Skip to content

Publisher Services: packages, distribution configuration and controlled rollout #765

Description

@ja573

Objective

Implement the approved Publisher Services and Distribution Configuration design across Thoth, thoth-app, thoth-dissemination and cc-license with additive schema, explicit authorization, audited migration, comparison-mode cutover, bounded pilots, monitoring and rollback.

Immutable authority at foundation review head

The Publisher Services design requires one fresh task branch and one PR per task. There is no long-lived feature/publisher-services integration branch.

Synchronization guard

Before applying this replacement: re-fetch the complete live issue body; re-fetch its current updatedAt; compare both exactly against the reviewed baseline updatedAt: 2026-07-24T17:17:09Z and body. If either the live body or updatedAt differs, do not write. Regenerate the minimal diff from the new live body, obtain fresh independent review, and obtain separate explicit CTO authorization before writing. Any later rollback must likewise re-fetch and compare the live body and updatedAt, preserve unrelated edits, and apply only a reviewed minimal reversal under explicit CTO authorization; it must never restore an old complete snapshot blindly.

Current gate

  • P0-01 independently approved, repository-finalized and merged
  • ADR-0001 approved
  • ADR-0002 approved
  • ADR-01 platform inventory approved
  • repository branch-readiness decisions recorded

No production implementation begins before the applicable gate passes.

Tasks

Foundation

  • P0-01 - Project control documents and tracker - CLOSED
  • ADR-01 - Platform inventory and final architecture
  • LIC-01 - Expand cc-license
  • LIC-02 - Enforce supported licences in Thoth

Backend

  • BE-01 - Publisher package model
  • BE-02 - Distribution platform model
  • BE-03 - Protected service configuration
  • BE-04 - Durable distribution jobs

Migration and interfaces

  • MIG-01 - Audit and production backfill
  • APP-01 - Publisher service configuration UI
  • APP-02 - Staff subscription report
  • APP-03 - API-backed licence options

Cutover and downstream services

  • DIS-01 - API publisher discovery and comparison mode
  • DIS-02 - Back-catalogue job worker
  • EXP-01 - OCLC KBART feed index
  • OAI-01 - Package and licence gating

Stabilization

  • OPS-01 - Monitoring, runbooks and cleanup
  • E2E-01 - Full workflow verification

P0-01 closure records completion of the engineering-control foundation only. It does not approve an ADR, approve the final inventory, satisfy branch readiness, or make another task ready.

Do not close a task at PR creation or CI success. Close only after independent approval, merge, required rollout/observation and repository tracker update.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions