Denne side er endnu ikke oversat til dansk. Du ser den engelske version.

· Author: Lars Kruse · Essays  · 12 min read

Shift-left: Take control of your development stack

There is a widespread trend in digital life that we should all be aware of: the concentration of power in US technology companies and the incentives that drive it. But this worry is not just relevant to SoMe; it is also relevant to the software development stack.

There is a widespread trend in digital life that we should all be aware of: the concentration of power in US technology companies and the incentives that drive it. But this worry is not just relevant to SoMe; it is also relevant to the software development stack.

“Shift Left” is a term used in computer science: it is a bitwise operation. Shifting all bits in a binary number to the left multiplies the decimal number by 2.

For this reason, “Shift Left” is also used in software development to mean a clever hack — a simple move in one context that creates a huge impact in another. It is a step beyond “low-hanging fruit”: it is so effective that it feels almost magical.

In modern software development, the term “Shift Left” has been adopted by quality workers, including software developers, to indicate that verification and validation should happen earlier in the process, further to the left, closer to the source, building quality in rather than gluing it on afterward. Software developers love these double meanings. It is still an impactful clever hack, and it also speaks to the direction of reading: things start on the left and move to the right.

“Shift Left” has become a mantra, and a sign of recognition within Continuous Delivery and the Developer Experience (DevX) movement.

Developer Experience (DevX)

A new term and movement grew out of the DevOps paradigm in the last decade or so: Developer Experience (DevX).

It asks:

— How does it feel to be a developer of this product?

DevX insists on a holistic socio-technological agenda. It embraces everything that affects the developer’s experience, including team leadership, the tool stack, the CI/CD pipeline, the development environment, the code review process, and the overall culture of the development team. It advocates recognizing and rewarding developers’ insights and contributions, rather than constantly suppressing them through short-sighted commercial interests or ignorant management. It is about creating an environment where developers can thrive, be creative, and produce high-quality software.

In the DevOps and Continuous Delivery (CD) context, the annual State of DevOps reports from DORA (DevOps Research and Assessment) have repeatedly linked healthy development practices and developer-friendly platforms with stronger delivery, reliability, and organisational performance.

So, optimizing DevX may be one of the most impactful — and almost magical — ways to improve software development processes, including quality, productivity — and as a consequence — potentially also revenue.

Don’t be evil

There is a widespread concern about the concentration of power in digital platforms and the commercial logic behind them. This concern seems to focus mostly on the negative impact of social media and messaging platforms.

But it is also relevant to the software development stack.

By “evil,” I do not mean that every person working for these companies has evil intentions. I mean systems whose incentives concentrate power, reduce user autonomy, and turn our data, code, and attention into someone else’s asset.

The concern is often overlooked by civilians (non-developers), yet as AI becomes more deeply embedded in society and software continues to shape our lives, it turns out that the software development stack is potentially evil too.

  • Cunning vendor lock-ins followed by spiralling costs.
  • U.S.-registered cloud providers that may remain subject to U.S. legal demands under the SCA and CLOUD Act, which can in some circumstances require disclosure of data even when it is stored outside the U.S.
  • Proprietary platforms that sniff your data and code, either for upselling or AI training purposes.
  • Proprietary protocols that you cannot inspect, extend, or improve, and which you must pay to use programmatically (APIs, SDKs).

While the evilness of social media platforms is widely debated, the ethical problems of the software development stack are often overlooked. But this is really the true battlefield for independence, since our digital lives are rooted in software. It is an attack on the very foundation of our digital autonomy.

Software is born free — and everywhere it is in chains

“Man is born free, and everywhere he is in chains.”

The quote is from Jean-Jacques Rousseau’s book The Social Contract (1762). Rousseau’s point is that humans are naturally independent and born without restrictions, yet civilization places them under unjust laws, rules, and social controls.

The field of “Participatory Design” has been around for decades, rooted in Scandinavian traditions. It advocates for the users of software to be involved in the design of the software they use. The claim is that software exists for the purpose of the users. It should serve humanity. The same basic pledge underpins academic research and knowledge. Participatory Design speaks directly to the Open Source tradition.

Imagine a world without:

  • Linux
  • HTTP/TCP
  • HTML
  • SMTP
  • Git
  • Apache Web Server
  • PostgreSQL, MySQL
  • Python, Rust, Go, PHP, C, C++, JavaScript, TypeScript, Java
  • React, Astro, Node.js

The list contains a mix of software, standards, protocols, and languages, but they all have one thing in common: they are part of a free and open digital commons. They are the invisible infrastructure of our digital lives.

As someone who has spent my professional life in software development, I often wonder whether the world understands the importance and impact that FOSS has on our lives.

These technologies are all maintained and shared on terms similar to academic knowledge. Much of the FOSS and digital commons ecosystem is stewarded by not-for-profit foundations and communities that provide continuity, maintenance, and independence.

The list is endless, and the impact of FOSS and digital commons is everywhere. Taking away even a handful of these technologies would disable large parts of the modern internet and many of the services built on top of it. It would throw the world back to the early 1990s, before the FOSS breakthrough and the subsequent rise of the LAMP stack revolutionised our world.

These technologies are part of a broader digital commons and a circular economy that seeks to decouple activity from extraction, waste, and exploitation. Much of their value is created through volunteer work, donations, and freely shared knowledge; it is therefore poorly captured by GDP, a metric built mainly to measure market activity and growth. They are the silent, invisible infrastructure of our digital lives.

Let me paraphrase Rousseau’s quote in the context of software:

“Software is born free, and everywhere it is in chains.”

There is barely a major software system in the world untouched by the free and open digital commons — Facebook, Microsoft Office, and the LLMs you can think of included.

But software is chained. Despite the importance of FOSS, the majority of software in the world is proprietary, and ultimately serves someone’s means to profit and exploit.

The rubric of evilness

The benefit of a rubric is that it provides a clear framework for evaluating complex concepts, ensuring that assessments are fair, transparent, and reproducible. It allows for nuanced evaluations by breaking down broad questions into specific criteria.

Yesterday, together with Claude Sonnet 🤖, I generated a rubric for evaluating the “evilness” of software tools, platforms, frameworks, protocols, and so on. The rubric is designed to help developers and organizations assess the ethical implications of the tools they use in their development stack — in short, to measure how evil a tool might be.

The rubric uses dimensions and weights to quantify the evilness of a software tool. Each dimension represents a specific aspect of ethical concern, and the weights reflect the relative importance of each dimension in the overall assessment.

The dimensions include:

  1. FOSS and source availability
  2. Open standards and interoperability
  3. Vendor lock-in and exit costs
  4. User ownership and control
  5. Privacy and surveillance
  6. Business model and commercial incentives
  7. Manipulation and attention capture
  8. Governance and accountability
  9. Communicative equality and power accountability (Would Habermas and Foucault be happy?)
  10. Security, resilience, and decentralization
  11. Labor, ecosystem, and social externalities

Some dimensions were added by Claude and some by me.

The rubric is designed as an AI skill; you can see it at lakruzz/evils. Feel free to fork it and do with it what you will.

I generated a list of tools and platforms that was basically all over the place, but the clever thing about the rubric is that it allows me to systematically evaluate each one based on the defined dimensions, even when they have very different characteristics.

My prompt was simply:

/tool-evilness-assessment
Use the skill on the list in techstack.md

If you are curious, have a look at the digital-autonomy-assessment-full.md. Note: the higher the score, the more evil.

So, at one end 😈, Meta scores 90+ on both Facebook and Instagram, and at the other 😇, Forgejo, the self-hosted FOSS alternative to GitHub, scores 1.5.

The Real Utopia

If Utopia is an imaginary place where software is once again free, then the real Utopia is a place that can actually be implemented — not a dream, but also not something you can buy a subscription to today. It is basically a D.I.Y. place: you have to stitch it together yourself, or jointly with others.

Let’s go!

In Mind over Machine (MoM), we are setting out to build this real Utopia — to prove that there exists a road to a truly free and open software ecosystem. But we also aim to prove that the feasibility of such a system is achievable. It will be a build-in-public process, with install parties, hackathons, and other community events.

We even intend to spin up actual infrastructure, on servers geographically located in Denmark, and host the running instances of all this FOSS software.

If you want to be part of this exploratory journey, you should join our MoM FOSS Alliance. As we progress, we will host FOSS projects that we steward ourselves, and FOSS initiatives run by MoM FOSS Alliance members.

Under 30

Our initial plan is to settle on tools with an evil score under 30. Some of them are genuine FOSS projects and others are tools with open-source cores or self-hostable alternatives.

This is what we imagine:

  • VSCodium IDE; while VS Code is open source, the Microsoft-branded version is not. The open-source build is fully FOSS and can be used without Microsoft telemetry.
  • Forgejo Git hosting; a self-hosted FOSS alternative to GitHub, allowing developers to maintain control over their code repositories, issues, project releases, and more.
  • Woodpecker CI Continuous Integration; a self-hosted, open-source alternative to GitHub Actions, enabling developers to automate their build, test, and deployment processes.
  • Ollama, vLLM, LocalAI Self-hosted LLMs on our infrastructure, connected to both our IDEs and our pipeline runners; we will host and run LLMs on our own infrastructure, allowing developers to use them without relying on proprietary cloud providers or exposing their data to third parties.
  • Matrix Team Communication; a decentralized, open standard for messaging and collaboration.
  • Element X, FluffyChat Populous Matrix clients; FOSS clients for the Matrix protocol, providing secure and private E2EE communication.
  • DevBox, DevEnv, Nix, Dagger.io, DevContainers, Docker, Podman, Kubernetes Containerized Development Environment; a collection of FOSS tools for creating isolated and reproducible development environments detached from any proprietary cloud provider, allowing developers to maintain control over their development stack and run the exact same verification and validation locally as they later execute in the CI/CD pipeline.
  • Mastodon/ActivityPub Social Media and community building; a decentralized, open-source social networking platform — the Fediverse — that allows users to create and share content without being subject to the control of a single corporation or platform.
  • POSSE (Publish on your own site, syndicate elsewhere); a strategy based on always publishing content on your own website first and then syndicating it to other platforms, giving you control over your content and audience. All documentation, blog posts, user manuals, user voice channels, and other content will be published on websites we host ourselves first, and only then shared (syndicated) to social media platforms like Mastodon. With this approach, we still maintain the option to syndicate to other platforms with evil scores over 30.

In all humility — that’s the plan!

As always, we will work by an MVP (Minimum Viable Product) approach, and we may start with a small subset of the tools and use publicly and non-commercially available resources such as matrix.org, codeberg.org, and mastodon.social.

We sincerely hope that this will inspire other developers and organizations to adopt similar practices, and to contribute to the development of a more ethical and sustainable software ecosystem.

As a company, when you join our MoM FOSS Alliance, you will gain firsthand access to the latest developments and opportunities, and participate in shaping the future of software development in a more ethical and regenerative direction. You will get complimentary advice and early access to test and use the infrastructure we are building.

Using the infrastructure for your FOSS projects will be included in the MoM FOSS Alliance membership. If you want to run your proprietary software projects on similar infrastructure, we will be happy to provide that as well — with the caveat that you will have to pay for it. Only FOSS projects will be included in the membership.

We will need help, so if you are a developer, designer, computer science student, or just someone who is passionate about software freedom and ethical development practices, we encourage you to get involved. Together, we can create a software ecosystem that prioritizes user autonomy, privacy, and ethical considerations.

Chat with us on Matrix:

#mindovermachine:matrix.org


Back to Blog

Related Posts

View All Posts »
Our Web

Our Web

Every technology has a culture. Over 30 years, the Web has drifted from a shared productivity platform designed by Tim Berners-Lee, towards a machine of "social media", ad campaigns and global consumption. The cognitive offloading effect of AI is now 'critically endangering' it before it had a chance to evolve. We are here to preserve it.

MoM's Love Letter to the Hybrid Intelligence Manifesto

MoM's Love Letter to the Hybrid Intelligence Manifesto

The Hybrid Intelligence Manifesto makes a rigorous case for keeping human judgment economically indispensable in an AI-accelerated world. This is Mind over Machine's open love letter to that vision, and a practical breakdown of how high-level theory meets the messy reality of software development.

DevOps Evolution

DevOps Evolution

What is DevOps? The answer changes over time, but the useful part of the answer is not what is is, but what it embrases: culture, delivery, infrastructure, observability, and now AI

Say AI again — I Dare You!

Say AI again — I Dare You!

AI is on the rise - the term is now used to describe any piece of software. In this rant I´ll take you through a journey, back to when AI was conceptually born to argue that we´re using the term wrong.