Proposals and decisions
Changes to the platform's public surface — a contract, a capability, an event type, or a major product policy — are proposed in the open and recorded as an architecture decision record (ADR) in OpenVibe.Contracts.
- Propose. Open an issue or pull request on OpenVibe.Contracts describing the change, who owns it, and who consumes it. A service that introduces capabilities ships proposals in its own repository (
docs/capabilities-proposal/,docs/service-manifest-proposal.json) — this portal's are in its repository. - Decide. An accepted proposal becomes an ADR with context, decision, alternatives, migration consequences, rollback and acceptance tests.
- Release. The contract lands in a tagged openvibe-contracts release; CI in every consuming service checks it (
openvibe-contracts-check). The SDK wraps it in the same or the next release, and these docs regenerate from the new pins.
Decision record
The ADRs in openvibe-contracts v0.114.0:
| Decision | Status |
|---|---|
| ADR-001: Canonical subject IDs and legacy identity mapping | Accepted, implemented 2026-09-22 |
| ADR-002: Contract repository and compatibility policy | Accepted, implemented 2026-09-22 (openvibe-contracts v0.1.0+) |
| ADR-003: Service/app principal authentication and capability grants | Accepted, implemented 2026-09-22. Amended 2026-09-24: delegated authorization semantics and approval UX (roadmap §28.3). |
| ADR-004: Durable event store, outbox/inbox and delivery semantics | Accepted 2026-09-22; implementation in progress (OpenVibe.Events) |
| ADR-005: Realtime topics, cursor/resume and whether OpenVibe.Realtime exists | Accepted 2026-09-22: realtime runs inside OpenVibe.Events |
| ADR-006: Media object, location and namespace model | Accepted 2026-09-22; implementation in progress (OpenVibe.Media Wave 4). Amended 2026-09-24: four placement classes, the local/dev provider, the infrequent-access tier deferred (roadmap §28.3 m1). |
| ADR-007: Logical data ownership and database technology | Accepted 2026-09-22. Superseded in part 2026-09-28 by ADR-035 (PostgreSQL and Valkey now, not on a trigger; the ownership rule and the 2026-09-24 runtime posture still hold). Amended 2026-09-24: PostgreSQL runtime posture (pooling, replicas, money-path isolation, Redis non-authoritative; roadmap §28.3 m10). |
| ADR-008: Shared package publication and release manifests | Accepted 2026-09-22; implementation in progress (OpenVibe.Shared). Amended 2026-09-25 (one copy: libraries take openvibe-shared as a peer). |
| ADR-009: Live versus OpenRe boundary | Accepted 2026-09-23. OpenRe.Stream deployed the same day (RTMP ingest + restream; WHIP, SFU and JSMPEG not yet ported). No slot has moved: per-slot cutover waits for the ingest DNS name, the public RTMP port and a broadcaster window. |
| ADR-010: Chat versus Live/Community boundary | Accepted and executed 2026-09-23 (cutover 02:03 UTC). Governs Wave 6. |
| ADR-011: Community paste and comment ownership migration | Accepted and executed 2026-09-22 |
| ADR-012: Billing vs loyalty, credits and currency classification | Accepted 2026-09-22. Gates Wave 8 (OpenVibe.Billing), Wave 9 (Tips) and Wave 10 (VIP). Amended 2026-09-24: ledger transaction types mapped to the roadmap's names; OpenCoins stays in Network; the payouts/refunds/plans table substitution. |
| ADR-013: Mod manifest, trust and sandbox/resource model | Accepted 2026-09-23. Gates Wave 12 (mods) and Wave 21 Stage C (sandboxed user code). Amended 2026-09-24: signing and review are open owner decisions; mod monetization only through Billing; manifest 1.1.0 (read/write grants, billing hooks, dependencies). |
| ADR-014: Developer project, tenant and quota model | Accepted 2026-09-23. Gates Wave 20 (Codes) and Wave 21 (Host tenants). |
| ADR-015: AI workflow and publication ownership boundary | Accepted 2026-09-23. OpenVibe.AI deployed the same day (loopback, port 4700); Live's switch |
| ADR-016: Active client update safety and the supported mixed-version window | Accepted 2026-09-23. Governs Track R. |
| ADR-017: Home of the source registry and ingestion runtime | Accepted 2026-09-23. Gates Wave 14. |
| ADR-018: Home of the search index and query contract | Accepted 2026-09-23. Gates Wave 14. |
| ADR-019: Home of the shared publishing packages | Accepted 2026-09-23. Gates Wave 15. |
| ADR-020: Notification delivery ownership | Accepted 2026-09-23. Wave 3 follow-through. |
| ADR-021: Analytics ownership and privacy bounds | Accepted 2026-09-23. Contract now; extraction decision at Wave 22. Amended 2026-09-24: extraction decided (no analytics service; analytics stays per service through `openvibe-shared/analytics`). |
| ADR-022: Moderation and policy console | Accepted 2026-09-23. Revisited at Wave 12 (2026-09-24): the decision stands, with no moderation service; next revisit at Wave 22 or when the trigger below is met. |
| ADR-023: First-party client surfaces and their home | Accepted 2026-09-23. Needed by Wave 18. |
| ADR-024: Theme authority boundary between Network and OpenVibe.Shared | Accepted 2026-09-23. |
| ADR-025: Marketplace and commerce scope | Accepted 2026-09-23. Binding on Wave 19 (Trade). |
| ADR-026: Producer redaction of its own events (`payload.redacts`) | Accepted 2026-09-23; implemented in OpenVibe.Events (`server/redaction.js`, `server/store.js`, |
| ADR-027: Tools platform API | Accepted 2026-09-23. Contracts in openvibe-contracts v0.33.0. Tools serves the registry |
| ADR-028: Expand, migrate, contract — schema changes that survive a rollback | Accepted 2026-09-25; enforced first in OpenVibe.Live (`test/destructive-migrations.test.js`, |
| ADR-029: Merging two accounts into one | Accepted 2026-09-26 (roadmap WS-B task 5). Implementation follows in OpenVibe.Network. |
| ADR-030: Who owns the follow graph | Accepted 2026-09-26 (roadmap WS-E task 4). Migration follows. |
| ADR-031: An S3-compatible surface for OpenVibe.Media | Accepted 2026-09-26 (roadmap WS-N task 8). Implementation follows in OpenVibe.Media. Amended 2026-10-02: named object zones (OpenVibe.Zone). A bucket is a named zone inside a project environment, resolved per access key. The environment's own namespace is the zone `default`. |
| ADR-032: Containers for platform services | Accepted 2026-09-26 (roadmap WS-N task 12). Revisit on any trigger below. |
| ADR-033: Exporting and deleting an account | Accepted 2026-09-27 (roadmap WS-B task 7). Implementation follows in OpenVibe.Network and each service that keeps data about a person. |
| ADR-034: The platform north star — an open, affordable cloud | Proposed 2026-09-28, for the owner's review. The owner's direction: "highly optimized, efficient, modular and fully scalable … powerful and interconnected, with a full SDK and API … the open affordable version of AWS one day … moddable." This ADR turns that into rules that every later decision and implementation follows. It guides roadmap workstream WS-W. |
| ADR-035: PostgreSQL and Valkey as the data tier | Accepted 2026-09-28, the owner's decision ("we should just get it over with now … so we don't waste time later"). Supersedes the "a service moves only on a measured trigger" rule of ADR-007's 2026-09-26 amendment. ADR-007's ownership rule and its 2026-09-24 runtime posture stay in force and bind every step below. Roadmap workstream WS-X2, requirement D48. |
| ADR-036: Run is an execution authority, not a Host detail | Proposed 2026-10-05 (plan track T14, "Run is not a Host detail"; plan §8 lists ADR-036 as one of the records |
| ADR-042: The events fabric — carrier classes, per-key ordering, cursors and tiers | Accepted 2026-09-29 (plan track T7, "Events complete"; the owner's plan names NATS JetStream as the |
| ADR-043: Bot — devices, pairing, control and safety | Accepted 2026-09-29 (plan track T15, "Bot complete"; owner direction the same evening: openvibe.bot is an open |
| ADR-044: The Actor runtime — the task contract, adapter interface, modes, signals, verification and trust | Proposed 2026-10-05 (plan track T17). This is the build-order item immediately after the engine: plan |
| ADR-045: The Node is OpenVibe's universal runtime | Proposed 2026-10-05 (plan §8: *"ADR-045 (Node; **revise: Node is the universal runtime, not a |
| ADR-046: The universal adaptive fabric — offers, requirements, placement, trust classes and signed plans | Proposed 2026-10-03 (plan track T1 step 3, for the owner's review). Builds on ADR-034 §5 (control plane |
| ADR-048: The Services control plane — authority aggregation, OVRN and one control-operation contract | Accepted 2026-10-04 (plan track T13, step 1). Amended 2026-10-05: the resource index owns |
| ADR-053: The Website/Host boundary — OpenVibe.Website authors, OpenVibe.Host serves | Proposed 2026-10-05 (plan track T19), for the owner's review. Builds on ADR-014 (developer |