FOSS Backstage

Florent Zara, Julien Millau – From Tires to Code: Building Michelin's OSPO #FOSSBack

28:40 · 16 Mar 2026 – 17 Mar 2026 · YouTube

About this talk

This talk covers Michelin's journey to adopting open source methodologies within their organization. The speaker, Florent Zara from the Eclipse Foundation, outlines the importance of collaboration across departments, including legal and security teams, to create an Open Source Program Office (OSPO). Julien Mio, an IT distinguished engineer at Michelin, shares how they evolved from consuming open source software to contributing to and creating open source projects, including their notable contributions to Jenkins, Kafka, and GitLab. The presentation also discusses their open source strategy that prioritizes compliance and security while encouraging contributions and community engagement. By leveraging internal champion networks and training programs, Michelin aims to foster a culture of open source and inner source collaboration among their teams. The session emphasizes the company's commitment to a transparent and collaborative approach to software development and governance.

Full transcript

Hi everyone. Thank you for coming to this talk. Uh it's going to be a journey feedback from what we've done and inside of Michelin. So, you know Michelin. Uh so, this is what the the the the journey to to open source. And we could have we named the title to how we get to lawyers to contribute on GitLab, too. And this is no joke, no metaphors. That's

uh And uh we we try to build the OSPO the the way we believe software should be built, you know, like in the open, collaboratively uh with everyone on the table, like lawyers, security security guys, like and our policy, the governance document that you will see, uh the legal templates, everything is versioned on on GitLab. And that's how we we got the lawyers, but we will come

back to that. And so, we're here to talk about uh this uh this journey today and to help me with that, uh meet uh so, I'm Florent Zara from the Eclipse Foundation and I was called by uh I'm providing professional services to our members to help them uh better embrace open source. uh I was called uh someday by by Michelin and uh Julien. So, hello everyone. I'm

Julien Mio. I'm IT distinguished engineer at Michelin for software development. I'm also member of the Michelin OSPO team as core member. So, let's talk a little bit about Michelin. When we speak about Michelin, what is Michelin? A Michelin is that. In France, we say Michelin. Uh a Michelin is a a train on tires. You know well Michelin, Michelin is three pillar. The one pillar is to sell

and create tires. The second pillar is to offer service around tire for fleet, for tires per kilometers. And the last pillar is about the red guide, about the Michelin wine that we have with Robert Parker, some hotels that we have with from tablet hotels. So, we have a a big ecosystem tied around tires and beyond tires. When we speak about IT in Michelin, we 4,000 more than

4,800 people that work in IT. We are mainly in in France, in India, in the US, and in in China. So, it's a distributed around multiple zone. And some key figure about the the world where where where we work. We have more than two 2,000 websites that we manage, and we have a lot of team that manage many application in So, the This is the OSS timeline

that we we have in Michelin. We start developing with open source program mainly in Java for Michelin. We start that in um 2002 where we start on framework that we build on framework with external component in open source. So, we mainly consume open source at the beginning. After that, in two 2000 in 2009, we start to contribute. So, we enable contribution. So, we we we decide that

some people in the company can contribute to external project. For the little joke or little reference, we participate when Oracle acquired Sun, we participate we participate to to that. And we decide to fork Hudson. Hudson was the the tools used to automate some some some task. And we decide with some core contributor to fork Hudson to create Jenkins. And for example, in Jenkins, we do all the

authentication part and all the the right management in Jenkins has been made by Michelin at the beginning. So, after some contribution, some year years of contribution, we have contributed to some critical project that we use in Michelin. So, for example, Kafka or GitLab, we have made huge contribution on that. And in 2020, we start to create open source, to create new project, export project that we create

internally and that's after that we decide to create an open source pool just to govern that and to help team to to be able to work with open source for usage, contribution, and consumption. And and creation, sorry. strategy. For for that, we have a huge Sorry. So, that you have a huge strong sponsorship from our CDIO. So, your CDIO is very sponsor of that and you want

that all the organization be open source first. Open source first not be should not be open source only. So, when we want to acquire something or to decide to build something, we check if the open source cannot fit our needs. If it not, we can think or get some some some other supplier for for example, but we need to check first for open source. But, it's not

only a top-down approach. We have at Michelin what we call participate strategy direction memo that's we ask employees to tell us what do how we will see Michelin in the next 6 years, for example. And with this participating strategy, we have a lot of people that say that they want at Michelin acquire an open source strategy when they work that work on open source that export their

project externally. So with that it's only a top-down and also a bottom-up approach where we want to use more open source in the Michelin ecosystem. We want to to use what are what are key driver for open source? The first one is to around for the Michelin brand externally. We know well Michelin for tires, but in fact to crack tire we have a lot of IT for

that. And the Michelin brand is not well known for the IT that we uh that we uh that we do. It also we have a lot of contribution with academics and open source is a very helpful for us to to be able to to work together with some academics and to publish some some thesis report or some some some material like that. And also one big thing

that we did not in the slide is that it's also for us it improve the way to avoid the the vendor locking of for the solution we have for example. And we can apply the same thing when we decide to use open source we apply the same thing in inner source. So for the inner source what are the benefits for us and what are the key driver?

In fact is that it will increase the level the technical level of our teams and it will also increase the collaboration between them avoiding to to reinvent the wheel and to to make the multiple time the same same product. So for that since two years Yeah, two years ago it was in March 2024 if I remember correctly. We decide to create an OSPO. So what is OSPO?

Open Source Program Office the core team is made by six person. We have the OSPO lead that is close to the to your OS CDIO, a fellow that is close to your CDIO. We have on-boarded also the legal, one lawyer for the from the legal team. We have on-boarding the the security team, so we have one person dedicated to that into the OSPO team, and we have

IT experts. the OSPO is not linked to IT only, it's more larger than than IT. It is bad also for R&D, for all the the the the part of the company. So, so the IT is an important contributor. And also, we have decided to create a a champion network on all the part of the company that we can have there are some relay of the usage of

open source and promote also inner source inside Michelin. Yeah, this is where they they asked me, you know, to come as an an open source advisor and to help build the governance for Michelin. Uh, so and that time, so I needed to to write down the strategy, the policies, open source policy, the inner source policy. Uh, we will see that just after. And this is where, you

know, for the the to to close the loop with the beginning, this is where the the legal counsel that was on the OSPO, you know, that she started to review changes through the merge merge requests. Uh, she contributes contributed directly in the repository. And so, we were able to make her collaborate make her collaborate on the same platform as the engineers. So, the the governance framework, you

know, uh, we started from a strategic memo from the the direction from the the man the top management. And we have a governance, an open source and inner source strategy at the beginning. So, big documents stating the the the view of the management, extract from what we've seen the the PSDM. And so, we drafted an open source policy with the rules for consumption, contributions, creation of of

open source project. An inner source policy, so how to onboard a project, how to contribute to a project outside of your And how to use just maybe just to use inner source project that are available to the company. Just like others, you know, like the just like what we're going to tell about Mercedes, you know, something they are this is open by default. And then we put

an inner source tag directly on the project that are welcoming contributions from external people, external to the team. And we currently also have an open data which is a work in progress. Currently which it's not finished. We are working closely with the the data scientist on that. So, let's have a quick focus on each of these policy. I won't go into too much detail as we don't

have time, but we will be open to question after that if you want. So, the consumption part is we want to to make the the compliance and security first, you know, and all every open source software you use inside Michelin directly you must take it from the internal artifactory, you know. So, there is an internal artifactory that allows us to control the security, the compliance, to do

and to also generate software bill of material. And to so, we can see if we have a vulnerability, who's using what, which component. So, to do some regular scanning, people internally you do not have the right to use you confirm that you do not have to download directly from the internet. Yeah. It's blocked. We also define with the legal license and a low list like pre-approved license.

So if the component you want to use is on this has a license which is on the low list, that's fine. Everything that's permissive is allowed and we have some copy left restriction on that. There is a strict prohibition of GPL and AGPL for legal reason and LGPL is also wise with exception and then you need to have a small approval And so in that case we've

got almost last year like half a million component that were downloaded in 2025. So that's basically for the consumption part. Then when you want to do contribution, that's the the the keyword is upstream We want to do so I so when it comes to IP management we rely on the DCO the developer certificate of origin and if you want you need to to contribute to sign the

CLA you need to go through the Ospo and the Ospo will review the CLA and sign it Michelin wise so you don't have to to everyone does not have to sign a CLA on its own. So they review the CLA they say okay and so far I think we've signed a couple of CLA like the Linux Foundation Google yes Google one and for for Eclipse for example

they sign part of the CLA not everything so part of the CLA is signed by the company and for the other part each developer must sign the tick the box for before contributing. And so I think that's usually you know developed GitHub GitHub app to track contribution done through GitHub. Do you want to tell a few words about it? Yeah, in fact what is very important for

us is who made contribution just to to to see and to check if the we want that the usage increase or about contribution, usage, and consumption. So, we want to track that. And so, for that we create a GitHub app. And all the member of the organization are linked to this GitHub app and we track all the public event made by the Michelin address on on GitHub

just to follow what has been done externally. And then we also have an allow list. So, each project when you want to contribute to a project, it's put on the set the the security response team response team allow list so that you don't get flagged each time there is a contribution with your Michelin address to that external And we kind of have a good contribution and I

think we will come back later that's we have we have a slide on this. And so, we have 32 active contributors that with more than 250 pull merge pull requests generated depending on if you are contributed to GitLab or And so, when you want to to create an open source project that's as Julian said that's open source first mindset. So, think open source and if you can't

go open source, maybe you need to justify and say no, I cannot for this and this reason because there is some sensitive issues and and maybe that's too critical. We don't want to expose that to our competitors. Uh so, the when you want to There is a due diligence did by the which is done by the OSPO. So, all your proposal must be submitted to the OSPO

desk. We have an OSPO desk which is uh a GitLab issue GitLab repository where you can create issues where we are you have templates for asking questions. So, you can just fill in the template. And we the OSPO is looking for the strategic field, the security issues, you know, know IP clearance, is everything is okay. And the default licensing at Michelin is Apache Apache 2. Uh because

compared to MIT or other permissive licenses, uh so they want to broaden up the adoption. And there is an explicit pattern grant, and uh it's business-friendly, so that's uh with Michelin. And the hosting governance, that's uh we have a Michelin that they have a no uh GitHub organization dedicated to Michelin. And you've done a job at streamlining all organiza Michelin organization which were done by the time

a bit everywhere, so everything is centralized now under github.com/michel. And I think there is the set uh which they have their own uh their own repository also, but I think it's going to be merged anytime soon. And we also make sure that you have all the mandatory files, uh the small governance inside the projects, so we like uh good students uh to the community. And we there

were nine project published in uh 2025, including a project related to AI, uh PyTorch, and uh documentation. We'll see that a bit later. So that's for the open source. Now for inner source, uh that's yes, we had that there as you know there there are some constraint the challenge is to Michelin is composed just like many large groups like uh Bosch like uh uh with many legal

entities. And what that we we do not have and we did not draft uh any specific inner source Uh we just rely on uh a contract which was already made between legal entities because they were used to sell software between them. And so we rely on this existing contract considering inner source as another service delivery internally. And so we have the internally they have a GitLab, so

we rely on GitLab and we we use the inner source topic tag so topic tag so people knows that they can project up into external contributions. And so so far we have 7 57 compliance inner source projects. Then another part is uh communication. So internally, we have this website called so ospo.michelin.com quite easy to remember. And so you see and on this on this website which is

just a static Hugo website generated from markdown again. And so we we we want so the the policies and the strategy they are written in markdown and then we generate this website based on the this markdown files and we also generate PDFs so everyone can download the policy if they want they can read it online. So we have access to all the governance document from this website

and this is also a single point of contact from what you want to do in for everything you want to do in open source inside Michelin. You have the link to the OSPO desk of course I talked before you have the link to the public landing page we will see in a minute. To the external GitHub organization we have so internally they have using Microsoft 365. And

so there is team channels dedicated for that for instant communication and we have emails for the open source champion network. So you have access to everything. And so externally if you want to have a look that's a static page also open source.michelin.io and not .com. There is nothing fancy you know that's everything the others are doing just saying yes we love open You have a link to

the IT blog the GitHub organization the Michelin's cybersecurity team. So if you want to know the Michelin footprint the open source footprint on the internet this is where you you want to have a look. Uh when it comes to driving the cultural change, uh we have two mains uh thing. One is the open source champion and the other one is the training program we've set up. The

open source uh champion program is just a gamification for people to not kind of kind of an incentivization for people to contribute uh some rewards uh but not financial to to do follow up on the previous question on the previous talk. Uh this is just for people to showcase their contributions, their skill when it comes to open source and inner source. So, we have six different topics

like if you do some contributions, if you do some inner source open source contributions, if you participate in talks, if you So, we have those all those badges and with three different levels from bronze to platinum and then we award badges uh depending on the what the the success you achieve. And I think you will uh get promoted for eco-shaper, you know, maybe today with your talk.

I already made some talk about open source, so yes. So, yes, the the the idea is to show people they are increasing their open source and inner source expertise and they can uh show it to the rest of the world at least internally and externally if they want to publish it on LinkedIn. We also have these uh monthly leaderboards we publish on the internally on the on

the social internal social networks uh where we list so the achievement shared goal because there are there are annual shared goals, uh the numbers of contribution this month, the top contributors, uh the top projects, and the projects uh looking for help. So, that's the open source champion program. Then, there is the training program. It's not uh nothing fancy there also. The different modules is based on what

we've seen that what they've done at Mercedes for example. I remember Wolfgang talking about the awareness, then consumption, contribution, creation and inner source. It's basically based on the the structure of the the policy and what I've seen in other company do doing this this kind of things. Under the hood, but we started to do it uh training as code, you know, using AsciiDoc and we will GS

just like the presentation you have in front of you. And from the start we separated the Michelin specific from the generic part, you know, like what is open source, what is inner source, how to contribute, how to be a good citizen. And Michelin decided that the generic part will be an open source project. And so now that's that's a related that's still a really young project which

is called Eclipse Oozilk, open source and inner source learning kit. This is where everyone can contribute, can reuse internally if they want and that's the content is under CC by 4.0. So you can reuse it as a permissive license. You don't need to that's not share alike. So you don't have to publish your if you integrate some specific, you don't have to publish it back. You're not

forced to so you can just use some the include mechanism provided with AsciiDoc which is kind of a markdown and that's and that's it. Another question you may have is and I've heard throughout the day is the funding and the resource challenge. Some of them call them you know, sometimes the tragedy of commons so internally or so. managers, people they seen open source and inner source as

a overhead for them like because you need to put more documentation sometimes, review the pull request, the management of the community. This is kind of a overburden, seen as a burden. Furthermore, there is no central OSPO budget allocated to maintain dedicated to to give to those individual projects involved in open source and And you know the team, the maintainers, they must accuse their own budget, their own

budget or maybe sometimes use what we call internally a liquid buffer. This is kind of the 20% time you have to work on your your your time, your internal time on free project, on the project you you you want to do. Uh the OSPO just have funding for really specific initiatives like the OSPO to build and the run of the OSPO, uh which is why I'm here

today in part. Also for the communication, to set up the trainings, and the last one is yes, if you have major strategic initiatives, sometimes you know when you we want we have big large external contribution like like the one you did on GitHub or GitLab, sorry, or Kafka. Sometimes the OSPO can find some some funding for that. Also, the OSPO and mission at large is there to

as we call that's not only participating but trying to sustain sustain the the ecosystem. Uh they are members of the Linux Foundation, the the CNCF, and also the Eclipse Foundation. Uh they work with some consortia to work to work with academic institution and research, but you you told told us about that a bit before. And you know they can also give some participate in some sponsorship programs,

give some money to specific uh project that are really critical internally like we've told before we've I think we've discussed this afternoon earlier in the boombox about the the log for shell, the heartbleed vulnerabilities. So, just to conclude on the road map uh so the major contribution if you have maybe in 10 seconds 10 15 seconds >> made some major contribution on Kafka for stream for GitLab

for to to implement some feature that very helpful for us. And Time Sketch is mainly for And we won an award. Uh it was very good to to see that Michelin can won an award close to Slack Uber and tech companies. And we are manufacturing manufacturing company that won an award on on Kafka. So, that's great. We recently also published the what we call internally the state

of open report the Michelin state of open report where you have figures what did the achievement in open source and inner source. So, that was first internally and I think we released it last week or 2 weeks ago publicly. If you go to the blog IT uh you go to the opensource.michelin.io you go to then blog the their blog the blog IT of Michelin and then we'll

find an article with the the state of open uh report. yes, monthly you have shared goals also. So, there you have the picture of the previous shared goals. So, we define uh in early 2025 uh metrics and you know numbers of contributions contributors needs to be achieved. And then you reach that's uh 100 120% of the the objectives were achieved last year. And so, we have uh

that's shared goals they are defined to foster contributions to foster inner uh we want this year to increase contribution by 25% for 2026. And so, speaking about 2026 the road map is as I told you before uh have an open data policy more training and more external contributions. And then some key takeaways yeah key takeaways. so there is no magic recipe we use what's working we were

inspired but what Porsche Mercedes and other Bosch did and that we need a strong you need to involve the wide range of skills right from the start inside the have a single point of contact and be pragmatic and try to be open by And maybe just to break the ice the first question as you have the DeLorean and can get back in time what would you have

done differently so this DeLorean they it's have they it's have Michelin tires of course and yes maybe one thing is to improve the tuning start earlier and smaller you know maybe we we we tackle this this part maybe a bit late. And You said you have a very prohibitive stance on the GPL I'm wondering why and doesn't that exclude you from using stuff like Linux and so

on. No we we want to avoid using GPL or contaminant license mainly to build software so for example we we use Git so in fact is you use GPL we use Unix we use we use Linux but we would don't want to use dependency that are GPL when we create software. Thank you very much. Thank you.

From event

FOSS Backstage

16 Mar 2026 – 17 Mar 2026

All event videos
Back to Watch