the community edition, should be usable. One of the reasons that it is unpalatable is that these companies often use their influence in the community to prevent the community from producing those value-added features. Someone in the community might produce a free plugin that does the super duper thing, and the company will use their influence to squash that. To me that is the part of it that is anti-community. But there are good and ethical ways to do open core.

Rich Bowen: And then the third model is what my company does, which is hosting. Apache Kafka, amazing project, does really cool things, and really smart people can set it up and run it themselves, but maybe you do not want to. Maybe setting up and running it yourself is a pain that you would rather outsource. So you outsource it to Amazon Web Services. We run managed streaming for Apache Kafka, and all you have to do is show up and use it. There is a ton of companies that do that at different levels.

Advice for the AI foundations

James Carman: I recently had a conversation with the Agentic AI Foundation, a sub-foundation of the Linux Foundation. There was always money involved in Apache, but this may be an unprecedented amount of money being poured into these things. What advice would you give them to keep this from going off the rails?

Rich Bowen: The advice that I do give when folks are joining a foundation like that is to focus on governance, make sure that governance is well documented. When I use the term governance, what I mean is who makes the decisions, and how can I become that person? Making sure that governance is open, making sure that not all of the decisions are being made by one person at the top. To me that is critical. Putting all of the decision making power in the hands of the people who stand to profit tends to produce solutions that benefit the people who have all the money and stand to profit. Crafting governance that weighs all voices equal, as near as possible, produces better solutions that are customer focused, that are user focused, rather than solutions that are investor focused. To me that is the most important thing, clear governance with a path for anybody, so that a college student in Dubai can become a governing board member, that you do not have to put in a million dollars in order to become a governing board member.

James Carman: What I worry about is one person gaining undue influence. But then also, if you do level the playing field, you almost reach this detente of the watered down version of the thing. The core cannot evolve in the best product way, because everybody says no, if you do that, my shiny bits are now in the core. You get to the least common denominator. Is that a concern for you?

Rich Bowen: It is a concern. The thing about governance is there has to be a ladder to climb to governance. You climb the ladder to governance in open source by doing the work. When you can buy a seat at the top of the ladder, then you bypass the earning trust. Earning trust and demonstrating merit, demonstrating that you have good ideas, not just that you have good ideas, but that you are willing to do the work to take ownership and make those ideas happen. That is how you rise to that decision-making capacity. Although in theory opening the floodgates means that everybody is going to come in and have a say, what we have seen in practice, even for extremely critical things like Linux, like Hadoop, is there are really only a dozen people that are actually willing to do the work and become part of that leadership. So it is almost self-filtering. You can open the floodgates, you can let everybody have a say. It does not mean you have to listen to everybody. It means that you listen to the people that are actually willing to do the work to make it happen.

Meritocracy, duocracy, and who gets to do the work

James Carman: Someone said Apache is a meritocracy, and I have heard people counter that with no, Apache is a duocracy.

Rich Bowen: The term meritocracy itself is a little bit problematic, because the people who determine merit are the people who already have merit, and so they tend to determine people that look like themselves. You do see a lot of people in leadership at open source that look like me, the 50-year-old white man with a beard. I feel like there have been moments in open source where we have started to break away from that. You definitely see a lot more diversity on many axes, corporate, gender, ethnicity, socioeconomic status, than we saw back in the nineties. But it is still a problem that meritocracy as a concept tends to make us select people that look like ourselves.

Rich Bowen: So I do like the duocracy thing. But it also has to be paired with a willingness to let people do. One of the things that I am trying really hard to do at Apache is create opportunities for people to step up and do work without having to run the gauntlet of proving themselves. They can say, I can do that thing, and let that be the path into maybe I can do that bigger thing. That is something that has to be very intentional. This is not something that happens automatically. The mindset in open source tends to be, if we say you can participate, then people will show up and participate. But humans are not like that. Humans need encouragement, and they need folks to say thank you, and they need the defined opportunity to say, this thing that I could do is actually useful.

Lightning round

James Carman: What is your favorite season of the year?

Rich Bowen: Summer. Absolutely summer. I am an African kid. I like it hot, I like it humid, and I hate, hate, hate being cold.

James Carman: If you were really hungry, would you eat a bug?

Rich Bowen: Well, I guess I would, because I have. Growing up in Kenya, the flying ants, the termites, would come up out of the ground and we would run around and catch and eat them. That was less because I was super hungry, it was more on a dare. But yeah, if I was real hungry, I would eat a bug.

James Carman: If you were given the opportunity to fly into space, given today's technology, would you take it?

Rich Bowen: Absolutely. I would jump on that in a heartbeat. I grew up reading Ray Bradbury. One of my favorite books is The Martian Chronicles. I would love to visit Mars, even though that is not a practical thing that will happen in my lifetime.

James Carman: Scale of one to ten, what would you rate yourself at wiffle ball?

Rich Bowen: Wiffle ball, maybe a two.

James Carman: Do you like the smell of gasoline?

Rich Bowen: No, I do not like the smell of gasoline. I hate having it on my hands after filling the tank.

James Carman: What is a country that you would be okay never visiting in your life?

Rich Bowen: Man, that is a hard question. I really do not have an answer to that. I want to go to all of them. There is beauty everywhere, even though some of those countries have some appalling governments.

James Carman: One to ten, how much do you enjoy garlic?

Rich Bowen: Eight.

James Carman: What do you feel about cranberries?

Rich Bowen: I do not like cranberries. Cranberries make my tongue itch. I think I might have a slight allergy even. They make my mouth pucker and feel sore for a couple of days.

James Carman: Do you find handlebar mustaches to be handsome?

Rich Bowen: I really do not. Like what you like, and people should do what they want with their own physique, but no, that is not something I care for.

Where Rich puts his free time

James Carman: Anything in closing you would like to share?

Rich Bowen: My next big thing that I am a big part of is communityovercode.org, which is the new name for the ApacheCon Apache Software Foundation conference. We would love to see folks there that are involved in open source in any way. I would also ask people to look at community.apache.org, which is my primary passion right now. It is what I am dumping all of my free time into. This is building communities around Apache projects and helping folks share their best practice and wisdom around open source and learn from each other and really just have fun and enjoy it.

James Carman: You also do an interview style show. What is that?

Rich Bowen: I do plusone.apache.org, where I do interviews with the folks that are involved in Apache projects or anything around the Apache ecosystem. It is extremely sporadic. I try to do one a month. But I do love talking with people about their projects, and I tend to focus on the problem. What problem does this thing solve? Why did you do this in the first place? Who is using it, and for what, to make the world a better place? Rather than on the nitpicky technical details.

James Carman: I love the name, plus one. For those who do not know, when you do code changes at Apache, the way people vote on things is plus one, minus one. That is a really cool name. Rich, thank you again for your mentorship through the years, and I appreciate you coming on.

Rich Bowen: Thanks for the opportunity. This was a fun chat, and there are so many other things to talk about.

Ship It or Skip It

The pattern: getting on a plane for in-person tech events in a world that got very comfortable being remote.

Verdict: ship it. Rich's reasoning is not networking, it is conflict resolution. Open source runs on strongly held opinions, and sharing a meal with someone makes them more than a name in a pull request thread. His caveat is that travel is a privilege not everyone has, which is why he also backs local meetups and asks the people who can travel to show up at them.

"I think that sitting down and having a meal with somebody is the most important thing in conflict resolution."

Where to find Rich

Got a topic for us?

The Forward Slash runs on questions worth arguing about. If there is something you want James to dig into, or someone you think belongs on the show, tell us.

theforwardslash@callibrity.com