GitHub user Xuanwo created a discussion: [DISCUSS][RFC] Draft proposal to 
establish Apache Reqsign as a top-level project

Hi all,

## Purpose

The OpenDAL and Reqsign communities have reached strong consensus to pursue 
establishing Reqsign as a standalone Apache top-level project, as recorded in 
[apache/opendal-reqsign#821](https://github.com/apache/opendal-reqsign/discussions/821).
 The proposed initial PMC membership and Chair candidate were subsequently 
confirmed in 
[apache/opendal-reqsign#846](https://github.com/apache/opendal-reqsign/discussions/846).

This thread asks the OpenDAL community and PMC to review the exact proposed ASF 
Board resolution and the associated transition plan.

This is a **DISCUSS/RFC**, not a vote. It does not reopen the general question 
of whether Reqsign should pursue TLP status, and it does not request separate 
votes on the PMC roster or Chair. Please focus feedback on the accuracy and 
completeness of the proposal below.

The [suitable-name search for "Apache 
Reqsign"](https://issues.apache.org/jira/browse/PODLINGNAMESEARCH-258) remains 
in progress in parallel. If the approved name differs, the draft resolution 
will be updated before submission to the ASF Board.

## Proposed ASF Board resolution

```text
Resolution to Establish the Apache Reqsign Project from the Apache
OpenDAL Reqsign Subproject

X. Establish the Apache Reqsign Project

WHEREAS, the Board of Directors deems it to be in the best interests
of the Foundation and consistent with the Foundation's purpose to
establish a Project Management Committee charged with the creation
and maintenance of open-source software, for distribution at no
charge to the public, related to signing HTTP requests to cloud
services.

NOW, THEREFORE, BE IT RESOLVED, that a Project Management Committee
(PMC), to be known as the "Apache Reqsign Project", be and hereby is
established pursuant to Bylaws of the Foundation; and be it further

RESOLVED, that the Apache Reqsign Project be and hereby is responsible
for the creation and maintenance of software related to signing HTTP
requests to cloud services; and be it further

RESOLVED, that the office of "Vice President, Apache Reqsign" be and
hereby is created, the person holding such office to serve at the
direction of the Board of Directors as the chair of the Apache
Reqsign Project, and to have primary responsibility for management
of the projects within the scope of responsibility of the Apache
Reqsign Project; and be it further

RESOLVED, that the persons listed immediately below be and hereby are
appointed to serve as the initial members of the Apache Reqsign
Project:

* Chojan Shang <[email protected]>
* Erick Guan <[email protected]>
* Han Xu <[email protected]>
* Hao Ding <[email protected]>
* Hao Jiang <[email protected]>
* Liuqing Yue <[email protected]>
* Mingzhuo Yin <[email protected]>
* Qinxuan Chen <[email protected]>
* Zili Chen <[email protected]>

NOW, THEREFORE, BE IT FURTHER RESOLVED, that Zili Chen be appointed
to the office of Vice President, Apache Reqsign, to serve in
accordance with and subject to the direction of the Board of
Directors and the Bylaws of the Foundation until death, resignation,
retirement, removal or disqualification, or until a successor is
appointed; and be it further

RESOLVED, that the Apache Reqsign Project be and hereby is tasked
with the migration and rationalization of the Apache OpenDAL Reqsign
subproject; and be it further

RESOLVED, that all responsibilities pertaining to the Apache OpenDAL
Reqsign subproject encumbered upon the Apache OpenDAL Project are
hereafter discharged.
```

## Background and rationale

Reqsign is an ASF-hosted Rust project for signing HTTP requests to AWS, Azure, 
Google, Huawei, Aliyun, Tencent, Oracle, and other cloud services without 
requiring full vendor SDKs. It already has a separate repository, release 
cycle, and users outside OpenDAL, including 
[uv](https://github.com/astral-sh/uv/blob/49e2fc5c821bb69a528308a036b17446bb5ab5a6/Cargo.toml)
 and 
[sccache](https://github.com/mozilla/sccache/blob/e9b15a35f7240a7edd1b9644583edb388c6cb5f9/Cargo.toml).

Reqsign has been developed under the Apache OpenDAL PMC and ASF processes. Its 
provenance and IP review are recorded in the [OpenDAL Reqsign IP 
clearance](https://incubator.apache.org/ip-clearance/opendal-reqsign.html), and 
its source releases are published through the [Apache OpenDAL distribution 
area](https://archive.apache.org/dist/opendal/).

The readiness assessment and remaining governance considerations are documented 
in 
[apache/opendal-reqsign#821](https://github.com/apache/opendal-reqsign/discussions/821).
 Establishing a focused PMC would give the distinct Reqsign community direct 
responsibility for releases, security, community growth, infrastructure, and 
Board reporting.

## Proposed transition plan

After the ASF Board approves the resolution, the new PMC would coordinate with 
the OpenDAL PMC and ASF Infrastructure to:

1. Rename `apache/opendal-reqsign` to `apache/reqsign`, retaining repository 
history, issues, pull requests, and discussions.
2. Establish `reqsign.apache.org` and migrate the project website.
3. Create `[email protected]`, `[email protected]`, and 
`[email protected]`, then update repository notification routing.
4. Move source-release distribution, KEYS references, release metadata, and 
archive paths from the OpenDAL area to the Reqsign area.
5. Transfer GitHub release environments, crates.io publishing access, and other 
release credentials to the new PMC.
6. Establish the initial committer roster in coordination with the OpenDAL PMC 
while preserving contributor history and appropriate existing access.
7. Publish standalone governance, security, community, compatibility, and 
release documentation.
8. Add Apache Reqsign project metadata, including its DOAP entry, and begin the 
Board reporting schedule for a newly established TLP.
9. Update OpenDAL documentation and metadata to describe Reqsign as a related 
standalone ASF project rather than an OpenDAL subproject.

Until the Board resolution is approved and the relevant infrastructure 
transition is complete, Reqsign remains an Apache OpenDAL subproject governed 
by the OpenDAL PMC.

## Feedback requested

Please review:

- the project scope and mission wording;
- the initial PMC names and Apache IDs;
- Zili Chen as the proposed initial Chair;
- the transfer clauses in the Board resolution;
- the infrastructure and governance migration plan; and
- any issue that should be resolved before the proposal is submitted to the ASF 
Board.

Concrete corrections and objections are especially useful. `+1` replies are not 
required for this RFC.

Best,
Xuanwo


GitHub link: https://github.com/apache/opendal/discussions/8138

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]

Reply via email to