Files
govoplan-core/docs/SEARCH_EVENT_INDEXING_CONTRACT.md
T

1.3 KiB

Search event indexing contract

Core defines, but does not implement, the optional Search indexing boundary. Feature modules register SearchSourceProvider implementations for bounded backfills and live authorization checks. A provider may additionally implement SearchEventSourceProvider to translate a committed PlatformEvent into one or more authoritative SearchIndexChange values.

When the Search index-writer capability is active, the platform event worker uses the durable consumer identity search.indexing.v1. It accepts only public and internal events, passes the outbox delivery key to each event-capable source, and then advances a bounded batch of queued index changes in the same worker transaction. Stable change IDs make delivery replay idempotent.

The boundary has three non-negotiable rules:

  • a source may emit changes only for its registered module, provider, resource type, and event tenant;
  • Search validates every upsert document before queueing it and rejects secret metadata keys;
  • an index ACL is only a candidate filter. Resources marked for authorization recheck are returned only after the owning source explicitly allows the current principal at query time.

Search and its worker remain optional. Core-only startup and feature-module operation do not require the Search package.