Running this yourself
The licence, what it asks of you if you host a modified copy, and where the source of the version you are talking to is.
Everything in Silent Outage's source is AGPL-3.0-only. You may run it, modify it, and host it — for yourself, for your team, or as a service you charge for. In exchange the licence asks for one thing that permissive licences do not, and it is the thing most operators miss because there is no download step to remind them: network use triggers a source-disclosure obligation.
This page is the operator's summary. It is not legal advice, and the licence text governs where this page and the licence disagree.
The clause: AGPL section 13
… if you modify the Program, your modified version must prominently offer all users interacting with it remotely through a computer network (if your version supports such interaction) an opportunity to receive the Corresponding Source of your version by providing access to the Corresponding Source from a network server at no charge, through some standard or customary means of facilitating copying of software.
Three parts decide whether it applies to you:
| Condition | Silent Outage specifics |
|---|---|
| You modified the Program | Any change to the source: a patched detector, a new alert channel, a removed plan gate, a rebranded dashboard. Configuration and .env are not modifications. |
| Users interact with it over a network | The dashboard, the ping and webhook endpoints, and a hosted status page all qualify. Employees on an internal deployment are users. |
| You must offer them the source | Of your version, from a network server, at no charge, prominently — reachable by the same people who use the app. |
Note what is not required: you do not have to publish your database, your customers' data, your credentials, or the fact that you run Silent Outage at all. Corresponding Source is source code, not operational data. Never publish your .env, your encryption keys, or your Stripe restricted keys as part of discharging this — they are not part of the Corresponding Source, and they are meant to be held encrypted at rest instead.
Note also what is required beyond the application code: Corresponding Source means everything needed to build, install and run your version, "including scripts to control those activities". For a Silent Outage deployment that means your database migrations, your deployment and verification scripts and any build configuration you changed — not just the file you edited.
Discharging it
Silent Outage makes the offer for you, provided you tell it where your source lives. Two environment variables:
# Your fork or source mirror. Point this at YOUR sources if you modified anything; # an offer that leads to upstream does not satisfy section 13 for a modified version. SILENTOUTAGE_SOURCE_URL=https://git.example.com/ops/silentoutage # The exact revision deployed, so the offer resolves to the version users are # talking to rather than to whatever is on the default branch today. SILENTOUTAGE_SOURCE_COMMIT=$(git rev-parse HEAD)
Every page of the dashboard renders a Source link in its footer from those values. Removing that link from a modified deployment is precisely the section 13 violation, so removing it from the code is a build failure rather than an option.
On Vercel, VERCEL_GIT_COMMIT_SHA is picked up automatically, so only SILENTOUTAGE_SOURCE_URL is needed for a fork.
A checklist for a modified self-hosted deployment:
- Publish your sources somewhere your users can reach without an account or a fee — a public repo, a mirror, or a tarball on a URL. A repository you can only see from inside your VPN does not serve users outside it.
- Include everything: your changes, migrations, deploy scripts, build config.
- Set
SILENTOUTAGE_SOURCE_URLandSILENTOUTAGE_SOURCE_COMMITon every part of the system that faces users, not only the dashboard. - Keep the offer current. Deploying a new revision without updating the pin leaves users pointed at source that is not what they are using.
- Keep the copyright and licence notices intact (sections 4 and 5). Rebranding the interface is allowed; stripping the notices or the Source link is not.
- If you redistribute the code — not just run it — section 5 also applies: your version ships under the AGPL, with your changes marked and the licence text carried along.
Frequently hit corners
- "We only run it internally." Section 13 says all users interacting with it remotely. Your colleagues are users. In practice, offering the source to them is a link on an internal page; the same environment variables do it.
- "We did not modify it." Then the offer is not triggered by the letter of the clause — you are running an unmodified upstream version, which is already published. Leaving the default Source link in place is the honest and zero-effort answer, and it stays correct the moment you do make a change.
- "Is a config change a modification?" Environment variables, plan settings and provider choices are configuration, not modified source. Editing the deployment layout, patching a detector, or vendoring a fork is a modification.
- "We want to run it as a paid service." The AGPL permits that. It requires the same section 13 offer, which means your competitors can read your changes. That trade is deliberate — it is why the licence is the AGPL and not a permissive one: a permissive licence gives no protection at all against a competitor taking this software and running it as a rival service.
- "Our lawyers will not accept the AGPL." Then talk to us about the commercial hosted offering or a commercial licence instead. Every contributor signs an agreement that makes that possible.
What Silent Outage's own hosted service does
The same thing this page asks of you: the footer of every page carries the section 13 offer for the exact revision the instance is running. The hosted service runs this AGPL core; the commercial half is the operation — running it, delivering the alerts, support, and the billing around it — and that half is not open source.