KCAE.CHANGE:4.3 - Publish and read one coherent generation
In a single store with a transaction that covers all relevant data, use that store’s actual transaction and isolation semantics. In a composition of object storage, a lexical database and a vector service, a metadata manifest is not a transaction over those stores. Obtain a different publication construction.
One workable construction uses immutable generation-specific objects and namespaces. Build and durably store all objects needed for a declared route; validate their resolvability; then atomically change a small catalogue pointer to the new manifest using a store that actually supports that operation. Readers acquire the pointer once and pass its generation through search, open and pagination. They can see the complete old generation or the complete new one; they must not independently fetch “latest” at every step. This claim depends on immutable names, durable objects, an atomic pointer operation and preserved objects during a read. Test these assumptions in the chosen stores.
Use an expected previous pointer or equivalent compare-and-swap when concurrent publishers are possible. A publisher that loses the race must reconcile its source basis; blindly installing its older candidate can regress currency. Preserve old objects while readers still hold them, through bounded read leases, reference tracking or a declared retention interval with an explicit expiry response. Garbage collection must not silently break an in-flight read.
If those facilities are unavailable, a maintenance interval with unavailable service during installation is a legitimate simpler construction. State that availability tradeoff. Do not claim atomic continuous service merely because the individual store updates usually finish quickly.