Why open source belongs on the mainframe

PopUp Mainframe joined a recent SHARE conference session to discuss one of the most persistent myths in enterprise IT: that mainframe and open source somehow sit on opposite sides of the technology divide. The truth, of course, is that the IBM mainframe is part of the open source ecosystem as much as anything else.

At the open source panel discussion at SHARE Pittsburgh, questions were deliberately direct, and provocative. We are grateful to the open mainframe project’s Joe Winchester, and session host Joe Westman, for the opportunity to participate. Here’s a summary of the open source mainframe myths we explored, debated, and debunked.

“Open source isn’t secure”

Security matters when software supports business-critical services, so it is a common objection. But the point is whether software is governed, tested, monitored, patched, and operated properly – which has nothing to do with its open source provenance.

Mainframe teams already understand rigor. They manage access controls, audit requirements, change processes, resilience targets, and regulatory scrutiny every day. The same discipline should be applied to open source. That means knowing what code is running, where it came from, how it is maintained, and how quickly it can be patched when something changes.

A sensible approach includes dependency audits, Software Bills of Materials, vulnerability scanning in pipelines, signed commits, least-privilege access, and clear incident response plans. It may also include taking supported distributions from vendors such as IBM Open Enterprise Foundation for z/OS or Rocket Open Source Solutions for Z, rather than pulling directly from a public repository.

While none of this makes open source completely risk-free (no software is risk-free), it does make those risks visible and manageable.

“The mainframe doesn’t do open source”

This objection is very misinformed. Open source already runs across the mainframe landscape. Linux on Z and LinuxONE depend on the Linux kernel and the broader open source ecosystem. z/OS teams use tools and runtimes such as Git, OpenSSH, Bash, Python, Node.js, Ansible, Docker, Kubernetes, and modern compiler toolchains. Many teams are already benefiting from open source; they may just not describe it that way.

The momentum is growing. Mainframe teams want the same things distributed teams want: less toil, faster delivery, better automation, stronger collaboration, and tools that fit the way developers work today. Open source can help provide those capabilities quickly, often alongside established vendor products rather than instead of them.

The Open Mainframe Project is an excellent starting point, with hosted projects and communities focused on making mainframe technology more accessible and more connected to modern development practices. The zopen community has ported hundreds of familiar tools to z/OS, helping mainframers use utilities such as Git, curl, vim, and others in familiar ways. The CBT Tape remains a valuable library of practical utilities. IBM’s z/OS core collection for Ansible continues to make automation on z/OS more accessible.

As the evidence shows, open source is already part of the enterprise technology fabric, and the mainframe environment can and should benefit from its advantages.

“Open source has no support”

The issue surrounded software support is legitimate, but not unique to open source and certainly not unique to the mainframe. Distributed systems have been running open source for years. They work because organizations put support models around them.

Support can be vendor-supplied in many cases. Alternatively, internal ownership for the tools that matter most is another option, enabling organizations to contribute and shape future direction of open source tooling.  By defining support and escalation paths before ensures that organizations can treat open source like any other software dependency.

The underlying risk in support models is unmanaged dependency, which is true regardless of whether it is open source, proprietary software, or in-house code. Good governance makes the difference.

“It is a big risk”

Risk management is another critical topic for open source – and “The community maintains it” is a not sufficient position. The right approach must use the same controls as for other enterprise software, covering supply-chain visibility, compliance scanning, licence management, security, patch processes, vulnerability monitoring, community health metrics, and clear ownership.

Is the bigger risk standing still?

With objections addressed, the question emerges: what is the risk of not using open source?

Avoiding open source limits tooling choices, hampers automation, and may limit opportunities of innovation inherited from the software community. It may also impact mainframe teams as their work may feel isolated from other platforms.

Open source brings practical advantages. It gives teams access to proven tools, accelerates automation, supports modern collaboration, and lowers the barrier for new joiners. Something as simple as using Git for code and configuration can unlock scanning, dashboards, pipeline automation, peer review, and a more collaborative way of working. Familiar tools such as VS Code can help developers new to Z become productive faster.

Open source also encourages teams to learn from one another. Mainframe teams can efficiently adopt patterns already proven in distributed systems, adapt them to the realities of Z, and contribute their own mainframe expertise back into the ecosystem.

The PopUp Perspective

At PopUp Mainframe, we see opportunities for mainframe and open source every day. Modern mainframe teams want speed, flexibility, cost control, reduced risk, and better access to skills. They need environments where change can be developed, tested, automated, replicated, and recovered quickly. Open source tech helps teams connect mainframe delivery to the broader practices already shaping enterprise IT.

PopUp Mainframe is built around the idea that mainframe change should not be slowed by avoidable friction. By providing on-demand, fully configured mainframe environments for development, testing, training, and delivery, PopUp helps teams experiment safely, move faster, and build confidence in the mainframe delivery cycle.

In our view, the IBM mainframe sits within the open source ecosystem as a vital part of it. Organizations that embrace that reality will be better placed to modernize delivery (mainframe and elsewhere), attract talent, and keep business-critical systems moving at the pace the business now expects.

Learn more

For more on how PopUp Mainframe team is using open source, click below:

Recommended Posts