Skip to content

Project progress

Scope: the implemented Go utilities, TypeScript v2.35.0 compatibility, verification and delivery. This is the project's progress record. Check an item only after its stated acceptance criteria pass. Existing IDs and dated evidence retain their original scope; later work does not turn a historical checkpoint into fresh acceptance.

Usage belongs in the utility guides. Feature comparison maps TypeScript capabilities and verification boundaries; ROADMAP.md records remaining priorities. Ordinary wording/link repairs do not need progress entries. Feature audits, implementation and newly verified acceptance do.

Documentation and feature audit

  • DOC-14: Publish the static documentation with Cloudflare Pages Git integration on main, using the existing locked dependency, navigation, guide and strict build checks. Associate powertools-lambda-go.rambow.cloud, configure its CNAME and verify a successful deployment plus active custom-domain/certificate status. All build checks and control-plane publication checks passed (2026-10-02). Keep credentials and private account identifiers out of Git. Evidence: CLOUDFLARE_ACCEPTANCE.json. Browser review remains separate under DOC-06.

  • DOC-12: Audit the seventeen pinned TypeScript utility guides against Go APIs and reference evidence; give every corresponding Go guide a complete example, input/output explanation, object lifecycle and feature map. Correct stale completed-versus-open claims. Preserve explicit OTel/native and unsupported data-key-cache boundaries. Guide/source coverage for eighteen Go guides, navigation and clean strict build passed (2026-10-01). Evidence: DOCUMENTATION_ACCEPTANCE.json.

  • DOC-13: Execute the maintained packaged-module/reference and local Docker acceptance scope for the audited implementation; record reused phases and both build architectures. Verify documentation examples and documented response/output shapes. Verified 31 modules/28 consumers across resumed phases, 19 compiled programs/18 executed local programs or direct handlers, both Linux builds, 868/868 RIE, 95/95 streaming and 14/14 saved Batch checks (2026-10-01). No exhaustive parity, arm64 execution or new AWS run is claimed. Evidence: DOCUMENTATION_ACCEPTANCE.json.

Foundation

  • F-01: Create a separate project directory and initialize Git on main.
  • F-02: Establish a Go module with pinned dependencies and typed Lambda handlers.
  • F-03: Record English documentation/comment policy and always-disabled CGO in AGENTS.md.
  • F-04: Share invocation identity and prefer runtime context trace headers over process state.
  • F-05: Document the OTel default and optional X-Ray backend decision.

Commons and Metadata

  • C-01: Map reference exports and inspect actual Logger/Metrics/Parameters reuse. Record Go equivalents and differences in COMMONS.md and COMMONS_REUSE.md.
  • C-02: Implement shared configuration/runtime, Base64, type helpers, indexed deep merge, LRU, decoded-value snapshots, and raw/native DynamoDB conversion with large integer preservation.
  • C-03: Migrate compatible Logger, Metrics, Tracer, Parameters, and invocation helpers. Preserve utility-specific cache, fallback, lifecycle, and serialization policies.
  • C-04: Implement opt-in SDK identity/version middleware; verify composed clients emit exactly one marker without changing AWS_SDK_UA_APP_ID.
  • C-05: Implement the independent Metadata client with authenticated requests, timeout/cancellation, unknown fields, caching/clearing, local behavior, snapshots, and coordinated concurrent fetches.
  • C-06: Verify TypeScript fixtures, consumer regression tests, Metadata/LRU functional concurrency, full tests/vet, both Linux builds, and 100/100 Docker assertions (2026-09-14).
  • C-07: Complete exhaustive cross-language type/encoding/error edge cases, real AWS LMDS acceptance, and performance budgets. Detailed remaining items: COMMONS_PLAN.md.

Logger

  • L-15: Apply descendant replacers to struct/custom-marshaler JSON without duplicate root callbacks, preserving field tags and large numeric tokens. Verify redaction, omission, and precision.
  • L-16: Accept compiled correlation extractors through a dependency-free interface. Verify callback precedence, diagnostic error reporting, business-result preservation, and request cleanup; Logger's dependency graph excludes JMESPath.

  • L-01: Implement structured JSON fields, level filtering, reserved fields, and field precedence; verify with unit tests.

  • L-02: Implement persistent/temporary attributes and child loggers; verify state isolation and custom child output.
  • L-03: Implement Lambda enrichment and isolated invocation state; verify 100 concurrent invocations and reject late writes.
  • L-04: Implement ALC precedence and invocation sampling; verify the reference integer boundary.
  • L-05: Implement buffering, eviction, oversized entries, error flush, and successful-invocation discard; verify lifecycle tests.
  • L-06: Preserve handler results, errors, and panic identity.
  • L-07: Generate actual TypeScript v2.35.0 log fixtures and compare normalized Go output.
  • L-08: Complete custom formatter/replacer, timezone, stdout/stderr routing, and all environment edge-case acceptance tests. APIs are present.
  • L-08a: Preserve replacer traversal through pointers without duplicate property callbacks; verify redaction, caller immutability, pointer cycles, formatter failures/replacement, UTC/Hong Kong/New York timestamps, and level stream routing. Remaining environment and serialization cases stay under L-08/L-09.
  • L-09: Close every Logger API/default/diagnostic and serialization parity gap.
  • L-10: Implement constructor sampling, first-invocation decision reuse, independent warm decisions, and diagnostic logs. Verify the pinned TypeScript sampling fixture and unit/concurrency regression suite (2026-09-14).
  • L-11: Add all nine reference built-in correlation sources for maps and JSON-tagged events, custom callback precedence, and invocation cleanup. Arbitrary JMESPath expressions remain deferred to the query package (2026-09-14).
  • L-12: Replace private merge routines with Commons indexed-array/object merge for persistent and temporary attributes; verify reserved fields, parent/child isolation, and consumer configuration modes.
  • L-13: Add reference getters GetLevelName, GetLogEvent, and GetCorrelationID; verify scoped levels, constructor configuration, temporary-only correlation semantics, and cleanup against the pinned source contract.
  • L-14: Support sampled/unsampled OTel contexts for buffering without a runtime X-Ray header, derive log trace/span/X-Ray IDs from the active context, and reject stale runtime correlation. Verify error flush, success discard, late-write rejection, and pure W3C success/error paths in Docker (2026-09-14).

Tracer

  • T-14: Add opt-in HTTP event-envelope extraction for API Gateway/Function URL/ALB/AppSync, preserving existing OTel context and cancellation. Verify typed/map events, multi-value precedence, and malformed/non-HTTP fallback.

  • T-01: Implement an interchangeable backend interface and a private OTel provider with OTLP/HTTP export.

  • T-02: Verify X-Ray parent extraction, nested OTel spans, parent sampling, service annotations, and response metadata.
  • T-03: Verify error redaction, panic cleanup, idempotent completion, and injected provider ownership.
  • T-04: Verify HTTP and AWS SDK v2 instrumentation with fake transports and propagation assertions.
  • T-05: Verify bounded flush deadlines and preserve business errors when flush fails.
  • T-06: Verify the optional X-Ray adapter's handler/child lifecycle and native metadata.
  • Retired T-07: The legacy SDK adapter is deprecated and frozen (2026-09-14). Preserve regression evidence and migration notices; no new SDK-specific features or compatibility fixes are planned. Maintained X-Ray delivery uses OpenTelemetry.
  • T-08: Validate OTLP collector delivery, X-Ray indexing/service maps, and Lambda freeze/timeout behavior in AWS.
  • T-08a: Verify collector-to-X-Ray delivery, indexed annotations, normal/error/panic closure, sampled/unsampled requests, and both architectures in ap-east-1. Evidence: AWS_VALIDATION.md. Hard timeout/freeze recovery and exhaustive service-map parity remain open.

  • T-09: Escape dots and percent signs in OTel metadata key components, preventing namespace/key collisions while retaining ordinary attribute names. Verify independent values with regression tests (2026-09-14).

  • T-10: Add explicit W3C/X-Ray HTTP context extraction with existing-context/W3C precedence, baggage and cancellation preservation, and invalid-header fallback. Trace queries recognize external OTel contexts and XRayTraceID uses the shared SDK-free formatter.
  • T-11: Honor OTEL_TRACES_SAMPLER and OTEL_TRACES_SAMPLER_ARG in the default provider. Verify default/always-off/ratio/parent-based cases and X-Ray-compatible root ID generation; injected provider ownership remains unchanged.
  • T-12: Deprecate and freeze tracer/xray in package/type/constructor/module metadata, add a once-per-process English migration warning, and verify the warning alongside existing regressions. Document OTel collector-to-X-Ray migration with the current AWS maintenance timeline.
  • T-13: Remove the legacy SDK from the maintained Lambda fixture and its dependency graph, retire new legacy cloud fixtures, and verify 12 packaged modules, nine independent consumers, both Lambda architecture builds, and 105/105 local Docker assertions. No new AWS deployment was performed.

Metrics

  • M-01: Add an independent EMF package using io.Writer, all 27 units, standard/high resolution, scalar/multiple values, and injected timestamps.
  • M-02: Implement default/request dimensions, independent dimension sets, metadata snapshots, merge precedence, projected dimension limits, and metric collision rejection.
  • M-03: Implement manual flush/clear, automatic 100-metric and 100-value boundaries, independent single metrics, and cleanup on failed writes.
  • M-04: Implement environment configuration, disabled emission, opt-in empty-metric errors, and Lambda wrappers preserving business results/errors/panics.
  • M-05: Verify 100 concurrent request scopes, rejected late writes including derived single metrics, and isolated cold-start EMF in Docker.
  • M-06: Compare eight EMF documents from four actual TypeScript v2.35.0 scenarios. Verify runtime composition with Logger/Tracer: five Docker invocations, 85 assertions; LOCAL_VALIDATION.md.
  • M-07: Complete remaining decorator/framework lifecycle mapping, metadata/native/encoding boundaries, the export/type audit and exhaustive reference fixtures; scoped store/diagnostic/cold-start/configuration/value/timestamp/wrapper behavior is verified under M-07a through M-07g. Current differences: METRICS.md and METRICS_PLAN.md.
  • M-07a: Implement selective store clears, presence queries, scoped runtime empty policy and deprecated alias; preserve timestamp and single-metric defaults. Verified 104 actual TypeScript store lifecycle scenarios, 64 concurrent scope policies, late-write rejection, all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 631/631 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. See METRICS_PLAN.md.
  • M-07b: Implement reference diagnostics, skipped invalid dimensions and warned timestamp storage with callback delivery after lock release and cleanup. Verified 203 actual TypeScript diagnostic scenarios, Unicode whitespace reuse, callback reentrancy/concurrent scopes, automatic flush and failed-output delivery, all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 646/646 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. See METRICS_PLAN.md.
  • M-07c: Implement manual cold-start capture, scoped deprecated function-name setter and constructor/environment/argument precedence. Verified 302 actual TypeScript cold-start cases, 64 concurrent captures, failed-write consumption, scoped function-name isolation and closed-scope rejection; all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 658/658 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks passed (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. See METRICS_PLAN.md.
  • M-07d: Implement strict configuration parsing, ConfigService getter precedence, WithSingleMetric and error-returning single-metric reconstruction; migrate all callers. Verified 532 actual TypeScript configuration cases, exact custom getter order/errors, strict environment validation, single-metric reconstruction and constructor publication mode; all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 673/673 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks passed (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. See METRICS_PLAN.md.
  • M-07e: Implement numeric JSON values, exact validation/conflict/sentinel errors, reserved/default-prototype key behavior and shared JavaScript key ordering. Verified 641 actual TypeScript value/error/key scenarios, exact warning/configuration error messages, shared key-order regression through Parser/Validation, all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 688/688 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. See METRICS_PLAN.md.
  • M-07f: Implement numeric and Date timestamp conversion, representable-range handling and lazy clock reads; verify clear/single/disabled/strict lifecycles and Lambda scope cleanup. Verified 968 actual TypeScript numeric/Date timestamp scenarios, exact warnings/errors and clock-read counts, 64 concurrent scopes and late-write rejection; all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 706/706 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks passed (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. See METRICS_PLAN.md.
  • M-07g: Implement scoped wrapper defaults/strict options, ordered multi-instance publication and optional reference error precedence; reuse scope creation and closure with manual and HTTP consumers. Verified 876 actual TypeScript middleware-hook cases, exact output/warning/error and publication-order comparisons, 64 concurrent nested invocations, option snapshots, panic precedence and callback/writer cleanup; all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 724/724 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks passed (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. See METRICS_PLAN.md.
  • M-08: Verify real CloudWatch metric extraction and establish allocation, latency, and payload-size budgets. No new AWS deployment was performed.

Parameters

Parameters acceptance (2026-09-14): see PARAMETERS.md for the exact API and compatibility boundaries.

  • P-01: Implement shared TTL caching, force fetch, clearing, transform-specific entries, isolated mutable results, missing/error handling, and cancellable callbacks. Verify expiry and functional concurrency tests.
  • P-02: Implement SSM reads, relative-path pagination, recursive/decryption precedence, version-returning writes, ten-name batches, per-name overrides, and strict/graceful modes.
  • P-03: Implement Secrets Manager string/binary values, version SDK options, missing normalization, and caching; verify actual SDK protocol requests.
  • P-04: Implement DynamoDB configurable attributes, native value decoding, projected gets, and paginated queries; verify SDK requests and mutable set snapshots.
  • P-05: Implement AppConfig session/token lifecycle, unchanged-response reuse, cache clearing, failed-poll recovery, expiry, and cancellation. Verify 100 concurrent same-profile requests without token reuse.
  • P-06: Implement AppConfig Agent HTTP, path escaping, timeout, local/development overrides, missing/error responses, transforms, and no extra cache.
  • P-07: Implement default SSM/Secrets/AppConfig helpers and global clearing with lazy initialization. Verify configuration loading against local endpoints and 100 concurrent initialization requests.
  • P-08: Generate actual TypeScript v2.35.0 cache/transform and SSM batch fixtures, including reference quirks; compare outputs and SDK operation sequences in Go.
  • P-09: Pass full Go tests/vet, Linux amd64/arm64 builds, and 94 Docker assertions with all five providers, warm caching, forced refresh, AppConfig token rotation, and existing Logger/Metrics/Tracer behavior.
  • P-10a: Reuse Commons configuration, Base64, SDK identity, snapshots, and precision-preserving DynamoDB helpers. Verify consumers, shared reference fixtures, and runtime SDK composition.
  • P-10: Close remaining native type/invalid-input/diagnostic and duration edge cases listed in PARAMETERS.md; finish exhaustive behavior audit. Shared parsing, Base64 validation, SDK marker, and large integer handling are implemented under P-10a.
  • P-11: Verify live AWS permissions, encryption/version changes, service polling/throttling, and establish latency/allocation/cache-size budgets.

Signer and JMESPath

  • S-IMPL: Implement and verify the independent Signer module: configuration/providers, standalone SigV4, body replay, typed errors, signed transport, redirect policy, thirteen reference cases, and endpoint examples. Detailed checklist: SIGNER_PLAN.md.
  • J-IMPL: Implement and verify the independent JMESPath module: standard queries, compiled cache, custom functions, three Powertools functions, thirteen envelopes, 78 reference cases, and optional Logger correlation. Detailed checklist: JMESPATH_PLAN.md.
  • SJ-LOCAL: Verify 14 packaged modules, 11 standalone consumers, Linux amd64/arm64 builds, and 114/114 Docker assertions. Synthetic signature verification and decoded/query correlation pass alongside existing utilities. No AWS deployment was performed.
  • SJ-PARITY: Complete the remaining exhaustive cross-language, live-service, and performance gates documented in SIGNER.md and JMESPATH.md. Known intentional differences are not hidden as fixture normalization.

Batch

  • B-IMPL: Implement the independent Batch module for SQS Standard/FIFO, Kinesis and DynamoDB Streams, response/error policy, sequential/parallel processing, bounded concurrency, context/cancellation, typed wrappers, and custom processors. Packaged module tests/vet and standalone consumer build passed; see BATCH_PLAN.md.
  • B-REF: Compare 43 actual TypeScript reference scenarios and verify FIFO warm reuse, panic/error identity, typed event adapters, and 100 concurrent calls.
  • B-LOCAL: Verify 15 packaged modules, 12 standalone consumers, both Lambda architectures, 129 Docker assertions, and 14 additional Batch/Logger/OTel composition assertions against the same runtime artifacts. Containers/network were cleaned up; no AWS deployment was performed.
  • B-COMPLETE: Finish remaining differential behavior, service-side retries/checkpoints, and performance budgets. DynamoDB-backed Idempotency composition passed under I-LOCAL; concrete Parser composition passed under PR-LOCAL.

Idempotency

  • I-CORE: Implement operation configuration, canonical keys, validation, lifecycle, persistence interfaces, typed wrappers, response hooks, and isolated local cache. Verify 25 reference keys, 14 lifecycle scenarios, concurrent acquisition, retry/error boundaries, and operation isolation. See IDEMPOTENCY_PLAN.md.
  • I-DDB: Implement DynamoDB conditional acquisition, strong reads, conflict snapshots, native data, custom/composite keys, and SDK identity; compare actual Go wire requests with two pinned TypeScript command scenarios.
  • I-LOCAL: Verify 16 packaged modules, 13 standalone consumers, both architecture builds, and 155/155 Docker assertions. Idempotency verifies warm replay, duplicate suppression, failed-record cleanup/retry, payload validation, native DynamoDB requests, SDK identity, and Logger/OTel record context. The same runtime artifacts passed 14/14 Batch composition checks; no AWS deployment was performed.
  • I-CACHE: Implement the independent Redis/Valkey store with sixteen reference scenarios, guarded orphan recovery, retained payload validation, and explicit reference differences. Verify 17 packaged modules, 14 standalone consumers, both architectures, 172/172 Docker assertions, and 14/14 Batch artifact checks. Real Valkey covers 32 overlapping duplicate requests per successful invocation, warm replay, orphan recovery and basic TypeScript/Go record exchange in both directions. Default key generation also avoids repeated custom marshaler calls.
  • I-COMPLETE: Complete exhaustive bidirectional persistence/serialization compatibility, cache topology/expiry acceptance, supported durable replay, live-service acceptance, and performance budgets.

Parser

  • PR-CORE: Implement typed Schema/SchemaFunc, Parse/SafeParse, structured issues, operational errors, manual/safe Lambda wrappers, and shared invocation identity. Verify cancellation, empty issue slices, handler result/error/panic identity and original-event retention.
  • PR-SCHEMA: Implement schema composition, transforms/refinements/defaults, unknown fields, extension, typed outputs and JSON/Base64 helpers. Verify mutable-default/output isolation and 100 concurrent calls. Initial SQS/EventBridge models and envelopes pass forty actual TypeScript cases; runtime-specific JSON syntax suffix normalization is documented.
  • PR-LOCAL: Verify 18 packaged modules, 15 independent consumers, both CGO-disabled Linux architecture builds, 184/184 Docker assertions and 14/14 Batch artifact checks. Parser validates typed SQS/EventBridge payloads, distinguishes safe aggregation from first-record failure, and rejects invalid orders before the Idempotency business handler. Containers and network were cleaned; no AWS deployment occurred.
  • PR-STREAMS: Implement all 22 stream/notification schema exports, six additional envelopes, DynamoDBMarshalled, Enum/Omit/Pipe and safe refinement composition. Reuse a single SDK-free Commons raw decoder while preserving the SDK adapter APIs. Verify 106 new TypeScript cases (146 total), pipeline/extension/concurrency regressions, all 18 modules and 15 consumers, both architecture builds, 205/205 Docker assertions and 14/14 Batch artifact checks (2026-09-15).
  • PR-HTTP: Implement eighteen HTTP schema exports and five body envelopes, sharing field extraction with EventBridge. Fix accepted missing unknown fields returning an internal absence marker. Verify 458 new reference cases (604 total), concurrent reuse and error/mode isolation, all 18 modules/15 consumers, both Lambda architectures, 226/226 Docker assertions and 14/14 Batch artifact checks. Add a safe HTTP 400 Lambda example; no AWS resources were used (2026-09-15).
  • PR-SERVICES: Implement fifteen Kafka/CloudFormation/Transfer/Connect/SES/S3 schema exports and the Kafka envelope. Reuse SQS/EventBridge models and shared text decoding; verify raw JSON ordering, safe paths, UTF-8 replacement, surrogate pairs, integer bounds and explicit runtime-error differences through 270 new reference cases (874 total). All 18 modules/15 consumers, both CGO-disabled Linux builds, 250/250 Docker assertions and 14/14 Batch artifact checks passed. Add a native RawMessage Kafka Lambda example (2026-09-15); see PARSER_SERVICES.md.
  • PR-IDENTITY: Implement 29 AppSync/shared, AppSync Events and Cognito schema exports using shared identity/request fields and the Null primitive. Verify 1,467 new reference cases (2,341 total), map all 90 public runtime schema names, add typed AppSync/Cognito Lambda examples, and pass all 18 modules/15 consumers, both CGO-disabled Linux builds, 274/274 Docker assertions and 14/14 Batch artifact checks (2026-09-15). See PARSER_IDENTITY.md.
  • PR-ERRORS: Preserve recursive union branch diagnostics, select the sole continuable branch, continue refinements and align array error order. Propagate safe mode and nested ParseError validation through composition; reuse Commons numeric conversion and remove the S3 union workaround. All 3,493 reference cases, error-tree ownership/mode/operational tests, 18 modules/15 consumers, both CGO-disabled Linux builds, 292/292 Docker assertions and 14/14 Batch artifact checks passed (2026-09-16, Asia/Shanghai). See PARSER_ERRORS.md.
  • PR-COMPLETE: Finish all export/type mappings, remaining constraint/error metadata, full numeric/encoding and envelope edge parity, Validation/Event Handler integration, and performance measurements. All 24 initial schema families and fourteen envelope families have implementations. See PARSER_PLAN.md and the linked contract documents.

Validation

  • V-CORE: Implement the independent JSON Schema module, reusable compilation, nullable/reference-sibling adaptation, formats, registered references, JMESPath extraction, typed input/output wrappers and structured errors. Verify snapshots, 32 concurrent callers, cancellation, business error/panic preservation and 502 actual TypeScript/AJV result/error cases.
  • V-LOCAL: Verify all 19 packaged modules and sixteen independent consumers, the native Lambda example, both CGO-disabled Linux builds, 316/316 Docker assertions and 14/14 Batch artifact checks (2026-09-16, Asia/Shanghai). All temporary containers/network were cleaned; no AWS resources were used. Commons and Parser retain zero third-party module dependencies.
  • V-REGEX: Add the pure-Go ECMAScript Unicode matcher and generated Unicode 16 property tables, preserving strict syntax, original patterns and encoded schema paths. Verify 6,085 additional reference cases (6,587 Validation total), all 19 modules/16 consumers, both Linux builds, 331/331 Docker assertions and 14/14 Batch artifact checks. Fix the Windows test runner's UTF-8 decoding; reuse verified binaries for runtime-only continuation. Resource-error, panic-identity and 32-caller concurrency tests pass. See VALIDATION_REGEX.md (2026-09-16, Asia/Shanghai).
  • V-COMPLETE: Complete AJV defaults/extensions, JavaScript regex/numeric/Unicode behavior, complex keyword diagnostics/order, middleware/decorator mapping, Parser/Event Handler composition, performance and release gates. See VALIDATION_PLAN.md and JSON_SCHEMA_VALIDATION.md.
  • V-APPLICATORS: Preserve scoped conditional, dependency, property-name, tuple and oneOf diagnostics; use source declaration order and Commons snapshots. Verify 1,207 new exact cases (7,794 Validation total), 32-caller concurrency, callback counts, returned-value ownership and single serialization snapshots. All 19 modules/16 consumers, both Linux builds, 343/343 Docker assertions and 14/14 Batch artifact checks passed with CGO disabled (2026-09-16, Asia/Shanghai). See VALIDATION_APPLICATORS.md; complete parity remains open.

  • V-REFERENCES: Mixed-type groups, nullable arrays, nested IDs, reference chains and recursive diagnostic scopes passed 1,271 new cases (9,065 Validation total), concurrent target reuse, all 19 modules/16 consumers, both CGO-disabled Linux builds, 355/355 Docker assertions and 14/14 Batch checks (2026-09-16, Asia/Shanghai). See VALIDATION_REFERENCES.md. The complete compatibility gate remains open.

  • V-STRICT-PATTERNS: Implement separate legacy UTF-16 strict-overlap matching, preserve Unicode payload patterns and shared regex resource limits, and skip unnecessary overlap checks. Verify 3,047 additional reference cases (12,112 Validation total), all 19 modules/16 consumers, both Linux builds, 364/364 Docker assertions and 14/14 Batch checks with CGO disabled (2026-09-16, Asia/Shanghai). Complete strict-schema setup stays open; see VALIDATION_STRICT.md.

  • V-SETUP: Validate original schema structure independently of reachable keyword/format/nullable/regex compilation. Cover definitions, aliases, nested IDs, unused external documents and always-valid patterns with 658 new cases (12,770 Validation total). All 19 modules/16 consumers, both CGO-disabled Linux builds, 382/382 Docker assertions and 14/14 Batch checks passed with cleanup (2026-09-16, Asia/Shanghai). Full setup/extension parity remains open; see VALIDATION_STRICT.md.

  • V-KEYWORDS: Add private adapters for fractional/negative/large sizes, non-string required entries, empty combinators and default floating-point multipleOf semantics. Verify 3,433 new cases (16,203 Validation total), concurrent diagnostic ownership, all 19 modules/16 consumers, both CGO-disabled Linux builds, 403/403 Docker assertions and 14/14 Batch checks with cleanup (2026-09-16, Asia/Shanghai). Full compatibility remains open; see VALIDATION_KEYWORDS.md.

  • V-SHAPES: Add deferred keyword-type checks, scoped primitive/annotation behavior, conditional compilation edges and mixed property dependencies without duplicate runtime callbacks. Verify 5,764 new cases (21,967 Validation total), all 19 modules/16 consumers, both CGO-disabled Linux builds, 424/424 Docker assertions and 14/14 Batch checks with cleanup (2026-09-16, Asia/Shanghai). Complete schema/graph compatibility remains open; see VALIDATION_SHAPES.md.

  • V-GRAPHS: Preserve ignored condition references, active conditional targets, nested dialect annotations, global resource aliases and ordered ExternalSchemas registration. Verify 1,104 new exact cases (23,071 Validation total), 32 concurrent callers, snapshots and callback counts. All 19 modules/16 consumers, both CGO-disabled Linux builds, 442/442 Docker assertions and 14/14 Batch checks passed with cleanup (2026-09-16, Asia/Shanghai). Complete schema identity/setup compatibility remains open; see VALIDATION_GRAPHS.md.

HTTP event handler

  • H-OBSERVABILITY: Implement optional independent HTTP Metrics/OTel middleware. Verified 176 Metrics and 128 Tracer middleware reference cases (2,066 HTTP cases across the three modules), scope/span concurrency and body lifecycle tests, all 22 packaged modules/19 independent consumers, both CGO-disabled Linux builds, 622/622 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks (2026-09-22, Asia/Shanghai). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. See HTTP_OBSERVABILITY.md.

  • H-CORE: Implement an independent eventhandler/http module with four event adapters, static/dynamic/regex routes, prefixes/inclusion, request/shared state, middleware, response conversion and error policies. Verify 414 reference cases, 64 concurrent callers, snapshots, context identity, cancellation, panic cleanup and body ownership. Reuse Commons decoding/environment helpers; keep HTTP free of third-party module dependencies.

  • H-COMPOSE: Add optional schema checks and compose actual Parser, JSON Schema Validation, Logger and OTel through callbacks/context. Verify rejection before the handler, error paths, response checks, all event formats and scoped log/span relationships.
  • H-LOCAL: All 20 packaged modules/17 consumers, both CGO-disabled Linux builds, 501/501 Docker assertions and 14/14 Batch checks passed (2026-09-16, Asia/Shanghai), with temporary resources cleaned and no AWS resources used. Docker ran amd64; arm64 was cross-compiled only.
  • H-MIDDLEWARE: Implement CORS/preflight and gzip/deflate compression with immutable configuration snapshots and route policies. Verify 1,076 additional reference cases, 64 concurrent callers, body/error/cancellation lifecycle, all 20 packaged modules/17 consumers, both Linux builds, 609/609 Docker assertions and 14/14 Batch checks (2026-09-17, Asia/Shanghai). Module checks preceded a test-event-only null-body correction; the passing Docker continuation rebuilt binaries and reused those checks. Compression representation differences and remaining edge boundaries are documented in HTTP_MIDDLEWARE.md.
  • H-STREAM: Implement ResolveStream/Streamify with shared routing, lazy reader ownership, Lambda HTTP framing and complete producer cleanup. Verify 272 additional reference cases (1,762 HTTP total), deterministic first-byte/cancellation/error tests and 95/95 real-Go-SDK/local-Runtime-API Docker checks. Existing RIE composition passed 609/609. Midstream errors reach runtime trailers; wrappers remain active through body transfer. AWS service behavior and response-mode configuration remain open. See HTTP_STREAMING.md.
  • H-OPENAPI-AUDIT: Reconcile the original OpenAPI inventory against actual TypeScript v2.35.0 package exports, Router members and declarations. No generator exists in the pinned baseline; retire that original requirement without claiming an implementation (2026-09-23).
  • H-COMPLETE: Complete URL/regex/native/header/error/configuration parity, cloud streaming/platform acceptance, observability edge cases, resource budgets and release gates. See HTTP_PLAN.md and HTTP.md.

AppSync Events

  • ASE-IMPL: Implement the independent AppSync Events module, scoped public API mapping, publish/subscribe registries, individual/aggregate execution, authorization, Commons LRU reuse and size diagnostics. Verified 100 actual TypeScript scenarios, 64 concurrent invocations, ordered concurrent item results, LRU eviction and authorization/callback error behavior; full verification passed 23 packaged modules/20 standalone consumers, both CGO-disabled Linux builds, 742/742 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. Final error-type packaging is verified separately in MODULE_ACCEPTANCE_SCOPED.json.
  • ASE-COMPLETE: Complete remaining type/native/serialization/async parity, actual AppSync service acceptance, performance and publication gates in APPSYNC_EVENTS_PLAN.md.

AppSync GraphQL

  • GQL-CORE: Implement independent single/batch routing, router inclusion, exact-name exception handling and scalar helpers. Verify 114 actual TypeScript resolver scenarios, 91 scalar cases, sequential batch semantics, 64 concurrent contexts, reentrant diagnostics and panic/error identity. See APPSYNC_GRAPHQL_PLAN.md.
  • GQL-LOCAL: Verify all 24 packaged modules/21 standalone consumers, both CGO-disabled Linux builds and native Lambda Parser/Logger/OTel composition. Passed 766/766 RIE assertions, 95/95 streaming Runtime API checks and 14/14 saved Batch artifact checks (2026-09-22). Docker executed amd64; arm64 was cross-compiled. The verified GraphQL archive matches all current module files. Temporary resources were cleaned; no AWS resources were used.
  • GQL-COMPLETE: Finish full public type/native/serialization/scalar boundaries, real AppSync service acceptance, performance and publication gates.

Bedrock Agents

  • BR-CORE: Implement the independent function-based Action Group module, ordered parameter conversion, response envelopes and diagnostics. Verify 371 actual TypeScript scenarios, exact body strings, 64 concurrent contexts, cancellation, nil/error ownership and callback reentrancy. Reuse Commons environment, number conversion and key ordering. See BEDROCK_PLAN.md.
  • BR-LOCAL: Verify all 25 packaged modules/22 standalone consumers, both CGO-disabled Linux builds and native Lambda Parser/Logger/OTel composition. Passed 790/790 RIE assertions, 95/95 streaming checks and 14/14 Batch artifact checks (2026-09-23). Bedrock and corrected GraphQL archives match current source. Docker executed amd64; arm64 was cross-compiled. Temporary runtime resources were cleaned; no AWS resources were used.
  • BR-COMPLETE: Complete remaining native/type/serialization compatibility, actual Bedrock service acceptance, performance and publication gates.

Kafka consumer

  • KAF-CORE: Implement the independent primitive/JSON consumer with lazy key/value/header access, original metadata, ordered flattening, typed errors, optional parsing and context-preserving native Lambda wrapper. Verify 143 actual TypeScript v2.35.0 CommonJS scenarios and 64 concurrent contexts. Reuse Commons; no third-party module dependency is added. See KAFKA_PLAN.md.
  • KAF-LOCAL: Verify all 26 packaged modules and 23 standalone consumers, both CGO-disabled Linux builds, and native Lambda Parser/Idempotency/Logger/OTel composition. Passed 808/808 RIE assertions, 95/95 streaming checks and 14/14 saved Batch artifact checks (2026-09-23). Docker executed amd64; arm64 was cross-compiled. The ten Kafka archive files match current source. No AWS resources were used and disposable runtime resources were cleaned. The runtime-only run reused completed module checks and builds.
  • KAF-BINARY-CORE: Implement independent Avro and Protobuf adapter modules. Verify 370 Avro reference scenarios, 123 Protobuf prefix scenarios and nine native proto2 message/descriptor scenarios, plus concurrency, lazy errors, isolation and callback reentrancy. See KAFKA_BINARY.md.
  • KAF-BINARY-LOCAL: Verify all 28 packaged modules and 25 standalone consumers with GOWORK=off, tests/vet/tidy and dependency isolation; build normal and streaming Lambda handlers for Linux amd64/arm64 with CGO_ENABLED=0. Passed 826/826 Docker RIE assertions, 95/95 streaming checks and 14/14 saved Batch checks (2026-09-23). Both adapter archives match all six current files. Docker executed amd64; arm64 was cross-compiled. Runtime resources were cleaned, and no AWS resources were used.
  • KAF-MODES-JSON: Verify 22 additional pinned-consumer scenarios for MSK/self-managed JSON delivery, selected key/value attributes, original schema metadata, no-registry events and explicit codec selection. The 165-case core passes packaged tests/vet/tidy and an independent consumer build with no external modules. These are constructed events, not live captures; full SOURCE/service acceptance remains open. See KAFKA_MODES.md.
  • KAF-MODES-SOURCE: Verify 172 constructed mixed SOURCE/JSON events against the pinned consumer, directly and through the native Go Lambda SDK. Cover both sources, Glue/Confluent metadata, every text/JSON/Avro/Protobuf key/value pair, parsers, original fields and null/empty/missing values. Record the SDK KafkaRecord metadata/presence loss and verify the RawMessage wrapper. See KAFKA_MODES.md.
  • KAF-PROTOBUF-LENGTH: Match the upstream schemaId length comparison for JSON object/array IDs by reusing Commons number parsing. Verify 97 additional cases (220 prefix cases total), nine native messages and the 172 mixed events; retain cyclic/prototype boundaries explicitly.
  • KAF-MODES-LOCAL: Verify the changed Protobuf and integration packaged modules with GOWORK=off, tests/vet/tidy and the independent Protobuf consumer. Session checkpoint-05 matches all six Protobuf and 45 integration archive files. Rebuilt Linux amd64/arm64 with CGO_ENABLED=0 and passed 829/829 RIE, 95/95 streaming and 14/14 Batch checks (2026-09-23). The runner reused completed module checks; Docker executed amd64 and cleanup succeeded. No AWS resources were used.
  • KAF-COMPLETE: Complete remaining Avro/Protobuf schema/native/error/serialization boundaries, registry wire modes, service, performance and release gates.

Data Masking

  • MASK-CORE: Implement the independent JSON-shaped erasure and provider-orchestration module, ordered rules/selectors, warnings and errors. Verify 240 actual v2.35.0 scenarios plus native ownership/concurrency/cancellation/error/panic behavior. Commons supplies number parsing and object-key order; no third-party module dependency is added. See DATAMASKING.md.
  • MASK-LOCAL: Verify all 29 packaged modules and 26 standalone consumers with GOWORK=off, tests/vet/tidy and dependency isolation. The final Data Masking source passes a subsequent scoped package check and matches all eight archive files. Both CGO-disabled Linux builds passed; a runtime-only retry passed 847/847 RIE, 95/95 streaming and 14/14 Batch checks using the previously built binaries and corrected UTF-8 assertions. Docker executed amd64; arm64 was cross-compiled. Resources were cleaned and no AWS resources were used. Provider probes are not cryptographic interoperability.
  • MASK-REGEX-CORE: Verify the optional shared commons/regex module and Validation/Data Masking composition: 7,671 Node replacement cases, 19 invalid patterns, 30 actual TypeScript masking scenarios and all 23,071 existing Validation cases pass. Combined packaged checks cover 30 modules/27 independent consumers, followed by both CGO-disabled Linux builds, 856/856 RIE, 95/95 streaming and 14/14 Batch checks. See REGEX.md, MODULE_ACCEPTANCE_REGEX.json and LOCAL_VALIDATION.md. Full ECMAScript parity remains open.
  • MASK-KMS-CORE: Implement and verify the optional uncached official AWS Encryption SDK provider: 39 TypeScript ciphertext cases, five malformed/tampered rejections, 108 Go-to-TypeScript assertions, multiple keys, authenticated context, 32 concurrent callers and cancellation/deadline/context preservation. Combined accepted checkpoints cover 31 modules/28 independent consumers; both CGO-disabled Linux builds, 868/868 RIE, 95/95 streaming and 14/14 Batch checks pass (2026-09-24). Docker executes amd64; arm64 is cross-compiled. Cache, full key/algorithm/error parity and actual KMS service acceptance remain open. See DATAMASKING_KMS.md and MODULE_ACCEPTANCE_KMS.json.
  • MASK-COMPLETE: Complete remaining JavaScript regex and optional AWS Encryption SDK provider parity, resolve data-key cache compatibility, close native/schema/serialization boundaries and complete service/performance/release gates. See DATAMASKING_PLAN.md.

Delivery

  • D-01: Add complete Lambda and offline local examples, usage instructions, API mapping, and explicit limitations.
  • D-02: Add CGO-disabled CI test, vet, and dual-architecture build definitions. Remote CI execution is not claimed.
  • D-03: Pass the final complete local Go test suite and go vet.
  • D-04: Cross-compile both Lambda architectures and verify static ELF files and executable ZIP entries.
  • D-05: Run the local example and record concrete validation evidence.
  • D-06: Deploy a disposable Lambda stack and verify CloudWatch logs and X-Ray traces. Evidence: 20 invocations, 206 scoped acceptance assertions, both backends and architectures in ap-east-1; AWS_VALIDATION.md. Temporary stack and bucket were deleted after evidence collection.
  • D-06a: Run local Docker Lambda RIE, OTLP, EMF, Parameters, and Commons/Metadata acceptance with an isolated network, synthetic credentials, and cleanup. Evidence: five amd64 invocations and 100 passing assertions; LOCAL_VALIDATION.md. Cross-compile arm64 without claiming local arm64 execution.
  • D-PUBLIC-CLEAN: Apply repository ignore rules, require explicit cloud test configuration, sanitize acceptance summaries and verify that module archives exclude private content. See PUBLICATION.md.
  • D-LICENSE: License original contributions under MIT, preserve pinned Powertools MIT-0 and Unicode/OpenTelemetry terms, and distribute self-contained LICENSE/NOTICE files in every module. Verify all 31 archives, 29 direct Go and 19 direct npm inventory entries, canonical notice synchronization and missing-license rejection (2026-09-26). CI checks synchronization. Binary-specific transitive notices remain a release responsibility; see third-party provenance.
  • D-TOOLING-REVIEW: Remove the one-time historical cloud report generator, retain nine maintained Python tools, remove stale executable references and refresh the local acceptance overview. Verify Python syntax, the upload/staging inventory and the integration archive without rerunning Go/Lambda tests (2026-09-27). See PUBLICATION.md.
  • D-NAMESPACE: Migrate all 31 module declarations, imports, requirements, workspace mappings and tooling to github.com/rambow-cloud/powertools-lambda-go; update usage documentation. Verify all 31 packaged modules and 28 independent public consumers, and audit tested source, upload candidates, existing staged files, ignored archive content and notices (2026-09-27). See PUBLICATION.md.
  • D-NAMESPACE-VERIFY: Complete integration-module tests/vet across the accepted checkpoints. Rebuild the basic Lambda example for Linux amd64/arm64 with CGO disabled; verify static ELF/build metadata and executable bootstrap ZIP entries. Combined checkpoints cover 31 modules and 28 independent consumers (2026-09-27). The full RIE/streaming suite was not rerun. See MODULE_ACCEPTANCE_MIGRATION.json.
  • D-PUBLIC-CONTENT: Remove personal repository identities and local execution metadata from public documentation and historical reports; preserve module directories, test counts and compatibility limitations. Extend ignore rules for local authentication and recovery files; verify public candidates, staged metadata and all module archives without rerunning runtime tests (2026-09-27).
  • D-07: Complete performance measurements, license/provenance review, public module identity, and release packaging.
  • D-07a: Assess Signer priority/reverse dependencies and optional utility publication against the pinned 14 public manifests and official Go module guidance. See SIGNER_PLAN.md and PUBLISHING_PLAN.md. Signer is subsequently implemented under S-IMPL; publication remains open. The original module split is tracked under D-07b.
  • D-07b: Split nine public and three development Go modules with independent dependency files/version entries, workspace-only development mappings, and preserved import paths/invocation identity. Verify all 12 packaged modules with GOWORK=off (tests, vet, tidy consistency), nine standalone consumer builds and dependency boundaries, both Linux architectures, and 100 Docker assertions. Evidence: MODULE_ACCEPTANCE.json, MODULES.md, and LOCAL_ACCEPTANCE.json. Internal proxy versions are synthetic local fixtures; no public release is claimed.

Race-detector execution is intentionally excluded because CGO must remain disabled. Functional concurrency coverage does not establish race-detector equivalence. Local cross-compilation is the standard build workflow.

Documentation site and GitHub Actions

  • DOC-01: Build an English MkDocs Material site with search, light/dark themes, utility navigation, a native Lambda quickstart, and dedicated Logger/OTel Tracer guides. Reuse existing guides and include the maintained Go example directly. Strict navigation/link/anchor/snippet validation passed (2026-09-30).
  • DOC-02: Isolate documentation dependencies in website/pyproject.toml and website/uv.lock; verify lock consistency and keep generated HTML, virtual environments, and caches ignored.
  • CI-01: Configure packaged multi-module verification, license checks, CGO-disabled Linux amd64/arm64 cross-compilation, static ELF/ZIP validation, and scoped verification artifacts. Validate both workflow files with actionlint v1.7.12. This records configuration validation, not a new remote Go CI run.
  • CI-02: Pin all seven Actions to the full commit of the latest official stable release checked on 2026-09-30, and configure weekly Dependabot Actions updates.
  • DOC-03: Configure PR documentation builds and main-only Pages deployment with deployment-scoped permissions. Enable GitHub Pages with build_type=workflow for rambow-cloud/powertools-lambda-go (2026-09-30).
  • DOC-04: Push the reviewed initial source, verify the first remote Go CI and Documentation runs, and inspect the published site's navigation, search, themes, and source links in a browser. Local build success does not establish deployment success.

  • DOC-05: Replace the stock tabbed theme with a developer-guide layout informed by the TypeScript site's public theme: light header, organization bar, persistent utility tree, breadcrumbs, right-hand contents, and coordinated typography/code/table styles. Preserve built-in search, palette, drawer, and copy behavior. Strict build passed for all 66 Markdown pages (2026-09-30).

  • DOC-06: Review the default modern theme's homepage, Logger, and quickstart in a browser at desktop and 390px mobile widths, including title permalinks, edit actions, light/dark mode, search, drawer navigation, keyboard focus, and code copying. The prior custom layout was replaced under DOC-11. No browser-based visual acceptance is claimed by the local build.

  • DOC-07: Remove inherited inline-layout offsets and clipping from the header repository label, and prevent icon/label shrinking in its flex layout. Strict documentation build passed; browser confirmation remains part of DOC-06 (2026-09-30).

  • DOC-08: Generate and store the project PNG logo, record its prompt and provenance, and replace the header, navigation drawer, and favicon icons. Verify strict build, root/nested asset URLs, both image placements, and byte-identical asset copying (2026-09-30). Browser visual acceptance remains part of DOC-06.

  • DOC-09: Replace the earlier G symbol with the user-selected ram/cloud identity plus an adapted Go Gopher. Save a full wordmark and compact emblem, update header/drawer/favicon references, and preserve Renee French / CC BY 4.0 attribution and modification notes. Verify transparency, strict build, both page depths, footer credits, and copied asset hashes (2026-09-30). Browser visual acceptance remains part of DOC-06.

  • DOC-10: Migrate the documentation builder to pinned Zensical 0.0.67 with its classic theme; preserve configuration, page paths, project overrides, CSS, artwork, and maintained Go snippet. Update local/CI commands and replace unsupported navigation validation with a separate coverage/target check. Verify the dependency lock, clean strict build of all 66 Markdown pages, missing/duplicate/omitted navigation rejection, broken-anchor and missing-snippet rejection, rendered snippet content after Markdown tab expansion, and byte-identical artwork/CSS copying (2026-10-01). Browser visual acceptance remains part of DOC-06; no remote deployment is claimed.

  • DOC-11: Replace the customized classic theme with Zensical's default modern theme, fonts, icons, and palette toggle; remove the old CSS and template overrides. Preserve navigation, logo/favicon, edit links, and Markdown features. Navigation coverage, a clean strict build of all 66 Markdown pages, and generated homepage/Logger/quickstart checks without the former styling/overrides passed (2026-10-01). Browser visual acceptance remains part of DOC-06.

  • D-PREUPLOAD-REVIEW: Review 657 candidate files and 32 existing index blobs; classify all 350 Gitleaks matches as synthetic fixture data or an artifact hash. Verify ignored/generated boundaries, example account/email values, logo metadata, and the updated root module archive (2026-09-30). Record the incomplete/outdated index separately in PUBLICATION.md; no staging, commit, push, Go suite, or AWS operation was performed.

  • D-STAGING-REVIEW: Replace the old partial index with all 657 reviewed public files and verify staged paths/content against the working tree and privacy-review inventory (2026-09-30). Retain all 64 synthetic testdata files and maintained generators; exclude ignored/private/generated content. Preserve upstream Unicode comment whitespace and recognize CRLF line endings during whitespace review. Back up the original index privately. No commit, push, Go suite, or AWS operation was performed. See PUBLICATION.md.