T5 SPIKE: ZDS S3 blob + CDN redirect PR eval (timeboxed)

closed
#23e262e opened by agent Sep 13

Parent: bug 75966cc (cell architecture tracking). Never blocks Sept — rclone covers launch; ZDS exit via CAR/PDSmoover/goat keeps this low-risk.

Goal

Evaluate a ZDS upstream PR adding S3 blob storage + CDN redirects (Cocoon/Tranquil shape), then prototype only if the eval passes.

Scope

  • 5a lib eval (do first): fellowtraveler/z3 (async std.http+std.Io, R2-tested, GET/PUT/DELETE/HEAD/Copy + multipart + presigned — best fit on paper) vs cloudboss/aws-sdk-zig (Smithy-generated, full-featured, heavier) vs algoflows/zig-s3 (simple SigV4 + custom endpoints). Avoid aws-c bindings. Criteria: R2 compat, multipart, presigned URLs (future), async fit, maintenance signs, license.
  • 5b prototype (only if 5a passes): backend enum (filesystem default | s3) over the 6-function blobstore.zig surface, key layout blobs/{did}/{cid}, env config (S3_ENDPOINT, region, bucket, keys, CDN_URL), multipart for the ~100MB cap, getBlob 302 to public R2/CDN (all ZDS blobs are public by design — no signed-URL split needed), GC delete wired to S3. Templates: Cocoon handle_sync_get_blob 302 branch, Tranquil storage-crate multipart shape.
  • Full upstream PR only after 5b proves out (bot-style read flood to prove CDN offload). ZeroFS explicitly out of scope (S3-direct needs no POSIX bridge).

Acceptance

  • Eval matrix + go/no-go recorded; no full implementation inside the spike.

1 Comment

agent 2b3deb2 Oct 8

Closing as moot (2026-10-08): the plan is to replace ZDS with one vlpds per cell (a4a3137), which keeps all state in the cell’s object storage, so a ZDS S3-blob PR isn’t worth pursuing. Reopen if vlpds isn’t adopted.