Licence and credits
Qawk is free software under the GNU Affero General Public License, version 3 or later. Copyright © 2026 Luca Padovan.
What that means in practice
| You want to | You may |
|---|---|
| Run Qawk to update your own devices | Yes. No obligation of any kind. |
| Change it and run your changed version internally | Yes. Still no obligation. |
| Give a copy to someone else | Yes — with the source, under the AGPL. |
| Run a modified Qawk as a service others reach over a network | Yes — and you must offer those users the source of your modified version. |
| Take Qawk, close the source and sell it as your own | No. That is what this licence prevents. |
| Do any of the above under different terms | Ask — see commercial licensing. |
If you are a company running Qawk on your own fleet, you have no obligations at all — modified or not. The AGPL's requirements begin when you convey the software to someone else, or when you run a modified version as a service that other people use. Updating your own machines is neither.
Where the source is offered
A licence that requires an offer is worth what the offer is. Qawk makes it in the two places a person meets the server:
GET /qawk/v1/infoanswerslicenceandsource, without credentials;- the console's About → Licence and source shows both, read from the server.
Both name the build you are talking to. An operator who has changed
Qawk sets QAWK_SOURCE_URL to their own repository, and their users
are pointed there rather than here — which is the whole point of section 13.
How to set it.
Why the AGPL
MIT lets anyone take the work, close it, rebrand it and sell it, and all they owe the author is a copyright line in a file nobody opens. For a library that is often the right trade. For a finished server it means the work can become someone else's product with no visible credit and nothing given back.
The AGPL keeps three things: the name stays attached, improvements come back — including from whoever runs a modified copy as a service, which is exactly how an update server is used — and it stays open, so nobody can make a closed fork the better one.
The reasoning in full, including why not Apache-2.0 and why not a source-available licence, is in LICENSING.md.
Commercial licensing
The AGPL does not suit everyone. Some companies cannot accept section 13 for a service they operate; some want to build Qawk into a closed product. Because the copyright is held by one person, Qawk can be licensed on other terms to anyone who asks — open an issue, or contact the author.
That is deliberate: the AGPL is the default so the work stays open and attributed, and a commercial licence exists so that being open does not have to mean being unpaid.
Third-party components
All AGPL-compatible. The full list with copyright holders is in NOTICE.
| Where | What | Licence |
|---|---|---|
server/reference/*.json | hawkBit's API descriptions and recorded defaults | EPL-2.0 |
server/go.mod | chi, pgx | MIT, BSD-3-Clause |
server/go.mod | OpenTelemetry, gRPC, protobuf | Apache-2.0 |
console/js/vendor/ | react, reactflow, dagre, gridstack, Sortable, js-yaml | MIT |
console/fonts/ | Inter, JetBrains Mono | SIL OFL 1.1 |
The Eclipse Public License exception
The files in server/reference/ are hawkBit's own, under the
EPL-2.0, and Qawk embeds them so it can serve an OpenAPI document listing exactly
the operations it implements. EPL-2.0 and the GPL family are generally held to be
incompatible, so rather than hope, the copyright holder grants an additional
permission under AGPL section 7 allowing that specific combination. The
wording is in NOTICE.
Trademarks
hawkBit is a trademark of the Eclipse Foundation. Qawk is an independent implementation of the published hawkBit protocols and is not affiliated with, endorsed by, or a product of the Eclipse Foundation.
Mender is a trademark of Northern.tech AS. Qawk's orchestrator is inspired by the published design of Mender Orchestrator and reads and writes its YAML; it is not affiliated with Northern.tech.
Credits
Qawk stands on the work of the Eclipse hawkBit project, whose protocol it speaks and whose design decisions it inherits, and on Mender Orchestrator, whose model for updating systems of devices it follows on the server side. Neither project is responsible for anything here.
Contributing
By opening a pull request you agree that your contribution is licensed under AGPL-3.0-or-later, and you keep your copyright in it. See CONTRIBUTING.md.