Skip to content

OSS vs Enterprise

OpenDome is open-core. The engine you run and consume is open source under Apache-2.0. The managed/Enterprise tier layers central orchestration, a console, curated packs and compliance tooling on top of the exact same cell charts — nothing in the open core is crippled to sell the upgrade.

Capability OSS Apache-2.0Enterprise Commercial
Cell (per-tenant data plane, Helm — standalone is the default profile) ✅ ✅
OSL engine — POST /osl/query + previews, domain map, metadata ✅ ✅
OSL spec, JSON Schemas, conformance ✅ ✅
Connectors — Postgres, MySQL, Salesforce, custom Singer taps ✅ ✅
Documents pipeline — extract → embed → Lance (external embedder endpoint) ✅ ✅
In-cell orchestration — per-tenant Dagster daemon (dagster.enabled) ✅ ✅
Policy enforcement (SQL allowlist, row filters, projection, ACL) — fail-closed, on by default ✅ ✅
Token minting (HS256 chart Secret) + BYO-OIDC (RS256 verifying key) ✅ ✅
Self-hosted on your own Kubernetes ✅ ✅
Console — domain-map UI, semantic modeler, governed previews — ✅
Control-plane — multi-tenant provisioning, lifecycle, JWT rotation — ✅
osl-ask — the natural-language companion (the NL seam itself is an open contract) — ✅
Vertical packs — Finance / Legal / HR curated models & metrics — ✅
Premium connectors — SAP, Workday, banking ERP — ✅
Compliance pack — audit chain, AI Act / DORA / GDPR artifacts — ✅
Agent packs — pre-configured MCP manifests — ✅
OpenDome-operated cloud + SLA + support — ✅

The cell is the same artifact in both editions. The differences are what runs around it:

OSS — standalone cell

You install charts/standard-tenant + charts/tenant-semantic-api (the default values are the standalone profile). The cell mints its own HS256 tokens, enforces policy in-process, and serves OSL over its own Ingress. No control-plane namespace ever exists.

Enterprise — OpenDome-operated fleet

A central control-plane provisions and rotates many cells via the values-managed.yaml overlays on the same charts, issues the signed ActorTokens, proxies the console’s calls (forwarding the Bearer token — the cell still verifies it and enforces the caller’s ACL), and adds packs, compliance and support.

A few capabilities are documented in the OSS spec but ship behind the Enterprise tier or are still landing — the docs say so inline rather than implying full coverage:

  • MetricFlow resolution in POST /osl/query covers single-model simple metrics today; ratio/cumulative/derived metrics, saved queries and multi-model joins are planned. See the query reference.
  • Hybrid retrieval (BM25 fusion, reranking) is planned — current ranking is vector cosine with scalar prefilters and server-side ACL.
  • The osl CLI and the conformance test suite are upcoming epics; GET /osl/conformance honestly declares no complete profile yet.
  • Cross-model joins / the metric engine for JointEntity attributes are deferred — selecting such an attribute fails fast with E0503 before any read (never a silent null).