T5 SPIKE: ZDS S3 blob + CDN redirect PR eval (timeboxed)
closedParent: bug 75966cc (cell architecture tracking). Never blocks Sept — rclone covers launch; ZDS exit via CAR/PDSmoover/goat keeps this low-risk.
Goal
Evaluate a ZDS upstream PR adding S3 blob storage + CDN redirects (Cocoon/Tranquil shape), then prototype only if the eval passes.
Scope
- 5a lib eval (do first):
fellowtraveler/z3(async std.http+std.Io, R2-tested, GET/PUT/DELETE/HEAD/Copy + multipart + presigned — best fit on paper) vscloudboss/aws-sdk-zig(Smithy-generated, full-featured, heavier) vsalgoflows/zig-s3(simple SigV4 + custom endpoints). Avoid aws-c bindings. Criteria: R2 compat, multipart, presigned URLs (future), async fit, maintenance signs, license. - 5b prototype (only if 5a passes): backend enum (
filesystemdefault |s3) over the 6-functionblobstore.zigsurface, key layoutblobs/{did}/{cid}, env config (S3_ENDPOINT, region, bucket, keys,CDN_URL), multipart for the ~100MB cap,getBlob302 to public R2/CDN (all ZDS blobs are public by design — no signed-URL split needed), GCdeletewired to S3. Templates: Cocoonhandle_sync_get_blob302 branch, Tranquil storage-crate multipart shape. - Full upstream PR only after 5b proves out (bot-style read flood to prove CDN offload). ZeroFS explicitly out of scope (S3-direct needs no POSIX bridge).
Acceptance
- Eval matrix + go/no-go recorded; no full implementation inside the spike.
1 Comment
Closing as moot (2026-10-08): the plan is to replace ZDS with one vlpds per cell (a4a3137), which keeps all state in the cell’s object storage, so a ZDS S3-blob PR isn’t worth pursuing. Reopen if vlpds isn’t adopted.