Considering Openjdk? It'S Time To Decide.: Featuring Research From Forrester
Considering Openjdk? It'S Time To Decide.: Featuring Research From Forrester
Considering OpenJDK?
It’s time to decide.
Today, software development teams are under more pressure than ever to cost-effectively
deliver feature-rich software to customers within shorter timelines. As Oracle has announced
it is starting to charge for its Java SE subscriptions, perhaps your organization is already
looking into OpenJDK as an alternative that can eliminate Java SE subscription costs while
keeping the organization well equipped to meet internal and external demands. OpenJDK
can certainly be part of this solution.
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)
WHITE PAPER
Contents
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)
WHITE PAPER
Managing new costs or have resources in place to monitor and keep systems up to date
as security and other upgrades become available, as well as
considering alternatives?
provide effective support to the application teams.
Last year, Oracle announced that effective January 2019, public
updates for Oracle Java SE 8 will no longer be available for DON’T DO ANYTHING (AND HOPE FOR THE BEST)
business, commercial, or production use without a commercial
As this Forrester report says, “we would tend to heavily discount
license. The announcement outlined a new support model for its
this option.”
commercial Java runtime product and introduces new fees and
higher expenses related to support and licensing costs.
A self-audit is imperative
According to this Forrester report, many well-informed In this report, Forrester recommends that before you make any
application development and delivery (AD&D) teams decisions about what is best for your organization, you start
immediately began sizing up their support options. The report by conducting a self-audit of your Java-dependent custom and
also indicates that many Forrester clients were asking questions third-party applications. Once you know what areas of the
about this licensing change. At Rogue Wave Software, we’ve business will be impacted, you can start to evaluate the costs,
also seen an increase in questions from our OpenLogic clients and make better-informed decisions.
relating to Java licensing and support and moving to OpenJDK
In particular, Forrester recommends:
while maintaining the stability and dependability of their
applications. • Analyzing and documenting your client exposure
It’s critical for AD&D leaders to make an informed choice • Documenting which Java versions your organization has
that considers the organization-wide impacts on cost, time, running in production
resources, and support for maintaining Java applications. In • Evaluating and documenting third-party application
this report, Forrester outlines four alternatives for organizations dependencies
to consider:
• Understanding and documenting your organization’s
DevOps maturity
CONTINUE TO USE ORACLE JAVA SE
The least disruptive but potentially costly option as it requires One other Forrester recommendation that really stands out
organizations to secure a commercial support license for Oracle in this report is the need to understand and benchmark what
Java SE from Oracle. alternative OpenJDK “support” actually means. In evaluating the
alternatives, development leaders need to check that supported
TRANSITION TO A SUPPORTED BUILD OF OPENJDK OpenJDK builds have “passed the technology compatibility kit
As there’s an open source alternative to almost every (TCK) specification process for highest Java SE compatibility.”
commercial software package available, for Oracle Java SE, its It’s also important to know how updates are made available,
OpenJDK. OpenJDK is functionally identical to Oracle Java SE, including updates from the larger OpenJDK community, to
however because it’s open source, there are options ensure your organization can leverage the latest innovations.
for support.
Next steps
EMBRACE THE OPENJDK COMMUNITY MODEL
The time to act is now. Read this report from Forrester to learn
Organizations can embrace the OpenJDK model and take over more about the new program and alternatives to Oracle’s Java
full ownership for ensuring security, availability, and support. SE subscription changes and determine the right path for
Teams evaluating the community model need to ensure they your organization.
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)
WHITE PAPER
Forrester Report
RUN A SELF-AUDIT TO IDENTIFY EXPOSURE Since Oracle acquired Sun Microsystems in 2009, users have
A self-audit will help development leaders identify custom and faced occasional bursts of uncertainty and angst regarding
third-party applications that use Java SE today and provide input Oracle’s intentions for Java. These concerns flared in 2016 as
into which support options are best in 2019 and beyond. Oracle increased audits of Java SE users to check for usage of
advanced options that were commercially licensed, but most
clients continued to use the implementation.3 But the new
Oracle Java SE Subscription appears to be the straw that will
break the camel’s back for many. Why? Customers with Oracle
Java SE:
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)
WHITE PAPER
REPORT STICKER SHOCK AT THE INCREASES. development. The Oracle Java SE Support road map identifies
Java 11 as a long-term support (LTS) release for which Oracle will
The new subscription’s prices for Oracle Java SE support — $25
provide up to eight years of premiere and extended support.
a month per server core and $2.50 a month per Java client —
But Oracle will only provide transitional support for Java 9 and
apply to all Oracle Java SE commercial customers. Previously,
10. We expect continued angst from AD&D leaders as they sort
only Oracle’s Java SE Advanced customers paid support fees
through this new release process of LTS and non- LTS releases
to obtain security patches among other benefits ($5,000 per
and as some brace themselves to jump all the way from Java 8
processor, plus 22%).4 Customers that ignored the advanced
(and earlier) to Java 11, which is incompatible with older
program now face unplanned cost increases if they want
Java releases.
security patches for Oracle Java SE. Customers in the advanced
support program may not see these cost increases.
Behind The New Oracle
Customers with thousands of Java virtual machines installed on Java SE Subscription
desktops face new yearly support costs of millions of dollars.
Why is Oracle disrupting such a mature, widely adopted release
For mature Java applications, big cost increases are anathema.
model? Oracle must do so to sustain Java’s relevance in the
Customers actually seek reductions in support costs over time.
cloud-native era and, we suspect, build a sustainable business
Yet, without a support subscription, customers can’t receive
case for supporting its own ongoing development costs. Thus,
security patches and other vital updates for Oracle Java SE.
for Java:
Many customers are wary of Oracle’s sales practices and expect SUPPORT MOVES TO A SUBSCRIPTION MODEL.
the vendor to use the new subscription policies against them
In the cloud era, monthly subscriptions are the norm, in part
in the form of additional audits. Oracle frequently employs
reflecting the pay-as-you-use business models of Amazon Web
software audits today; customers don’t want still more.
Services (AWS) and many other vendors. Even Salesforce,
WANT SIMPLER REGIMES. with its weak pay-as-you-use pricing model, employs
monthly subscriptions. For Java runtimes, however, monthly
Navigating this transition is complicated, raising the risk of
subscriptions have minimal advantage, as most applications are
costly mistakes along the way — especially for firms that don’t
now stable workloads. Most customers don’t need pricing that
have experience working with open source, community-based
allows them to scale down, as they almost never will.
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)
WHITE PAPER
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)
WHITE PAPER
AN ONGOING NEED FOR CLIENT- out at $341,500 per year for unlimited desktops and servers.
SIDE JAVA ON WINDOWS. Azul supports Linux, macOS, and Windows, and it plans to
Oracle is still packaging Java SE builds and making them freely support Java 13 and 15 with 18-month medium term updates in
available for noncommercial use, and these installers are well addition to Java 11 and 17, Oracle’s current designates for long-
tested and easy to use. We’ll document other options for client- term release support.
side Java below, but Oracle Java SE remains a reliable way for
AMAZON, WHICH SHARES ITS SELF-SUPPORT EF-
application development leaders to run a supported version of
FORTS VIA CORRETTO.
Java on Windows clients.
Amazon is resolving its own substantial dependency on running
UNVERIFIED THIRD-PARTY APPS Java at scale with the Corretto project.9 While Corretto 8 has
WITH JAVA DEPENDENCIES. only recently been made generally available (as of January
Organizations with many third-party applications that have 31, 2019), Amazon has been running it in production for over
Java dependencies may find it tough to get ready answers from 20 months. Amazon has made builds for its own Linux, Mac
vendors about their OpenJDK support status. If these vendors OS X 10.10 and higher, and Windows 7 and higher available
do not provide a Java installation as part of their installation and committed to providing security fixes and performance
process, then the least-risky short term approach is to keep enhancements to it for long-term support. Self-support
using an incumbent distribution of Java like Oracle Java SE. allows the company to: fix regressions, improve operations,
and enhance performance at its own pace; create a single
Option 2: Transition To A distribution of JDK 8 customers can use across operating
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)
WHITE PAPER
RED HAT, WHICH GIVES RED HAT ENTERPRISE Instead of letting a thousand flowers bloom, we’d suggest that
LINUX USERS COMMERCIAL JAVA SUPPORT. enterprise architects create guidelines for per-platforms builds,
Red Hat currently supports OpenJDK 7, 8, and 11 for Red Hat targeting versions of Java 8 and Java 11 for developer adoption.
Enterprise Linux (RHEL) and Windows, and it has committed to
MONITOR COMMUNICATION FROM
supporting major versions of OpenJDK for six years after they are
THE OPENJDK VULNERABILITY GROUP.
introduced. Note that Red Hat skipped support for OpenJDK
The OpenJDK Vulnerability Group is charged with reviewing and
9 and 10, so we’d expect a similar approach to future non-LTS
announcing vulnerabilities and fixes to OpenJDK. Development
versions of OpenJDK (12 to 16). It also remains to be seen is how
organizations that choose to self-support on OpenJDK-derived
IBM will rationalize the IBM Runtimes for Business Java support
binaries are well advised to monitor its mailing list for up-to-date
offering if the pending acquisition of Red Hat is completed. Red
information about security patches.14
Hat’s commercial support for OpenJDK 8 and 11 is obviously a
great option for clients already running Java server workloads on
ENCOURAGE INCREASED ENGAGEMENT
RHEL or Windows. WITH THE JAVA COMMUNITY.
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)
WHITE PAPER
Take A Tactical Approach For 2019, vendors in the decision process. Note that if you choose Azul,
IBM, or Red Hat for enterprise support, you’ll need to swap out
With An Eye Toward Modernization
the versions of Java already installed on supported machines,
The future of Java is already here, and it’s built on OpenJDK;
so plan to test dependent applications to ensure that they don’t
as of Java 11, even Oracle Java SE is a commercially supported
depend on features historically only available via a commercial
downstream build of it. Accordingly, the question for
license from Oracle.
application development leaders isn’t, “Should we move to
OpenJDK?”, it’s, “How fast will we move to OpenJDK” and BENCHMARK WHAT ALTERNATIVE
“What commercial support might we need?”. To answer OPENJDK “SUPPORT” ACTUALLY MEANS.
those questions: When evaluating options, development leaders should
check whether supported OpenJDK builds have passed the
RUN YOUR SELF-AUDIT ASAP!
technology compatibility kit (TCK) specification process for
Complete your self-audits as soon as possible, even if you highest Java SE compatibility. It’s also important to ask how
haven’t gotten a visit from your friendly Oracle salesperson yet. updates are made available and what the process the process
Ask the questions we’ve provided above and build a matrix of (if any) is for including updates from the larger OpenJDK
custom and third-party applications that depend on Java, as well community. Also, development leaders should benchmark
as the versions of it they require. This will provide valuable input support hours, response-window commitments, and the length
for triage activities and conversations with development teams of support for specific versions of Java. Finally, it’s important
and software vendors that provide third-party applications. to match platform support options to the specific operating
systems and cloud providers your applications run on.
TRIAGE DEPENDENCIES AND ALIGN YOUR
STRATEGIES WITH RISK TOLERANCE AND MAKE SURE YOU’VE INSTALLED NON-OPENJDK
BUDGET REALITIES. BUILDS ONLY WHERE NECESSARY.
If you can execute a single support strategy across all the
It should go without saying, but there was a time when client-
dependencies you’ve identified, consider yourself fortunate
side Java at enterprise scale was simply a given — think the .NET
(or at least well-funded). We expect that large application
runtime or Adobe Flash. Those days are long past, and modern
development organizations will apply support strategies 1,
development teams need to clear a high bar to install any of
2, and 3 in combination to systemically minimize risk while
these runtimes on an employee client. Be sure that employees
minimizing support costs for 2019. It makes sense for teams
aren’t installing new copies of Java SE that Oracle makes
that are actively developing or maintaining apps built on Java
available for personal use in order to support applications they
to prioritize updating to Java 8 or Java 11, testing on OpenJDK
might use for business purposes, violating the Oracle Java SE
if they have not already done so. Likewise, it makes sense to
licenses terms in the process.
prioritize upgrading third-party apps to versions tested against
OpenJDK. Use your audit to drive these conversations and set TACTICS MAY DICTATE PAID SUPPORT IN 2019.
near-term dates that remove explicit dependency on Java SE.
Even after you’ve minimized dependencies, updated apps
under maintenance, installed updates to third-party apps, and
USE THE RFP PROCESS TO MINIMIZE
SUPPORT JAVA SUPPORT COSTS. removed unnecessary copies of Java SE, don’t be surprised if
you still find dependencies on Java 7 or earlier that you can’t
Since multiple vendors are prepared to provide commercial
address immediately. Maybe support has lapsed on a third-
support for Java, it makes sense to ask them for quotes. Clients
party app, or maybe there aren’t any dev and QA professionals
indicate seeing price flexibility when they involve multiple
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)
WHITE PAPER
to update and retest a custom app still in active use. In these Endnotes
cases, it may well make sense to buy commercial support for
1
Source: “Oracle Java SE Support Roadmap,” Oracle, November
2019 instead of doing nothing and hoping for the best. That
18, 2018 (https://www.oracle.com/technetwork/java/java-se-
tactical decision would buy application development pros at
support-roadmap.html).
least another 12 months to find a more strategic solution to
applications that have stubborn dependencies on older version 2
Source: Customers with Oracle Java SE Advanced plans may
of Java. not see larger bills, depending on the number of Java clients
they employ. The advanced program levied per-server charges;
Engage With An Analyst the new subscription includes per-client fees, as well.
Gain greater confidence in your decisions by working with 3
Source: Gavin Clarke, “Oracle finally targets Java non-payers –
Forrester thought leaders to apply our research to your specific
six years after plucking Sun,” The Register, December 16, 2016
business and technology initiatives.
(https://www.theregister.co.uk/2016/12/16/oracle_targets_
To help you put research into practice, connect with an analyst For Oracle’s Java SE offerings at the time, check the following.
to discuss your questions in a 30-minute phone session — or opt Source: Donald Smith, “Java SE Offerings,” Java Platform Group,
for a response via email. Product Management Blog, December 21, 2016 (https://blogs.
oracle.com/java-platform-group/javase- offerings).
LEARN MORE
4
Oracle Java SE Advanced included access to security updates
ANALYST ADVISORY and fixes for current and older releases, as well as use of
three features — Advanced Management Console, Java Flight
Translate research into action by working with an analyst on a
Recorder, and Java Mission Control — and access to root-cause-
specific engagement in the form of custom strategy sessions,
analysis support services from Oracle.
workshops, or speeches.
5
Oracle’s policy is to provide two “feature updates” and four
LEARN MORE
“security updates” for each feature update per year under the
GPL license.
WEBINAR
6
Oracle indeed reduced the number of changes included in a
Join our online sessions on the latest research affecting your
Java SE release starting with JDK SE 8. According to Oracle, for
business. Each call includes analyst Q&A and slides and is
example, Java SE 10 contained 2,700 source-code changes, less
available on-demand.
than 20% of the source-code changes included in Java SE 9.
LEARN MORE
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)
WHITE PAPER
7
Source: Donald Smith, “Oracle JDK Releases for Java 11 and 11
Source: “IBM Runtimes for Business,” IBM (https://www.ibm.
Later,” Java Platform Group, Product Management Blog, com/us-en/marketplace/support-for-runtimes).
September 11, 2018 (https://blogs.oracle.com/java-platform-
12
Source: “Make the move from Oracle JDK to OpenJDK,”
group/oracle-jdk-releases-for-java-11-and-later).
Rouge Wave Software (https://www.roguewave.com/sites/
8
Source: Azul Systems (https://www.azul.com/downloads/ rw/files/resources/rw_oracle_java_openjdk-ds.pdf).
zulu/).
13
For binary builds of Java, check the following. Source: “Latest
9
Source: “What Is Amazon Corretto 8?” AWS Documentation release,” AdoptOpenJDK (https://adoptopenjdk.net/ releases.
(https://docs.aws.amazon.com/corretto/latest/corretto-8- html?variant=openjdk8&jvmVariant=hotspot); Azul Systems
ug/what-is-corretto-8.html). (https://www.azul.com/downloads/zulu/); and “Boost
your Java™ application performance,” OpenJ9 (https://www.
10
Amazon has received mounting criticism from some areas of
eclipse.org/openj9/).
the open source community over the past few years as being an
exploiter of open source instead of a contributor. While there’s 14
Source: “OpenJDK Vulnerability Group,” OpenJDK (http://
no explicit penalty attached to a consumptiononly approach to openjdk.java.net/groups/vulnerability/).
open source, it can become a brand liability when a company is
explicitly trying to attract developers as part of its go-to-market
strategy.
About Perforce
Perforce powers innovation at unrivaled scale. With a portfolio of scalable DevOps solutions, we help modern enterprises overcome complex product
development challenges by improving productivity, visibility, and security throughout the product lifecycle. Our portfolio includes solutions for Agile
planning & ALM, API management, automated mobile & web testing, embeddable analytics, open source
support, repository management, static & dynamic code analysis, version control, and more. With over 9,000 customers, Perforce is trusted by the
world’s leading brands, including NVIDIA, Pixar, Scania, Ubisoft, and VMware. For more information, visit www.perforce.com.
www.openlogic.com OpenLogic by Perforce © Perforce Software, Inc. All trademarks and registered
trademarks are the property of their respective owners. (0320JB20)