GitHub user Xuanwo created a discussion: [DISCUSS] Graduate Apache OpenDAL 
Reqsign to a top-level project

## Background

In [Discussion 
#820](https://github.com/apache/opendal-reqsign/discussions/820), @tisonkun 
suggested that Reqsign could graduate from Apache OpenDAL and become a 
standalone ASF project. This thread follows up on that idea.

Reqsign is already broader than OpenDAL's internal needs. [uv uses Reqsign 
directly](https://github.com/astral-sh/uv/blob/49e2fc5c821bb69a528308a036b17446bb5ab5a6/Cargo.toml)
 for AWS, Azure, and Google authentication, [sccache depends on 
it](https://github.com/mozilla/sccache/blob/e9b15a35f7240a7edd1b9644583edb388c6cb5f9/Cargo.toml)
 for remote-storage authentication, and Reqsign has its own repository, release 
cycle, and [website work](https://github.com/apache/opendal-reqsign/pull/818).

This is a **DISCUSS** thread, not a binding graduation vote. "Graduate" here 
means spinning an existing ASF subproject out as a standalone top-level project 
(TLP), not graduating a podling from the Incubator. The [ASF Board creates TLP 
PMCs by resolution](https://www.apache.org/foundation/governance/pmcs), and ASF 
has direct spin-off precedents such as [Apache 
Submarine](https://cwiki.apache.org/confluence/display/HADOOP/Submarine+Project+Spin-Off+to+TLP+Proposal)
 and [Apache 
DataFusion](https://whimsy.apache.org/board/minutes/DataFusion.html#17-April-2024).

## Readiness assessment

The [Apache Project Maturity 
Model](https://community.apache.org/apache-way/apache-project-maturity-model) 
is a guide, not a points-based pass/fail checklist. I used it to review the 
current project evidence.

| Area | Current evidence | Assessment |
| --- | --- | --- |
| Product scope | Reqsign is a standalone multi-cloud request-signing library 
with users outside OpenDAL, a separate repository, and an independent release 
cycle. | Ready |
| Code, licenses, and IP | The repository is ASF-hosted and Apache-2.0 
licensed. The [OpenDAL Reqsign IP 
clearance](https://incubator.apache.org/ip-clearance/opendal-reqsign.html) 
recorded the provenance, ICLAs, dependency-license review, and an initial 
trademark search. | Ready |
| Releases | Five final source releases, 0.20.0 through 0.20.4, are present in 
the [Apache release archive](https://archive.apache.org/dist/opendal/). They 
used signed artifacts and digests, public PMC votes, and the documented 
[repeatable release 
process](https://github.com/apache/opendal-reqsign/blob/main/release/SKILL.md). 
Two people have acted as release managers, and at least six OpenDAL PMC members 
have cast binding votes across those releases. | Ready, but the release-manager 
pool should grow |
| Development community | Since the Apache branding change on 2025-10-01, the 
repository has merged 111 PRs from 14 human authors, excluding bots and ASF 
infrastructure accounts. User issues are being handled, and external adoption 
is real. | Promising |
| Sustainability | 78 of the 93 human-authored merged PRs in that period came 
from two people (63 from @Xuanwo and 15 from @tisonkun). The same two people 
are the only release managers so far. | Main readiness risk |
| Consensus and infrastructure | Work, release votes, and decisions are public; 
repository notifications are routed to ASF lists through 
[`.asf.yaml`](https://github.com/apache/opendal-reqsign/blob/main/.asf.yaml). | 
Ready as a subproject; standalone lists and ownership would need migration |
| Governance | Reqsign currently relies on the OpenDAL PMC. It has no agreed 
standalone PMC roster, chair, charter, public decision-power roster, or 
Reqsign-specific committer/PMC growth record. | Blocking unknown |
| Quality, security, and community documentation | CI and provider tests are 
strong, but Reqsign does not yet publish standalone security, governance, 
committer, and compatibility-policy pages. The official website is still a 
draft PR. | Preparation work remains |
| Brand and identity | The current product name is "Apache OpenDAL Reqsign". A 
TLP would normally become "Apache Reqsign" with `reqsign.apache.org`. Even 
though the 2025 IP clearance recorded no trademark search result, the [ASF 
naming process](https://www.apache.org/foundation/marks/naming.html) applies 
when establishing a TLP and needs formal approval. | Preparation work remains |

My current assessment is:

- Reqsign has the product scope, code/IP, release discipline, and operational 
maturity needed to **start pursuing TLP status**.
- It is **not yet ready for a Board resolution** because the most important 
evidence is still missing: a sustainable, organizationally diverse standalone 
PMC that is willing to own releases, security, community growth, brand, and 
Board reporting.
- The remaining question is primarily community and governance maturity, not 
technical maturity.

## Proposed next steps

If the community agrees that becoming a TLP is desirable, I propose that we:

1. Identify a credible initial PMC, initial committers, and a chair candidate. 
The PMC needs at least three active members and should be organizationally 
diverse; we should not infer current affiliations from email domains or 
historical employment.
2. Publish a Reqsign maturity self-assessment and standalone governance, 
security, community, compatibility, and release documentation.
3. Expand operational ownership, especially release management and routine 
review, beyond the current two-person core.
4. Complete the ASF suitable-name review and decide the final project name, 
website, and branding.
5. Draft the charter, Board resolution, and an infrastructure migration plan 
covering mailing lists, repository naming, dist/KEYS, crates.io publishing, the 
website, DOAP metadata, and Board reporting.
6. Confirm the direct subproject-to-TLP path with experienced ASF members and 
the Board, then hold a formal OpenDAL community/PMC vote before submitting a 
resolution.

## Feedback requested

Do we want to pursue this TLP preparation work, or is Reqsign better kept as an 
OpenDAL subproject?

Non-binding signals are welcome:

- **+1**: pursue TLP preparation
- **+0**: keep evaluating
- **-1**: remain an OpenDAL subproject

If you support the move, please also say whether you are willing to help as an 
initial PMC member, committer, release manager, or chair candidate, and call 
out any missing evidence or transition risk.

GitHub link: https://github.com/apache/opendal-reqsign/discussions/821

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]

Reply via email to