1.3 KiB
Search event indexing contract
Core defines, but does not implement, the optional Search indexing boundary.
Feature modules register SearchSourceProvider implementations for bounded
backfills and live authorization checks. A provider may additionally implement
SearchEventSourceProvider to translate a committed PlatformEvent into one
or more authoritative SearchIndexChange values.
When the Search index-writer capability is active, the platform event worker
uses the durable consumer identity search.indexing.v1. It accepts only public
and internal events, passes the outbox delivery key to each event-capable
source, and then advances a bounded batch of queued index changes in the same
worker transaction. Stable change IDs make delivery replay idempotent.
The boundary has three non-negotiable rules:
- a source may emit changes only for its registered module, provider, resource type, and event tenant;
- Search validates every upsert document before queueing it and rejects secret metadata keys;
- an index ACL is only a candidate filter. Resources marked for authorization recheck are returned only after the owning source explicitly allows the current principal at query time.
Search and its worker remain optional. Core-only startup and feature-module operation do not require the Search package.