Rust Foundation with Bec Rumbul, Lori Lorusso, and David Wood
About investing in the positive impact of Rust
2026-07-16 54 min
Description & Show Notes
Most Rust developers use the language, compiler, package registry, and tooling every day without thinking too much about the organization that helps keep parts of that ecosystem funded and sustainable.
This episode is a re-introduction to the Rust Foundation: what it does, what it does not do, how it relates to the Rust Project, and why that distinction matters for teams using Rust professionally.
My guests are Rebecca Rumbul, Executive Director and CEO of the Rust Foundation, Lori Lorusso, Director of Outreach at the Rust Foundation, and David Wood, Principal Software Engineer at Arm, Compiler Team Co-Lead in the Rust Project, and a Rust Foundation board member. Together we talk about the practical side of ecosystem stewardship: infrastructure, security, interop, maintainer support, governance, corporate membership, open-source funding, and the pressure new technologies like AI put on language ecosystems.
About the Rust Foundation
The Rust Foundation is an independent non-profit organization supporting the success, sustainability, and positive impact of the Rust programming language. Its work includes funding and supporting ecosystem infrastructure, security and interoperability initiatives, maintainer support, project administration, community programs, events, and collaboration with member companies and donors.
The Foundation is separate from the Rust Project. The Rust Project governs the language, compiler, standard library, and technical direction through its own teams and decision-making processes. The Foundation provides organizational, financial, legal, and operational support around that work, without owning Rust’s technical roadmap.
About the Guests
Rebecca Rumbul is the Executive Director and CEO of the Rust Foundation. She leads the Foundation’s work on organizational strategy, member engagement, sustainability, and support for the broader Rust ecosystem.
Lori Lorusso is Director of Outreach at the Rust Foundation. Her work connects the Foundation with the Rust community, member organizations, trainers, contributors, and companies adopting Rust in production.
David Wood is a Principal Software Engineer at Arm, CE-SW Rust Team Lead, Compiler Team Co-Lead in the Rust Programming Language Project, and a board member of the Rust Foundation. In this episode, David adds the perspective of someone involved in Rust’s technical work as well as Foundation governance.
Links From The Episode
- Mozilla - The first home of the Rust language
- Python Steering Council - The governing body of the Python Project
- How to Write a C++ Language Extension Proposal - Bjarne Stroustrup, the inventor of C++, on why C++ needed a standards committee
- SCRC - The Safety-Critical Rust Consortium
- FLS - The Ferrocene Language Specification, a specification of the Rust language that is required for certain steps in the certification of Rust for safety-critical applications
- Foundation Membership Tiers - The different quantifiable benefits from Diamond to Silver and Associate Memberships
- Rust Commercial Network - A group of organisations that use Rust in production working together with the Rust Project
- Rust-C++ Interoperability Initiative - An initiative of the Rust Foundation to improve interoperability between Rust and C++
- Rust Embedded Working Group - An official working group of the Rust language to improve usability of the language in hardware-constrained environments
- An AI Security Engineer in Residence for the Rust Ecosystem - Describing the position of the security engineer made possible by funding from Alpha-Omega
- Rust Foundation Maintainers Fund - The Foundation’s fund to support Rust maintainers
- Rust Foundation Trusted Training - The Foundation’s accreditation program for Rust training providers
Official Links
Transcript
Welcome to Rust in Production, a podcast about companies who use Rust to shape
the future of infrastructure.
I'm Matthias Endler and today we talk to Rebecca Rumbul, Lori Lorusso and David
Wood from the Rust Foundation about investing in the positive impact of Rust.
Today we've got a very special episode because we talked to three guests from
the Rust Foundation and I would like to introduce themselves.
Bec, Lori, David, say a few words about yourselves, please.
I'll jump in first. Hi, everyone. I'm Bec Rumble. I'm the executive director
and CEO of the Rust Foundation.
And I'm Lori Lorusso. I am the director of outreach for the foundation.
I've been with the foundation since August.
And it's been a wild ride, almost coming up to a year.
I'm David Wood. I've been a Rust container for eight or nine years now.
But I'm also on the board of the Rust Foundation to represent the Rust Projects interests.
Now, before we get started, I wanted to ask a bit of a spicy question.
If I am a production user of Rust, why should I care about the Rust Foundation?
What does the Rust Foundation do for me, quote unquote?
I'd say if you care about Rust in any form, you should definitely care about
the Rust Foundation and what we do. We are here to make sure that Rust continues
to be useful and productive for everyone.
And we do that through a variety of ways, which I'm sure we can talk about over
the course of the episode.
But I think if you are uninterested in the foundation, then you are basically,
throttling your ability, I think, to be as productive as you can be.
What are these ways that the Rust Foundation supports Rust as a community?
Well, obviously, we are responsible for all of the kind of basic infrastructure.
So without a foundation,
there's not a lot of support for everything that just provides the baseline,
even just really boring things like hosting crates.
These things don't happen by themselves.
But of course, you know, we want to make sure that Rust is also growing,
that it's developing, that it has a bright future.
So we're obviously investing in various different things like programs and individuals,
to make sure that, yeah, there's a huge resource for people.
I think, too, why you should care about the foundation, and I think David being,
on this podcast with us is directly to the point, is that the foundation's board
is not just made up of corporate members.
It's also made up of project members that represent the project and how they work.
So it is sort of your link to a connection to the project itself,
where, you know, when you have things that you'd like to get done,
bringing them, you know, being more involved in the foundation gives you an
extra link to the project.
David, how would you describe this link as someone who works in that area?
Like, what is the day-to-day looking like for you as part of the Rust Foundation?
Yeah, I mean, all the sort of work that the Rust maintainers do is in some extent
made possible because of the foundation's support of the project.
We can't do any of the improvements, the language we'd like to make without
running lots of CI jobs and doing our releases and publishing those on all the,
CDNs that host all those binaries on the releases. And all that's funded by the foundation's work.
So all the stuff that we do in the foundation side, or on the project side rather,
others enabled by the Foundation's support of the project.
And what we also then try and do is make sure that everything the Foundation
does to help and all the engineering efforts they have going on as well,
that we work to make sure that's what goes smoothly within the project and those
contributions are accepted and that,
you know it's a collaborative relationship that works well and the benefits of all of us.
Now as someone who has been part of the rust community for quite a while just like david as well,
we didn't always have a foundation in the past the project organized itself,
and i wondered when did the rust foundation get started and for what reason.
So rust used to live inside mozilla so you know it was incubated inside mozilla,
and the thing about these kinds of languages is that for them to truly grow
for for them to be truly kind of supercharged and and widely supported by plurality of organizations,
you need a certain level of independence other companies are not gonna you know
would not have been giving money to mozilla to help develop rust they obviously
want a very vendor-neutral space for that to happen.
So, you know, Rust needed its own foundation in order to kind of keep growing
and to kind of inspire confidence in its neutrality for all of the businesses that want to use it.
I think that,
most languages have a foundation, and I think that's a good thing.
It enables people to kind of coalesce around the things that they really care about.
And obviously, the members that are investing in the foundation are very,
very committed to making sure that Rust is a very successful and well-used open source language.
It might be an obvious question, but why is that neutrality important,
the neutrality from vendors?
Well, I think it's important across open source, right?
The principles of open source is that, you know, pretty much anyone can turn
up and anyone can use something.
And it's the best possible space and arrangement to be able to collaborate and work together.
You know, this is another thing that the foundation is here for is to create
this space for collaboration, which businesses a lot of the time would not be
able to achieve by themselves.
You know, when you're thinking about developing software or indeed any kind
of product, it's very, very difficult sometimes for businesses to work together
with all the NDAs and the legal kind of stuff.
Whereas actually, this open source space is a huge enabler of innovation and productivity.
Is that also what you would tell a company that uses Rust heavily but hasn't
engaged with the foundation?
About why they should?
Well, I think of any company that is wanting to put Rust in their stack,
they should, you know, be interested in the organization that is continuing to keep Rust moving.
Like Bec said, and David said, you know, the foundation is running,
you know, is behind the scenes in the infrastructure.
So the project can continue to innovate on the language, you know,
like, so we're sort of the building blocks in which they're building off of
and continuing to improve the language.
So if you want to be confident in the fact that the language you're going to
adopt is going to stick around, you should be really interested in supporting
the foundation that is making sure that that's happening.
And I think that's one of the big values of having a foundation is that we aren't
going to let the lights turn off.
We are the checks and balances that are in place to make sure that if you run
a job today, you'll be able to run that job tomorrow.
And I think, you know, it would be interesting to hear from David's standpoint,
from being with the project before the foundation, you know,
if there's been sort of a more stabilizing effect.
But I think with the mass adoption, you know, with Rust being around now for
11 years, having confidence in the foundation should give you more confidence in Rust.
Yeah, I mean, I think that's definitely, we as a, you know, the maintainers
can take us for granted that when we submit a pill request the CI runner
or that if there's ever a problem with
the trademark that there's people that are confident in the care at the foundation
who are going to sort those things out
and that lets us focus on just building the language and making the best possible language.
And is that where you draw the line between let's say the organizational things
that would be handled by the Ross Foundation versus say things that affect purely
the language for example,
i don't know an ai policy or a contributing guideline or things that are purely
developer focused developer related is that where you would draw the line between
the foundation and rust the language.
Yeah, absolutely. I mean, the project is still sort of self-governing.
We still have our compiler teams and library teams and we decide how those work
and how the membership policies are and what contributions we accept and all
those things are decided to end the project.
And so what RFCs get accepted, whether we stabilize a feature,
all that's decided by the contributors and the maintainers.
What the Foundation does is let us focus on doing that. And of course,
the Foundation are themselves contributors to the project, like all the big
companies that support Rust and support foundation.
They're just another contributor and they support the sort of fundamentals,
the stuff we build on, the foundations that enable us to do all that good work.
How is the Rust governance different to say the C++ governance?
's governance is quite different from other kind of large programming language
projects, particularly projects like C++ that are a lot older than we are.
Projects like C++ are very standardized as part of international standard organizations
that are representatives from national bodies that are sent forward and they
vote on all the features that go through and the people who post papers.
That's very different from how we work.
It seems quite different languages like Python, which are relatively closer
to us work, where they've got a steering council that decide on every PIP that gets proposed.
Rust has lots of individual teams that are sort of responsible for individual
parts of the toolchain that we all tend to deliver to our users.
So I call it the compiler team. We're responsible for making sure that the compiler's,
well maintained, that we're fixing bugs, that we are able to cut our release
every six weeks, and that we're developing the features in it.
And then there's a separate team that focuses on the language evolution and
making sure that sort of the the language surface area is coherent and makes
sense and we do that for things like library crates creates io cargo,
all sorts of things and all those teams work together to deliver ultimately what is rust overall,
and they all just do it in the way that makes more sense for them and the people
who work on those parts of the project.
Recently i watched a documentary about c plus plus and the creator of c plus
plus be honest He said one day a couple of companies knocked on his door and
said they needed some standardization, like a form of,
governing body or maybe an ISO standard of sorts.
How do you see that being different to what Rust does?
I think Rust is not an ISO standard yet, as far as I'm aware.
Is that not relevant for the Rust governance, or is that just a misunderstanding
and the story is different?
Well, I think that standardization is very important, and you can see Rust sort
of moving in that way with the Safety Critical Rust Consortium.
I think that's, I get confused. It's like SCRC. But that is a,
group that was formed a couple years ago of
companies that need to have standards in which they operate because they're
creating devices like medical devices, planes, automobiles, things in which
they have a certain level that they have to be,
held accountable to because they're
building devices that have significant impact on if they fail or not.
So there is the Ferrocene system that's coming through, the FLS that the rest is working on.
The embedded group is very, very key to that. So I think when we look at governance,
it's different than standards that are needed for organizations to move forward.
I think that's kind of the differing body between C++, for instance,
where everything is uniform.
You said FLS in the context of Ferroscene, what's that about?
Yeah, so Ferrous Systems, one of the foundation's members, they developed a specification
for the language, sort of laying out the rules of how the language works.
They generously donated that to the Rust project and we now maintain it with their help.
And that's the type of thing that's really interesting and valuable to some
commercial users who really need that extra guarantee that here's what the language
says it's going to do. They need that for certification, for qualification, for some of the sort of,
legal aspects of delivering the software they deliver. And so,
Ferrous and Ferrous Systems developed that for their qualified compiler.
They donated to the project and that's sort of one of the standards for the
specifications of the language, which is like what you said, separate to...
The fact that we have a specification is separate from the fact that we aren't
part of a standardized process for governing the language.
At the risk of being slightly too technical for one question,
I had a follow up, which is for the language specification, is the compiler
qualified or is the standard library also qualified already?
I think it, well, the Rust project itself doesn't do any of the qualifications,
so I think it depends on where you procure your qualified compiler.
I believe different vendors, some of them qualify the standard library.
I don't believe all of them do yet. I'm not certain.
The key part, I think, is that oftentimes they'll deliver their own sort of
distribution of the language alongside a spec and they're sort of asserting,
as a legal entity that the compiler they're shipping, which is ultimately just
a derivative of what we've produced in the open source,
complies with the standard that they or the specification of the language they're also providing.
That in turn complies with the requirements of the law that they are the sort
of ISO 26262 for cars or whatever the legal requirements that they have to comply with are.
Which benefits do I get as a member of the Rust Foundation? There's a tiered
system, maybe you can also elaborate on that.
And then how does communication work? Do you regularly meet in chats or even in person?
So we have three tiers of paid membership, silver, gold and platinum.
And your benefits will depend on which level you are a member at.
Our platinum members, that's the top level of membership, they are entitled
to a seat on the board, so sitting on the board alongside David and our other project directors.
In addition to that, there's a whole package of benefits around,
sponsoring RustConf, it's access to us as the foundation staff,
and it's the access that you get to the project.
But there are various kind of discounts on things like the training program,
its access to things like the Rust Commercial Network, being able to not only
join those groups, but be able to actually take leadership positions.
As lots of promotional opportunities, we basically want to make sure that we're
telling really good stories about Rust.
So we are always working with our members to try and promote the great stuff
that they are doing in Rust. But I think one of the kind of.
One of the key benefits that's like a kind of fluid, it's kind of difficult
to pin down, but it's being part of this huge network of incredibly talented, innovative,
great people that are all kind of invested in making Rust as good as it can possibly be.
So yeah, we have like a lot of communication. You've asked about communication.
We try and facilitate communication between the members as much as possible.
You know, as I said earlier, it's really important for us to create space for
people to be able to kind of collaborate and network and work together.
So the Rust Commercial Network is a great example of that. But,
you know, we also try and facilitate things that people are interested in.
You know we are basically here to serve our members so if our members come to
us and say we're like there's a few of us that are really interested in doing
this kind of kind of work over here can you help we are more than happy
to try and facilitate that you know that's why we have the safety critical consortium
because a few members came to us and said you know we really we need to do some
work in this area can you help facilitate that,
so I think that's one of like the biggest benefits it's like you know I can't
sit here and promise you that you'll network with all the right people within
the first five minutes of becoming a member but being part of the foundation
and being part of this journey,
presents a wealth of opportunities.
But those members, they don't have an influence on the language design,
or this is also where you draw the line.
Absolutely, yeah. I mean, the foundation is here to provide governance and support.
We do not dictate to the Rust Project what happens in the language.
All of those decisions, as David said earlier, are made by the members of the
Rust Project. We are just here. We're just the support team.
The project also benefits from the networking part Bec was mentioning what the
companies get and that we're always looking to learn more about how people are
using Rust and what problems they're running into and how we can improve the language.
And having things like the Rust Commercial Network or just our member companies,
being able to reach out to them and say, what problems are you having?
Tell us about how you're using Rust. That helps inform the decisions we make
or our priorities as far as, as a language, how we'd like to evolve and change
and grow and support all the other users of Rust.
So it definitely benefits the project to have this sort of commercial arm of
the language and the foundation that has all this network, this large network
of projects and organizations.
Yeah, I like that because the reverse is also true where this feedback sometimes
gets anonymized and then published as a blog post, which kind of feeds back into the community.
So at least from time to time, I see a blog post and it's very helpful to get some,
curated quotes from people who use the language professionally to see where
we are as a community. So thanks for that.
And is there a regular meeting as in a teams meeting or a zoom call or anything
like this where where people have chats or do they typically organize separate
groups and then decide on their own meeting cadence.
So we we're in regular contact with the members via you know our new our regular
newsletter we have a zulip channel where anyone can kind of drop in and have a chat.
Specific programs have specific channels. So the Rust Commercial Network has
its own kind of Zulip area where anyone can kind of show up and start collaborating.
We have a get to the, so we're having our first ever member summit in person
at RustConf in September, which we're very much looking forward to.
That's kind of, you know, it's the first time we're running it but again this
is a an opportunity a new a new opportunity to create that kind of space for
collaboration I was talking about earlier,
and yeah we're really excited to see what the members want to get out of that,
and yeah we're hoping you know we're reaching out to them to to kind of collaborate
on the agenda and and what kind of work they want to get done there so yeah
there are definite spaces I think we're conscious that,
You know, people have a lot of calls all the time and there's a lot of events
that people go to, so we don't want to, like, clutter people's calendars too
much. But we want to try and be there for when people want to show up, basically.
So we're always open to ideas about if people want to meet, great.
You know, we're happy to support that.
We touched on the Rust commercial network before, but we haven't formally introduced it yet. Let's do that.
And also, maybe we can also separate it from being Rust member or a member of the Rust Foundation.
Sweet. So I'm very happy to say that the Rust Commercial Network is something
that I've been working on since last fall.
It was sort of an initiative that was driven out of the membership needs.
They wanted a newer space to network with other commercial users of Rust, other people.
Like, what kind of development frameworks are you using?
What reference architecture are you using? What can you share?
Like, how can we make this more open?
How can we make this easier for people to adopt Rust into their stack?
How can we say, hey, you should start with Rust from the beginning and all of
that. So this, again, was born out of the foundation, and it's called the Rust
Commercial Network. You can check out our GitHub repo. You can create an issue
to join. You do not need to be a foundation member.
What's really cool is that we have a steering committee and the steering committee
is comprised of members.
There is one platinum member, one gold, two silver, one associate.
And then there is someone from the Rust Foundation that sits on the board in an advisory position.
And then also someone from the project, which actually happens to be David,
which is awesome, which help just sort of look at what's coming up. You can create your own.
Initiative. And then the steering committee's job is not to put any strict governance
on what you want to do, but maybe just help you sort of corral
other people into getting on board with what your initiatives to make sure that
you can be fully supported.
We do have a monthly meeting, which is we just had our first one last week, which was awesome.
And then we realized, as Bec said, nobody wants to be meeting to death.
So we're just going to do one general meeting. And if you go
to the Zulip channel under the Commercial Network Zulip channel,
you'll see a ton of different initiatives that companies and users of Rust have
started to try and get more people involved with working on
specific things that are important to them, whether it's Async, Tokio,
GUI interfaces.
There's just a bunch of different conversations that were not able to be had
beforehand in a way where we are in the Project Zulip channel.
So you actually have commercial industry and those developing the language working
together to make things happen.
Again, we're not telling the project what to do, but we're just sort of showing
the project what people are looking to do, what kind of initiatives,
and then where can there be help, whether it's funding help,
development help, like how can we actually bring.
The users closer to the project so that everyone can get what they want done,
and understand, like you were saying, the feedback loop.
Like, well, we would like this feature done, but, you know, we realize now talking
to the project, there are tons of other things that need to happen first, you know?
And so can people from this commercial network work on development help or is
it a funding issue or what can we do to try and unblock some of those things
that eventually we can get where we need to be?
It's, it, like I said, we started working on it last fall. We just had our first
meeting and the, you know,
participation has been awesome and the feedback from the community has just
been really like very welcoming and excited,
and i don't know david if you want to talk about it from sort of the steering
committee project side and what you hope to to see.
Yeah i mean it's it's like i think you covered a lot of it but it's a great
opportunity for us in the project to like talk directly with people using the
language and learn what the paper cuts are and also,
help them understand what goes into building these features and where they can
help either with development resources or with funding.
And that same applies not just to project, but for the ecosystem creates as well.
A lot of these companies may get together and realize, oh, we all depend on
this library and it isn't that well supported. Maybe we can help there.
And so hopefully it becomes a kind of a rising tide that lifts all boats in
the project, the ecosystem and the companies as well.
Some of the more seasoned listeners might wonder about the following.
On one side, we have these initiatives for example asyncrust or Tokio specifically,
but then we also used to have or we still have working groups,
where do we draw the line here for example a i don't know c plus plus interrupt
story would that be an initiative or would that be a working group.
I think it can happen organically. We do have what's called the C++ Interop
Initiative. We were given funding to create this.
We have contracted a maintainer, Teor. He's doing amazing. He's actually also
a part of GSOC. So now we have more contributors working on this Interop issue
in addition to what Google's doing and other companies are doing.
It's just another entryway, if you will, into the project.
Will there be overlap? Of course. Like there's the embedded working group that's
been around for, I don't know, I don't want to say forever, but it's been around a really long time.
And now we have a commercial network where other people can talk to the embedded.
You know, it might be the same people. It might be the same companies are involved.
But I think it's just like another entryway into the project and you can determine
your path forward, whether it's, you know, I'm doing this on my own time,
you know, so maybe just a working group within the project sounds better to
me because, you know, I'm not beholden to what my company wants to do,
or your company has an initiative that they want you to bring forward.
So you come in through the commercial network that way. I think the main thing
is we want to give you more access to Rust and how can we be,
how can we do that efficiently?
And you can determine, you know, is it a working group? Is it a commercial network initiative?
Is it signing on to help with something else that's already happening within the project?
It's just giving more awareness to all of the different layers that are happening within Rust.
Well, I personally could see some friction there because let's say I was part of a working group.
Let's take the embedded working group. And then there's an initiative on the other side.
I would be worried that it would kind of affect my agenda or the agenda that
their working group created for themselves?
Is that a valid concern or is it in reality two different things?
I think it ends up being two different things in a lot of cases.
You know, the working groups, especially the embedded one, they have their own
governance, much like the project.
They maintain a lot of crates. Ultimately, they own those crates and they decide what goes into them.
Where the Foundation's commercial network comes in is it can be sort of an entryway
for companies that maybe aren't already aware of the embedded working group
to become aware of their work and,
contribute to that or support them or just, you know, participate.
And a venue that's more familiar to sort of how they expect and interact with
other companies and organizations like in a commercial network where the embedded
working group is less commercial and corporate in that way.
And so hopefully this is a, like I said before, a rising tide of boats.
It's a way of getting everyone in the same room so that everyone can benefit from it.
And everyone's still, everyone's still governed by the same people that all
those are governed by. But now there's hopefully more people in the room and
hopefully people with some cash that can help contribute as well.
Yeah, to me, it doesn't even have to be a conflict to begin with because I might
be interested purely in the technical part and I could inform usage of that
technology in production at some point.
But also the reverse is true where maybe I'm only interested in the commercial part as in like…,
guarantees or liability or things like breaking changes and then i might come
in through an initiative on commercial networks so maybe this is kind of at the end how it will,
settle down or yeah um but that doesn't necessarily have to be a conflict.
And i think again the value of having the the commercial network in the project
zulip will hopefully show the the collaborated nature of what we hope to get to, right?
So you can see, as David's been saying, what commercial interests are like regarding,
a certain aspect of something, say an embedded.
And the embedded working group can just kind of be like, okay,
but now the commercial network has an avenue where they can sort of bring up what they're doing.
You know, ask somebody from that working group to say, hey, can you help steer
us in the right direction?
Like what are we doing that's wrong? You know, it's again, the making the awareness
there of the things that are happening within the project and letting the commercial
interests know what's happening.
I think what we realize is that there's a lot of silos that happen, right?
And the nature of open source is to open the doors on everything.
We should all collaborate together. But when you're hyper-focused on one thing, you can lose that.
So having everything in the Project Zulip, having it be public,
having you be able to access that kind of stuff, I think, is just one more way
of collaborating in the open space and in open source, which,
you know, is what Rust is all about.
That is very true. Specifically, asking about Rust and C++ Interop initiative,
what's the payoff for teams working at the C-C++ boundary?
What's the story there right now? Where are we at?
One of the things that the great technical team at the foundation are working
on with regards to Interop is there's some experimental support for function
overloading, so that you'll be able to express in your,
interrupt boundary, you'll be able to kind of declare overloaded,
C and C++ functions and call those.
And that will just, it's something you have to kind of fix on the language side
of the fence and enables a whole new sort of function of APIs you could never
have called before now you can. And so things like that are coming out of it.
If there's a very concrete language feature we hope to eventually ship on Stable
that is coming out of this work.
Is that a change that requires as a new addition, or could you ship that as part of a normal update?
I'm not as involved in the teleengineering or the RFC for it to know the specific
way that it requires an addition, but I'm sure the people that are reviewing
it and stuff are very much top of the question.
And I think one of the things that's really cool is that this has become also
a project goal, and you can follow along, and you can see the updates that Teor
makes monthly on what's happening in the initiative.
So I would say if you're interested in what's going on in that space to,
again, get in the Zulip and start clicking around and see what's happening so
that if you wanted to contribute, you could do that as well.
Let's briefly talk about maintainer funding. How does that work in practice
and which parts of the project have benefited so far?
So, maintainer funding is, you know, there is never enough money to fund as
many maintainers as you want to, as we want to. But, you know...
We've got to start somewhere. So when we kind of started spinning up the foundation,
what, five years ago now,
you know, we had a look, the board at the time kind of had a look at,
right, okay, where are the most critical places that we need to provide,
you know, a reliable service?
So kind of infrastructure, I think, is kind of the obvious big thing that,
you know, We exist to make sure that the language can be used without infrastructure, there's
no Rust for anyone.
So one of our very first hires was an infrastructure engineer to make sure that,
someone was actually being paid to be responsible for all of this.
And it wasn't just burden on volunteer maintainers.
So that's where we started. Similarly, you know, crates.io is just,
you know, crates.io is rust.
So that was, again, an area where we thought, right, we really need to fund
a full-time maintainer for this and make sure that, you know,
there's always someone that is paid to do this that is responsible.
And we're not putting in reasonable expectations on unpaid volunteers.
So we have a full-time crates.io maintainer as well.
I know, you know, security is something that isn't terribly exciting for a lot
of people. I know an awful lot of
people are quite bored by thinking about security, but it's so important.
It's getting even more important. And luckily, people in the US government of
the time and in a lot of the big tech organizations also thought it was very important.
So these people put together a fund called Alpha Omega that actually enabled
us, they gave us some money to enable us to hire a security engineer to take
care of security maintenance as well.
So we've been really lucky that we've been able to afford to actually have some
salaried maintainers on staff.
I would love to have a lot more, but, you know, we have to kind of live within our budget.
In addition to those full-time salaried staff, though, we do try whatever possible
to talk with our members, to talk with companies interested in Rust,
and encourage them to invest in the foundation so that we can,
at the very least, contract maintainers or provide some other kind of form of grants or assistance.
Because we totally understand that, you know, you mentioned burnout earlier.
We totally understand that people do end up burning out, especially because,
you know, they're doing a lot of hours to get paid.
We currently have the Rust Foundation Maintainers Fund. So that is something
that we invite companies to donate to.
And that's something that we work incredibly closely with the project to allocate
any funding that goes in there.
But otherwise, we also have kind of an ecosystem fund, which enables companies
to direct funds towards things that are of specific interest to them.
So if a company comes up to us and says, Actually, I want to give you some money,
but I really want it to be targeted towards work on, I don't know,
async or embedded or whatever.",
and we can use those kind of contracts to pay maintainers in those areas if they want to be paid.
So there's quite a lot of different layers of maintainer funding here.
We try very, very hard to raise funds to pay maintainers, but,
we understand that not every maintainer actually wants to be employed.
Like, we have to remember that as well. This is an open source project.
We can't just assume that everyone wants to be a full-time maintainer.
Some people just want to turn up and do the thing that they're really interested
in and not be expected to be responsible for this thing forever.
So yeah, there's various things. I mean, Lori, is there anything else you
kind of want to talk about on that?
So yeah, one of the things that I wanted to touch on is that when we started,
the Rust Foundation Maintainers Fund,
I think we really got the project to start thinking about what they're worth
and what, you know, can we really come together and figure out,
like, how can we best support you?
And what do you want to do? So,
there's these project goals that were started, I think, a year or so ago.
And the evolution has been really interesting. So project goals are sort of,
what maintainers want to work on.
Whereas what Bec said is sometimes
companies come to us and say what work they would like to get done.
So it's the reverse where project people are saying, I would really like to
do this. And now what we're doing is we're assigning dollar values to what they
would like to do. So we're trying to actively help them get funded for things
that they would like to do.
Part of this with the Rust Foundation Maintainers Fund is I'm on the funding team.
And there's four of us. And we created this application.
And at the all hands, we asked everyone there to submit an application to let
us know like, what kind of funding they needed?
What do they want to work on? How can we better serve you?
You know, like, do you want to be full time? Do you want to be part time?
Is there only like a project goal you would like to work on that you think is
going to take six months, but you can't even touch it because you need the funding
to be able to put other things aside.
So from that standpoint, now you have the project telling you what they want to get done.
And when we think about the Rust Commercial Network, one of the arms of what
we want to do is, again, funding, funding maintainers.
So we have now a funding directory where you can look and see kind of what project
goals are out there, what might help you long term.
Do they need financial support? Do they also need developer support.
Part of a project goal is you have to have sort of a team in place.
You need a champion within the project. You need reviewer capacity.
You need all of that. And people sign on to do that when they sign on to be a part of a project goal.
So to me, I think this is an awesome thing that the project is doing because
they're saying, this is what we want to do.
This is what we'd like to get funded to do. Can you meet us where we're at?
And like, think of all the things that you might get unblocked by like letting
us focus our attention on certain things and making sure that we're getting
compensated to do those certain things we'd like to do so i encourage anyone
to check that out the the project goals page.
Yeah i think Lori covered a lot of that there one of the things we're learning as a project,
thanks to the foundation's help is that it's not enough for us to say hey we're
open source maintainers we build this great thing called rust come give us money
we need to put the structures in place within the project within the way we
work to advertise, hey, here's where your dollars can go and where they would make a difference.
And with those structures, then we can attract more funding and support more maintainers.
It's not going to come just from asking, we need to do some work to make it easy for that to happen.
Why does Rust specifically deserve investment from companies,
from governments, from the community, compared to other languages and ecosystems
competing for the same attention?
So I'm not going to say that we are unique in that we think that we should be funded.
I think that in the value of open source, we really need to shift the mindset
that it's not free as in beer, it's freedom of choice.
And if you choose to build using Rust, you should also choose to support those
that are creating the infrastructure that you're using to build your products.
And again, I think the project goals, having a maintainers fund is a way that
we are setting ourselves apart and saying, this is what we would like to do.
And I'm using we as a project that we would like to do.
You know, it would be great if you could meet us not just halfway,
but you could support us so that look at what we could unlock for you.
And the cool thing, too, is that not all project goals are, you know,
I want to get this done in six months. It's experimentation.
And you need to support innovation and experimentation within open source,
because how else are you going to unlock all of these other opportunities and potential?
So, like, yes, there's maintenance, but there's also, like, I want to try this new thing.
Can you support me in trying this new thing? it might fail, but that's okay.
Because again, that's the value of open source is that getting behind people
that are willing to take chances. And you never know.
I think also in open source, you know, sometimes winning can kind of feel like failing.
Say you have a crate that's been super successful, lots of adoption,
and now you're getting pull requests that you can't handle because it's just you,
you know, can you support that crate maintainer to either hire on additional
help can you be their development help you know
so i'm not saying rust is unique in its problems and its challenges in terms
of funding but i am saying as it is growing as a language is growing in adoption you know,
we need to grow in our in our support and financial support is one really big way of doing that.
I guess also the companies that are using rust in production that's not like
a one time if you're using rust now that's that you're depending on rust and
rust is a living thing that has bugs and that has security things we need to fix and,
that long tail of maintenance that is part of now the project or the the your
product you've built on this foundation you need to make sure that foundation's
solid and supporting the maintainers how you do that,
you can't just adopt trust and say well that's that it's perfect now forever
because there are going to be things they need fixing the people that are fixing
those they need supported.
And when we talk about, again, the Rust Foundation Maintainer Fund,
it's this idea of they're calling it maintainer in residence.
And so that is someone that is in the project that is maintaining something
that we hope to be able to fund for one to two years.
And then we see the next cycle, as what Bec said, is like taking that maintainer
in residence, realizing they're good work and that this is a core part of the
project and then bringing them in as a new employee of the foundation so that
maintainer in residence position can go to someone else.
So in supporting the foundation maintainers fund you're really supporting the
strength of rust because the more we can support that the more employees we
can bring in the more opportunity to give more funding to new people.
I hope many organizations hear this because at least historically there has been,
issues with adequately funding open source projects companies depend on but
it's almost seen as if it's a commons a thing that is just there for everyone and,
you know free to be used in whatever capacity you like which is not true of course.
Yeah i think we're i think a lot of people across open source are trying very
hard to change that narrative now i feel like,
i have these conversations with a lot of other foundations as well and especially
things like the package repository you know crates.io for us these things take
a huge amount of money to run.
Again, as Lori said earlier, open source is not free as in beer,
it's free as in puppy, right?
It's something that, yes, okay, it's free, but you actually have to take care
of it. It's a responsibility as well as a proof.
So I think, you know, we're having these conversations and we are very much trying to.
To shift that narrative to companies should not see this as a charitable thing.
You know, we want to move away as much as possible from, oh,
I'm going to give you guys a donation because it gives me the warm and fuzzies.
We're trying to kind of demonstrate to businesses that this is part of the cost
of doing business, you know, supporting the foundation, supporting maintainers.
That should be a line item in your company's budget.
That should be a standing thing that you pay for every year,
just like you pay for utilities, just like you pay for your lawyer.
You know, if you need this, if you need rust to work so that you can sell your
products, then there should be a cost to your business of supporting that.
Because otherwise, you know, all it takes is,
you know, a poor economy for a year or two or businesses going bust or,
you know, an economic bubble bursting or whatever.
If all of the companies at the same time decide, oh, actually,
I can't really afford to like donate money to open source this year.
It makes the infrastructure very, very unstable.
It means that, yeah, we can't pay people to do things.
And ultimately, it means that businesses will not be able to rely on these kinds of things.
So yeah, we're definitely trying to kind of drive a narrative that this should
not be seen as a charitable, philanthropic thing, giving money to the foundation.
It should be seen as you being a responsible business and making sure that you
are actually supporting the thing that you are relying on.
And a big part of it is putting a price tag on it, just to say,
that's the number that we're dealing with making it tangible,
because that's also historically been missing for for many such projects that
have to organize themselves and so on how expensive is it to run,
rust?
It's very expensive. We are very lucky because we get a lot of things donated
in kind, so we do not have to pay for absolutely everything.
And if we did, I think we'd probably already have buckled, to be honest,
because the numbers are eye-watering and the usage trends are going up,
so yeah it's it it would be in the millions and millions of dollars a year,
in cash terms if we had to actually pay market price for absolutely everything
as i say we're very lucky that a lot an awful lot of things we get given in kind,
by very generous businesses that understand that they they rely on this but it's,
it's mind-boggling i think the numbers that we're talking about.
Like all of the work you do is amazing because i think it drives rust adoption
which means more people come into the language into the community but of course
if rust gets adopted by organizations,
they are looking for training,
what's the history there what's the story around training programs regarding the rust foundation.
So there's always been this kind of accusation.
I think that Rust is really difficult to learn. People made a lot of the kind
of steep learning curve.
And I think it probably put some people off.
You know, we don't want to put people off. And we talked a lot to our members.
Like, well, this is, you know, this is a learning problem. This is not a,
you know, this is not a, oh, this language is just impossible.
It's like, how do we make sure it's friendlier? How do we make sure it's easier for people to learn?
And what can we as a foundation do to help with that?
So, yeah, we looked, okay, do we develop our own course?
Do we do something else? Do we work with other providers?
And, you know, over the years, a lot of courses actually did come out that are absolutely fantastic.
So I think you know if you were not particularly experienced engineer a lot
of people would struggle to have just picked up the Rust book and like gone from there,
but an awful lot of great courses have been open sourced as well the yeah Google
did a Rust course which is fantastic on which they've open sourced.
There's many many courses out there now so while we were having these conversations
it kind of became obvious that it's not necessarily the courses themselves ourselves
that we needed to kind of contribute to that universe.
Actually, we were moving into a space where, okay, which course should I take?
Which providers should I hire? You know, when we're talking about adoption,
as you said, businesses, the question businesses are asking is,
okay, who do I get to train my staff in this?
And I think that was where sort of talking to our.
Kind of accreditation of actual existing trainers was where there was a kind
of gap and where we could hopefully be of some assistance to people out there.
Because, you know, having a stamp of approval from the Rust Foundation that
you are a trusted trainer, you know what you're talking about.
We've reviewed your materials. We know that you were able to communicate,
these ideas coherently and and you know enable people to to become productive
pretty quickly so yeah that seemed to be a the best thing for the trainers out
there many of them you know there are members,
but also us as a foundation actually being useful I don't think it would have
been particularly useful for us to just create and yet another course but creating the ability,
for But for excellent trainers to
be immediately recognizable as trusted experts, I think that adds value.
That's us adding value to them and hopefully making sure that lots more people can enjoy Rust.
Can people already apply to become trusted trainers already?
Yes, the program is now open. It launched last week. We have,
I think, three or four founding training programs on there. But yeah,
we are open to applications and all the information can be found on our website.
Do we even need trainers now that we have AI?
I think anyone who is a trainer would say absolutely.
I don't think we're in a position yet where good quality training can just be
wholesale replaced with AI.
As great a tool as AI is for many things and as much as it's improving every day,
I think everyone has a different learning style and preference and for a lot
of people that is having a sympathetic human being explaining things to them
so I don't think we're there yet.
And what's the foundation's view on AI-generated Rust code?
I don't think it's for us to necessarily have a view. We're here to make sure
that Rust is useful, productive, relevant, fun for people to use.
And it's up to, I think, individuals and companies to figure out how they want to do that.
What I will say is that we want to make sure, as stewards of the language,
it's our job to make sure that Rust has a bright future and that people still
want to use it in 10, 20 years' time.
So I do think there's something, there's some responsibility for us to make
sure that if people want to use it with AI, then we have to make sure that we can support that.
But I also don't think that we're in a position to mandate anything.
You know, we just want to make sure it's as useful and as available as people need it to be.
Traditionally, the final question is, what's your message to the Rust community?
Well, I love that there's three of us, so we can each kind of give a little
extra message from one. We now have three.
And for me, it would be to really check out the Rust commercial network.
This is an opportunity to have a different entry point into Rust with others that are adopting Rust
and for you to find a way to make it easier for you, for your company,
for you to share what you're working on with other organizations and to find
some common ground, which, you know, is the spirit of open source.
Yeah, and for my part, I'd say, you know, think about supporting open source
projects that you depend on.
Whether that's Rust or other languages or other projects, there are lots of
really passionate open source containers out there who could do with some support.
For me, I just want to encourage everyone out there to get in touch with us
and tell us how we can help you.
You know, the reason for the Rust Foundation to exist is to steward the language
and support the people that love it.
We want your input. So, yeah, tell us how we can help.
And that's everything I have to say. Bec, Lori, David, thanks so much for taking
time. That was amazing. And thanks for all your hard work.
Thanks so much.
Thank you.
Thanks for having us.
Rust in Production is a podcast by Corrode It is hosted by me,
Matthias Endler and produced by Simon Brüggen
For show notes, transcripts and to learn more about how we can help your company
make the most of Rust visit Corrode.dev Thanks for listening to Rust in Production.
Bec
00:00:34
Lori
00:00:41
David
00:00:53
Matthias
00:01:03
Bec
00:01:20
Matthias
00:01:53
Bec
00:01:59
Lori
00:02:40
Matthias
00:03:11
David
00:03:25
Matthias
00:04:14
Bec
00:04:34
Matthias
00:05:49
Bec
00:05:55
Matthias
00:06:43
Lori
00:06:52
David
00:08:05
Matthias
00:08:25
David
00:08:50
Matthias
00:09:28
David
00:09:34
Matthias
00:10:52
Lori
00:11:30
Matthias
00:12:36
David
00:12:41
Matthias
00:13:29
David
00:13:45
Matthias
00:14:29
Bec
00:14:43
Matthias
00:17:25
Bec
00:17:32
David
00:17:51
Matthias
00:18:33
Bec
00:19:16
Matthias
00:20:40
Lori
00:20:57
David
00:24:20
Matthias
00:24:53
Lori
00:25:19
Matthias
00:26:48
David
00:27:11
Matthias
00:28:08
Lori
00:28:48
Matthias
00:30:02
David
00:30:17
Matthias
00:30:53
David
00:31:01
Lori
00:31:13
Matthias
00:31:35
Bec
00:31:45
Lori
00:36:13
David
00:38:50
Matthias
00:39:18
Lori
00:39:30
David
00:41:25
Lori
00:41:56
Matthias
00:42:34
Bec
00:42:59
Matthias
00:45:29
Bec
00:45:48
Matthias
00:46:41
Bec
00:47:04
Matthias
00:49:55
Bec
00:49:59
Matthias
00:50:12
Bec
00:50:16
Matthias
00:50:48
Bec
00:50:53
Matthias
00:51:44
Lori
00:51:49
David
00:52:18
Bec
00:52:30
Matthias
00:52:46
Lori
00:52:54
Bec
00:52:55
David
00:52:56
Matthias
00:52:57