Most companies that depend on open source hit governance and sustainability problems well before they’re ready to hire a full-time OSPO. OSPO++ is fractional open source program leadership: the strategy, governance, and community work, delivered as a consulting engagement instead of a headcount.

I’m not coming at this from the outside. I co-founded the Rocky Enterprise Software Foundation and led its infrastructure team, I’m the PTL for RDO and sit on OpenELA’s Technical Steering Committee, I maintain packages for Fedora and EPEL, and I review for OpenStack-Ansible. I’ve built and run the kind of systems and communities that OSPO advice is usually written about secondhand.


Problems this actually solves

You might recognize one of these:

  • “We open-sourced the project. Apparently now we have to govern it.”
  • “Legal wrote a contribution policy nobody can actually follow.”
  • “Half our product depends on projects we’ve never once talked to.”
  • “One maintainer leaving would be a material business event.”
  • “We’re donating this to a foundation and have just discovered there are rules.”
  • “Engineering says we do InnerSource. Nobody contributes to anything.”

These are governance and sustainability problems, not vertical problems. The fix looks broadly similar whether you’re a software company, a biotech, or a manufacturer — so I’m not going to invent a separate story for each industry.


What I can do

  • Contribution & governance models — Contribution guidelines, decision-making structures, and governance people can actually follow, sized to your project rather than copied from a foundation ten times your size.
  • Maintainer sustainability — Reducing the bus-factor risk around key maintainers: shared ownership, succession, and the unglamorous process work that keeps people from burning out.
  • Upstream strategy — Which projects to contribute to, how much, and why — and how to keep a working relationship with the dependencies your product rests on.
  • Foundation & project transitions — Preparing a project to move to a foundation (or to stand one up), and living with the governance and legal reality that comes with it.
  • InnerSource — Applying open source practices inside the company so code actually gets shared across teams instead of quietly re-implemented three times.
  • Release & process design — Release engineering, signing, and the repeatable process work that separates a real project from a code dump over the wall.
  • Dependency & community risk — Understanding the health and risk of the open source you depend on, including for M&A or investment due diligence.

Why me

Real experience, honestly framed:

  • Rocky Linux / RESF — I co-founded the Rocky Enterprise Software Foundation and served as its Director of Infrastructure, leading a global volunteer team of thirty-plus. I built and ran the build and distribution systems behind the project — at their peak serving 3 billion+ requests and over a petabyte of traffic a month — including Peridot, the open-source build system, and a cryptographic enclave for UEFI Secure Boot signing. That chapter has wrapped up, but it’s the clearest proof of what this work actually involves.
  • RDO & OpenELA — I’m the PTL for RDO, steering how its OpenStack packaging lives and ships, and I sit on the Technical Steering Committee for OpenELA, which exists to keep a vendor-neutral source of enterprise Linux honest.
  • Fedora & EPEL — Package maintainer and community contributor.
  • OpenStack-Ansible — Core reviewer for enterprise OpenStack deployment tooling.

That’s the difference: this is work I’ve actually done, not a framework I read about.


Engagement models

  • Monthly retainer — Ongoing strategic guidance, policy work, and access for the urgent decisions. $2,000–4,000/month depending on scope.
  • Project-based — Bounded engagements: standing up an initial OSPO, a community health assessment, an InnerSource rollout, or foundation-readiness work.
  • Due diligence — Assessment of open source assets, licensing, and community risk for M&A or investment, on a shorter timeline.

Schedule an OSPO Consultation → Email Me Instead →


Fractional OSPO and open source strategy from someone who maintains open source, not just advises on it. Based in Bedford, MA, serving the Route 128 corridor and beyond.