GitHub user Xuanwo created a discussion: [DISCUSS] Graduate Apache OpenDAL Reqsign to a top-level project
## Background In [Discussion #820](https://github.com/apache/opendal-reqsign/discussions/820), @tisonkun suggested that Reqsign could graduate from Apache OpenDAL and become a standalone ASF project. This thread follows up on that idea. Reqsign is already broader than OpenDAL's internal needs. [uv uses Reqsign directly](https://github.com/astral-sh/uv/blob/49e2fc5c821bb69a528308a036b17446bb5ab5a6/Cargo.toml) for AWS, Azure, and Google authentication, [sccache depends on it](https://github.com/mozilla/sccache/blob/e9b15a35f7240a7edd1b9644583edb388c6cb5f9/Cargo.toml) for remote-storage authentication, and Reqsign has its own repository, release cycle, and [website work](https://github.com/apache/opendal-reqsign/pull/818). This is a **DISCUSS** thread, not a binding graduation vote. "Graduate" here means spinning an existing ASF subproject out as a standalone top-level project (TLP), not graduating a podling from the Incubator. The [ASF Board creates TLP PMCs by resolution](https://www.apache.org/foundation/governance/pmcs), and ASF has direct spin-off precedents such as [Apache Submarine](https://cwiki.apache.org/confluence/display/HADOOP/Submarine+Project+Spin-Off+to+TLP+Proposal) and [Apache DataFusion](https://whimsy.apache.org/board/minutes/DataFusion.html#17-April-2024). ## Readiness assessment The [Apache Project Maturity Model](https://community.apache.org/apache-way/apache-project-maturity-model) is a guide, not a points-based pass/fail checklist. I used it to review the current project evidence. | Area | Current evidence | Assessment | | --- | --- | --- | | Product scope | Reqsign is a standalone multi-cloud request-signing library with users outside OpenDAL, a separate repository, and an independent release cycle. | Ready | | Code, licenses, and IP | The repository is ASF-hosted and Apache-2.0 licensed. The [OpenDAL Reqsign IP clearance](https://incubator.apache.org/ip-clearance/opendal-reqsign.html) recorded the provenance, ICLAs, dependency-license review, and an initial trademark search. | Ready | | Releases | Five final source releases, 0.20.0 through 0.20.4, are present in the [Apache release archive](https://archive.apache.org/dist/opendal/). They used signed artifacts and digests, public PMC votes, and the documented [repeatable release process](https://github.com/apache/opendal-reqsign/blob/main/release/SKILL.md). Two people have acted as release managers, and at least six OpenDAL PMC members have cast binding votes across those releases. | Ready, but the release-manager pool should grow | | Development community | Since the Apache branding change on 2025-10-01, the repository has merged 111 PRs from 14 human authors, excluding bots and ASF infrastructure accounts. User issues are being handled, and external adoption is real. | Promising | | Sustainability | 78 of the 93 human-authored merged PRs in that period came from two people (63 from @Xuanwo and 15 from @tisonkun). The same two people are the only release managers so far. | Main readiness risk | | Consensus and infrastructure | Work, release votes, and decisions are public; repository notifications are routed to ASF lists through [`.asf.yaml`](https://github.com/apache/opendal-reqsign/blob/main/.asf.yaml). | Ready as a subproject; standalone lists and ownership would need migration | | Governance | Reqsign currently relies on the OpenDAL PMC. It has no agreed standalone PMC roster, chair, charter, public decision-power roster, or Reqsign-specific committer/PMC growth record. | Blocking unknown | | Quality, security, and community documentation | CI and provider tests are strong, but Reqsign does not yet publish standalone security, governance, committer, and compatibility-policy pages. The official website is still a draft PR. | Preparation work remains | | Brand and identity | The current product name is "Apache OpenDAL Reqsign". A TLP would normally become "Apache Reqsign" with `reqsign.apache.org`. Even though the 2025 IP clearance recorded no trademark search result, the [ASF naming process](https://www.apache.org/foundation/marks/naming.html) applies when establishing a TLP and needs formal approval. | Preparation work remains | My current assessment is: - Reqsign has the product scope, code/IP, release discipline, and operational maturity needed to **start pursuing TLP status**. - It is **not yet ready for a Board resolution** because the most important evidence is still missing: a sustainable, organizationally diverse standalone PMC that is willing to own releases, security, community growth, brand, and Board reporting. - The remaining question is primarily community and governance maturity, not technical maturity. ## Proposed next steps If the community agrees that becoming a TLP is desirable, I propose that we: 1. Identify a credible initial PMC, initial committers, and a chair candidate. The PMC needs at least three active members and should be organizationally diverse; we should not infer current affiliations from email domains or historical employment. 2. Publish a Reqsign maturity self-assessment and standalone governance, security, community, compatibility, and release documentation. 3. Expand operational ownership, especially release management and routine review, beyond the current two-person core. 4. Complete the ASF suitable-name review and decide the final project name, website, and branding. 5. Draft the charter, Board resolution, and an infrastructure migration plan covering mailing lists, repository naming, dist/KEYS, crates.io publishing, the website, DOAP metadata, and Board reporting. 6. Confirm the direct subproject-to-TLP path with experienced ASF members and the Board, then hold a formal OpenDAL community/PMC vote before submitting a resolution. ## Feedback requested Do we want to pursue this TLP preparation work, or is Reqsign better kept as an OpenDAL subproject? Non-binding signals are welcome: - **+1**: pursue TLP preparation - **+0**: keep evaluating - **-1**: remain an OpenDAL subproject If you support the move, please also say whether you are willing to help as an initial PMC member, committer, release manager, or chair candidate, and call out any missing evidence or transition risk. GitHub link: https://github.com/apache/opendal-reqsign/discussions/821 ---- This is an automatically sent email for [email protected]. To unsubscribe, please send an email to: [email protected]
