<?xml version='1.0' encoding='utf-8'?>
<?xml-model href="rfc7991bis.rnc"?>
<!DOCTYPE rfc [
<!ENTITY RFC1930 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.1930.xml">
<!ENTITY RFC2119 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.2119.xml">
<!ENTITY RFC3339 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.3339.xml">
<!ENTITY RFC3986 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.3986.xml">
<!ENTITY RFC8126 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8126.xml">
<!ENTITY RFC6707 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.6707.xml">
<!ENTITY RFC8259 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8259.xml">
<!ENTITY RFC8006 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8006.xml">
<!ENTITY RFC8007 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8007.xml">
<!ENTITY RFC7336 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.7336.xml">
<!ENTITY RFC7337 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.7337.xml">
<!ENTITY RFC7736 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.7736.xml">
<!ENTITY RFC7975 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.7975.xml">
<!ENTITY RFC8174 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8174.xml">
<!ENTITY RFC8216 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8216.xml">
<!ENTITY RFC9110 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.9110.xml">
<!ENTITY RFC9112 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.9112.xml">
<!ENTITY RFC9325 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.9325.xml">
<!ENTITY RFC9388 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.9388.xml">
<!ENTITY RFC9562 SYSTEM "https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.9562.xml">
]>
<rfc category="std" submissionType="IETF" docName="draft-ietf-cdni-ci-triggers-rfc8007bis-20" obsoletes='8007' ipr="trust200902">
   <?rfc strict="yes"?>
   <?rfc compact="yes"?>
   <?rfc subcompact="no"?>
   <?rfc symrefs="yes"?>
   <?rfc sortrefs="yes"?>
   <?rfc tocdepth="4"?>
   <?rfc text-list-symbols="o*+-"?>
   <?rfc toc="yes"?>
   <front>
   <title abbrev="CDN Interconnect Triggers">Content Delivery Network Interconnection (CDNI) Control Interface / Triggers 2nd Edition</title>

    <author fullname="Nir B. Sopher" initials="N.B." surname="Sopher">
      <organization>Qwilt</organization>

      <address>
        <postal>
          <street>6, Ha'harash</street>

          <city>Hod HaSharon</city>

          <region></region>

          <code>4524079</code>

          <country>Israel</country>
        </postal>

        <phone></phone>

        <email>nir@apache.org</email>
      </address>
    </author>

   <author fullname="Ori Finkelman" initials="O." surname="Finkelman">
      <organization>Qwilt</organization>


      <address>
        <postal>
          <street>6, Ha'harash</street>

          <city>Hod HaSharon</city>

          <region></region>

          <code>4524079</code>

          <country>Israel</country>
        </postal>

        <phone></phone>

        <email>ori.finkelman.ietf@gmail.com</email>
      </address>
    </author>

    <author fullname="Sanjay Mishra" initials="S." surname="Mishra">
      <organization>Verizon</organization>

      <address>
        <postal>
          <street>13100 Columbia Pike</street>

          <city>Silver Spring</city>

          <region>MD</region>

          <code>20904</code>

          <country>USA</country>
        </postal>

        <phone></phone>

        <email>sanjay.mishra@verizon.com</email>
      </address>
    </author>

    <author fullname="Jay K. Robertson" initials="J.K." surname="Robertson">
      <organization>Qwilt</organization>

      <address>
        <postal>
          <street>275 Shoreline Dr Ste 510</street>

          <city>Redwood City</city>

          <region>CA</region>

          <code>94065</code>

          <country>USA</country>
        </postal>

        <phone></phone>

        <email>jayrobertson@acm.org</email>
      </address>
    </author>

    <author fullname="Alan Arolovitch" initials="A." surname="Arolovitch">
      <organization>2you.io</organization>

      <address>
        <postal>
          <street>1295 Beacon Street Unit 249</street>

          <city>Brookline</city>

          <region>MA</region>

     <code>02446</code>

          <country>USA</country>
        </postal>

        <phone></phone>

        <email>alan.arolovitch@gmail.com</email>
      </address>
    </author>
   <date/>
   <abstract><t>
   This document obsoletes RFC8007. The document describes the part of Content Delivery Network
   Interconnection (CDNI) Control interface that allows a CDN to trigger activity in an interconnected CDN 
   that is configured to deliver content on its behalf. 
   The upstream CDN MAY use this mechanism to request that the downstream CDN preposition, invalidate, and/or purge 
   metadata and/or content. 
   The upstream CDN MAY monitor the status of activity that it has triggered in the downstream CDN.</t>

   </abstract>
   </front>

   <middle>
   <section title="Introduction" anchor="introduction"><t>
   <xref target="RFC6707"/> introduces the problem scope for Content Delivery Network
   Interconnection (CDNI) and lists the four categories of interfaces
   that may be used to compose a CDNI solution (Control, Metadata,
   Request Routing, and Logging).</t>

   <t>
   <xref target="RFC7336"/> expands on the information provided in <xref target="RFC6707"/> and
   describes each of the interfaces and the relationships between them
   in more detail.</t>

   <t>
   The CDNI Control Interface / Triggers 1st edition <xref target="RFC8007"/>, deprecated by this document, 
   describes the "CI/T" interface -- "CDNI Control Interface / Triggers". It does not consider those parts of the
   Control interface that relate to the configuration, bootstrapping, or
   authentication of CDN Interconnect interfaces. Section 4 of
   <xref target="RFC7337"/> identifies the requirements specific to the CI/T interface;
   requirements applicable to the CI/T interface are CI-1 to CI-6.</t>
   
   <t>
           This document is a second edition of the CDNI Control Interface / Triggers, 
           which defines a new version, "v2", of the interface objects. 
           The new version aims to support <xref target="REST">REST</xref> architectural style in a way that 
           improves the interface's flexibility, extensibility, and interoperability, and allows encoding 
           of the interface using OpenAPI <xref target="OpenAPI"/>.  
           The new objects replace the main CI/T objects as follows:
   </t>
   <list style="symbols">
           <t>The "ci-trigger-command" object and its matching "ci-trigger-status" object are replaced 
           with the "ci-trigger.v2" object representing a trigger resource</t>
           <t>The "ci-trigger-collection" object is replaced with the "ci-trigger-collection.v2" that is 
           expanded to support filtering by trigger state and trigger labels</t>
   </list>
   <t>
           The second edition of the CI/T interface further allows the use of separate Control interface endpoints for 
           content and metadata.
   </t>
   <t>
           The document also provides a trigger extension mechanism that MAY be used to provide further instruction
           on the trigger execution.
   </t>
   <t>
           This second edition also includes cascaded CDN error propagation and extended trigger status reporting 
           for improved trigger execution monitoring, as well as the use of external object lists for improved scale and 
           integration of trigger-based APIs with existing content workflows.
   </t>


   <t><list style="symbols"><t><xref target="model-for-cdni-triggers"/> outlines the model for the CI/T interface at a high
      level.</t>
      
   <t><xref target="cdni-trigger-interface"/> defines the CI/T interface offered by the downstream CDN.</t>

   <t><xref target="cit-objects-properties-and-encoding"/> defines the encoding of the standard CI/T objects and 
           introduces trigger spec and trigger extension types.</t>

   <t><xref target="footprint-and-capabilities"/> describes the FCI capabilities objects used to inform on the supported
           CI/T-related capabilities.</t>

   <t><xref target="examples"/> contains example messages.</t>

   </list>
   </t>

   <section title="Terminology" anchor="terminology"><t>
   This document reuses the terminology defined in <xref target="RFC6707"/> and uses
   "uCDN" and "dCDN" as shorthand for "upstream CDN" and "downstream CDN", respectively.</t>
   <t>This document also introduces additional terminology extending <xref target="RFC6707"/>, defined as follows:</t>

   <t>
   Node: A Node is a device or function participating in content delivery within a Content Delivery Network (CDN). 
   A Node extends the Surrogate defined in <xref target="RFC6707"/>, by additionally allowing requests originating from other Nodes, 
   performed to satisfy requests ultimately initiated by User Agents. A Node therefore includes cache systems operating at any position 
   within a CDN delivery topology, regardless of whether they directly receive requests from User Agents.
   </t>
   <t>
   Terminal State: A trigger state indicating that processing of the trigger has concluded and no further execution progress is expected.
   Terminal States are "complete", "processed", "failed", and "cancelled".
   </t>
   <t> 
   Transit CDN (tCDN): A CDN that receives a CI/T trigger from an upstream CDN and forwards (redistributes) it to one or more downstream 
   CDNs as part of a cascaded CDN deployment.
   </t>
   <t>
      The keywords "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL
      NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED",
      "MAY", and "OPTIONAL" in this document are to be interpreted as
      described in BCP 14 <xref target="RFC2119"></xref> 
      <xref target="RFC8174"></xref> when, and only when, they
      appear in all capitals, as shown here.</t>

   </section>

   </section>

   <section title="Model for CDNI Triggers" anchor="model-for-cdni-triggers">
   <section title="REST Architecture" anchor="model-for-cdni-triggers-rest">

        <t>
        The CI/T interface utilizes the HTTP/1.1 protocol <xref target="RFC9112"/> and follows the principles 
        of the Representational State Transfer (REST) architectural style.
        The uCDN, in its capacity as a CI/T interface client, requests the dCDN to carry out an action ("trigger")
        related to metadata and/or content stored by the dCDN on behalf of the uCDN.  
        </t>
        <t>
        The dCDN, as a CI/T interface server,  governs the triggers as a set of resources, which can be dynamically created 
        and deleted, and whose state can be retrieved and/or modified by the uCDN.  
        Each such trigger is identified by a unique Uniform Resource Identifier (URI) 
        as defined in Section 4.2 of <xref target="RFC9110"/>.
        </t>

        <t>
        Once a trigger is created, the uCDN can retrieve its representation from the dCDN or request the trigger to be modified by 
        transferring an updated representation of it to the dCDN.
        The CI/T interface supports the representation of trigger resources using JSON <xref target="RFC8259"/>.
        </t>
        <t>
        This RESTful data model, built around a common "trigger" resource, replaces the command-oriented model 
        of <xref target="RFC8007"/>, wherein the uCDN passed commands to the dCDN using "ci-trigger-command" objects, 
        and the dCDN generated "ci-trigger-status" objects in response.  
        </t>


   </section>

   <section title="HTTP Methods" anchor="model-for-cdni-triggers-http-methods">
        <t>
        Section 9.3 of <xref target="RFC9110"/> defines the set of methods in HTTP. 
        The CI/T interface uses some of these methods for resource creation, retrieval of resource state, modification 
        of resources, and deletion of resources. 
        The HTTP methods not listed here are not supported by the CI/T interface.
        </t>

        <list style="symbols">
                <t>     
                        GET - retrieves a representation of the target resource. 
                        GET is a "safe" method: it is not intended to cause state changes on the server.
                </t>
                <t>
                        POST - requests that the target resource process the representation enclosed in the request. 
                        When processing results in the creation of a new resource, the server responds with 201 ("Created") 
                        and a Location header field containing the URI of the newly created resource.
                </t>
                <t>        
                        DELETE - requests removal of the target resource.
                </t>
                <t>        
                        HEAD - identical to GET, except that the server MUST NOT return a message body. 
                        HEAD is used to inspect response metadata (e.g., to verify resource existence, or to check Last-Modified, 
                        ETag, or Content-Length headers) without transferring the representation.
                </t>
        </list>
   </section>

   <section title="Trigger" anchor="model-for-cdni-triggers-trigger">
        <t>
                The uCDN requests creation of a trigger resource to instruct the dCDN to perform an action.
                If the dCDN accepts the request, it creates a new trigger resource and returns its unique URI to the uCDN.
                The uCDN MUST use this URI for all requests associated with the created trigger resource.
        </t>
        <t> 
                Note that the version of the trigger resources that the uCDN requests to create MUST match the version 
                of CI/T trigger objects reported as supported by the dCDN. 
        </t>

        <t>     The CI/T interface supports the following types of trigger action:</t>

        <t>
                <list style="symbols">
                <t>preposition - used to instruct the dCDN to fetch metadata from the uCDN or content from any origin, including the uCDN.</t>
                <t>invalidate - used to instruct the dCDN to revalidate specific metadata and/or content before its next use.</t>
                <t>purge - used to instruct the dCDN to delete specific metadata and/or content.</t>
                   </list>
        </t>
        <t>Note that additional action types can be defined and registered in the future. </t>

        <t>
                The trigger resource has a "state" attribute.  
                The dCDN creates new triggers in the "pending" state. Once the dCDN starts processing a pending trigger, the trigger 
                state is set to "active". 
                The uCDN MAY explicitly request the trigger to be created in the "active" state. If accepted by the dCDN, it MAY create
                the new trigger in the "active" state and start its processing immediately upon creation.
                Once the trigger processing is complete, the state is set to either "complete" or "failed", 
                depending on the processing outcome.
        </t>
        <t>
                The uCDN MAY request the cancellation of a trigger from the dCDN.
                If such a request is accepted, the trigger state is changed to 
                "cancelling", and when the cancellation is complete, the trigger state changes to "cancelled".
        </t>        
        <t>         
                For a full description of the trigger resource, please refer to <xref target="ci-trigger-resource"/>.
        </t>

   </section>
   <section title="Trigger Access Control and Multi-Tenancy" anchor="model-for-cdni-triggers-trigger-access-control">
        <t>     The dCDN MUST only allow the uCDN access to the trigger resources it created. </t>
        <t>     The dCDN MUST ensure that triggers created in response to a uCDN request apply only to content and metadata objects associated with that uCDN.</t>
        <t>     
                In case of content prepositioning, the dCDN MUST be able to associate content objects referenced in a trigger 
                created by the uCDN with delivery CDNI metadata objects in its possession that are associated with the same uCDN.
                These CDNI metadata objects include HostIndex, HostMatch, HostMetadata, PathMatch, PatternMatch, and
                PathMetadata, as described in Section 3.1 of <xref target="RFC8006"/>.
                For example, if the dCDN has no MI metadata objects that enable the dCDN to respond to requests for 
                video.example.com, it MUST NOT allow prepositioning of content objects with this hostname in the object URL.
        </t>
        <t>
        In case of metadata prepositioning, the prepositioned metadata objects MUST be consistent with pre-existing metadata, 
        e.g., prepositioning of the MI HostMatch object in the absence of MI HostIndex would be rejected.
        </t>
        <t>
                If such association between a trigger and pre-existing delivery metadata cannot be established, 
                the dCDN MUST reject it by responding with 400 ("Bad Request") HTTP status code.
        </t>
        <t>
        Furthermore, the dCDN SHOULD similarly reject a trigger from the uCDN A that seeks to
        preposition delivery metadata objects that are in conflict with the
        pre-existing metadata objects belonging to another uCDN B, e.g., if it
        could cause the dCDN to match a content request with metadata objects from
        multiple uCDNs.
        </t>
   </section>
   <section title="Trigger Index and Trigger Collections" anchor="model-trigger-index-trigger-collections">
   <t>
   The Trigger Index is the top-level resource that references all trigger resources belonging to a particular uCDN.  
   The dCDN MUST maintain one Trigger Index resource for each uCDN, and MUST enforce that each uCDN has access only to its own Trigger Index.  

   The Trigger Index contains references to Trigger Collection resources.  
   Each collection contains triggers that are optionally filtered by parameters - for example, all triggers in the 
   "pending" state  or all triggers labeled "video". The same trigger resource can be present in more than one collection.
   The supported trigger collection representations are listed in 
   <xref target="ci-trigger-collection-resource"/> and include filtering of triggers by state and label.
   The dCDN selects which filtered collections it publishes, as described in <xref target="ci-trigger-collection-resource"/>.
   Note that additional trigger collection representations can be defined in the future. 
   </t>
   </section>
   <section title="Session Overview" anchor="model-for-cdni-triggers-session-overview">

           <t>
                Figure 1 is an example showing the basic message flow in a CI/T interface session used by the
                uCDN to trigger activity in the dCDN and for the uCDN to discover the status of that activity. 
                Only successful triggering is shown.
                Please note that the example below uses simplified trigger identifiers for brevity. 
                It is RECOMMENDED that the actual implementations use unique UUID identifiers as specified 
                in <xref target="RFC9562"/>.
                Examples of the messages are shown in <xref target="examples"/>.
        </t>

           <figure title="Basic CDNI Message Flow for Triggers" anchor="ure-basic-cdni-message-flow-for-triggers">
   <artwork><![CDATA[
   uCDN                                                   dCDN
    |  (1) POST https://dcdn.example/cit/uCDN               |
   [ ] --------------------------------------------------> [ ]--+
    |                                                      [ ]  | (2)
    |  (3) HTTP 201 Response                               [ ]<-+
   [ ] <-------------------------------------------------- [ ]
    |     Loc: https://dcdn.example/cit/uCDN/123            |
    |                                                       |
    .                           .                           .
    .                           .                           .
    .                           .                           .
    |                                                       |
    | (4) GET https://dcdn.example/cit/uCDN/123             |
   [ ] --------------------------------------------------> [ ]
    |                                                      [ ]
    | (5) HTTP 200 Trigger resource representation         [ ]
   [ ] <-------------------------------------------------- [ ]
    |                                                       |
    |                                                       |
    | (6) DELETE https://dcdn.example/cit/uCDN/123          |
   [ ] --------------------------------------------------> [ ]--+
    |                                                      [ ]  | (7)
    | (8) HTTP 204 No Content                              [ ]<--
   [ ] <-------------------------------------------------- [ ]
    |                                                       |
]]></artwork>
   </figure>
   <t>         The steps in Figure 1 are as follows:</t>

   <t>
   <list style="numbers">
        <t>        
                The uCDN requests creation of a new trigger resource by POSTing its representation to
                the trigger index resource with a well-known URI "https://dcdn.example/cit/uCDN".
        </t>
        <t>
                The dCDN authenticates the request, validates the trigger resource in it, and if the request is accepted,
                creates a new trigger resource.
        </t>
        <t>
                The dCDN responds to the uCDN with an HTTP 201 ("Created") response status and the location of the trigger resource.
        </t>

        <t>
                The uCDN MAY query, possibly repeatedly, the trigger resource in the dCDN.
        </t>

        <t>
                The dCDN responds to each query with the current trigger resource representation, including the trigger state
                that reflects the progress of the uCDN request.
        </t>
        <t>
                Once the trigger reaches a terminal state, the uCDN MAY request deletion of the trigger resource. 
        </t>
        <t>
                The dCDN validates the request and the trigger resource state. 
                If successful, the trigger resource is removed by the server,
                and subsequent requests for this resource MUST result in 404 ("Not Found").
        </t>
        <t>
                The dCDN responds to the deletion request with a 204 ("No Content") status code.
        </t>
   </list>
   </t>
   <t>
        This section provides an overview of a regular session. For detailed discussions of trigger modification, 
        cancellation, and deletion, see <xref target="modifying-triggers"/>, <xref target="cancelling-triggers"/>, 
        and <xref target="deleting-triggers"/>.
   </t>
   </section>

   <section title="Trigger Processing" anchor="trigger-processing">
   <section title="Timing and Order" anchor="timing-of-trigger-processing">
   <t>
        The uCDN MAY place limits on the timing and order of execution of a trigger through optional 
        <xref target="time-policy">TimePolicy</xref> and/or <xref target="execution-policy">ExecutionPolicy</xref> 
        extensions. 
        If neither of these extensions are present in the trigger resource, the timing and order 
        of the trigger execution is under the dCDN's control, including the start time, pacing 
        of the activity in the network, and order in which the dCDN chooses to process pending triggers.
   </t>        
   <t>
        The CI/T "invalidate" and "purge" trigger actions MUST be applied to all data acquired before the dCDN begins 
        the trigger processing (i.e., enters "active" state).
        The dCDN implementation SHOULD apply "invalidate" and "purge" triggers to content acquisition that is in progress 
        when the trigger becomes active, to avoid placing purged or invalidated content into the cache upon completion 
        of the content acquisition.
        The dCDN SHOULD NOT apply CI/T "invalidate" and "purge" actions to data acquired after the trigger processing started, 
        but this may not always be achievable, so the uCDN SHOULD NOT rely on it.
   </t>

   <t>
        If the uCDN wishes to invalidate or purge content and then immediately preposition replacement content at the same URLs, 
        it SHOULD ensure that the dCDN has processed the invalidate/purge before initiating the prepositioning. 
        Otherwise, there is a risk that the dCDN prepositions the new content, then immediately invalidates or
        purges it (as a result of the two uCDN requests running in parallel).
        
        The uCDN MAY use the <xref target="execution-policy">Execution Policy</xref> extension to condition the start 
        of preposition trigger processing on completion of the earlier invalidate/purge trigger(s).
   </t>

   </section>

   <section title="Scope" anchor="scope-of-trigger-processing">
   <t>
        Each trigger can operate on multiple metadata and/or content elements. 
        These elements are targeted by specifying
        both their subject (i.e., "metadata" or "content") as well as specification 
        method (e.g., URL Regexes) and value.
   </t>

   <t>
        Multiple representations of an HTTP resource may share the same URL.
        Triggers that invalidate or purge metadata and/or content apply to all resource representations with matching URLs.
   </t>

   </section>
   <section title="Results" anchor="results-of-trigger-processing">
   <t>
         Possible trigger states are defined in <xref target="trigger-state"/>.
   </t>

   <t> 
        Trigger state MUST NOT be reported as "complete" until all operations listed in the trigger have been 
        completed successfully. In case of CDN cascading, the completion of operations includes processing of the trigger
        in downstream CDNs. For detailed discussion of the cascading use case, see <xref target="multiple-interconnected-cdns"/>.
        The reasons for failure, and URLs or patterns affected, SHOULD be made available 
        in the trigger state representation.  For more details about error handling, see <xref target="error-handling"/>.
   </t>
   </section>
   </section>
   <section anchor="trigger-extensibility" title="Trigger Extensibility">
   <t>
        The CDNI Control Interface / Triggers 1st edition <xref target="RFC8007"/> defines a set of properties
        and objects used by the trigger commands. This 2nd edition defines an extension mechanism
        to the triggers interface that enables applications to add instructions for 
        finer control over the trigger execution, for example indicating a time window in which to execute the trigger. 
        This document specifies a generic trigger extension object wrapper for managing CDNI trigger extensions in a uniform manner.
   </t>
   <t>
           All trigger extensions are OPTIONAL, and it is thus the responsibility of the extension specification to 
           define a consistent default behavior for the case the extension is not present.
   </t>
  
   <t>
           All trigger extensions MUST have their type registered in the IANA "CDNI CI/T Trigger Extension Types" registry 
           (see <xref target="IANA.CDNI.TriggerExtensionTypeReg"/>).
   </t>

   <t>
           This document also defines an initial set of trigger extension types and registers them in the 
           IANA "CDNI CI/T Trigger Extension Types" registry:
   </t>
      
   <texttable style="full"><ttcol align="left">JSON string</ttcol>
   <ttcol align="left"> Description</ttcol>
   <c>location-policy</c>
   <c>Allowing the control over the locations in which the trigger is executed.</c>
   <c>time-policy</c>
   <c>Allowing the scheduling of a trigger to run in a specific time window.</c>
   <c>execution-policy</c>
   <c>Allowing the control over the order and timing in which triggers are executed.</c>

   </texttable>

   </section>


   <section title="Multiple Interconnected CDNs" anchor="multiple-interconnected-cdns">
        <t>
                   In a network of interconnected CDNs, a uCDN distributes a trigger referencing metadata and/or content items to 
                   one or more dCDNs. When a dCDN further distributes the trigger to downstream dCDNs, it acts in the capacity 
                   of a Transit CDN (tCDN).
        </t>

           <t>
                   The dCDN that creates trigger resources at the request of a transit CDN
                   MUST associate the triggers with the transit CDN from which it receives the request,
                   regardless of where the trigger request may have originated.
           </t>
           <t>
                If the dCDN is also acting as the uCDN in a cascade, it MUST forward trigger requests to any dCDNs 
                that may be affected. 
                The trigger state MUST NOT be reported as "complete" by a transit CDN until it is "complete" 
                in all of its dCDNs and in the transit CDN itself.
                If a trigger is reported as "processed" in the transit CDN or any one of its dCDNs, transit CDNs 
                MUST report the trigger as "processed" as well. 
                If a trigger is reported as "failed" by the transit CDN or any one of its dCDNs, the transit
                CDN MUST report the trigger as "failed" only after its processing is finished in it and  all of its dCDNs.
                A cancelled trigger MUST be reported as "cancelling" until it has been reported as "cancelled",
                "complete", or "failed" by all cascaded dCDNs.
           </t>
           <t>     Security considerations are discussed further in <xref target="security-considerations"/>.</t>
        <section title="Diamond Configurations" anchor="diamond-configurations">
           <t>
                   A "diamond" configuration is one where the dCDN can potentially acquire metadata
                   and content originated in one uCDN from that uCDN itself and a
                   transit CDN, or via more than one transit CDN.
           </t>
           <t>
                   The "diamond" configuration may cause configuration consistency problems, where
                   the dCDN may end up in possession of multiple, potentially conflicting metadata objects belonging 
                   to the multiple uCDNs that match the same content request.
                   The conflict may arise due to the differences in trigger processing by the transit CDNs 
                   and/or variances in trigger propagation delay across different paths in the "diamond" topology.
           </t>
           <t>
                   Because of this, the "diamond" configuration is considered a configuration error.
                   A dCDN that receives identical trigger creation requests from different uCDNs 
                   SHOULD reject duplicate trigger requests, as described in <xref target="model-for-cdni-triggers-trigger-access-control"/>.
           </t>
   
        </section>

   <section title="Loop Detection and Prevention" anchor="loop-detection-and-prevention">
   <t>
   Given three CDNs, A, B, and C, if CDNs B and C delegate delivery of CDN A's content to each other, 
   CDN A's trigger creation requests could be passed between CDNs B and C in a loop. 
   More complex networks of CDNs could contain similar loops involving more hops.
   </t>

   <t>
   When such CDN topologies become possible, it is RECOMMENDED that CDNs participating in it utilize a
   <xref target="cdn-pid">CDN Provider ID (PID)</xref> to detect and prevent loops as follows:
   <list style="symbols">
   <t>
   The uCDNs that originate a new trigger request SHOULD specify their CDN PID using the
   trigger "cdn-path" attribute (see <xref target="ci-trigger-resource"/> for details).
   </t>
   <t>
   A dCDN that receives a trigger creation request that contains a "cdn-path" attribute SHOULD check it for its own CDN PID.
   If the dCDN's PID is already present, and the dCDN is not the CDN initiating the trigger, this condition likely indicates a loop.
   In such case, the dCDN MUST reject the trigger with status code 400 ("Bad Request"), which would result in a trigger rejection being returned to the 
   originating uCDN. If the dCDN receives a trigger that it itself originated, the dCDN MAY process the trigger as required.
   </t>
   <t>
   A dCDN that acts as a transit CDN by cascading trigger requests to additional dCDNs SHOULD NOT reject
   triggers that contain CDN PIDs matching any of its downstream CDNs in their CDN path, allowing each CDN to do its own loop detection.
   </t>
   <t>
   Transit CDNs MUST append their CDN PID to the CDN path of a trigger before sending it to its downstream CDNs.
   </t>
   <t>
   The dCDNs SHOULD advertise their CDN PID to the uCDNs using the "cdn-id" attribute of the 
   <xref target="ci-trigger-index-resource">trigger index</xref> resource.
   </t>

   </list>
   </t>

   </section>
   </section>

   </section>
   <section title="CDNI Trigger Interface" anchor="cdni-trigger-interface">
   <t>
   This section describes an interface to enable the uCDN to trigger activity in the dCDN.
   </t>

   <t>
   The CI/T interface builds on top of HTTP, so the dCDNs MAY make use of any HTTP feature when implementing the CI/T Interface. 
   For example, the dCDN SHOULD make use of HTTP's caching mechanisms to reduce the uCDN's trigger status polling overhead by 
   indicating the modification status of a requested resource representation.
   </t>

   <t>
   The dCDNs MAY implement separate CI/T interfaces per <xref target="trigger-subject"/>,
   i.e., one CI/T interface for trigger operations on metadata and another for operations on content.
   In this case, the dCDN MUST advertise separate interface endpoints via 
   <xref target="cit-trigger-endpoints-capability-object"/>.
   </t>
   <t>
   All dCDNs implementing CI/T MUST support the HTTP GET, HEAD, POST, and DELETE methods as defined 
   in <xref target="RFC9110"/>.
   </t>

   <t>
   The only resource representation specified in this document is JSON <xref target="RFC8259"/>.
   It MUST be supported by both the uCDN and the dCDN.
   </t>
   <t>
   The CI/T interface uses a root URI for the retrieval of the trigger index resource and creation of new triggers.
   The mechanism for discovery of that URL is part of the CI/T interface bootstrapping and is outside the scope of this
   document.
   </t>
   <t>
   The uCDN requests to create a new trigger resource by POSTing its representation to the trigger index resource 
   URI, discovered at the time of interface bootstrapping, e.g., "https://dcdn.example/cit/ucdn/triggers".
   If the request is accepted by the dCDN, it creates a new trigger resource and returns its URI to the uCDN in an HTTP 
   201 ("Created") response. 
   </t>
   <t>
   Once created, the new trigger URI also becomes available via the trigger collection resources described in 
   <xref target="ci-trigger-collection-resource"/>.
   Additionally, the uCDN MAY discover the URIs of multiple trigger collection representations by retrieving the 
   trigger index resource, which is accessible at the interface root URI.

   This means that the URIs for all trigger resources and trigger collection representations can be discovered by the uCDN through
   the top-level trigger index resource, allowing dCDNs to use any URI structure they choose for CI/T resources.
   Therefore, uCDNs MUST NOT make any assumptions regarding the structure of CI/T URIs or the mapping between CI/T
   objects and their associated URIs. The URIs used in the examples in this document are purely illustrative and are not 
   intended to impose a definitive structure on CI/T interface implementations.
   </t>

   <section title="Creating Triggers" anchor="creating-triggers">
   <t>
   To create a new trigger, the uCDN makes an HTTP POST request with the trigger representation to the trigger index 
   resource URI.  The trigger representation MUST include the mandatory attributes of 
   <xref target="ci-trigger-resource">the trigger resource</xref>.
   </t>
   <t>
   The uCDN MAY also specify trigger v2 specification attributes, namely trigger labels and 
   trigger extensions, as well as the "cdn-path" attribute of the trigger resource. 
   </t>

   <t>
   The dCDN MUST validate the trigger resource representation sent by the uCDN. If the representation is malformed or the uCDN 
   does not have sufficient access rights, the dCDN MUST respond with an appropriate 4xx HTTP error code.
   </t>

   <t>
   The new trigger resource is created in a "pending" state. 
   If successful, The HTTP response to the uCDN trigger creation request MUST have status code 201 ("Created") 
   and MUST convey the URI of the newly created trigger resources in the Location response header field 
   <xref target="RFC9110"/>. 
   The HTTP response SHOULD include the updated representation of the trigger resource. 
   This is particularly important in cases where the dCDN processed the trigger immediately.
   </t>

   <t>
   Once a trigger resource has been created, the dCDN MUST NOT reuse its URI, even after the trigger resource has been 
   fully removed. 
   It is therefore RECOMMENDED that the dCDN utilize unique UUID identifiers as specified in <xref target="RFC9562"/>.
   </t>

   <t>
   The dCDN SHOULD respond with updated trigger resource representations to the subsequent uCDN requests sent to the created trigger URI.
   If the dCDN is unable to do that, it MUST indicate that it has accepted the request but will not be providing 
   further status updates, setting the trigger state to "processed" at creation time. 
   In this case, the dCDN SHOULD continue processing as if it were a request in the "complete" state.
   It is RECOMMENDED that the dCDN provide an estimate of trigger completion ("etime") when the trigger state is set to "processed".
   </t>

   <t>
   The uCDN MAY request the new trigger to be created in the "active" state so that its processing begins immediately.
   If agreed to by the dCDN, the dCDN MUST start the new trigger processing immediately.
   </t>
   <t>
   Otherwise, the dCDN MUST set the state of the new trigger to "pending".
   Once trigger processing has started, the status MUST be changed to "active". 
   Finally, once the trigger processing is complete, the trigger state MUST be set to "complete" or "failed".
   </t>

   <t>
   Once created, trigger resources can be cancelled, modified, or deleted by the uCDN, subject to the constraints 
   described below.
   </t>

   </section>

   <section title="Modifying Triggers" anchor="modifying-triggers">
   <t>
   Modification of existing triggers is useful for the uCDN to correct an error in trigger specification or 
   trigger extension(s) that may govern when the trigger is to be processed.
   </t>
   <t>
   The uCDN can request modification of an existing trigger resource by sending an updated trigger representation 
   to the trigger URI using HTTP POST command. 
   The POST method is used here to mutate an existing resource; no new resource is created.
   </t>
   <t>
   The dCDN MAY accept modifications of the trigger specifications, trigger extensions and trigger labels, 
   when the trigger is in a "pending" state, i.e., the dCDN hasn't started its processing yet.
   </t>
   <t>
   The dCDN MAY also accept a request to change the trigger state subject to the following constraints:
   <list style="symbols">
   <t>the requested state is "cancelled", and the trigger was in either "pending" or "active" state when the dCDN 
   receives the request</t>
   <t>the requested state is "active", and the trigger was in a "pending" state when dCDN received the request</t>
   </list>

   <xref target="cancelling-triggers"/> describes the processing of trigger cancellation requests in detail.
   The uCDN MAY request to set the trigger state to "active" to prompt the dCDN to re-examine the trigger resource and start 
   its processing immediately.
   </t>


   <t>
   The dCDN MUST respond to the trigger modification request appropriately.
   Thus, the HTTP status code 200 ("OK") SHOULD be returned if the modification has been processed, 202 ("Accepted") 
   if the command has been accepted but the modification is not fully complete yet, 404 ("Not Found") when the trigger 
   resource does not exist, 409 ("Conflict") when the trigger resource is in a state that doesn't allow the requested 
   modification, 501 ("Not Implemented") if the modification is not supported by the dCDN or an appropriate 4xx HTTP 
   error code in case of a malformed request.
   </t>
   <t>
   In case of successful 2xx response, the dCDN MUST provide the updated trigger resource representation in the response body.
   </t>

   </section>
   <section title="Cancelling Triggers" anchor="cancelling-triggers">
   <t>
   The uCDN MAY request cancellation of a trigger by requesting its state to be set to "cancelled", as described in
   <xref target="modifying-triggers"/>.
   The dCDN MUST respond to such requests, however, the actual cancellation of a trigger resource is OPTIONAL to implement.
   </t>

   <t>
   The dCDN MUST respond to the trigger cancellation request with an appropriate HTTP response status code as documented 
   in <xref target="modifying-triggers"/>
   </t>

   <t>
   If cancellation of a "pending" trigger is accepted by the dCDN, the dCDN SHOULD NOT start the processing of that activity.
   However, a uCDN's observation of the "pending" state does not guarantee that the trigger will still be "pending" when the
   cancellation request is processed by the dCDN; consequently, processing may still occur.
   </t>

   <t>
   If cancellation of an "active" or "processed" trigger is accepted by the dCDN, the dCDN SHOULD stop processing the trigger.
   However, as with the cancellation of a "pending" trigger, the dCDN does not guarantee that the trigger processing 
   doesn't run to completion in the meantime.
   </t>

   <t>
   If the dCDN cannot stop the trigger processing immediately after receiving the request from the uCDN to do so, it 
   MUST set the trigger state to "cancelling" and provide this state in the trigger representation in its response. 
   If the trigger processing is stopped before its normal completion, the trigger state MUST be set to "cancelled".
   </t>

   <t>
   Cancellation of a "complete", "failed" or "cancelled" trigger requires no processing in the dCDN. 
   Its state MUST NOT be changed.
   </t>

   </section>
   
   <section title="Checking Triggers' Status" anchor="checking-status">
   <t>
   The uCDN has two ways to check the progress of its triggers' processing, as described in 
   <xref target="polling-collections"/> and <xref target="polling-trigger-resources"/>.
   </t>

   <t>
   To enable the uCDN to use client-side caching of the trigger index resource, as well as all trigger and trigger 
   collection resources,  each resource representation sent by the dCDN SHOULD include at least one of the following 
   HTTP response headers: "ETag" or "Last-Modified".

   The dCDN SHOULD respond with the HTTP 304 ("Not Modified") status code and no response body for conditional 
   resource requests using the 'If-None-Match' and/or 'If-Modified-Since' headers, as specified in Section 13 
   of <xref target="RFC9110"/>, if it does not have a more recent resource representation.
   </t>
   <t>
   The dCDN SHOULD also use the cache control headers for responses to GET requests for its resources to indicate the
   frequency at which it recommends that the uCDN and/or intermediate proxies should poll for change.
   If provided, the uCDN should match the frequency of polling to the cache control information provided by the dCDN.
   </t>

   <section title="Polling Trigger Collections" anchor="polling-collections">
   <t>
   The uCDN MAY fetch the Trigger Collection that contains all of its triggers,  
   or one of the collections that filter triggers based on a parameter such as state or label.
   This makes it possible for the uCDN to poll the status of all trigger resources or selected trigger subsets.
   </t>
   <t>
   The set of filtered trigger collections is chosen by the dCDN, and the uCDN cannot request collections with other filters. 
   If the uCDN requires a subset of triggers for which the dCDN publishes no matching collection, the uCDN retrieves the narrowest 
   published collection containing that subset, or the unfiltered collection, and selects the relevant triggers itself using the 
   "state" and "labels" attributes of each trigger.
   </t>
   </section>

   <section title="Polling Triggers" anchor="polling-trigger-resources">
   <t>
   The dCDN provides the uCDN with a trigger resource URI at creation time. Alternatively, the uCDN MAY discover the URI 
   by retrieving the trigger index resource and the appropriate trigger collection referenced therein. The uCDN MAY obtain an 
   up-to-date representation of the trigger resource at any time using an HTTP GET request, including the current trigger state. 
   </t>
   </section>

   <section title="Extended representation" anchor="polling-collections-extended">
   <t>
   If the dCDN advertises support for extended status, the uCDN MAY request an
   extended representation of trigger resources and trigger collections.
   The extended representation provides additional information beyond the
   default resource representation.
   </t>
   <t>
   When applied to a trigger collection resource, the extended representation
   embeds full representations of trigger resources within the collection.
   This allows retrieval of complete trigger resource representations for a
   specific trigger state (e.g., all triggers in a "pending" state).
   </t>

   <t>
   When applied to an individual trigger resource, the extended representation
   includes the list of objects derived by the dCDN during trigger processing,
   in addition to the default trigger resource attributes.
   </t>

   <t>
   The uCDN MAY request the extended representation by passing the query string
   parameter "status=extended" when requesting either a trigger collection
   resource or a trigger resource. The dCDN SHOULD respond with HTTP status
   200 ("OK") when such a request can be satisfied, 501 ("Not Implemented")
   if the capability has not been implemented or advertised, and 400
   ("Bad Request") for a malformed query.
   </t>

   <t>
   By default, entries in a trigger collection represent trigger resources
   using only their resource URI, and individual trigger resources do not
   include derived object lists unless the extended representation is
   requested.
   </t>
   </section>

   </section>

   <section title="Deleting Triggers" anchor="deleting-triggers">
   <t>
   The uCDN MAY request the deletion of trigger resources at any time using the HTTP DELETE method, 
   as defined in the CDNI Control Interface / Triggers 1st edition <xref target="RFC8007"/>,
   </t>
   <t>
   Once deleted, the deleted trigger MUST be removed from all trigger collections.
   Subsequent requests to the trigger resource URI MUST be rejected by the dCDN with HTTP error 404 ("Not Found"). 
   </t>
   <t>
   The effect of deletion is similar to cancellation, except that the trigger resource becomes unavailable after 
   the deletion is complete. For this reason, the uCDN SHOULD cancel triggers rather than delete them when 
   it needs to access the trigger status after processing has terminated.
   </t>

   <t>
   If deletion of a "pending" trigger is accepted by the dCDN, the dCDN SHOULD NOT start processing that activity. 
   However, a uCDN's observation of the "pending" state does not guarantee that the trigger will still be "pending"
   when the deletion request is processed by the dCDN; consequently, processing may still occur.
   </t>

   <t>
   When an "active" or "processed" trigger is deleted, the dCDN SHOULD stop processing it.
   However, as with the deletion of a "pending" trigger, the dCDN does not guarantee this.
   </t>
   <t>
   Deletion of a "complete", "cancelled", "cancelling", or "failed" trigger MUST result in no further processing by the dCDN.
   </t>
   <t>
   The dCDN MUST respond to the trigger deletion request appropriately.
   The dCDN MUST respond with status code 204 ("No Content") without a response body if the trigger has been deleted immediately, 
   202 ("Accepted") if the command has been accepted but the trigger has not yet been deleted, 404 ("Not Found") if the 
   trigger resource does not exist, or 501 ("Not Implemented") if deletion is not supported by the dCDN.
   </t>

   <t>
   The trigger state MUST be set to "cancelling" while the dCDN is processing a deletion request asynchronously.
   </t>

           
   </section>

   <section title="Expiry of Triggers" anchor="expiry-of-triggers">
   <t>
   The dCDN MAY automatically delete trigger resources sometime after they reach a terminal state. 
   In this case, after the dCDN has removed such a trigger, it MUST respond 
   to subsequent requests for it with the HTTP error 404 ("Not Found") and remove it from all trigger collections.
   </t>
   <t>
   A dCDN SHOULD NOT expire triggers in the "processed" state while they can reasonably be expected to remain active, 
   such as when execution or redistribution to other dCDNs may still be ongoing.
   </t>

   <t>
   If the dCDN does remove triggers in a terminal state automatically, it MUST report the expiry timeout period, 
   using an attribute "staleresourcetime" of the trigger index resource (see <xref target="ci-trigger-index-resource"/> for details.
   </t>

   <t>
   It is RECOMMENDED that the dCDN sets the value of the "staleresourcetime" attribute to at least 24 hours. 
   It is further RECOMMENDED that the uCDN sets its trigger polling period to less than this period, 
   so it doesn't miss trigger status updates before the "complete" or "failed" triggers are expired by the dCDN.
   </t>

   </section>

   <section title="Error Handling" anchor="error-handling">
   <t>
   The dCDN SHOULD reject invalid CI/T interface requests with a 4xx or 5xx HTTP status code.
   For example, the dCDN MAY respond with 400 ("Bad Request") if the request is malformed, 
   or 403 ("Forbidden") or 404 ("Not Found") if the request could not be properly authenticated 
   or if the uCDN is trying to act on another CDN's resources.
   The HTTP status codes used by this interface are summarized in <xref target="http-error-codes" format="title"/>.
   </t>
   <t>
   The response body for a rejected request SHOULD contain an Error.v2 Description object identifying the reason for the rejection.
   Providing the full Error.v2 Description allows a transit CDN that receives the rejection when propagating a trigger to relay 
   the error upstream without loss of information (see <xref target="error-propagation"/>). 
   A rejected request does not create a trigger resource.
   </t>
   <t>
   The response body is sent with the MIME media type "application/cdni" and the payload type
   "ci-trigger-error.v2" (<xref target="IANA.CDNI.payload.ci-trigger-error.v2"/>).
   The dCDN SHOULD include the response body irrespective of the "Accept" header field of the
   rejected request.
   </t>
   <t>
   Once a request has been accepted, processing errors are reported within the trigger as a list of 
   <xref target="error-v2-description">Error.v2 Descriptions</xref>. 
   Each Error.v2 Description reports errors against one or more of the URLs or patterns in the trigger specification.
   </t>

   <t>
   If any part of the trigger processing fails, the trigger SHOULD be reported as "failed" once its activity 
   completes, or once no further errors will be reported. The "errors" property in the trigger enumerates which actions failed and why.
   It MAY be present while the trigger is still "pending" or "active" if processing is still running for some of the URLs or patterns 
   in the trigger specification.
   </t>

   <t>
     If the dCDN experiences an internal outage or is unable to propagate a
     trigger to one or more cascaded dCDNs, it SHOULD report an error
     for the affected trigger.
   </t>
   
   <t>
     The temporary unavailability of individual nodes within the dCDN is an
     internal operational condition. The dCDN SHOULD handle this internally,
     and such unavailability SHOULD NOT, by itself, affect the reported state of the trigger.
     The dCDN SHOULD ensure that nodes returning to service are brought into
     a state consistent with previously executed trigger operations before
     those nodes resume normal operation.
   </t>
   
          <section anchor="http-error-codes" title="HTTP Error Codes">
          <t>
            This section summarizes the HTTP status codes referenced by the CI/T
            interface. Unless otherwise specified, the semantics of HTTP status
            codes are defined in <xref target="RFC9110"/>.
          </t>
        
          <t>
            The dCDN uses HTTP status codes to indicate the outcome of requests
            performed by the uCDN. The table below provides a summary of the
            status codes used by this specification and their typical usage
            within the CI/T interface.
          </t>
        
          <table anchor="http-error-codes-table" align="center">
            <name>HTTP Status Codes Used by the CI/T Interface</name>
            <thead>
              <tr>
                <th align="left">Code</th>
                <th align="left">Reason Phrase</th>
                <th align="left">Usage in this Specification</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td>200</td>
                <td>OK</td>
                <td>Returned when a request has been successfully processed.</td>
              </tr>
              <tr>
                <td>201</td>
                <td>Created</td>
                <td>Returned when a trigger resource is successfully created. The
                Location header conveys the URI of the new trigger resource.</td>
              </tr>
              <tr>
                <td>202</td>
                <td>Accepted</td>
                <td>Returned when a request has been accepted for processing but the
                operation has not yet completed.</td>
              </tr>
              <tr>
                <td>204</td>
                <td>No Content</td>
                <td>Returned for successful DELETE requests when no response body is provided.</td>
              </tr>
              <tr>
                <td>304</td>
                <td>Not Modified</td>
                <td>Returned for conditional GET requests when the requested
                resource representation has not changed.</td>
              </tr>
              <tr>
                <td>400</td>
                <td>Bad Request</td>
                <td>Returned when a request is malformed or otherwise invalid.</td>
              </tr>
              <tr>
                <td>403</td>
                <td>Forbidden</td>
                <td>Returned when the requester is not authorized to act on the specified resource.</td>
              </tr>
              <tr>
                <td>404</td>
                <td>Not Found</td>
                <td>Returned when the referenced trigger resource does not exist
                or has been removed.</td>
              </tr>
              <tr>
                <td>409</td>
                <td>Conflict</td>
                <td>Returned when the trigger resource state does not allow the requested operation.</td>
              </tr>
              <tr>
                <td>501</td>
                <td>Not Implemented</td>
                <td>Returned when the requested operation is not supported by the dCDN.</td>
              </tr>
            </tbody>
          </table>

          <t>
          The 501 status code indicates a lack of support for the operation itself, for example, 
          deleting or modifying a trigger, or returning an extended representation of a trigger or 
          trigger collection. A trigger whose type, spec, subject or extension the dCDN does not support is
          rejected with a 400 status code.
          </t>
        
        </section>
          <section anchor="error-propagation" title="Error Propagation">

        <t>
        CDNI triggers may be propagated over a chain of downstream CDNs. 
        For example, an upstream CDN A ("uCDN-A") delegates to a downstream CDN B ("dCDN-B"), 
        and dCDN-B in turn delegates to a downstream CDN C ("dCDN-C"). 
        Triggers sent from uCDN-A to dCDN-B may be redistributed from dCDN-B to dCDN-C, and errors can occur anywhere along the path. 
        It is therefore desirable for uCDN-A, which originated the trigger, to be able to trace an error back to the 
        downstream CDN where it occurred. This document adds a mechanism to convey the PID of the dCDN at which a fault occurred back 
        to the uCDN by including that PID in the Error.v2 Description.
        </t>
        <t>
        Errors arising within a cascaded CDN may be either synchronous request rejections or asynchronous processing failures. 
        A downstream CDN that accepts a trigger creation request with a 2xx status code reports any subsequent processing failures 
        asynchronously, through Error.v2 Descriptions in the trigger status resource. 
        However, when such a CDN propagates the trigger further downstream, the next CDN in the chain may reject the propagated 
        request with a 4xx or 5xx HTTP status code. Because the upstream request has already been accepted, this rejection cannot be 
        reported upstream as an HTTP status code. Instead, the CDN that received the rejection MUST translate it into an Error.v2 
        Description and report it in its trigger status resource.
        </t>
        <t>
        Accordingly, when dCDN-B propagates a trigger to dCDN-C, it MUST propagate back the errors associated with that trigger,
        whether dCDN-C rejected the propagated request synchronously or reported processing failures asynchronously, by adding the 
        corresponding Error.v2 Descriptions to the "errors" array in the trigger status resource it returns to uCDN-A. 
        When doing so, dCDN-B MAY include dCDN-C's PID in each propagated Error.v2 Description, indicating the CDN at which the 
        error originated. uCDN-A then receives an "errors" array containing the errors that occurred across all downstream CDNs along 
        the execution path, where each error MAY identify the CDN at which it occurred.
        </t>

        <t>
            <xref target="error-propagation-seq"/> below is an example showing the message flow used by
            uCDN-A to trigger activity in dCDN-B, followed by dCDN-C, as well as the discovery of the
            status of that activity, including the Error Propagation.
        </t>
        <figure anchor="error-propagation-seq" title="CDNI Message Flow for Triggers, Including Error Propagation">
            <artwork><![CDATA[
uCDN-A                         dCDN-B                         dCDN-C
 |                              |                              |    
 | (1) POST                     |                              |    
 | https://dcdn-b.com           |                              |    
 | /cit/uCDN-A                  |                              |    
[ ]--------------------------->[ ]--+                          |    
 |                             [ ]  | (2)                      |    
 |                             [ ]<-+                          |    
 | (3) HTTP 201 Response.      [ ]                             |    
 |<----------------------------[ ]                             |    
 | Loc:                        [ ]                             |    
 | https://dcdn-b.com          [ ] (4) POST                    |    
 | /cit/ucdn-a/123             [ ] https://dcdn-c.com          |    
 |                             [ ] /cit/dcdn-b                 | (5)
 |                             [ ]--------------------------->[ ]--+
 |                              |                             [ ]  |
 |                              |                             [ ]<-+
 |                              | (6) HTTP 400 Response.      [ ]   
 |                             [ ]<---------------------------[ ]   
 |                              |                              |    
 |                             [ ]--+                          |
 |                             [ ]  | (7)                      |
 |                             [ ]<-+                          |
 .                              .                              .   
 .                              .                              .   
 .                              .                              .   
 | (8) GET                      |                              |    
 | https://dcdn-b.com           |                              |    
 | /cit/ucdn-a/123              |                              |    
[ ]--------------------------->[ ]                             |    
 |                             [ ]                             |    
 | (9) HTTP 200                [ ]                             |    
 | Trigger resource            [ ]                             |    
[ ]<---------------------------[ ]                             |    
         ]]></artwork>
        </figure>
               <t>
                The steps in <xref target="error-propagation-seq"/> are as follows:
        </t>
        <t><list style="numbers">
                <t>
                uCDN-A creates a trigger in dCDN-B by POSTing a new trigger representation to 
                "https://dcdn-b.com/cit/ucdn-a". 
                </t>
                <t>
                dCDN-B authenticates the request, validates the trigger creation request, and, 
                if it accepts the request, creates a new trigger resource.
                </t>
                <t>
                dCDN-B responds to uCDN-A with an HTTP 201 ("Created") response status
                and the location of the newly created trigger.
                </t>
                <t>
                dCDN-B creates a trigger in dCDN-C by POSTing the newly received trigger representation to
                "https://dcdn-c.com/cit/dcdn-b". 
                </t>
                <t>
                dCDN-C authenticates the request and validates the trigger creation request.
                dCDN-C does not support an element of the request (for example, the trigger definition 
                contains an "action" type that dCDN-C does not support).
                </t>
                <t>
                dCDN-C rejects the request with a 4xx HTTP status code (for example, 400 "Bad Request").
                The response body contains an Error.v2 Description with the error code "eunsupported" and the 
                offending portion of the trigger specification. No trigger resource is created at dCDN-C.
                </t>
                <t>
                dCDN-B receives the rejection from dCDN-C and translates it into an Error.v2 Description, 
                setting the state of its own trigger resource to "failed".
                </t>
                <t>
                uCDN-A queries, possibly repeatedly, the trigger resource in dCDN-B.
                </t>
                <t>
                dCDN-B responds with the updated trigger resource representation. The trigger state is "failed", 
                and the Error.v2 Description carries the error code "eunsupported" received from dCDN-C, 
                with dCDN-C's PID identifying where the error originated. 
                Including dCDN-C's PID is OPTIONAL; dCDN-B MAY instead use its own PID, thereby 
                obfuscating the identity of dCDN-C from the upstream CDN.
                </t>
        </list> </t>
      </section>

   </section>
   </section>



<section title="CI/T Object Properties and Encoding" anchor="cit-objects-properties-and-encoding">
   <t>
   The <xref target="ci-trigger-resource">Trigger</xref>, <xref target="ci-trigger-index-resource">Trigger Index</xref>, 
   and <xref target="ci-trigger-collection-resource">Trigger Collection</xref> resources and their respective properties are encoded in JSON format.
   When sending the JSON-based representation of these resources, the MIME media type 
   "application/cdni" MUST be used, with parameter "ptype" values as defined below and 
   in <xref target="cdni-payload-type"/>.
   </t>

   <t>
   Names in JSON are case-sensitive. The names and literal values
   specified in the present document MUST always use lowercase.
   </t>

   <t>
   JSON types, including "object", "array", "number", and "string", are defined in <xref target="RFC8259"/>.
   </t>

   <t>
   Unrecognized attributes in JSON objects SHOULD NOT be treated
   as an error by either the uCDN or the dCDN. They SHOULD be ignored
   during processing and passed on by the dCDN to any further dCDNs in a
   cascade.</t>

   <section title="Trigger Resource" anchor="ci-trigger-resource">
   <t>
   Trigger resource is encoded as a JSON object and MUST use a MIME media type of "application/cdni; ptype=ci-trigger.v2".
   Please note that the dCDN MUST include all existing trigger attributes in the trigger resource representation
   when requested by the uCDN.  The trigger resource contains the following attributes:
   </t>
   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">
   
   <t hangText="Name: action">
   <vspace blankLines="1"/>
   Description: Defines the type of the CI/T trigger action.
   <vspace blankLines="1"/>
   Value: Trigger action type, as defined in <xref target="trigger-action"/>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: It is optional for trigger update requests sent by the uCDN, otherwise mandatory.
   </t>

   <t hangText="Name: specs">
   <vspace blankLines="1"/>
   Description: Array of trigger specs representing the trigger's targets, as described in <xref target="trigger-specs"/>.
   <vspace blankLines="1"/>
   Value: Array of GenericTriggerSpec objects (see <xref target="generic-spec-object"/>).
   <vspace blankLines="1"/>
   Mandatory-to-Specify: It is optional for trigger update requests sent by the uCDN, otherwise mandatory. 
   Furthermore, when mandatory, the list MUST NOT be empty.
   </t>

   
   <t hangText="Name: extensions">
   <vspace blankLines="1"/>
   Description: Array of trigger extensions, as described in <xref target="trigger-extensions"/>.
   <vspace blankLines="1"/>
   Value: Array of GenericTriggerExtension objects (see <xref target="generic-extension-object"/>).
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The default is no extensions. 
   </t>

   <t hangText="Name: labels">
   <vspace blankLines="1"/>
   Description: Trigger labels, as described in <xref target="trigger-labels"/>.
   <vspace blankLines="1"/>
   Value: A JSON object, whose members are the trigger labels. Each member name is a label key and each member value
   is the corresponding label value; both are JSON strings.
   A label key and a label value MUST each be no more than 63 characters in length, 
   MUST begin with a letter or a number, and MAY contain letters, numbers, hyphens, dots, and underscores.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The default is no labels. 
   </t>

   <t hangText="Name: cdn-path">
   <vspace blankLines="1"/>
   Description: The chain of CDN PIDs of CDNs that have already created this trigger resource. 
   <vspace blankLines="1"/>
   Value: An array of JSON strings, where each string is a CDN PID as defined in <xref target="cdn-pid"/>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The default is no CDN path.
   </t>

   <t hangText="Name: ctime">
   <vspace blankLines="1"/>
   Description: The time at which the trigger resource was received by the dCDN. 
   The time is determined by the dCDN; there is no requirement to synchronize clocks between interconnected CDNs.
   <vspace blankLines="1"/>
   Value: Time, as defined in Section 4.3.4 of <xref target="RFC8006"/>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: The dCDN MUST specify in trigger status representations. 
   It is ignored when included in trigger representations sent by the uCDN.
   </t>

   <t hangText="Name: mtime">
   <vspace blankLines="1"/>
   Description: The time at which the trigger resource was last modified. 
   The time is determined by the dCDN; there is no requirement to synchronize clocks between interconnected CDNs.
   <vspace blankLines="1"/>
   Value: Time, as defined in Section 4.3.4 of <xref target="RFC8006"/>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: The dCDN MUST specify in trigger status representations. 
   It is ignored when included in trigger representations sent by the uCDN.
   </t>

   <t hangText="Name: etime">
   <vspace blankLines="1"/>
   Description: The estimate of the time at which the dCDN expects to complete the trigger processing. 
   Time is determined by the dCDN; there is no requirement to synchronize clocks between interconnected CDNs.
   <vspace blankLines="1"/>
   Value: Time, as defined in Section 4.3.4 of <xref target="RFC8006"/>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: The dCDN MAY specify in trigger status representations. 
   It is ignored when included in trigger representations sent by the uCDN.
   </t>

   <t hangText="Name: state">
   <vspace blankLines="1"/>
   Description: The current trigger state.
   <vspace blankLines="1"/>
   Value: Trigger state, as defined in <xref target="trigger-state"/>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: The dCDN MUST include trigger state in the trigger resource representations it sends. 
   The trigger state defaults to "pending" when a trigger is created and is optional in trigger update requests sent by the uCDN.
   </t>
   
   <t hangText="Name: state-reason">
   <vspace blankLines="1"/>
   Description: A human-readable explanation for the object state.
   <vspace blankLines="1"/>
   Value: A JSON string, the human-readable reason.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The dCDN MAY include the trigger reason in the trigger resource representations it sends.
   </t>
   
   <t hangText="Name: errors">
   <vspace blankLines="1"/>
   Description: Descriptions of errors that have occurred while processing the trigger.
   <vspace blankLines="1"/>
   Value: An array of Error.v2 Descriptions, as defined in <xref target="error-v2-description"/>. 
   An empty array is allowed and is equivalent to omitting the "errors" attribute from the object.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The dCDN SHOULD include this attribute in the trigger resource representations it sends 
   when the trigger is in a "failed" state.
   </t>

   <t hangText="Name: total-objects-count">
   <vspace blankLines="1"/>
   Description: Total aggregate number of objects affected by the trigger, e.g., number of objects purged, 
   invalidated or prepositioned as a result of trigger processing.  
   <vspace blankLines="1"/>
   Value: Integer.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. This attribute is "optional-to-implement". When supported, the dCDN SHOULD include this attribute 
   in the trigger resource representations requested by the uCDN.
   </t>


   <t hangText="Name: total-nodes-count">
   <vspace blankLines="1"/>
   Description: The total number of unique dCDN nodes affected by the trigger.
   <vspace blankLines="1"/>
   Value: Integer.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. This attribute is "optional-to-implement". When supported, the dCDN SHOULD include this attribute 
   in the trigger resource representations requested by the uCDN.
   </t>

   <t hangText="Name: total-objects-size">
   <vspace blankLines="1"/>
   Description: Total aggregate size of objects affected by the trigger, in bytes.
   <vspace blankLines="1"/>
   Value: Integer.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. This attribute is "optional-to-implement". When supported, the dCDN SHOULD include this attribute 
   in the trigger resource representations requested by the uCDN.
   </t>

   <t hangText="Name: objects">
   <vspace blankLines="1"/>
   Description: List of objects derived by the dCDN when processing the trigger. When the "content-objectlist" trigger specification 
   is used, the trigger MAY include one or more manifest files that form a hierarchical structure (e.g., media HLS playlists referenced 
   by master HLS playlists, or JSON object lists referenced by other JSON object lists). 
   The purpose of this optional attribute is to provide a single, flattened list of content objects derived from the input trigger.
   <vspace blankLines="1"/>
   Value: An array of <xref target="content-object">ContentObject</xref> objects.
   The dCDN SHOULD provide the list of objects it used as input for processing the trigger with <xref target="objectlist-spec"/>, 
   provided that the dCDN advertised <xref target="extended-status-capability-object"> support for extended status</xref>.
      
   An empty array is allowed and is equivalent to omitting "objects" from the trigger representation. This field is intended to provide 
   the list of all objects used in processing. The objects that failed to process SHOULD be specified using the Error.v2 Description resource.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The dCDN SHOULD only send this attribute in the trigger resource 
   representation when it advertises support for the extended representation via FCI and
   and the extended representation is requested by the uCDN.
   </t>

   </list></t>
   </list></t>

   <t>
   The attributes "total-objects-count", "total-nodes-count", and "total-objects-size" are cumulative progress indicators. 
   It is RECOMMENDED that the dCDN maintains these attributes as cumulative counters across all of its nodes, as well as any cascaded dCDNs,
   without de-duplicating the same objects processed in multiple nodes.
   The dCDN MAY update these values as trigger processing progresses while the trigger is in the "active" state. 
   The primary purpose of these attributes is to help the uCDN detect abnormal trigger processing
   results, e.g., a purge or preposition trigger that impacted a lower or higher number of objects than expected.
   </t>


   <section title="Trigger Action" anchor="trigger-action">
   <t>
   A trigger action is used in a trigger resource to describe trigger actions. 
   It was previously referred to in <xref target="RFC8007"/> as "Trigger Type".
   </t>

   <t>
   All trigger actions MUST be registered in the IANA "CDNI CI/T Trigger Types" 
   registry (see <xref target="IANA.CDNI.TriggerTypeReg"/>).
   </t>

   <t>
   A dCDN that receives a request containing a trigger action it does not recognize or support MUST reject the request with a 4xx 
   HTTP status code (for example, 400 "Bad Request"), as described in <xref target="http-error-codes"/>.
   Such a request does not create a trigger and therefore produces no Error.v2 Description.
   </t>

   <t>
   The following trigger actions are defined by this document:
   </t>

   <texttable style="full"><ttcol align="left"> JSON string</ttcol>
   <ttcol align="left"> Description</ttcol>
   <c>preposition</c>
   <c>A request for the dCDN to acquire metadata and/or content.</c>
   
   <c>invalidate</c>
   <c>
   A request for the dCDN to invalidate metadata and/or content. After servicing this request, 
   the dCDN will not use the specified data without first revalidating it using, for example, 
   an "If-None-Match" HTTP request. The dCDN need not erase the associated data.
   </c>
   
   <c>purge</c>
   <c>
           A request for the dCDN to erase metadata and/or content. After servicing the request, 
           the specified data MUST NOT be held on the dCDN (the dCDN MUST reacquire the metadata 
           and/or content from the uCDN if it needs it).
   </c>
   </texttable>
   <t>
   The dCDN MUST support at least one of the trigger actions. 
   </t>

   <t>
   An "invalidate" or "purge" trigger that does not match any objects known to the dCDN MUST NOT be treated as an error condition. In such
   cases, the trigger MAY be completed successfully even if no objects were affected.
   </t>
   </section>
   <section anchor="trigger-specs" title="Trigger Specs">
   <t>
   The CDNI Control Interface / Triggers 1st edition <xref target="RFC8007"/> defines a set of properties
   and objects used by the trigger commands to specify the targets upon which the trigger is applied.
   This document modifies the trigger interface objects so that it has a list of trigger specs. 
   Such structure improves the interface's extensibility and flexibility. 
   Furthermore, the document defines a generic trigger spec object that acts as a wrapper for managing 
   individual CDNI trigger specs in an abstract manner, allowing future extension of the interface.
   </t>
   
   <t>
   All trigger specs MUST be registered in the IANA "CDNI CI/T Trigger Specs" registry 
   (see <xref target="IANA.CDNI.TriggerSpecReg"/>).
   </t>

   <t>
   A dCDN that receives a trigger creation request containing a trigger specification it does not recognize or support 
   MUST reject the request with a 400 ("Bad Request") HTTP status code.  The response body SHOULD contain an Error.v2 Description 
   with the error code "espec", including the portion of the trigger specification that caused the rejection, 
   as defined in <xref target="error-code"/>, and a human-readable description identifying the unsupported or unrecognized element. 
   Such a request does not create a trigger resource.
   </t>

   <t>
        This document defines an initial set of trigger spec objects and registers them in 
        the IANA "CDNI CI/T Trigger Specs" registry:
   </t>
      
   <texttable style="full"><ttcol align="left"> JSON string</ttcol>
   <ttcol align="left"> Description</ttcol>
   <c>urls</c>
   <c>Allowing the specification of trigger targets via URLs.</c>
   <c>ccids</c>
   <c>Allowing the specification of trigger targets via CCIDs content groupings, as defined in section 4.2.8 <xref target="RFC8006"/>.</c>
   <c>uri-pattern-match</c>
   <c>Allowing the specification of trigger targets via <xref target="RFC3986"/> URI patterns.</c>
   <c>uri-regex-match</c>
   <c>Allowing the specification of trigger targets via regexes matching their URI, as defined in <xref target="uri-regex-match-spec"/>.</c>
   <c>content-objectlist</c>
   <c>Allowing the specification of trigger targets using lists of objects.</c>
   </texttable>
   <t>
        The dCDN MUST support the "urls" trigger spec. Support for all other trigger specs is OPTIONAL.
   </t>
   <t>
        Each trigger usually refers to the targets by the target URLs, using a "urls" trigger spec object or
        some aggregating spec such as the "url-regex-match".
        If content URLs are transformed by a transit CDN in a cascade,
        that transit CDN MUST similarly transform URLs in triggers it passes to its dCDNs.</t>
   <t>
        When processing a trigger, CDNs MUST ignore the URL scheme (HTTP or HTTPS) in comparing URLs.
        For example, for a CI/T "invalidate" or "purge" action, content MUST be invalidated or
        purged regardless of the protocol clients used to request it.
   </t>


   <section anchor="generic-spec-object" title="Generic Spec Object">
   <t>
        A trigger resource, as defined in <xref target="ci-trigger-resource"/>, includes an array of trigger spec objects. 
        Each trigger spec object contains properties that are used as trigger target selection directives for the dCDN when 
        processing the trigger, e.g., content URLs or metadata URL patterns. Each such trigger spec is a specialization 
        of a CDNI GenericTriggerSpec object. 
        The GenericTriggerSpec object abstracts the basic information required for trigger distribution from the 
        specifics of any given property (i.e., property semantics, enforcement options, etc.). 
   </t>
   <t> The semantics of the trigger specs list is additive, i.e., the trigger applies to any object matching one of the listed specs.
   </t>

   <t> A GenericSpecObject object is a wrapper for managing individual CDNI trigger specs in an opaque manner.</t>
   <t>It is encoded as a JSON object containing the following attributes:</t>
   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">
   <t hangText="Name: trigger-subject">
           <vspace blankLines="1"/>
        Description: Case-insensitive CDNI trigger subject.
        <vspace blankLines="1"/>
        Value: String containing the type of the subject matching the "cit-spec-value" property, 
        such as "content" or "metadata" as defined in <xref target="trigger-subject"/>.
        <vspace blankLines="1"/>
        Mandatory-to-Specify: Yes.
        </t>

   <t hangText="Name: cit-spec-type">
        <vspace blankLines="1"/>
        Description: Case-insensitive CDNI trigger spec type.
        <vspace blankLines="1"/>
        Value: String containing the spec type of the object contained
        in the cit-spec-value property (see table in <xref target="trigger-specs"/>).
        <vspace blankLines="1"/>
        Mandatory-to-Specify: Yes.
        </t>


   <t hangText="Name: cit-spec-value">
        <vspace blankLines="1"/>
        Description: A CDNI trigger spec object.
        <vspace blankLines="1"/>
        Value: Defined by the value of the cit-spec-type property.
        <vspace blankLines="1"/>
        Mandatory-to-Specify: Yes.
        </t>
   </list></t>
   </list></t>

   <t>The structure of a JSON-serialized GenericTriggerSpec object, containing a specific trigger spec is illustrated below:</t>

      <sourcecode type="json" name="GenericTrigger Spec">
             <![CDATA[ 
{
  "cit-spec-type":
     <Type of this trigger spec>,
  "cit-spec-value":
      {
        <properties of this trigger spec object>
      },
   "trigger-subject":
     <Category of this trigger spec subject>

}
       ]]></sourcecode>
   </section>

   <section anchor="trigger-subject" title="Trigger Subject">

   <t>
   Because the scope of the trigger may relate to metadata and/or content, 
   the "trigger spec object" also specifies the trigger's target subject (i.e., "metadata" or "content") 
   against which to match.
   </t>
   
   <t>
   All trigger subjects MUST be registered in the IANA "CDNI CI/T Trigger Subjects" registry 
   (see <xref target="IANA.CDNI.TriggerSubjectReg"/>).
   </t>

   <t>
   A dCDN that receives a trigger creation request containing a trigger subject it does not recognize or support MUST reject 
   the request with a 400 ("Bad Request") HTTP status code.  The response body SHOULD contain an Error.v2 Description with 
   the error code "esubject", identifying the unrecognized or unsupported subject.
   Such a request does not create a trigger resource.
   </t>

   <t>
   This document also defines an initial set of trigger subject values and registers them in 
   the IANA "CDNI CI/T Trigger Subjects" registry:
   </t>
      
   <texttable style="full"><ttcol align="left"> JSON string</ttcol>
   <ttcol align="left"> Description</ttcol>
   <c>metadata</c>
   <c>Indicating the trigger target specification refers to Metadata object(s), as defined at <xref target="RFC8006"/>.</c>
   <c>content</c>
   <c>Indicating the trigger target specification refers to client-facing content objects.</c>
   </texttable>
   <t>
   The dCDN MUST support at least one of the trigger subjects. 
   The dCDN MAY advertise separate endpoints for each one of the two trigger subjects, using the
   <xref target="cit-trigger-endpoints-capability-object">CI/T Endpoint Capability Object</xref>.
   </t>
   </section>


   <section anchor="spec-constraints" title="Spec Constraints">
   <t>
           There are certain constraints on the way the trigger specs can be combined with trigger subject and 
           trigger actions:
   </t>
   <texttable anchor="spec-constraints-table" title="Summary of trigger spec constraints">
           <ttcol align="left">Trigger spec types</ttcol>
           <ttcol align="left">Trigger subject ("content" and "metadata") </ttcol>
           <ttcol align="left">Trigger action ("preposition", "purge", and "invalidate") </ttcol>
           <c>urls</c><c>Any</c><c>Any</c>
           <c>ccids</c><c>"content" only</c><c>"purge" or "invalidate"</c>
           <c>uri-pattern-match</c><c>Any</c><c>"purge" or "invalidate"</c>
           <c>uri-regex-match</c><c>Any</c><c>"purge" or "invalidate"</c>
           <c>content-objectlist</c><c>Any</c><c>Any</c>
   </texttable>

   <t>
   The trigger specification types "ccids", "uri-pattern-match", and "uri-regex-match" operate by matching 
   attributes of objects already known to the dCDN. As a result, these specification types can only identify
   objects that are present in, or otherwise known to, the dCDN at the time the trigger is processed, 
   and therefore cannot be used for "preposition" actions.
   </t>
   
   <t>
   CCIDs, as defined in <xref target="RFC8006"/>, apply to groupings of content objects and are not defined for 
   metadata objects.  Consequently, the "ccids" trigger specification type is limited to triggers whose subject is "content".
   </t>

   </section>
   <section anchor="urls-spec" title="URLs Spec">
   <t>
        The "urls" spec type allows the uCDN to manage uCDN content or metadata objects held by the dCDN based on the objects' URLs. 
        Full URLs SHOULD be used to ensure unambiguous identification of the referenced objects.
   </t>

   <t>The URLs spec is encoded as a JSON object containing the following attributes:</t>

        <t><list style="empty" hangIndent="3">
        <t><list style="hanging" hangIndent="3"><t hangText="Name: urls">
        <vspace blankLines="1"/>
   Description: An array of URLs over which the trigger MUST be executed.
        <vspace blankLines="1"/>
   Value: A JSON array of URLs, each represented as a JSON string.
        <vspace blankLines="1"/>
        Mandatory-to-Specify: Yes.
        </t>

        <t hangText="Name: url-type">
        <vspace blankLines="1"/>
   Description: Type of URL used.
        <vspace blankLines="1"/>
   Value: URL Type as defined in <xref target="url-types"/>.
        <vspace blankLines="1"/>
        Mandatory-to-Specify: No. When omitted or empty, the "published" URL type is assumed.
        </t>

        </list></t>
        </list></t>


        <t>Below is an example of a JSON-serialized URLs spec object, matching the metadata at 
        metadata.example.com/a/b/c.
        </t>
<sourcecode type="json" name="urls-spec-json"><![CDATA[
{
  "trigger-subject": "metadata",
  "cit-spec-type": "urls",
  "cit-spec-value": {
    "urls": [ "https://metadata.example.com/a/b/c" ],
    "url-type": "published"
  }
}
       ]]></sourcecode>
      </section>



      <section anchor="ccids-spec" title="CCIDs Spec">

      <t> The "ccids" spec type allows the uCDN to specify the
      Content Collection IDentifier (CCID) of content to which the trigger applies.
      The CCID is a grouping of content as defined by <xref target="RFC8006"/>.
      The "ccids" spec type is valid only for the "content" spec subject (see <xref target="trigger-subject"/>).
      </t>
      <t>CCIDs spec is encoded as a JSON object containing the following attributes:</t>

      <t><list style="empty" hangIndent="3">
      <t><list style="hanging" hangIndent="3"><t hangText="Name: ccids">
      <vspace blankLines="1"/>
      Description: An array of Content Collection IDentifiers over which the trigger MUST be executed.
      <vspace blankLines="1"/>
      Value: A JSON array of strings, where each string is a Content Collection IDentifier.
      <vspace blankLines="1"/>
      Mandatory-to-Specify: Yes.
      </t>

      </list></t>
      </list></t>

      </section>

      <section anchor="uri-pattern-match-spec" title="URI Pattern Match Spec">
      <t>
      The "uri-pattern-match" spec type allows the uCDN to manage its content or metadata objects
      held by the dCDN based on the objects' URI pattern. The value is a UriPatternMatch object, 
      as defined in <xref target="url-pattern-match"/>.
      </t>

      <section title="UriPatternMatch" anchor="url-pattern-match">
      <t>
      A UriPatternMatch consists of a string pattern to match against a URI,
      and flags describing the type of match.</t>
      <t>It is encoded as a JSON object containing the following attributes:</t>

      <t><list style="empty" hangIndent="3">
      <t><list style="hanging" hangIndent="3"><t hangText="Name: pattern">
      <vspace blankLines="1"/>
      Description: A pattern for URI matching.
      <vspace blankLines="1"/>
      Value: The pattern represented as a JSON string. The pattern can
         contain the wildcards "*" and "?", where "*" matches any sequence of
         <xref target="RFC3986"/> pchar or "/" characters (including the empty string)
         and "?" matches exactly one <xref target="RFC3986"/> pchar character. The three
         literals "$", "*",  and "?" MUST be escaped as "$$", "$*" and "$?" (where "$"
         is the designated escape character). All other characters are
         treated as literals.
      <vspace blankLines="1"/>
      Mandatory-to-Specify: Yes.
      </t>

      <t hangText="Name: case-sensitive">
      <vspace blankLines="1"/>
      Description: Flag indicating whether or not case-sensitive matching SHOULD be used.
      <vspace blankLines="1"/>
      Value: A JSON boolean. When set to "true", matching is case-sensitive; when set to "false", matching is case-insensitive.
      <vspace blankLines="1"/>
      Mandatory-to-Specify: No; default is "false", i.e., a case-insensitive match.
      </t>

      <t hangText="Name: match-query-string">
      <vspace blankLines="1"/>
      Description: Flag indicating whether to include the query part
         of the URI when compared against the pattern.
      <vspace blankLines="1"/>
      Value: One of the JSON values "true" (the full URI including
         the query part SHOULD be compared against the given pattern)
         or "false" (the query part of the URI SHOULD be dropped before
         comparison with the given pattern).
      <vspace blankLines="1"/>
      Mandatory-to-Specify: No; default is "false". The query part of the URI
         SHOULD be dropped before comparison with the given pattern.
      </t>
      <t hangText="Name: url-type">
      <vspace blankLines="1"/>
      Description: Type of URLs to match.
      <vspace blankLines="1"/>
      Value: URL Type as defined in <xref target="url-types"/>.
      <vspace blankLines="1"/>
      Mandatory-to-Specify: No. When omitted or empty, "published" URL type is assumed.
      </t>


      </list></t>
      </list></t>

   <t>Example of case-sensitive prefix match against "https://www.example.com/trailers/":</t>
<sourcecode type="json" name="prefix-match">
<![CDATA[
{
  "pattern": "https://www.example.com/trailers/*",
  "case-sensitive": true
}
]]></sourcecode>
   </section>
</section>



     <section anchor="uri-regex-match-spec" title="URI Regex Match Spec">
        <t>The "uri-regex-match" spec type allows the uCDN to manage content or metadata objects
           held by the dCDN based on the objects' URI regex.
        </t>

        <section anchor="regex-match" title="RegexMatch">
          <t>
             A RegexMatch consists of a regular expression string against which a URI is matched,
             and flags describing the type of match. It is encoded as a JSON object with
             the following properties:
     </t>

        <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">
   <t hangText="Name: regex">
        <vspace blankLines="1"/>
   Description: A JSON string containing the regular expression for URI matching.
        <vspace blankLines="1"/>
        Value: A regular expression to match against the URI, i.e., against the path-absolute
                 and the query string parameters <xref target="RFC3986"/>. The regular expression
                 string MUST be compatible with <xref target="POSIX.1">POSIX</xref> Section 9
                 Extended Regular Expressions. This regular expression MUST be evaluated in
                 the POSIX locale (<xref target="POSIX.1">POSIX</xref> Section 7.2).

              <t>Note: Because '\' has a special meaning in JSON <xref target="RFC8259"/> as the escape
                 character within JSON strings, the regular expression character '\' MUST be escaped as '\\'.</t>
        <vspace blankLines="1"/>
        Mandatory-to-Specify: Yes.
        </t>

   <t hangText="Name: case-sensitive">
        <vspace blankLines="1"/>
   Description: Flag indicating whether or not case-sensitive matching should be used.
        <vspace blankLines="1"/>
   Value: JSON boolean. Either "true" (the matching is case-sensitive) or "false" 
   (the matching is case insensitive).
        <vspace blankLines="1"/>
   Mandatory-to-Specify: No; default is "false", i.e., a case-insensitive match.
        </t>
   <t hangText="Name: match-query-string">
        <vspace blankLines="1"/>
   Description: Flag indicating whether to include the query part of the URI when
                 compared against the regex.
        <vspace blankLines="1"/>
   Value: JSON Boolean. Either "true" (the full URI, including the query part,
                 should be compared against the regex) or "false" (the query part of the URI
                 should be dropped before comparison with the given regex).
        <vspace blankLines="1"/>
        Mandatory-to-Specify: No; default is "false". The query part of the URI MUST be dropped
                 before comparison with the given regex. This makes the regular expression simpler
      and safer for cases in which the query parameters are not relevant to the match.
   </t>

        <t hangText="Name: url-type">
        <vspace blankLines="1"/>
        Description: Type of URLs to match against.
        <vspace blankLines="1"/>
        Value: URL Type as defined in <xref target="url-types"/>.
        <vspace blankLines="1"/>
   Mandatory-to-Specify: No. When omitted or empty, "published" URL type is assumed.
   </t>
   </list></t> 
   </list></t>

   <t>Example of a case-sensitive, no query parameters, regex match against is below.</t>
   <t>Please note that some lines in the example are wrapped for clarity.</t>
   <sourcecode type="json" name="regex-match-no-query-param">
<![CDATA[
"^(https:\/\/video\.example\.com)\/([a-z])\/
 movie1\/([1-7])\/*(index.m3u8|\d{3}.ts)$"
   ]]></sourcecode>

            <sourcecode type="json" name="regex-match-2"><![CDATA[
{
  "regex": "^(https:\\/\\/video\\.example\\.com)\\/([a-z])\\/
           movie1\\/([1-7])\\/*(index.m3u8|\\d{3}.ts)$",
  "case-sensitive": true
}
         ]]></sourcecode>

          <t>This regex matches URLs of the domain "video.example.com" where the path structure is
             /(single lower case letter)/(name-of-title)/(single digit between 1 to 7)/(index.m3u8 or a 3 digit number with ts extension).
             For example:</t>
     <sourcecode type="json" name="regex-match-3"><![CDATA[ https://video.example.com/d/movie1/5/index.m3u8 ]]></sourcecode>
     <t>or</t>
     <sourcecode type="json" name="regex-match-3"><![CDATA[ https://video.example.com/k/movie1/4/013.ts ]]></sourcecode>
        </section>
   </section>


      <section anchor="objectlist-spec" title="ObjectList Spec">
      <t>
        The "objectlist" spec type allows the uCDN to manage content or metadata held by the dCDN based on structured object lists. 
        The ObjectList spec type is valid only for the "content" spec subject (see <xref target="trigger-subject"/>).
      </t>
      <t>
        An object list is encoded as a JSON object with the following properties:
      </t>
        <t><list style="empty" hangIndent="3">
        <t><list style="hanging" hangIndent="3">
        <t hangText="Name: objects">
        <vspace blankLines="1"/>
        Description: An array of objects to be used in the trigger
        <vspace blankLines="1"/>
        Value: Array of <xref target="content-object">ContentObject</xref> objects
        <vspace blankLines="1"/>
        Mandatory-to-Specify: Yes.
        </t>

        </list></t>
        </list></t>
   </section>
   </section>
   <section anchor="trigger-extensions" title="Trigger Extensions">
          <t>
            A "trigger" object, as defined in <xref target="ci-trigger-resource"/> includes an
            optional array of trigger extension objects. A trigger extension contains properties
            that are used as directives for the dCDN when executing the trigger command, e.g., 
            location policies, time policies, and so on. Each such CDNI trigger extension is a specialization
            of a CDNI GenericTriggerExtension object. The GenericTriggerExtension object abstracts the basic
            information required for trigger distribution from the specifics of any given property
            (i.e., property semantics, enforcement options, etc.). All trigger extensions are optional,
            and it is thus the responsibility of the extension specification to define a consistent default
            behavior for extensions supported by the dCDN when not specified by the uCDN.
          </t>

          <section anchor="enforcement-options" title="Enforcement Options">
           <t>
             The trigger enforcement options concept is in accordance with the metadata enforcement options
             as defined in Section 3.2 of <xref target="RFC8006"/>.
           </t>
           <t>
             The GenericTriggerExtension object defines the properties contained within it
             as well as whether or not the properties are "mandatory-to-enforce".
             If the dCDN does not understand or support a mandatory-to-enforce
             property, the dCDN MUST NOT execute the trigger command. If the extension is
             not mandatory-to-enforce, then that GenericTriggerExtension object can be
             safely ignored and the trigger command can be processed in accordance
             with the rest of the CDNI trigger spec.
           </t>
           <t>
             Although a CDN MUST NOT execute a trigger command if a
             mandatory-to-enforce extension cannot be enforced, it could still be
             safe for a transit CDN (tCDN) to redistribute that trigger (the "safe-to-redistribute"
             property) to another CDN without modification, provided the tCDN does not need to
             do trigger processing of its own and only pass the trigger to one or more dCDNs.

             For example, in the cascaded CDN case, a transit CDN (tCDN) could convey
             mandatory-to-enforce trigger extension to the dCDN. For a trigger extension
             that does not require customization or translation (i.e., trigger extension
             that is safe-to-redistribute), the data representation received off the wire
             MAY be stored and redistributed without being understood or supported
             by tCDN. However, for a trigger extension that requires translation,
             transparent redistribution of the uCDN trigger values might not be
             appropriate. Certain trigger extensions can be safely, though perhaps not
             optimally, redistributed unmodified. For example, a preposition command might
             be executed in suboptimal times for some geographies if transparently
             redistributed, but it might still work.
           </t>
           <t>
             Redistribution safety MUST be specified for each GenericTriggerExtension
             listed. If a CDN does not understand or support a given
             GenericTriggerExtension object that is not safe-to-redistribute, the CDN
             MUST set the "incomprehensible" flag to true for that GenericTriggerExtension
             object before redistributing it. The "incomprehensible"
             flag signals to the dCDN that trigger metadata was not properly transformed
             by the tCDN. A CDN MUST NOT attempt to execute a trigger with an extension that has been
             marked as "incomprehensible" by the uCDN.
           </t>
           <t>
             tCDNs MUST NOT change the value of mandatory-to-enforce or
             safe-to-redistribute when propagating a trigger to the dCDN. Although a
             tCDN can set the value of "incomprehensible" to true, a tCDN MUST NOT
             change the value of "incomprehensible" from true to false.
           </t>
           <t>
             <xref target="tcdn-actions"/> describes the action to be taken by a tCDN for the
             different combinations of mandatory-to-enforce ("MtE") and safe-to-redistribute
             ("StR") properties when the tCDN either does or does not understand the trigger
             extension object in question:
           </t>

           <texttable anchor="tcdn-actions" title="Action to be taken by a tCDN for the different combinations of MtE and StR properties">
             <ttcol align="left">MtE</ttcol>
             <ttcol align="left">StR</ttcol>
             <ttcol align="left">Extension object understood by tCDN</ttcol>
             <ttcol align="left">Trigger action</ttcol>
               <c>False</c>
               <c>True</c>
               <c>True</c>
               <c>Can execute and redistribute.</c>

               <c>False</c>
               <c>True</c>
               <c>False</c>
               <c>Can execute and redistribute.</c>

               <c>False</c>
               <c>False</c>
               <c>False</c>
               <c>Can execute. MUST set "incomprehensible" to true when redistributing.</c>

               <c>False</c>
               <c>False</c>
               <c>True</c>
               <c>Can execute. Can redistribute after transforming the trigger extension
                  (if the CDN knows how to do so safely); otherwise, MUST set
                  "incomprehensible" to true when redistributing.</c>

               <c>True</c>
               <c>True</c>
               <c>True</c>
               <c>Can execute and redistribute.</c>

               <c>True</c>
               <c>True</c>
               <c>False</c>
               <c>MUST NOT execute but can redistribute, provided own processing is not required.</c>

               <c>True</c>
               <c>False</c>
               <c>True</c>
               <c>Can execute. Can redistribute after transforming the trigger extension
                  (if the CDN knows how to do so safely); otherwise, MUST set
                  "incomprehensible" to true when redistributing.</c>

               <c>True</c>
               <c>False</c>
               <c>False</c>
               <c>MUST NOT execute. May redistribute, provided own processing is not required. MUST set "incomprehensible" to true when redistributing.</c>

           </texttable> 
          
           <t>         
             <xref target="dcdn-actions"/> describes the action to be taken by the dCDN for the different
             combinations of mandatory-to-enforce and "incomprehensible" ("Incomp")
             properties, when the dCDN either does or does not understand the trigger extension object in question:
           </t>

           <texttable anchor="dcdn-actions" title="Action to be taken by the dCDN for the different combinations of MtE and Incomp properties">
             <ttcol align="left">MtE</ttcol>
             <ttcol align="left">Incomp</ttcol>
             <ttcol align="left">Extension object understood by the dCDN</ttcol>
             <ttcol align="left">Trigger action</ttcol>
               <c>False</c>
               <c>False</c>
               <c>True</c>
               <c>Can execute.</c>

               <c>False</c>
               <c>True</c>
               <c>True</c>
               <c>Can execute but MUST NOT interpret/apply any trigger extension marked as "incomprehensible".</c>

               <c>False</c>
               <c>False</c>
               <c>False</c>
               <c>Can execute.</c>

               <c>False</c>
               <c>True</c>
               <c>False</c>
               <c>Can execute but MUST NOT interpret/apply any trigger extension marked as "incomprehensible".</c>

               <c>True</c>
               <c>False</c>
               <c>True</c>
               <c>Can execute.</c>

               <c>True</c>
               <c>True</c>
               <c>True</c>
               <c>MUST NOT execute.</c>

               <c>True</c>
               <c>False</c>
               <c>False</c>
               <c>MUST NOT execute.</c>

               <c>True</c>
               <c>True</c>
               <c>False</c>
               <c>MUST NOT execute.</c>

           </texttable>

          </section>

   <section anchor="generic-extension-object" title="GenericExtensionObject">
   <t>
      A GenericTriggerExtension object is a wrapper for managing individual CDNI
      Trigger extensions in an opaque manner.
   </t>

   <t>It is encoded as a JSON object containing the following attributes:</t>

   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">

   <t hangText="Name: cit-extension-type">
        <vspace blankLines="1"/>
        Description: Case-insensitive CDNI trigger extension object type.
        <vspace blankLines="1"/>
        Value: String containing the CDNI Extension Type of the object contained
        in the "cit-extension-value" property (see table in <xref target="trigger-extensibility"/>).
        <vspace blankLines="1"/>
        Mandatory-to-Specify: Yes.
   </t>

   <t hangText="Name: cit-extension-value">
        <vspace blankLines="1"/>
        Description: CDNI trigger extension object.
        <vspace blankLines="1"/>
        Value:  Defined by the value of the "cit-extension-type" property above.
        <vspace blankLines="1"/>
        Mandatory-to-Specify: Yes.
   </t>

   <t hangText="Name: mandatory-to-enforce">
        <vspace blankLines="1"/>
        Description: Flag identifying whether or not the enforcement of this trigger extension is mandatory.
        <vspace blankLines="1"/>
        Value: Boolean.
        <vspace blankLines="1"/>
        Mandatory-to-Specify: No. The default is to treat the trigger extension as mandatory to enforce (i.e., a value of True).
   </t>

   <t hangText="Name: safe-to-redistribute">
        <vspace blankLines="1"/>
   Description: Flag identifying whether or not this trigger extension can be safely redistributed 
   without modification, even if the CDN fails to understand the extension.
        <vspace blankLines="1"/>
   Value: Boolean.
        <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The default is to allow transparent redistribution (i.e., a value of True).
   </t>

   <t hangText="Name: incomprehensible">
        <vspace blankLines="1"/>
   Description: Flag identifying whether or not any CDN in the chain of delegation has failed to understand and/or failed to
   properly transform this trigger extension object. Note: This flag only applies to trigger extension objects whose 
   "safe-to-redistribute" property has a value of False.
        <vspace blankLines="1"/>
   Value: Boolean.
        <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The default is comprehensible (i.e., a value of False).
   </t>
        </list></t>
   </list></t>

            <t>The structure of a JSON-serialized GenericTriggerExtension object containing a specific trigger extension object is illustrated below:</t>
           <sourcecode type="json" name="GenericTriggerExtension">
<![CDATA[
{
  "cit-extension-type":
     <Type of this trigger extension object>,
  "cit-extension-value":
      {
        <properties of this trigger extension object>
      },
  "mandatory-to-enforce": <bool>,
  "safe-to-redistribute": <bool>,
  "incomprehensible": <bool>
}
]]></sourcecode>
   </section>
   <section anchor="trigger-extension-objects" title="Trigger Extension Objects">
      <t>The objects defined below are intended to be used in the GenericTriggerExtension
         object's cit-extension-value field as defined in
         <xref target="generic-extension-object"/>, and their cit-extension-type
         property MUST be set to the appropriate Extension Type as defined in <xref target="trigger-extensibility"/>.
      </t>

      <section anchor="location-policy" title="LocationPolicy Extension">
        <t>A content operation may be relevant for a specific geographical region or need to
           be excluded from a specific region. In this case, the trigger should be applied
           only to parts of the network that are either "included" or "not excluded" by the location policy.
           Note that the restrictions here are on the cache location rather than the client location.</t>

        <t>The LocationPolicy object defines the cache or CDN locations in which the trigger is to be executed, 
        thereby constraining the trigger's scope to those locations. Although users are typically proximate to the 
        corresponding cache nodes, the policy applies to the caches themselves, not to the users' locations.
        </t>

        <t>Example use cases:<list style="symbols">

            <t>Preposition: Because modern streaming content often includes numerous renditions - 
                across resolutions, bitrates, and languages - prepositioning all variants can be untenable.
                The uCDN MAY perform location-aware prepositioning by selecting which content renditions 
                to preposition based on the languages prevalent in a given region. 
                For example, only Danish, Norwegian and Swedish audio or subtitle renditions might be prepositioned 
                in southern Scandinavia. 
            </t>
            <t>Purge: In certain cases, content may have been located on servers in regions
               where the content must not reside. In such cases, a purge operation to
               remove content specifically from that region is required.</t>

        </list></t>



   <t>Object specification:</t>
        <t><list style="empty" hangIndent="3">
        <t><list style="hanging" hangIndent="3"><t hangText="Name: locations">
        <vspace blankLines="1"/>
   Description: An Access List that allows or denies (blocks) the trigger execution per cache location.
        <vspace blankLines="1"/>
        Value: Array of LocationRule objects (see Section 4.2.2.1 of <xref target="RFC8006"/>). 
        The LocationRule utilizes Footprint objects to define footprints in which the rule is to be applied, 
        as defined in Section 4.2.2.2 of <xref target="RFC8006"/> and extended by <xref target="RFC9388"/> to support 
        the "subdivisioncode" footprint type.
        <vspace blankLines="1"/>
        Mandatory-to-Specify: Yes. 
   </t>
   </list></t>
   </list></t>


        <t>
           If a location policy object is not listed within the trigger command, the default behavior is to
           execute the trigger in all available caches and locations of the dCDN.
        </t>
        <t>
           The trigger command is allowed or denied for a specific cache location according to the action of 
           the first location whose footprint matches that cache's location. The evaluation order is implicit 
           and follows the sequence of LocationRule objects as they appear in the extension.
           If two or more footprints overlap, the first footprint that matches against the cache's location
           determines the action a CDN MUST take.
        </t>
        <t>
   If the "locations" property is an empty list, or if none of the listed footprints match the location 
   of a given cache, the trigger MUST be treated as not applicable to that cache - that is, the result 
   is equivalent to a "deny" action.
        </t>


        <t>The following is an example of a JSON-serialized generic trigger extension object containing a location policy
           object that allows the trigger execution in the US but blocks its execution in Massachussetts. 
   The execution of the trigger outside of the US is blocked implicitly.
        </t>
<sourcecode type="json" name="trigger-extension-json"><![CDATA[
{
  "cit-extension-type": "location-policy",
  "cit-extension-value": {
    "locations": [
      {
        "action": "allow",
        "footprints": [{
          "footprint-type": "countrycode",
          "footprint-value": [ "us" ]
        }]
      },
      {
        "action": "deny",
        "footprints": [{
          "footprint-type": "subdivisioncode",
          "footprint-value": [ "us-ma" ]
        }]
      }
    ]
  }
}
       ]]></sourcecode>
      </section>

    <section anchor="time-policy" title="TimePolicy Extension">
    <t>
    The uCDN MAY wish to perform content management operations on the dCDN on a specific schedule.
    The TimePolicy extension allows the uCDN to instruct the dCDN to execute the trigger command
    in a desired time window. For example, a video content provider may wish to pre-populate a new
    episode during off-peak hours so that it is ready on caches at prime time when the episode
    is released for viewing. A scheduled operation enables the uCDN to direct the dCDN in what
    time frame to execute the trigger.
    </t>
    <t>
    This specification supports region-by-region time scheduling when used in conjunction with the Location Policy 
    defined in <xref target="location-policy"/>. The uCDN can trigger separate commands for different geographical regions 
    using a different schedule for each region. This allows the uCDN to control the execution time per region.
    </t>

    <t>Object specification:</t>

    <t><list style="empty" hangIndent="3">
    <t><list style="hanging" hangIndent="3"><t hangText="Name: unix-time-window">
    <vspace blankLines="1"/>
    Description: A UNIX epoch time window in which the trigger SHOULD be executed.
    <vspace blankLines="1"/>
    Value: TimeWindow object using UNIX epoch timestamps (see Section 4.2.3.2 of <xref target="RFC8006"/>).
    <vspace blankLines="1"/>
    Mandatory-to-Specify: No, but exactly one of either "unixEpochWindow" or "utcWindow" MUST be present.
    </t>
    </list></t>
    </list></t>


    <t><list style="empty" hangIndent="3">
    <t><list style="hanging" hangIndent="3"><t hangText="Name: utc-window">
    <vspace blankLines="1"/>
    Description: A UTC time window in which the trigger SHOULD be executed.
    <vspace blankLines="1"/>
    Value: UTCWindow object as defined in <xref target="utc-window"/>.
    <vspace blankLines="1"/>
    Mandatory-to-Specify: No, but exactly one of either "unixEpochWindow" or "utcWindow" MUST be present.
    </t>
    </list></t>
    </list></t>

    <t>
    If a time policy object is not listed within the trigger command, the default behavior
    is to execute the trigger in a time frame most suitable to the dCDN taking under consideration
    other constraints and / or obligations.
    </t>

   <t>
   If trigger processing cannot be completed within the limits specified by the
   TimePolicy extension, the dCDN SHOULD set the trigger state to "failed" and
   include an Error.v2 Description with error "eextension" (see <xref target="error-code"/>).
   </t>

    <t>
    Example of a JSON-serialized generic trigger extension object containing a time policy object that schedules the
    trigger execution to a window between 09:00 01/01/2000 UTC and 17:00 01/01/2000 UTC, using
    the "unix-time-window" property:
    </t>

        <sourcecode type="json" name="genric-trigger-extension-time-policy"><![CDATA[
{
   "cit-extension-type": "time-policy",
   "cit-extension-value":
    {
      "unix-time-window": {
         "start": 946717200,
         "end": 946746000
      }
    },
   "mandatory-to-enforce": true,
   "safe-to-redistribute": true,
   "incomprehensible": false
}
       ]]></sourcecode>

   <section anchor="utc-window" title="UTCWindow">
        <t>
           A UTCWindow object describes a time range in UTC or UTC and a zone offset that can
                be applied by a TimePolicy.
   </t>
   <t>It is encoded as a JSON object containing the following attributes:</t>

   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">
   <t hangText="Name: start">
        <vspace blankLines="1"/>
   Description: The start time of the window.
        <vspace blankLines="1"/>
   Value: Internet date and time as defined in <xref target="RFC3339"/>.
        <vspace blankLines="1"/>
        Mandatory-to-Specify: No. but at least one of "start" or "end" MUST be present and non-empty. 
        If "start" is empty or not specified, the time range is considered to begin at an arbitrary (unspecified) time.
        </t>

        <t hangText="Name: end">
        <vspace blankLines="1"/>
        Description: The end time of the window.
        <vspace blankLines="1"/>
        Value: Internet date and time as defined in <xref target="RFC3339"/>.
        <vspace blankLines="1"/>
        Mandatory-to-Specify: No. but at least one of "start" or "end" MUST be present and non-empty.
        If "end" is empty or not specified, the time range is considered to end at an arbitrary (unspecified) time.
        </t>

          </list></t>
        </list></t>

        <t>
           Example JSON-serialized UTCWindow object that describes a time window from 02:30
           01/01/2000 UTC to 04:30 01/01/2000 UTC:
        </t>
            <sourcecode type="json" name="utcwindow-object"><![CDATA[
{
  "start": "2000-01-01T02:30:00.00Z",
  "end": "2000-01-01T04:30:00.00Z"
}
         ]]></sourcecode>

         <t>
           Example JSON-serialized UTCWindow object that describes a time window in New York time zone offset
           UTC-05:00 from 02:30 01/01/2000 to 04:30 01/01/2000:
         </t>
        <sourcecode type="json" name="utcwindow-object-2"><![CDATA[
{
  "start": "2000-01-01T02:30:00.00-05:00",
  "end": "2000-01-01T04:30:00.00-05:00"
}
         ]]></sourcecode>
        </section>
   </section>
   <section anchor="execution-policy" title="ExecutionPolicy Extension">
   <t>
   Unless specified otherwise, the dCDN is at liberty to decide how to choose trigger commands for execution from all 
   pending commands, whether to process trigger commands sequentially or in parallel, immediately upon acceptance, 
   or with a delay in batches. The uCDN MAY wish to control trigger processing in more detail, including the order 
   of execution, dependencies, and concurrency.
   </t>
   <t>
   Please note that the uCDN MAY request immediate processing of a trigger either by setting its state to "active" at creation time  
   or by modifying a pending trigger to set its state to "active".
   </t>
   <t>
   Example use cases:
   <list style="symbols">
   <t>
   Priority:  The uCDN MAY have multiple trigger commands in "pending" and/or "active" mode. For example, trigger 
   commands with policy constraints, a large number of content objects affected, or other dCDN business logic 
   may take a long time to execute.
   The uCDN MAY wish to prescribe the order in which the dCDN picks up its trigger commands for execution from the 
   "pending" queue, by indicating a relative priority of each trigger. The priority would affect the selection of 
   trigger commands specific to the requesting uCDN. The dCDN MAY separately prioritize triggers from multiple uCDNs 
   subject to its business logic. 
   Additionally, the uCDN MAY wish to prescribe the order in which parts of "active" triggers are processed.
   The priority may affect the order within the same trigger and/or multiple triggers that are in "active" state 
   at the same time. 

   Multiple priority-related use cases exist: 
   <list style="symbols">
   <t> The uCDN needs to introduce an urgent "purge" or "invalidate" trigger into an existing queue of trigger commands 
   to correct wrong versions of content objects published by it</t>
   <t> The uCDN needs to indicate which content objects should be prepositioned, purged, or invalidated first, 
   for example prepositioning newer released content before prepositioning updates to an existing catalog
   </t>
   </list>
   </t>

   <t>
   Prerequisite:  In some cases, the uCDN MAY wish to indicate what trigger commands should be processed and completed 
   before another trigger command is processed. 
   For example, the uCDN MAY want to rectify incorrectly published content by purging content objects and then 
   prepositioning them again. In this case, the uCDN MAY want the preposition trigger command to be processed only 
   after the purge trigger command has been processed because the concurrent processing of these triggers MAY cause 
   the new version of these content objects to be purged. 

   Alternatively, the uCDN MAY wish to condition the execution of purge or invalidation triggers upon the completion 
   or cancellation of long-running preposition triggers to avoid race conditions that would result from processing 
   these in parallel.

   The prerequisite requirement implies that a previous trigger reaches one of the following states:   
   <list style="symbols">
   <t>"complete" for successful completion</t>
   <t>"failed" for failed processing</t>
   <t>"cancelled" for completion of cancellation</t>
   </list>

   </t>
   </list>
   </t>

   <t>
   The ExtensionPolicy extension is encoded as a JSON object containing the following attributes:
   </t>
   <t>
   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">
   <t hangText="Name: priority">
   <vspace blankLines="1"/>
   Description: Relative weight of the trigger. 
   When picking a trigger for execution from all pending triggers posted by each uCDN, 
   the dCDN MUST choose the trigger with the highest priority first. 
   <vspace blankLines="1"/>
   Value: An integer in the range -100 to 100, inclusive.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The value defaults to zero if omitted.
   </t>


   <t hangText="Name: prerequisites">
   <vspace blankLines="1"/>
   Description: Links to trigger resources whose processing should fully finish before starting execution of the current trigger. 
   The triggers SHOULD be in one of the following states to be considered finished: "complete", "failed" or "cancelled".
   <vspace blankLines="1"/>
   Value: A JSON array of zero or more URLs represented as JSON strings.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. In case of a missing or an empty list, no dependencies are assumed.
   </t>

   </list></t>
   </list></t>

   </t>

   <t>
   If the dCDN receives a new trigger with the ExecutionPolicy extension that does not reference an existing trigger URL  
   in the "prerequisites" extension attribute, the dCDN MUST set the trigger state to "failed", set the error to "eextension",  
   and MAY include an optional error description.  
   A trigger modification request that would result in the "prerequisites" attribute containing invalid trigger URLs  
   MUST be rejected by the dCDN with status code 409 ("Conflict").  
   URL values that reference existing finished triggers are allowed but ignored.
   </t>

   <t>
   A dCDN SHOULD reject a trigger whose ExecutionPolicy contains a "prerequisites" dependency referencing a trigger in the "processed" 
   state, since completion of such a trigger cannot be confirmed.  
   The rejection MUST be indicated by returning HTTP status code 400 ("Bad Request").
   </t>


   <t>
   The following is an example of a JSON-serialized generic extension trigger object containing an execution 
   policy object that specifies trigger priority of 100, and makes its execution 
   dependent on the completion of the previously created triggers:


   <sourcecode type="json" name="extension-execution-policy"><![CDATA[
{
  "cit-extension-type": "execution-policy",
  "cit-extension-value":
  {
    "priority": 100,
    "prerequisites": [ 
     "https://dcdn.example/cit/b1467469-3cf3-4613-8629-814cd938f30b",
     "https://dcdn.example/cit/c73a9911-298b-4ee3-bbab-03bce07b7d5c"
    ]
  }
}
       ]]></sourcecode>
   </t>


   </section>

   <section title="Combining Trigger Extensions" anchor="combining-trigger-extensions">
   <t>
   The uCDN MAY combine multiple options in the same trigger command. 
   The dCDN determines how to handle an incoming trigger according to the following rules:
    <t>
   <list style="numbers">

   <t>
   When the dCDN receives a request to create a trigger, it MUST reject the request with status code 400 ("Bad Request")
   if the trigger depends on other pending triggers with lower priority in order to prevent deadlocks.
   </t>

   <t>
   Otherwise, if the request for new trigger resource creation sets its state to "active":
   <list style="symbols">
<t>
If the trigger has a TimePolicy extension that has a "start" attribute set in the future,
the dCDN MUST reject the request.
</t>
<t>
Otherwise, if the trigger has an ExecutionPolicy extension, with prerequisite triggers that
are not finished at the time of the request, the dCDN MUST reject the request.
</t>
<t>
Otherwise, if the trigger has a lower priority than pre-existing triggers in "pending" state, 
the dCDN MUST reject the request. Please note that the trigger has 
an implicit priority of zero if no priority is explicitly specified.
</t>

<t>
Otherwise, if the trigger has a TimeWindow that ends before the start of the TimeWindow of 
any trigger on which it depends,  or before the start of the TimeWindow of any pending trigger with 
higher priority,  the dCDN MUST reject the request.
</t>

<t>
Otherwise, the dCDN MAY still reject the trigger due to its 
business logic (e.g,, if the dCDN processes triggers at specific times during the day).
</t>

<t>
Otherwise, the dCDN SHOULD create the trigger in "active" state and begin its processing.
</t>

<t>
In all of the above failure cases, the dCDN MUST reject the request by returning a 4xx or 5xx HTTP status code.  The response body 
for a rejected request SHOULD contain an Error.v2 Description object identifying the reason for the rejection.
</t>
</list>
</t>

<t>
Otherwise, the dCDN SHOULD create the new trigger resource as requested and set its state to "pending". 
</t>

<t>
The dCDN MAY start the trigger processing at any time after the trigger creation, as long as the 
prerequisites are met, i.e., the start of processing is within the TimePolicy window, there are 
no other pending triggers with higher priority, and there are no incomplete prerequisite triggers.
</t>

<t>
The dCDN SHOULD periodically re-evaluate the pending trigger queue for triggers that have a TimePolicy set,
to ensure that processing of such triggers completes before the corresponding TimePolicy window expires.
If during such evaluation a pending trigger is deemed to have expired, the dCDN MUST set the trigger
state to "failed".
</t>

<t>
Whenever a trigger reaches a terminal state, the dCDN SHOULD re-evaluate the queue of pending triggers.
If during such evaluation a pending trigger is deemed to have expired, the dCDN MUST set the trigger
state to "failed" and the error to "ereject".
Otherwise, the dCDN MAY start processing triggers that were previously dependent on the completed trigger.
</t>

<t>
Whenever a pending trigger becomes eligible for processing, the dCDN SHOULD re-evaluate the pending 
trigger queue.
If during such evaluation a pending trigger is deemed to have expired, the dCDN MUST set the trigger
state to "failed" and the error to "ereject".  Otherwise, the dCDN MAY start processing additional 
triggers that could not be processed earlier due to their lower priority relative to the active trigger.
</t>

<t>
When the dCDN receives a request to modify the priority and/or dependencies and/or TimeWindow of 
a pending trigger, it MUST reject the request with status 409 ("Conflict") if the change would result in 
that trigger depending on other triggers with lower priority, or its TimeWindow ending before the start of 
the TimeWindow of any trigger it depends on,  or before the start of the TimeWindow of any trigger with 
higher priority.
</t>

<t>
Otherwise, the dCDN MUST reject the request with status code 409 ("Conflict") if the change would 
result in the trigger depending on other triggers that, directly or indirectly, depend on the 
modified trigger.
</t>

<t>
When the dCDN receives a request to modify the TimeWindow extension, it MUST reject the request with 
status code 409 ("Conflict") if the modification would set the "end" time to a value in the past.
</t>


<t>
Otherwise, the dCDN SHOULD accept the request and evaluate whether the modified trigger becomes
eligible for processing as a result of the change.
If at this time, the modified trigger has a TimePolicy "end" time set in the past, the dCDN MUST set the trigger
state to "failed" and the error to "ereject".
</t>


<t>
When the dCDN receives a request to change the state of a pending trigger to "active",  
it MUST reject the request with status code 409 ("Conflict") if, as a result of the change,  
the trigger would depend on incomplete triggers, have lower priority than other pending triggers,  
have a TimeWindow start time in the future, or set a new TimeWindow end time in the past.
</t>
<t>
Whenever a 409 ("Conflict") status code is returned, the dCDN SHOULD include an Error.v2 Description 
in the response body, with the error code set to "eextension" and a human-readable error description.
</t>
<t>
In all of the above cases involving asynchronous error reporting within accepted triggers, the dCDN SHOULD 
also provide a human-readable error description in the Error.v2 Description returned in the trigger resource.
</t>

<t>
Otherwise, the dCDN MAY still reject the request with status code 409 ("Conflict") if the processing of the trigger
could not be started immediately due to the dCDN business logic. 
</t>

<t>
Otherwise, the dCDN MUST set the trigger state to "active" and start its processing.
</t>
</list>
   </t> 
   </t>
   </section>

   </section>
   </section>
   <section title="Trigger Labels" anchor="trigger-labels">
   <t>
   Trigger labels provide a framework for the uCDN to associate a set of key-value pairs with trigger resources.
   </t>

   <t>
   The labels may be used to simplify the management of a large number of triggers by grouping related triggers
   and tracking their status using the trigger collection resource associated with the label value, when published by the dCDN
   (see <xref target="ci-trigger-collection-resource"/> for more details).
   In this case, the label values remain fully opaque to the dCDN and are evaluated for trigger grouping purposes only.
   </t>
   </section>

   <section title="Trigger State" anchor="trigger-state">
   <t>
   The trigger state describes the current state of the triggered activity. 
   It MUST be one of the JSON strings in the following table:
   </t>

   <texttable style="full"><ttcol align="left">JSON string</ttcol>
   <ttcol align="left"> Description </ttcol>
   <c>pending</c>
   <c>The trigger processing has not begun yet.</c>
   <c>active</c>
   <c>The trigger is currently being executed.</c>
   <c>complete</c>
   <c>The trigger processing completed successfully.</c>
   <c>processed</c>
   <c>The trigger has been created, and no further status update 
           will be made (can be used in cases where completion cannot be confirmed).</c>
   <c>failed</c>
   <c>The trigger processing could not be completed.</c>
   <c>cancelling</c>
   <c>The trigger cancellation has been requested by the uCDN.</c>
   <c>cancelled</c>
   <c>The trigger has been cancelled in response to a uCDN request.</c>
   </texttable>
   
   <t>
   Along with the trigger state, the trigger resource has a state reason property,
   allowing the dCDN to provide additional information for the trigger state.
   For example, the dCDN may indicate that the trigger state is "pending" due to one of the execution prerequisites not
   being fulfilled. Such a prerequisite may be specified via one of the extensions.
   </t>

   </section>
   <section title="Trigger Errors" anchor="trigger-errors">
   <section title="Error.v2 Description" anchor="error-v2-description">
   <t>
   An Error.v2 Description reports an error associated with a trigger. The same representation is used in two contexts: 
   within an accepted trigger, to report failures that occur during trigger processing; and within the body of a 4xx 
   or 5xx response, to report the reason a trigger creation request was rejected.
   </t>

   <t>
   A request rejected with a 4xx or 5xx status code (see <xref target="http-error-codes"/>) does not create a trigger resource; 
   the Error.v2 Description in the response body identifies the cause of the rejection. Once a request has been accepted, 
   failures in the resulting trigger processing are reported only through Error.v2 Descriptions in the trigger resource, 
   not through HTTP status codes.
   </t>
   <t>
   In a 4xx or 5xx response body, the Error.v2 Description is carried as a standalone JSON object
   with the payload type "ci-trigger-error.v2". Within a trigger resource, it is carried as a member
   of the "errors" array with the payload type of the enclosing resource.
   </t>

   <t>
   The Error.v2 Description is encoded as a JSON object with the following attributes:
   </t>

   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3"><t hangText="Name: error">
   <vspace blankLines="1"/>
   Description: Specifies the known error code for the condition that caused the trigger to fail.
   <vspace blankLines="1"/>
   Value: Error Code, as defined in <xref target="error-code"/>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: Yes.
   </t>

   </list></t>
   </list></t>

   
   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3"><t hangText="Name: description">
   <vspace blankLines="1"/>
   Description: A human-readable description of the error.
   <vspace blankLines="1"/>
   Value: A JSON string, the human-readable description.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No.
   </t>

   </list></t>
   </list></t>

   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3"><t hangText="Name: specs">
   <vspace blankLines="1"/>
   Description: Array of trigger spec objects from the corresponding "specs" array in the trigger resource.
   Only those specs to which the error applies are listed. 
   <vspace blankLines="1"/>
   Value: Array of trigger specs, as defined in <xref target="trigger-specs"/>, where each spec object 
   MUST be exactly as it appears in the trigger resource.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: Yes. 
   </t>

   </list></t>
   </list></t>

      <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3"><t hangText="Name: extensions">
   <vspace blankLines="1"/>
   Description: Array of trigger extension objects copied from the corresponding "extensions" array
   in the trigger resource.  Only those extensions to which the error applies are included, but 
   those extensions MUST be exactly as they appear in the trigger resource.
   <vspace blankLines="1"/>
   Value: Array of GenericTriggerExtension objects, where each extension object is copied
   from the "extensions" array values in the trigger resource.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The "extensions" array SHOULD be used only if the error relates to
                extension objects. Property omission should be interpreted as 
                "the error is not related to any extension".
   </t>

   </list></t>
   </list></t>

   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3"><t hangText="Name: cdn-id">
   <vspace blankLines="1"/>
   Description: The CDN PID of the CDN where the error occurred. The "cdn-id" property is used
                by the originating uCDN or by the propagating dCDN to distinguish in which CDN the 
                error occurred.
   <vspace blankLines="1"/>
   Value:  A non-empty JSON string, where the string is a CDN PID as defined in <xref target="cdn-pid"/>
   <vspace blankLines="1"/>
   Mandatory-to-Specify: Yes. The dCDN may use its own CDN PID if it does not want to expose the PIDs of its dCDNs.
   </t>

   </list></t>
   </list></t>

   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3"><t hangText="Name: objects">
   <vspace blankLines="1"/>
   Description: List of objects that failed to be processed during trigger execution.
   <vspace blankLines="1"/>
   Value:  An array of <xref target="content-object">ContentObject</xref> objects. 
   The dCDN SHOULD provide the list of objects that it failed to process during trigger execution with 
   <xref target="objectlist-spec"/>, provided that the dCDN advertised 
   <xref target="extended-status-capability-object">support for extended status</xref>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. An empty array is allowed and is equivalent to omitting "objects" from the Error.v2 Description.
   </t>
   </list></t>
   </list></t>

   <t>
   In a cascade of CDNs, a downstream CDN MAY reject a propagated trigger creation request with a 4xx or 5xx status code, 
   returning an Error.v2 Description in the response body. Because the transit CDN has already accepted the corresponding 
   request from its own upstream, it cannot relay this rejection as an HTTP status code. Instead, the transit CDN includes
   the received Error.v2 Description in the "errors" array of its own trigger status resource, reporting it to the upstream CDN 
   as a processing error of the accepted trigger. 
   </t>


          <t>Example of a JSON-serialized Error.v2 Description object reporting a malformed HLS playlist:
          </t>

          <sourcecode type="json" name="Error.v2 Description">
<![CDATA[
{
  "error": "econtent",
  "description": "Failed to parse HLS object list",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/title/index.m3u8",
        "type": "hls"
      }]
   }}
  ],
  "objects": [{ 
    "href": "https://www.example.com/hls/title/index.m3u8", 
    "type": "hls"
  }],
  "cdn": "AS64500:0"
}
         ]]></sourcecode>

          <t>Example of a JSON-serialized Error.v2 Description object reporting an unsupported extension object:
          </t>

<sourcecode type="json" name="Error.v2 Description unsupported extension"><![CDATA[
{
  "errors": [{
    "error": "eextension",
    "description": "unrecognized extension location-policy",
    "specs": [{
      "trigger-subject": "content",
      "cit-spec-type": "urls",
      "cit-spec-value": {
        "urls": [
          "https://www.example.com/a/b/c/1",
          "https://www.example.com/a/b/c/2"
        ]
      }
    }],
    "extensions": [{
      "cit-extension-type": "location-policy",
      "cit-extension-value": {
        "locations": [{
          "action": "deny",
          "footprints": [{
              "footprint-type": "countrycode",
              "footprint-value": [ "ca" ]
            }]
          }]
        }
    }],
    "cdn": "AS64500:0"
  }]
}
]]></sourcecode>

   </section>

   <section title="Error Code" anchor="error-code"><t>
   This type is used by the dCDN to report an error associated with a trigger (see <xref target="error-v2-description"/>), 
   whether it arises during asynchronous processing or is reported in a synchronous 4xx or 5xx response to a rejected request.
   All Error Codes MUST be registered in the IANA "CDNI CI/T Error Codes" registry 
   (see <xref target="cdni-cit-error-code-registry"/>). Unknown Error Codes
   MUST be treated as fatal errors, and the request MUST NOT be automatically retried without modification.</t>

   <t>
   The following Error Codes are defined by this document and MUST be supported by 
   an implementation of the CI/T v2 interface.
   </t>

   <texttable style="full">
   <ttcol align="left"> Error Code</ttcol>
   <ttcol align="left"> Description</ttcol>
   <c>emeta</c>
   <c>The dCDN was unable to acquire and/or does not have metadata required to fulfill the request.</c>
   <c>econtent</c>
   <c>The dCDN was unable to acquire content (CI/T "preposition" commands only).</c>
   <c>eperm</c>
   <c>The uCDN does not have permission to create the trigger as requested 
      (e.g., the data is owned by another CDN).
   </c>
   <c>ereject</c>
   <c>The dCDN is not willing to process the trigger (for example, a "preposition" request for content 
      whose TimePolicy extension time limit has expired).
   </c>
   <c>ecdn</c>
   <c>An internal error in the dCDN or one of its dCDNs.</c>
   <c>ecancelled</c>
   <c>The uCDN cancelled the request.</c>
   <c>eunsupported</c>
   <c>The trigger resource used an "action type" that is not supported by the dCDN.</c> 
   <c>espec</c>
   <c>An error occurred while parsing a trigger spec, or that the specific trigger spec is not supported by the CDN.</c>
   <c>esubject</c>
   <c>An error occurred while parsing a trigger subject, or that the specific trigger subject is not supported by the CDN.</c>
   <c>eextension</c>
   <c>An error occurred while parsing or applying a trigger extension, or that the specific extension is not supported by the CDN.</c>
   </texttable>

   <t>
   A dCDN MUST use these Error Codes only to communicate errors that arise during asynchronous trigger processing after the trigger 
   has been created, or when a transit CDN receives a synchronous rejection from one or more of its downstream CDNs after it has 
   already created the trigger resource itself.
   Any error condition that the dCDN can determine at trigger creation time MUST be communicated then, using a 4xx HTTP status code, 
   and MUST NOT be deferred to an asynchronous Error Code. Such conditions include, but are not limited to, the dCDN's own lack of 
   support for a trigger type, spec, subject, or extension, and a lack of permission for the uCDN to create the trigger as requested.
   </t>

   </section>
   </section>
   </section>
 

   <section title="Trigger Index Resource" anchor="ci-trigger-index-resource">
   <t>        
   As described in <xref target="model-for-cdni-triggers-rest"/>, the dCDN maintains RESTful trigger resources that  
   represent actions ("triggers") requested by the uCDN for execution by the dCDN.
   </t>
   
   <t>
   The trigger index resource maintains references to all trigger collection resources that can be used to retrieve triggers.
   The dCDN MUST create the trigger index resource when it first instantiates the CI/T interface for a uCDN, 
   before any trigger resources are created.
   The dCDN MUST also create the unfiltered trigger collection containing all triggers, as well as trigger collections for 
   each trigger state, and include references to these collections in the top-level trigger index resource.
   The dCDN MUST NOT remove the trigger index resource, the unfiltered trigger collection, or the state-based trigger 
   collections once they have been created, as long as it continues to offer CI/T services to the uCDN.
   </t>

   <t>
   The dCDN MUST update the unfiltered trigger collection, the state-based trigger collections, and any additional filtered 
   trigger collections it publishes, when triggers are created or deleted or when their state changes.
   </t>

   <t>
   The dCDN MAY create additional trigger collection resources with other filters, such as per-label collections or collections 
   combining state and label criteria. The dCDN is not required to publish a collection for every label or filter combination in use; 
   the set of filtered collections beyond those required above is chosen by the dCDN. For every filtered collection it publishes, 
   the dCDN MUST keep the collection contents and its trigger index reference current, and SHOULD remove the collection when no 
   triggers remain that match its filter.
   </t>
   <t>
   As a top-level resource, the trigger index also includes global dCDN attributes, such as the "staleresourcetime" attribute,
   which regulates the expiration of completed triggers, and the "cdn-id" attribute, which indicates the CDN PID of the dCDN.
   </t>
   <t>
   The trigger index resource representation MUST use a MIME media type of "application/cdni; ptype=ci-trigger-index.v2".
   </t>
   <t>
   A trigger index is encoded as a JSON object containing the following attributes:
   </t>
   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">

   <t hangText="Name: collections">
   <vspace blankLines="1"/>
   Description: Array of <xref target="trigger-collection-view">Trigger Collection View</xref> objects.
   <vspace blankLines="1"/>
   Value: An array of JSON-encoded Trigger Collection View objects, one for each existing trigger collection resource.
   This includes the unfiltered trigger collection, per-state trigger collections (one for each trigger state 
   as specified in <xref target="trigger-state"/>), and any additional filtered trigger collections the dCDN publishes.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: Yes.
   </t>
   <t hangText="Name: staleresourcetime">
   <vspace blankLines="1"/>
   Description: The length of time for which the dCDN guarantees to keep a completed trigger resource. 
   After this time, the dCDN SHOULD delete the trigger resource and all references to it from the collection.
   <vspace blankLines="1"/>
   Value: A JSON number, which must be a positive integer, representing time in seconds.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: Yes.
   </t>

   <t hangText="Name: cdn-id">
   <vspace blankLines="1"/>
   Description: The dCDN PID.
   <vspace blankLines="1"/>
   Value: A JSON string, dCDN's PID, as defined in <xref target="cdn-pid"/>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. 
   </t>
   </list></t>
   </list></t>


   </section>

   <section title="Trigger Collection Resource" anchor="ci-trigger-collection-resource">

   <t>
   The collection of trigger resources represents triggers created by the dCDN, optionally filtered by a parameter.
   </t>
   <t>
   Trigger resources in a collection are usually represented using their unique URIs. 
   Note that the collection may refer to CI/T Resources from several versions of CI/T objects,
   i.e., a subsequent call for the retrieval of the relevant trigger resource may provide 
   objects of various MIME media types: ci-trigger-status as defined in <xref target="RFC8007"/>, ci-trigger.v2 
   defined in this document, or objects of future CI/T objects versions, based on the version of the JSON object 
   used to create the trigger.
   </t>

   <t>
   To allow the uCDN to check the status of multiple triggers in a single request, the dCDN maintains filtered 
   representations of the trigger collection that contain a subset of all triggers.
   Per-state trigger collections are mandatory, as specified in Section 4.2. Trigger collections with any other filter 
   are optional-to-implement. For every filtered collection it implements, the dCDN MUST include a reference to it in 
   the trigger index resource. 
   </t>

   <t>
   All trigger collection representations MUST use a MIME media type of "application/cdni; ptype=ci-trigger-collection.v2".
   </t>

   <t>
   A trigger collection is encoded as a JSON object containing the following attributes:
   </t>

   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">

   <t hangText="Name: trigger-urls">
   <vspace blankLines="1"/>
   Description: Links to trigger resources in the collection.
   <vspace blankLines="1"/>
   Value: A JSON array of zero or more URLs represented as JSON strings.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: Yes.
   </t>

   <t hangText="Name: trigger-objects">
   <vspace blankLines="1"/>
   Description: Array of all triggers in the collection. SHOULD be returned only when an extended trigger 
   collection view is requested as described in <xref target="polling-collections-extended"/>.
   <vspace blankLines="1"/>
   Value: An array of JSON-encoded trigger resources.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The "trigger-objects" attribute SHOULD only be used by the dCDN that supports and advertises 
   the appropriate extended status for trigger collections (see <xref target="extended-status-capability-object"/> 
   for details).
   </t>

   <t hangText="Name: filter">
   <vspace blankLines="1"/>
   Description: Describes the filter applied to select the triggers in the collection.
   <vspace blankLines="1"/>
   Value: A Trigger Filter object, as defined in <xref target="trigger-filter"/>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. If the "filter" attribute is omitted or is an empty object,
   the trigger collection MUST include all existing triggers.
   </t>
   
   </list></t>
   </list></t>

      <section title="Trigger Collection View" anchor="trigger-collection-view">
      <t>
      The Trigger Collection View provides a brief description of a trigger
      collection resource within the trigger index. It is encoded as a JSON
      object containing the following attributes:
      </t>
      <t>
      The "filter" attribute describes the selection criteria used for the
      referenced trigger collection.  If "filter" is omitted, the
      collection represents all triggers.
      </t>
      <t><list style="empty" hangIndent="3">
      <t><list style="hanging" hangIndent="3">


      <t hangText="Name: filter">
      <vspace blankLines="1"/>
      Description: Describes the filter applied to select the triggers included in the described trigger collection.
      <vspace blankLines="1"/>
      Value: A Trigger Filter object, as defined in <xref target="trigger-filter"/>.
      <vspace blankLines="1"/>
      Mandatory-to-Specify: No. If the "filter" attribute is omitted or is an empty object,
      the described trigger collection includes all existing triggers.
      </t>
      
      <t hangText="Name: collection-uri">
            <vspace blankLines="1"/>
            Description: URI of the trigger collection.
            <vspace blankLines="1"/>
            Value: A URI represented as a JSON string.
            <vspace blankLines="1"/>
            Mandatory-to-Specify: Yes.
      </t>
      
      </list></t>
      </list></t>
      </section>
   </section>

   <section title="Other CI/T Objects and Properties" anchor="other-cit-objects-and-properties">
   <t>
   This section describes common CI/T objects, which are used as part of the specification of several other CI/T 
   objects, and their encodings.
   </t>

   <section title="URL Type" anchor="url-types">
   <t>
   This type is used by the uCDN to indicate how URLs referenced by trigger specifications are to be interpreted. 
   URL types apply to trigger specs that reference URLs, such as <xref target="urls-spec"/>,
   <xref target="uri-pattern-match-spec"/>, <xref target="uri-regex-match-spec"/>, and <xref target="objectlist-spec"/>.
   </t>
 
   <t> The following URL types are defined by this document: </t>
   <texttable style="full">
     <ttcol align="left">URL Type</ttcol>
     <ttcol align="left">Description</ttcol>
     <c>published</c>
     <c>Published URLs used by end users to access content.</c>
     <c>private</c>
     <c>Private URLs used by the dCDN to look up content objects in cache.</c>
   </texttable>
   <t>Implementations of the CI/T interface MUST support the "published" URL type. Support for the "private" URL type is OPTIONAL. </t>
   <t> If both URL types are supported by the dCDN, the uCDN MUST use only one URL type within a given trigger.</t>
 
   <section title="Published URL Type" anchor="url-type-published">
   <t>
   Published URLs are the URLs used by end users. When processing a trigger that uses this URL type, the dCDN MUST be able to match the
   URLs with metadata objects provided by the uCDN. When this is not the case, the dCDN MUST return the error code "emeta".
   </t>
 
   <t>
   When processing published URLs in a "preposition" trigger action, the dCDN MUST invoke the metadata processing it would 
   normally perform during content acquisition to satisfy an end-user request, for example SourceMetadata (see Section 4.2.1 of 
   <xref target="RFC8006"/>).
   </t>
   </section>
 
   <section title="Private URL Type" anchor="url-type-private">
   <t>
   Private URLs are based on cache keys dynamically constructed from properties of HTTP requests and/or responses. For example, an origin
   might specify a cache key using a value returned in a specific HTTP response header.
   </t>
 
   <t>The uCDN MAY use private URLs in "purge" or "invalidate" trigger actions to simplify processing.</t>
 
   <t>
   A dCDN supporting the private URL type SHOULD advertise this capability via FCI using <xref target="url-type-capability-object"/>. 
   If the private URL type is not supported, the dCDN MUST reject the request with a 400 ("Bad Request") HTTP status code. 
   The response body SHOULD contain an Error.v2 Description with the error code "eunsupported", identifying the unsupported action. 
   Such a request does not create a trigger resource.
   </t>
   </section>
   </section>

   <section title="Content Object" anchor="content-object">
   
   <t>
   A ContentObject represents a content object referenced by a trigger and is used to construct lists of objects both in trigger specifications and in
   trigger status reporting. ContentObject objects convey metadata associated with objects, including labels, object type, and object size.
   </t>
   
   <t>
   The object type determines how the referenced object is processed by the dCDN. A ContentObject MAY represent either a single content object or an
   object that, when processed, yields references to additional objects. Such expansion allows structured object descriptions to be resolved into
   individual objects affected by a trigger.
   </t>
   
   <t>ContentObject objects are used in two contexts:</t>
   
   <t>
   <list style="symbols">
   <t>to identify objects that are the subject of a trigger action; and</t>
   <t>to report objects derived or processed by the dCDN during trigger execution.</t>
   </list>
   </t>

   <t>
   Please note that when the uCDN accesses ContentObject resources published by the dCDN, the same
   interface authentication and authorization requirements would apply, as when accessing the interface itself.
   </t>
   <t>Unless otherwise specified, the ordering of ContentObject elements does not imply processing order.</t>
   <t>
   It is RECOMMENDED that ContentObject lists be flattened, when used by the dCDN to return trigger status, avoiding the
   use of recursion, in order to simplify processing.
   </t>
   
   <t>
   The ContentObject properties are defined as follows:
   </t>
   
   <t><list style="hanging" hangIndent="3">
   
   <t hangText="Name: href">
   <vspace blankLines="1"/>
   Description: URI identifying the referenced object.
   <vspace blankLines="1"/>
   Value: A URI represented as a JSON string.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: Yes.
   </t>
   
   <t hangText="Name: type">
   <vspace blankLines="1"/>
   Description: Indicates how the referenced object is interpreted during trigger processing.
   <vspace blankLines="1"/>
   Value: ContentObjectType (see <xref target="content-object-types"/>).
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. If omitted, the object is treated as a single content object.
   </t>
   
   <t hangText="Name: size">
   <vspace blankLines="1"/>
   Description: Object size in bytes. 
   This attribute MAY be used by the dCDN to make processing decisions, such as ignoring objects that are too small or too large.
   <vspace blankLines="1"/>
   Value: Integer.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No.
   </t>
   
   <t hangText="Name: labels">
   <vspace blankLines="1"/>
   Description: Labels associated with the ContentObject. The semantics are identical to trigger labels.
   <vspace blankLines="1"/>
   Value: A JSON object, whose members are the object labels. Each member name is a label key and each member value
   is the corresponding label value; both are JSON strings.
   A label key and a label value MUST each be no more than 63 characters in length, 
   MUST begin with a letter or a number, and MAY contain letters, numbers, hyphens, dots, and underscores.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. The default is no labels.
   </t>
   
   </list></t>
   <t>
   The following is an example of JSON-serialized ContentObjects:
<sourcecode type="json" name="content-object-json"><![CDATA[
  {
    "href": "https://example.com/hls/35cdc008/index.m3u8",
    "type": "hls", 
    "labels": { 
      "type": "video", 
      "protocol": "hls"
    } 
  }

  {
    "href": "https://example.com/dash/35cdc008/main.mpd",
    "type": "dash",
    "labels": { 
      "type": "video", 
      "protocol": "mpeg-dash"
    } 
  }

  {
    "href": "https://example.com/img/35cdc008/thumb-l.jpg",
    "size": 102600,
    "labels": { "type": "thumbnail" } 
  }

  {
    "href": "https://example.com/img/35cdc008/thumb-s.jpg",
    "size": 14535,
    "labels": { "type": "thumbnail" } 
  }
]]></sourcecode>
   </t>
   
   <section title="Content Object Types"
            anchor="content-object-types">
   
   <t>
   The "type" attribute specifies how a ContentObject is interpreted by the
   dCDN. The following ContentObject types are defined by this document:
   </t>

   <texttable style="full">
   <ttcol align="left">Content Object Type</ttcol>
   <ttcol align="left">Description</ttcol>
 
   <c>object</c>
   <c>A single object identified by a URI.</c>
 
   <c>hls</c>
   <c>An object containing references to additional objects using the playlist format defined by HTTP Live Streaming (HLS)
   (<xref target="RFC8216"/>).</c>
 
   <c>dash</c>
   <c>An object containing references to additional objects using the description format defined by MPEG-DASH
   (<xref target="MPEG-DASH"/>).</c>
 
   <c>mss</c>
   <c>An object containing references to additional objects using the format defined by Microsoft Smooth Streaming
   (<xref target="MSS"/>). The referenced object MAY be used to derive individual content objects.</c>
 
   <c>json</c>
   <c>List of objects encoded using JSON as defined in <xref target="content-object-type-json"/>.</c>
 
   <c>text</c> <c>List of objects encoded as plain text, as defined in <xref target="content-object-type-text"/>.</c>
   </texttable>   
   </section>

   <section title="JSON-encoded Content Object type" anchor="content-object-type-json">
 
   <t>
   When encoded using JSON, the representation consists of an array of ContentObject JSON objects. 
   Depending on the specified ContentObject type, an object MAY expand into additional content objects, 
   enabling recursive object lists that MAY combine ContentObjects of different types.
   </t> 
   <t> The content objects encoded using JSON should follow the JSON grammar specification <xref target="ECMA404"/>,
   including explicit newline encoding and absolute URLs MUST be used at all times.
   </t>
   </section>

   <section title="Text-encoded Content Object type" anchor="content-object-type-text">
   <t>
   When encoded using the text representation, each line contains a single object URI.
   Lines are separated by a line-feed character. Empty lines MAY be ignored. 
   </t>
   <t>
   Unlike the <xref target="content-object-type-json">JSON-encoded Content Object type</xref>,
   the text-based ContentObject  will not support a recursive object list structure, and
   every object specified in it SHOULD be acted upon without additional processing.
   </t>
   
   </section>
   </section>

   <section title="Extended Status Type" anchor="extended-status-types">
   
   <t>
   Extended Status Type identifies optional representations that provide
   additional information about trigger processing beyond the base resource representation. 
   Support for Extended Status is advertised by the dCDN using the FCI capability defined in <xref target="extended-status-capability-object"/>.
   </t>
   
   <t>
   When supported and requested, Extended Status representations MAY be returned in 
   trigger resources or trigger collections to expose additional status information or processing details.
   </t>
   
   <t>
   The following Extended Status Types are defined by this document:
   </t>
   
   <texttable style="full">
     <ttcol align="left">Extended Status Type</ttcol>
     <ttcol align="left">Description</ttcol>
   
     <c>trigger-state</c>
     <c>Provides additional information using "objects" attribute in the <xref target="ci-trigger-resource">Trigger</xref> object.</c>
   
     <c>error-v2-description</c>
     <c>Provides additional information using the "objects" attribute in the <xref target="error-v2-description">Error.v2 description</xref> object.</c>
   
     <c>trigger-collection</c>
     <c>Provides an extended representation of triggers using the "trigger-objects" attribute in the <xref target="ci-trigger-collection-resource">Trigger Collection</xref> object.</c>
   </texttable>
   
   <t>
   A dCDN MAY support one or more Extended Status Types. A uCDN MAY request an Extended Status representation. 
   If the uCDN requests an Extended Status Type that the dCDN has not advertised as a capability, the dCDN MUST
   reject the request with an appropriate error response.
   </t>
   
   </section>


   <section anchor="cdn-pid" title="CDN Provider ID">
   <t>  
   The CDN PID consists of the two characters "AS" followed by the CDN provider's Autonomous System number 
   <xref target="RFC1930"/>, then a colon (":") and an additional qualifier that is used to guarantee uniqueness in case 
   a particular AS has multiple independent CDNs deployed -- for example, "AS64496:0".
   </t>

   <t>  
   If the CDN provider has multiple ASes, the same AS number SHOULD be used in all messages from that CDN provider, 
   unless there are multiple distinct CDNs.
   </t>

   <t>  
   If the CDNI Request Routing Redirection interface (RI) described in <xref target="RFC7975"/> is implemented by the dCDN, 
   the CI/T interface and the RI SHOULD use the same CDN PID.
   </t>

   <t>
   The use of an Autonomous System (AS) number as part of the CDN PID provides a convenient identifier for many deployments; 
   however, not all CDN providers operate their own AS, and some providers may operate multiple CDNs spanning several ASes or 
   within networks owned by third parties. 
   Consequently, the AS-based format described above SHOULD be considered one possible identifier construction rather than a mandatory
   or universally applicable scheme.
   </t>
   
   <t>
   A CDN provider MAY use an alternative identifier construction, provided that the resulting CDN PID remains globally unique 
   within the scope of CDNI interactions and is used consistently across CDNI interfaces.
   Future specifications may define additional or more flexible mechanisms for CDN provider identification.
   </t>


   </section>
   <section anchor="trigger-filter" title="Trigger Filter">
   <t>
     The Trigger Filter object describes the criteria used to select the
     triggers in a trigger collection.  It is used by the Trigger Collection
     resource (<xref target="ci-trigger-collection-resource"/>) and the Trigger
     Collection View (<xref target="trigger-collection-view"/>).
   </t>
   <t>
     A Trigger Filter is encoded as a JSON object containing the following
     attributes, each of which is optional:
   </t>
   <t>
     <list style="hanging">
       <t hangText="Name: state">
       <vspace blankLines="1"/>
       Description: The trigger state shared by all triggers in the collection.
       <vspace blankLines="1"/>
       Value: Trigger state, as defined in <xref target="trigger-state"/>.
       <vspace blankLines="1"/>
       Mandatory-to-Specify: No.
       </t>

       <t hangText="Name: labels">
       <vspace blankLines="1"/>
       Description: Labels shared by all triggers in the collection.
       <vspace blankLines="1"/>
       Value: A JSON object containing one or more members, each representing a label.  
       Each member name is a label key and each member value is the corresponding label value; both are JSON strings, 
       subject to the same syntax constraints as the "labels" trigger attribute (<xref target="ci-trigger-resource"/>).  
       The "labels" attribute, if present, MUST NOT be an empty object.
       <vspace blankLines="1"/>
       Mandatory-to-Specify: No.
       </t>
    </list>
  </t>

  <t>
  A trigger belongs to the collection if and only if it satisfies every
  attribute of the Trigger Filter object: the trigger's state MUST equal
  the value of the "state" attribute, if present, and the trigger MUST
  carry every label listed in the "labels" attribute, if present.  Filter
  criteria are combined as a logical AND; a filter offers no means of
  expressing alternatives.
  </t>
  </section>
  </section>
  </section>

    <section anchor="footprint-and-capabilities" title="Footprint and Capabilities">
      <t>
        This section covers the FCI objects required for the advertisement of the specs, extensions, and properties
        introduced in this document.
      </t>


     <section title="CI/T Endpoint Capability Object" anchor="cit-trigger-endpoints-capability-object">
        <t>
      The CI/T trigger endpoint capability object is used to advertise one or more CI/T interface endpoints 
      along with CI/T interface versions supported by these endpoints. 
      The capability type is "FCI.CITEndpoint".
      Version 1, as originally defined in <xref target="RFC8007"/>, is the default if this capability is not explicitly declared.
        </t>

   <t>
        A CI/T Endpoint capability object is encoded as an array of JSON objects containing the following
        attributes:
   </t>

        <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">

      <t hangText="Name: trigger-endpoint-uri">
      <vspace blankLines="1"/>
      Description: CI/T endpoint URI 
      <vspace blankLines="1"/>
      Value: A URL represented as a JSON string.
      <vspace blankLines="1"/>
      Mandatory-to-Specify: Yes.
      </t>

           <t hangText="Name: trigger-versions">
      <vspace blankLines="1"/>
      Description: A list of CI/T versions supported by the trigger endpoint.
      <vspace blankLines="1"/>
      Value: An array of JSON strings. Valid values include "v2", corresponding to this version of the interface, 
      and "v1", corresponding to <xref target="RFC8007"/>.
      <vspace blankLines="1"/>
      Mandatory-to-Specify: Yes. 
      </t>

      <t hangText="Name: trigger-subjects">
      <vspace blankLines="1"/>
      Description: Array of trigger subjects supported by the trigger endpoint.
      <vspace blankLines="1"/>
      Value: An array of Strings containing the type of the subject matching the cit-spec-value property, 
      such as "content" or "metadata" as defined in <xref target="trigger-subject"/>.
      <vspace blankLines="1"/>
      Mandatory-to-Specify: No. A missing or empty "trigger-subjects" list means that all trigger subjects 
      are supported by the endpoint.
      The dCDN SHOULD advertise only one endpoint for every trigger subject and CI/T interface version pair. 
      If more than one interface endpoint supports the same trigger subject and CI/T interface version 
      (e.g., CI/T version 2 interface for content objects), the uCDN SHOULD be able to use any of the advertised 
      CI/T interface endpoints interchangeably.
      </t>

        </list></t>
        </list></t>

      <section anchor="cit-endpoints-capability-object-serialization" title="CI/T Endpoint Capability Object Serialization">
      <t>
      The following example shows the serialization of a CI/T Endpoint Capability object for a dCDN that supports  
      version 2 of the CI/T interface for content trigger subjects and version 1 for metadata trigger subjects,  
      with one metadata endpoint for both the US and Brazil, and two separate content endpoints for the two countries.
      </t>
<sourcecode type="json" name="fci-endpoints"><![CDATA[

{
  "capabilities": [
    {
      "capability-type": "FCI.CITEndpoint",
      "capability-value": {
        "trigger-endpoint-uri": 
          "https://dcdn.example/configuration/",
        "trigger-versions": [ "v1" ],
        "trigger-subjects": "metadata"
      },
      "footprints": {
        "footprint-type": "countrycode",
        "footprint-value": [ "us", "br" ]
      }
    },
    {
      "capability-type": "FCI.CITEndpoint",
      "capability-value": {
        "trigger-endpoint-uri": 
          "https://dcdn.example/cache-management-us/",
        "trigger-versions": [ "v2" ],
        "trigger-subjects": "content"
      },
      "footprints": {
        "footprint-type": "countrycode",
        "footprint-value": [ "us" ]
      }
    },
    {
      "capability-type": "FCI.CITEndpoint",
      "capability-value": {
        "trigger-endpoint-uri": 
          "https://dcdn.example/cache-management-br/",
        "trigger-versions": [ "v2" ],
        "trigger-subjects": "content"
      },
      "footprints": {
        "footprint-type": "countrycode",
        "footprint-value": [ "br" ]
      }
    }
  ]
}
]]></sourcecode>
        </section>
      </section>


    <section title="CI/T Trigger Scope Capability Object" anchor="trigger-scope-capability-object">
    <t>
    The CI/T supports several trigger actions for different trigger subjects as defined in
    <xref target="trigger-action"/> and <xref target="trigger-subject"/>. Additional actions, as well as
    subjects, may be defined in the future. 
    The trigger scope capability object is used to indicate support for a trigger action for a subject. 
    It further specifies the trigger generic spec types that may be used for selecting the targets to which
    the triggers apply, along with the supported trigger generic extension types.
    </t>
    <t>
    All supported combinations of trigger actions and trigger subjects MUST be explicitly advertised, with one FCI.CITScope object 
    provided for each combination. 
    </t>

    <t>   
    The "trigger-scope-capability" object matches the "FCI.CITScope" capability type and
    is encoded as a JSON object containing the following attributes:
    </t>

    <t><list style="empty" hangIndent="3">
    <t><list style="hanging" hangIndent="3">
    <t hangText="Name: trigger-action">
    <vspace blankLines="1"/>
    Description: The supported CDNI CI/T trigger action.
    <vspace blankLines="1"/>
    Value: A string corresponding to an entry from the "CDNI CI/T Trigger Types" registry
    <xref target="IANA.CDNI.TriggerTypeReg"/>, which corresponds to a CDNI CI/T trigger action.
    <vspace blankLines="1"/>
    Mandatory-to-Specify: Yes.
    </t>

    <t hangText="Name: trigger-subject">
    <vspace blankLines="1"/>
    Description: The supported CDNI CI/T trigger subject.
    <vspace blankLines="1"/>
    Value: A string corresponding to an entry from the "CDNI CI/T Trigger Subjects" registry
    <xref target="IANA.CDNI.TriggerSubjectReg"/>, which corresponds to a CDNI CI/T trigger subject.
    <vspace blankLines="1"/>
    Mandatory-to-Specify: Yes.
    </t>   

    <t hangText="Name: trigger-specs">
    <vspace blankLines="1"/>
    Description: A list of supported CDNI CI/T GenericSpecObject types for trigger action and subject.
    <vspace blankLines="1"/>
    Value: List of JSON strings corresponding to entries from the "CDNI CI/T Trigger Specs" registry
    <xref target="IANA.CDNI.TriggerSpecReg"/>, which correspond to CDNI CI/T GenericSpecObject objects.
    <vspace blankLines="1"/>
    Mandatory-to-Specify: No.
    The default in case of a missing or an empty list MUST be interpreted as "no GenericSpecObject types 
    supported". A non-empty list MUST be interpreted as containing "the only GenericSpecObject types 
    that are supported".
    </t>   

    <t hangText="Name: trigger-extensions">
    <vspace blankLines="1"/>
    Description: A list of supported CDNI CI/T GenericExtensionObject types for trigger action and subject.
    <vspace blankLines="1"/>
    Value: List of JSON strings corresponding to entries from the "CDNI CI/T Trigger Extension Types" registry
    <xref target="IANA.CDNI.TriggerExtensionTypeReg"/>, which corresponds to a CDNI CI/T GenericExtensionObject object.
    <vspace blankLines="1"/>
    Mandatory-to-Specify: No.
    The default in case of a missing or an empty list MUST be interpreted as "no GenericExtensionObject types 
    are supported".  A non-empty list MUST be interpreted as containing "the only GenericExtensionObject types 
    that are supported".
    </t>   

    </list></t>
    </list></t>


    <section title="CI/T Trigger Scope Capability Object Serialization">
    <t>
    The following shows an example of a JSON-serialized CI/T Trigger Scope Capability objects serialization for
    the dCDN that supports the prepositioning and invalidation of content, using "urls" and "ccids" 
    generic spec types, with "time-policy" but only for the "preposition" action. Note that in this example, 
    purge is not supported, and no actions involving metadata are supported either.
    </t>

<sourcecode type="json" name="fci-citscope"><![CDATA[
{
     "capabilities": [
        {
          "capability-type": "FCI.CITScope",
          "capability-value": {
             "trigger-action": "preposition",
             "trigger-subject": "content",
             "trigger-specs": [ "urls", "ccids" ],
             "trigger-extensions": [ "time-policy" ]
          },
          "footprints": {
            "footprint-type": "countrycode",
            "footprint-value": [ "us" ]
         }
       },
       {
          "capability-type": "FCI.CITScope",
          "capability-value": {
             "trigger-action": "invalidate",
             "trigger-subject": "content",
             "trigger-specs": [ "urls", "ccids" ]
          },
          "footprints": {
            "footprint-type": "countrycode",
            "footprint-value": [ "us" ]
          }
       }
    ]
}
]]></sourcecode>
           </section>
         </section>


   <section anchor="content-object-type-capability-object" title="CI/T Content Object Type Capability Object">
        <t>
      Given a dCDN supports "content-objectlist" trigger spec, the CI/T Content Object Type capability object is used to 
      indicate support for one or more Content Object types listed in <xref target="IANA.CDNI.ContentObjectTypeReg"/> 
      by the type property of the "ContentObject" object. The capability type is "FCI.CITContentObjectType".
        </t>
        <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">

      <t hangText="Name: content-object-types">
      <vspace blankLines="1"/>
      Description: A list of supported ContentObject types.
      <vspace blankLines="1"/>
      Value: An array of JSON strings representing <xref target="content-object-types">ContentObjectTypes</xref>.
      <vspace blankLines="1"/>
      Mandatory-to-Specify: No. A missing or an empty list MUST be interpreted as no ContentObject types are supported.
      </t>

   </list></t>
   </list></t>

           <section title="CI/T Content Object Type Capability Object Serialization">
      <t>
                The following shows an example of a JSON-serialized CI/T Content Object Type Capability object serialization
      for the dCDN that supports "hls", "dash", and "json", in the US only.
             </t>
<sourcecode type="json" name="cit-content-object-json"><![CDATA[
{
  "capabilities": [{
    "capability-type": "FCI.CITContentObjectType",
    "capability-value": {
      "content-object-types": [ "hls", "dash", "json" ]
    },
    "footprints": {
      "footprint-type": "countrycode",
      "footprint-value": [ "us" ]
    }
  }]
}
]]></sourcecode>
           </section>
         </section>

   <section anchor="url-type-capability-object" title="CI/T URL Type Capability Object">
        <t>
      The CI/T URL Type capability object is used to indicate support for <xref target="url-types">URL types</xref>.
      The capability type is  "FCI.CITUrlType".
        </t>
        <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">

      <t hangText="Name: cit-url-types">
      <vspace blankLines="1"/>
      Description: Array of supported URL types.
      <vspace blankLines="1"/>
      Value: An array of JSON strings representing <xref target="url-types">URL types</xref>.
      <vspace blankLines="1"/>
      Mandatory-to-Specify: No. A missing or an empty attribute MUST be interpreted as support for "published" URL types.
      </t>

   </list></t>
   </list></t>

   <section title="CI/T URL Type Capability Object Serialization">
   <t>
   The following shows an example of a JSON-serialized CI/T URL Type Capability object serialization
   for the dCDN that supports the private URL type in URL-based trigger spec types.
   </t>

<sourcecode type="json" name="cit-url-type-json"><![CDATA[
{
  "capabilities": [{
    "capability-type": "FCI.CITUrlType",
    "capability-value": {
      "cit-url-types": [ "published", "private" ]
    },
    "footprints": {
      "footprint-type": "countrycode",
      "footprint-value": [ "us" ]
    }
  }]
}
]]></sourcecode>
           </section>
   </section>

   <section anchor="extended-status-capability-object" title="CI/T Extended Status Capability Object">
   <t>
   The CI/T extended trigger status capability object is used to indicate support for extended trigger status, as specified in 
   <xref target="extended-status-types"/>.
   The capability type is "FCI.CITExtendedStatus".
   </t>
   <t><list style="empty" hangIndent="3">
   <t><list style="hanging" hangIndent="3">

   <t hangText="Name: extended-status-objects">
   <vspace blankLines="1"/>
   Description: List of CI/T objects that support extended attributes.
   <vspace blankLines="1"/>
   Value: An array of JSON strings representing <xref target="extended-status-types">Extended Status types</xref>.
   <vspace blankLines="1"/>
   Mandatory-to-Specify: No. By default, in case of a missing or an empty list, no 
   extended status objects are supported.
   </t>

   </list></t>
   </list></t>

   <section title="CI/T Extended Status Capability Object Serialization">
   <t>
   The following shows an example of a JSON-serialized CI/T Extended Status Capability object serialization
   for the dCDN that supports extended status in trigger, Error.v2 description, and trigger collections objects.
   </t>

<sourcecode type="json" name="fci-citextendedstatus"><![CDATA[
{
  "capabilities": [{
    "capability-type": "FCI.CITExtendedStatus",
    "capability-value": {
      "extended-status-objects": [
        "trigger-state",
        "error-v2-description",
        "trigger-collection"
      ]
    },
    "footprints": {
      "footprint-type": "countrycode",
      "footprint-value": [ "us" ]
    }
  }]
}
]]></sourcecode>
           </section>
   </section>
   </section>




   <section title="Examples" anchor="examples">
   <t>
   This section provides examples of using the CI/T interface and its features.
   </t>

   <t>
   The discovery of the CI/T interface is out of the scope of this document.  
   In an implementation, all CI/T URLs are under the control of the dCDN. 
   The uCDN MUST NOT attempt to ascribe any meaning to individual elements of the path.
   </t>

   <t>
   In examples in this section, the root URI "https://dcdn.example/cit/" is used as the location of the 
   trigger collection resource, and the PID of the uCDN is "AS64496:1".
   </t>

   <section title="Creating Triggers" anchor="examples-creating-triggers">

   <section title="Preposition" anchor="examples-preposition">
   <t>
   Below is an example of a "preposition" trigger creation.
   The uCDN sends HTTP POST request to the trigger collection URI with the trigger representation in the request body.
   </t>

   <figure><artwork><![CDATA[
REQUEST:

POST /cit HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 574

{
  "action": "preposition",
  "specs": [
    {
      "trigger-subject": "metadata",
      "cit-spec-type": "urls",
      "cit-spec-value": {
      "urls": [ "https://metadata.example.com/a/b/c" ]
           }
    },
    {
      "trigger-subject": "content",
      "cit-spec-type": "urls",
      "cit-spec-value": {
        "urls": [
          "https://www.example.com/a/b/c/1",
          "https://www.example.com/a/b/c/2",
          "https://www.example.com/a/b/c/3",
          "https://www.example.com/a/b/c/4"
        ]
      }
    }
  ],
  "cdn-path": [ "AS64496:1" ]
}


RESPONSE:

HTTP/1.1 201 Created
Date: Tue, 1 Sep 2026 08:48:10 GMT
Content-Length: 662
Content-Type: application/cdni; ptype=ci-trigger.v2
Location: https://dcdn.example/cit/3f2d259d-a980-4742-beeb-9392a58129f5
Server: example-server/0.1

{
  "ctime": 1730119690,
  "etime": 1730119750,
  "mtime": 1730119690,
  "state": "pending",
  "action": "preposition",
  "specs": [
    {
      "trigger-subject": "metadata",
      "cit-spec-type": "urls",
      "cit-spec-value": {
        "urls": [ "https://metadata.example.com/a/b/c" ]
      }
    },
    {
      "trigger-subject": "content",
      "cit-spec-type": "urls",
      "cit-spec-value": {
        "urls": [
          "https://www.example.com/a/b/c/1",
          "https://www.example.com/a/b/c/2",
          "https://www.example.com/a/b/c/3",
          "https://www.example.com/a/b/c/4"
        ]
      }
    }
  ],
  "cdn-path": [ "AS64496:1" ]
}
]]></artwork>
   </figure>
   </section>

   <section title="Invalidate" anchor="examples-invalidate2">
   <t>
   Below is an example of a CI/T "invalidate" trigger creation. 
   This trigger instructs the dCDN to revalidate:
   </t>
   <list style="symbols">
   <t>the metadata objects with URLs prefixed by "https://metadata.example.com/a/b/" using case-insensitive matching</t>
   <t>a single content object identified by the URL "https://www.example.com/a/index.html"</t>
   <t>the content objects with URLs prefixed by "https://www.example.com/a/b/" using case-sensitive matching</t>
   </list>

   <figure><artwork><![CDATA[
REQUEST:

POST /cit HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 711

{
  "action": "invalidate",
  "specs": [
     {
        "trigger-subject": "metadata",
        "cit-spec-type": "uri-pattern-match",
        "cit-spec-value": {
           "pattern": "https://metadata.example.com/a/b/*"
        }
     },
     {
        "trigger-subject": "content",
        "cit-spec-type": "urls",
        "cit-spec-value": {
           "urls": [
              "https://www.example.com/a/index.html"
           ]
        }
     },
     {
        "trigger-subject": "content",
        "cit-spec-type": "uri-pattern-match",
        "cit-spec-value": {
           "pattern": "https://www.example.com/a/b/*",
           "case-sensitive": true
        }
     }
  ],
  "cdn-path": [ "AS64496:1" ]
}

RESPONSE:

HTTP/1.1 201 Created
Date: Tue, 1 Sep 2026 08:48:11 GMT
Content-Length: 735
Content-Type: application/cdni; ptype=ci-trigger.v2
Location: https://dcdn.example/cit/327df5b8-1df8-4cff-92f8-fda27774c171
Server: example-server/0.1

{
  "ctime": 1730119691,
  "etime": 1730119751,
  "mtime": 1730119691,
  "state": "pending",
  "action": "invalidate",
  "specs": [
    {
      "trigger-subject": "metadata",
      "cit-spec-type": "uri-pattern-match",
      "cit-spec-value": {
        "pattern": "https://metadata.example.com/a/b/*"
      }
    },
    {
      "trigger-subject": "content",
      "cit-spec-type": "urls",
      "cit-spec-value": {
        "urls": [ "https://www.example.com/a/index.html" ]
      }
    },
    {
      "trigger-subject": "content",
      "cit-spec-type": "uri-pattern-match",
      "cit-spec-value": {
        "pattern": "https://www.example.com/a/b/*",
        "case-sensitive": true
      }
    }
  ],
  "cdn-path": [ "AS64496:1" ]
}
]]></artwork>
   </figure>
   </section>


   <section anchor="invalidate-with-regex" title="Invalidation with Regex">
   <t> 
   In the following example, a CI/T "invalidate" trigger uses the Regex property to specify the range of 
   content objects for invalidation. The dCDN accepts the trigger creation request. A failure occurs
   asynchronously during trigger processing, when the dCDN cannot process the regex due to its complexity, 
   and the resulting error is reflected in the trigger resource.
   </t>
   <t>Please note that some lines in the example are wrapped for clarity.</t>

   <figure>
   <artwork><![CDATA[
REQUEST:

POST /cit HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 368

{
  "action": "invalidate",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "uri-regex-match",
    "cit-spec-value": {
      "regex": "^(https:\\/\\/video\\.example\\.com)\\/
        ([a-z])\\/movie1\\/([1-7])\\/*(index.m3u8|\\d{3}.ts)$",
      "case-sensitive": true,
      "match-query-string": false
    }
  }],
  "cdn-path": [ "AS64496:0" ]
}

RESPONSE:

HTTP/1.1 201 Created
Date: Tue, 1 Sep 2026 08:48:12 GMT
Content-Length: 916
Content-Type: application/cdni; ptype=ci-trigger.v2
Location: https://dcdn.example/cit/991b9fb9-d0be-4d05-be06-64c0e5c5a5f9
Server: example-server/0.1

{
  "errors": [{
    "specs": [{
      "trigger-subject": "content",
      "cit-spec-type": "uri-regex-match",
      "cit-spec-value": {
      "regex": "^(https:\\/\\/video\\.example\\.com)\\/([a-z])\
        \/movie1\\/([1-7])\\/*(index.m3u8|\\d{3}.ts)$",
        "case-sensitive": true,
        "match-query-string": false
      }
    }],
    "description": "The dCDN rejected a regex due to complexity",
    "error": "ereject",
    "cdn": "AS64500:0"
  }],
  "ctime": 1730119692,
  "etime": 1730119692,
  "mtime": 1730119692,
  "state": "failed",
  "action": "invalidate",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "uri-regex-match",
    "cit-spec-value": {
      "regex": "^(https:\\/\\/video\\.example\\.com)\\/([a-z])\
        \/movie1\\/([1-7])\\/*(index.m3u8|\\d{3}.ts)$",
      "case-sensitive": true,
      "match-query-string": false
    }
  }],
  "cdn-path": [ "AS64496:0" ]
}
         ]]></artwork>
          </figure>
   </section>

   <section anchor="preposition-with-objectlists" title="Preposition with ObjectLists">
   <t>
   In the following example, a CI/T "preposition" trigger uses the ObjectList property to specify the full
   media library of a specific content. The command fails due to object list parse error and an appropriate
   error is reflected in the response.
   </t>
   <figure>
   <artwork><![CDATA[
REQUEST:

POST /cit HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 304

{
  "action": "preposition",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/title/index.m3u8",
        "type": "hls"
      }]  
     }
  }],
  "cdn-path": [ "AS64496:0" ]
}

RESPONSE:

HTTP/1.1 201 Created
Date: Tue, 1 Sep 2026 08:48:13 GMT
Content-Length: 793
Content-Type: application/cdni; ptype=ci-trigger.v2
Location: https://dcdn.example/cit/86633e6e-d2da-4185-a285-b3d087a5d711
Server: example-server/0.1

{
  "errors": [{
    "specs": [{
      "trigger-subject": "content",
      "cit-spec-type": "content-objectlist",
      "cit-spec-value": {
        "objects": [{
          "href": "https://www.example.com/hls/title/index.m3u8",
          "type": "hls"
        }]
      }
    }],
    "description": "The dCDN was not able to parse the object list",
    "error": "econtent",
    "cdn": "AS64500:0"
  }],
  "ctime": 1730119693,
  "etime": 1730119693,
  "mtime": 1730119693,
  "state": "failed",
  "action": "preposition",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/title/index.m3u8",
        "type": "hls"
      }]      
    }
  }],
  "cdn-path": [ "AS64496:0" ]
}
]]></artwork>
          </figure>
    </section>
  </section>
  <section title="Changing, Cancelling and Deleting Triggers" anchor="examples-changing-triggers">
    <section title="Modifying Triggers" anchor="examples-modifying-triggers">
    <t>
    The uCDN can modify triggers while they are in a "pending" state. One example of this might be to adjust a trigger's 
    "specs" and/or "labels" attributes.
    In the below example, the uCDN updates a trigger created earlier by removing the metadata portion of the trigger spec and
    adding trigger labels. The dCDN responds with a 200 ("OK") response containing the updated trigger representation.
    </t>
    <figure><artwork><![CDATA[
REQUEST: 

POST /cit/3f2d259d-a980-4742-beeb-9392a58129f5 HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 374

{
  "specs": [
    {
      "trigger-subject": "content",
      "cit-spec-type": "urls",
      "cit-spec-value": {
        "urls": [
          "https://www.example.com/d/e/f/1",
          "https://www.example.com/d/e/f/2",
          "https://www.example.com/d/e/f/3",
          "https://www.example.com/d/e/f/4"
        ]
      }
    }
  ],
  "labels": { "type": "video" }
}

RESPONSE: 

HTTP/1.1 200 OK
Date: Tue, 1 Sep 2026 08:48:14 GMT
Content-Length: 493
Content-Type: application/cdni; ptype=ci-trigger.v2
Server: example-server/0.1

{
  "ctime": 1730119694,
  "etime": 1730119754,
  "mtime": 1730119694,
  "state": "pending",
  "action": "preposition",

  "specs": [
    {
      "trigger-subject": "content",
      "cit-spec-type": "urls",
      "cit-spec-value": {
        "urls": [
          "https://www.example.com/d/e/f/1",
          "https://www.example.com/d/e/f/2",
          "https://www.example.com/d/e/f/3",
          "https://www.example.com/d/e/f/4"
        ]
      }
    }
  ],
  "labels": { "type": "video" }
}
]]></artwork>
   </figure>
    </section>
    <section title="Cancelling Triggers" anchor="examples-cancelling-trigger">
    <t>
    The uCDN can cancel triggers that are not in a terminal state by requesting to update the trigger state to "cancelled". 
    In case of asynchronous processing, the dCDN will respond by setting the trigger state to "cancelling" and update it
    "cancelled" when the cancellation is complete.
    </t>
    <figure><artwork><![CDATA[
REQUEST: 

POST /cit/3f2d259d-a980-4742-beeb-9392a58129f5 HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 27

{
  "state": "cancelled"
}

RESPONSE: 

HTTP/1.1 200 OK
Date: Tue, 1 Sep 2026 08:48:15 GMT
Content-Length: 496
Content-Type: application/cdni; ptype=ci-trigger.v2
Server: example-server/0.1

{
  "ctime": 1730119695,
  "etime": 1730119755,
  "mtime": 1730119695,
  "state": "cancelling",
  "action": "preposition",

  "specs": [
    {
      "trigger-subject": "content",
      "cit-spec-type": "urls",
      "cit-spec-value": {
        "urls": [
          "https://www.example.com/d/e/f/1",
          "https://www.example.com/d/e/f/2",
          "https://www.example.com/d/e/f/3",
          "https://www.example.com/d/e/f/4"
        ]
      }
    }
  ],
  "labels": { "type": "video" }
}
]]></artwork></figure>
    </section>

    <section title="Deleting Triggers" anchor="examples-deleting-trigger">
    <t>
    The uCDN can delete completed and failed triggers to reduce the size of the collections, as described in 
    <xref target="deleting-triggers"/>.  For example, to delete the "preposition" trigger from earlier examples:
    </t>

   <figure><artwork><![CDATA[
REQUEST:

DELETE /cit/3f2d259d-a980-4742-beeb-9392a58129f5 HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*

RESPONSE:

HTTP/1.1 204 No Content
Date: Tue, 1 Sep 2026 08:48:16 GMT
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Server: example-server/0.1
]]></artwork>
   </figure>
    </section>
  </section>
  <section title="Examining Trigger Status" anchor="examples-examining-trigger-status">
  <t>
  Once triggers have been created, the uCDN can check their status as shown in the following examples.
  </t>

    <section title="Trigger Index" anchor="examples-trigger-index">
    <t>
    The uCDN can fetch all active trigger collections, representing  all existing trigger resources.
    </t>


    <figure><artwork><![CDATA[
REQUEST:

GET /cit HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*

RESPONSE:

HTTP/1.1 200 OK
Content-Length: 940
Expires: Tue, 1 Sep 2026 08:49:18 GMT
Server: example-server/0.1
ETag: "936094426920308378"
Last-Modified: Tue, 1 Sep 2026 08:40:17 GMT
Cache-Control: max-age=60
Date: Tue, 1 Sep 2026 08:48:18 GMT
Content-Type: application/cdni; ptype=ci-trigger-index.v2

{
  "cdn-id": "AS64496:0",
  "staleresourcetime": 86400,
  "collections": [
    {
      "collection-uri": "/cit/all"
    },
    {
      "filter": { "state": "pending" },
      "collection-uri": "/cit/state/pending"
    },
    {
      "filter": { "state": "active" },
      "collection-uri": "/cit/state/active"
    },
    {
      "filter": { "state": "complete" },
      "collection-uri": "/cit/state/complete"
    },
    {
      "filter": { "state": "processed" },
      "collection-uri": "/cit/state/processed"
    },
    {
      "filter": { "state": "failed" },
      "collection-uri": "/cit/state/failed"
    },
    {
      "filter": { "state": "cancelling" },
      "collection-uri": "/cit/state/cancelling"
    },
    {
      "filter": { "state": "cancelled" },
      "collection-uri": "/cit/state/cancelled"
    },
    {
      "filter": { "labels": { "type": "video" } },
      "collection-uri": "/cit/labels/type=video"
    }
  ]
}
]]></artwork>
    </figure>
    </section>

    <section title="Trigger Collection" anchor="examples-trigger-collection">
    <t>
    Before the dCDN starts processing the remaining trigger shown above,
    it will appear in the collection of pending triggers. For example:
    </t>

   <figure><artwork><![CDATA[
REQUEST:

GET /cit/state/pending HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*

RESPONSE:

HTTP/1.1 200 OK
Content-Length: 96
Expires: Tue, 1 Sep 2026 08:49:19 GMT
Server: example-server/0.1
ETag: "4331492443626270781"
Last-Modified: Tue, 1 Sep 2026 08:40:17 GMT
Cache-Control: max-age=60
Date: Tue, 1 Sep 2026 08:48:19 GMT
Content-Type: application/cdni; ptype=ci-trigger-collection.v2

{
  "trigger-urls": [
    "https://dcdn.example/cit/327df5b8-1df8-4cff-92f8-fda27774c171"
  ]
}
]]></artwork>
   </figure>
   <t>
   At this point, if no other triggers had been created, the trigger collection for failed triggers 
   would hold the two failed triggers shown above while other trigger collections would be empty.
   For example:</t>

   <figure><artwork><![CDATA[
REQUEST:

GET /cit/state/complete HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*

RESPONSE:

HTTP/1.1 200 OK
Content-Length: 25
Expires: Tue, 1 Sep 2026 08:49:20 GMT
Server: example-server/0.1
ETag: "7958041393922269003"
Last-Modified: Tue, 1 Sep 2026 08:48:17 GMT
Cache-Control: max-age=60
Date: Tue, 1 Sep 2026 08:48:20 GMT
Content-Type: application/cdni; ptype=ci-trigger-collection.v2

{
  "trigger-urls": []
}
]]></artwork>

   </figure>
   <figure><artwork><![CDATA[
REQUEST:

GET /cit/state/failed HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*

RESPONSE:

HTTP/1.1 200 OK
Content-Length: 165
Expires: Tue, 1 Sep 2026 08:49:21 GMT
Server: example-server/0.1
ETag: "4331492443626270781"
Last-Modified: Tue, 1 Sep 2026 08:48:13 GMT
Cache-Control: max-age=60
Date: Tue, 1 Sep 2026 08:48:19 GMT
Content-Type: application/cdni; ptype=ci-trigger-collection.v2

{
  "trigger-urls": [
    "https://dcdn.example/cit/991b9fb9-d0be-4d05-be06-64c0e5c5a5f9",
    "https://dcdn.example/cit/86633e6e-d2da-4185-a285-b3d087a5d711"
  ]
}

           ]]></artwork></figure>

     </section>

     <section title="Individual Trigger Resources" anchor="examples-trigger-resources">
     <t>
     The uCDN can also examine individual triggers:
     </t>


     <figure><artwork><![CDATA[
REQUEST:

GET /cit/327df5b8-1df8-4cff-92f8-fda27774c171 HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*

RESPONSE:

HTTP/1.1 200 OK
Content-Length: 704
Expires: Tue, 1 Sep 2026 08:49:22 GMT
Server: example-server/0.1
ETag: "554385204989405469"
Last-Modified: Tue, 1 Sep 2026 08:48:17 GMT
Cache-Control: max-age=60
Date: Tue, 1 Sep 2026 08:48:22 GMT
Content-Type: application/cdni; ptype=ci-trigger.v2

{  
  "ctime": 1730119691,
  "etime": 1730119751,
  "mtime": 1730119691,
  "state": "pending",
  "action": "invalidate",
  "specs": [
    {
      "trigger-subject": "metadata",
      "cit-spec-type": "uri-pattern-match",
      "cit-spec-value": {
        "pattern": "https://metadata.example.com/a/b/*"
      }
    },
    {
      "trigger-subject": "content",
      "cit-spec-type": "urls",
      "cit-spec-value": {
        "urls": [ "https://www.example.com/a/index.html" ]
      }
    },
    {
      "trigger-subject": "content",
      "cit-spec-type": "uri-pattern-match",
      "cit-spec-value": {
        "pattern": "https://www.example.com/a/b/*",
        "case-sensitive": true
      }
    }
  ]
}
]]></artwork>
     </figure>
     </section>

     <section title="Polling for Changes in Status" anchor="examples-polling-status-changes">
     <t>
     The uCDN SHOULD use the ETags and/or Last-Modified headers when polling for changes in trigger collections 
     or the status of individual triggers, as shown in the following examples:
     </t>

   <figure><artwork><![CDATA[
REQUEST:

GET /cit/state/pending HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
If-None-Match: "4331492443626270781"
If-Modified-Since: Tue, 1 Sep 2026 08:40:23 GMT

RESPONSE:
HTTP/1.1 304 Not Modified
Content-Length: 0
Expires: Tue, 1 Sep 2026 08:49:21 GMT
Server: example-server/0.1
ETag: "4331492443626270781"
Last-Modified: Tue, 1 Sep 2026 08:48:17 GMT
Cache-Control: max-age=60
Date: Tue, 1 Sep 2026 08:48:23 GMT
Content-Type: application/cdni; ptype=ci-trigger-collection.v2

REQUEST:

GET /cit/327df5b8-1df8-4cff-92f8-fda27774c171 HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
If-None-Match: "6990548174277557683"
If-Modified-Since: Tue, 1 Sep 2026 08:49:10 GMT

RESPONSE:

HTTP/1.1 304 Not Modified
Content-Length: 0
Expires: Tue, 1 Sep 2026 08:49:24 GMT
Server: example-server/0.1
ETag: "554385204989405469"
Last-Modified: Tue, 1 Sep 2026 08:48:17 GMT
Cache-Control: max-age=60
Date: Tue, 1 Sep 2026 08:48:24 GMT
Content-Type: application/cdni; ptype=ci-trigger.v2

]]></artwork>
   </figure>
   <t>
   When the trigger processing is complete, the contents of the filtered collections will be updated.
   The dCDN SHOULD also update the "ETag" and/or "Last-Modified" response headers - whichever was previously sent - 
   when delivering the updated collection representations.
   The dCDN SHOULD also use cache control headers, such as "Expires" and "Cache-Control", to indicate how caching of
   the resource representation should happen by the uCDN and intermediate proxies. 

   For example, when the two example triggers are complete, the
   collections of pending and complete triggers look as follows:</t>

   <figure><artwork><![CDATA[
REQUEST:

GET /cit/state/pending HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*

RESPONSE:

HTTP/1.1 200 OK
Content-Length: 51
Expires: Tue, 1 Sep 2026 08:49:25 GMT
Server: example-server/0.1
ETag: "1337503181677633762"
Last-Modified: Tue, 1 Sep 2026 08:48:17 GMT
Cache-Control: max-age=60
Date: Tue, 1 Sep 2026 08:48:25 GMT
Content-Type: application/cdni; ptype=ci-trigger-collection.v2

{
  "staleresourcetime": 86400,
  "triggers": []
}

REQUEST:

GET /cit/state/complete HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*

RESPONSE:

HTTP/1.1 200 OK
Content-Length: 122
Expires: Tue, 1 Sep 2026 08:49:26 GMT
Server: example-server/0.1
ETag: "4481489539378529796"
Last-Modified: Tue, 1 Sep 2026 08:48:17 GMT
Cache-Control: max-age=60
Date: Tue, 1 Sep 2026 08:48:26 GMT
Content-Type: application/cdni; ptype=ci-trigger-collection.v2

{
  "staleresourcetime": 86400,
  "triggers": [
    "https://dcdn.example/cit/327df5b8-1df8-4cff-92f8-fda27774c171"
  ]
}
]]></artwork>
   </figure>
  </section>
  </section>


  <section anchor="examples-extensions" title="Extensions">
    <section anchor="examples-execution-extensions" title="Execution Policy Extension">
    <t>
    This subsection illustrates the uses of the Execution Policy extension.
    The uCDN can create a dependency between triggers. For example, a preposition trigger should only be processed by the dCDN
    after a previous purge trigger has been completed.
    </t>
    <figure>
    <artwork><![CDATA[

REQUEST:

POST /cit HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 270

{
  "action": "purge",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/1a910c8e/index.m3u8",
        "type": "hls"
      }]
     }
  }]
}

RESPONSE:

HTTP/1.1 201 Created
Date: Tue, 1 Sep 2026 08:48:27 GMT
Content-Length: 361
Content-Type: application/cdni; ptype=ci-trigger.v2
Location: https://dcdn.example/cit/564cc45e-9099-4a37-b95e-60342f2647ba
Server: example-server/0.1

{
  "ctime": 1730119707,
  "etime": 1730119767,
  "mtime": 1730119707,
  "state": "pending",
  "action": "purge",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/1a910c8e/index.m3u8",
        "type": "hls"
      }]
     }
  }]
}


REQUEST:

POST /cit HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 487

{
  "action": "preposition",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/09000b67/index.m3u8",
        "type": "hls"
      }]
     }
  }],
  "extensions": [{
    "cit-extension-type": "execution-policy",
    "cit-extension-value": {
      "prerequisites": [
        "https://dcdn.example/cit/564cc45e-9099-4a37-b95e-60342f2647ba"
      ]
    }
  }] 
}


RESPONSE:

HTTP/1.1 201 Created
Date: Tue, 1 Sep 2026 08:48:28 GMT
Content-Length: 578
Content-Type: application/cdni; ptype=ci-trigger.v2
Location: https://dcdn.example/cit/f6dde35f-703f-49e9-bb80-4964dff3bca5
Server: example-server/0.1

{
  "ctime": 1730119708,
  "etime": 1730119768,
  "mtime": 1730119708,
  "state": "pending",
  "action": "preposition",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/09000b67/index.m3u8",
        "type": "hls"
      }]
     }
  }],
  "extensions": [{
    "cit-extension-type": "execution-policy",
    "cit-extension-value": {
      "prerequisites": [
        "https://dcdn.example/cit/564cc45e-9099-4a37-b95e-60342f2647ba"
      ]
    }
  }] 
}

]]></artwork>
    </figure>
    <t>
    The uCDN can also stagger long-running triggers to control processing order.
    In the following example, the uCDN creates a preposition trigger with higher priority, 
    which dCDN should pick up for execution before the earlier triggers.
    </t>

    <figure>
    <artwork><![CDATA[


REQUEST:

POST /cit HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 395

{
  "action": "preposition",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/b89d49df/index.m3u8",
        "type": "hls"
      }]
     }
  }],
  "extensions": [{
    "cit-extension-type": "execution-policy",
    "cit-extension-value": { "priority": 100 }
   }]   
}
    
RESPONSE:

HTTP/1.1 201 Created
Date: Tue, 1 Sep 2026 08:48:30 GMT
Content-Length: 486
Content-Type: application/cdni; ptype=ci-trigger.v2
Location: https://dcdn.example/cit/e5483c4a-7c8e-4820-91c8-3c0a9f2edba8
Server: example-server/0.1

{
  "ctime": 1730119710,
  "etime": 1730119770,
  "mtime": 1730119710,
  "state": "pending",
  "action": "preposition",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/b89d49df/index.m3u8",
        "type": "hls"
      }]
     }
  }],
  "extensions": [{
    "cit-extension-type": "execution-policy",
    "cit-extension-value": { "priority": 100 }
   }]   
}
]]></artwork>
    </figure>


    </section>

<section anchor="trigger-with-extensions" title="Extensions with Error Propagation">
    <t>
    The following example shows error propagation in a cascade. An upstream CDN, uCDN-A
    ("AS64496:0"), sends a CI/T "preposition" command that uses two extensions to control the
    way the trigger is executed. The receiving CDN, tCDN-B ("AS64500:0"), supports both
    extensions, accepts the request, and creates the trigger resource. tCDN-B then propagates
    the trigger to its own downstream CDN, dCDN-C ("AS64501:0"), which does not support the
    "time-policy" extension and rejects the propagated request with a 400 ("Bad Request")
    status code and an Error.v2 Description in the response body.
    </t>
    <t>
    tCDN-B has already accepted the request from uCDN-A and cannot relay the rejection as an
    HTTP status code. It sets the state of its own trigger resource to "failed" and records the
    Error.v2 Description received from dCDN-C in the "errors" array, retaining dCDN-C's CDN PID
    in the "cdn-id" attribute. uCDN-A retrieves the error when it queries the trigger resource.
    </t>
    <figure>
    <artwork><![CDATA[
(1) uCDN-A creates the trigger in tCDN-B:

POST /cit HTTP/1.1
User-Agent: example-user-agent/0.1
Host: tcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 951

{
  "action": "preposition",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/title/index.m3u8",
        "type": "hls"
      }]
    }
  }],
  "extensions": [
    {
      "cit-extension-type": "location-policy",
      "cit-extension-value": {
        "locations": [{
          "action": "allow",
          "footprints": [{
            "footprint-type": "countrycode",
            "footprint-value": [ "us" ]
          }]
        }]
      },
      "mandatory-to-enforce": true,
      "safe-to-redistribute": true
    },
    {
      "cit-extension-type": "time-policy",
      "cit-extension-value": {
        "unix-time-window": {
          "start": 1730174400,
          "end": 1730260800
        }
      },
      "mandatory-to-enforce": true,
      "safe-to-redistribute": true
    }
  ],
  "cdn-path": [ "AS64496:0" ]
}

(2) tCDN-B accepts the request and creates the trigger resource:

HTTP/1.1 201 Created
Date: Tue, 1 Sep 2026 08:48:31 GMT
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 1042
Location: https://tcdn.example/cit/bcca1cde-ddf0-47db-b859-6a2c043baaa9
Server: example-server/0.1

{
  "ctime": 1730018911,
  "etime": 1730019031,
  "mtime": 1730018911,
  "state": "pending",
  "action": "preposition",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/title/index.m3u8",
        "type": "hls"
      }]
    }
  }],
  "extensions": [
    {
      "cit-extension-type": "location-policy",
      "cit-extension-value": {
        "locations": [{
          "action": "allow",
          "footprints": [{
            "footprint-type": "countrycode",
            "footprint-value": [ "us" ]
          }]
        }]
      },
      "mandatory-to-enforce": true,
      "safe-to-redistribute": true
    },
    {
      "cit-extension-type": "time-policy",
      "cit-extension-value": {
        "unix-time-window": {
          "start": 1730174400,
          "end": 1730260800
        }
      },
      "mandatory-to-enforce": true,
      "safe-to-redistribute": true
    }
  ],
  "cdn-path": [ "AS64496:0" ]
}

(3) tCDN-B propagates the trigger to dCDN-C, appending its own CDN PID
    to "cdn-path":

POST /cit HTTP/1.1
User-Agent: example-user-agent/0.1
Host: dcdn.example
Accept: */*
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 964

{
  "action": "preposition",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/title/index.m3u8",
        "type": "hls"
      }]
    }
  }],
  "extensions": [
    {
      "cit-extension-type": "location-policy",
      "cit-extension-value": {
        "locations": [{
          "action": "allow",
          "footprints": [{
            "footprint-type": "countrycode",
            "footprint-value": [ "us" ]
          }]
        }]
      },
      "mandatory-to-enforce": true,
      "safe-to-redistribute": true
    },
    {
      "cit-extension-type": "time-policy",
      "cit-extension-value": {
        "unix-time-window": {
          "start": 1730174400,
          "end": 1730260800
        }
      },
      "mandatory-to-enforce": true,
      "safe-to-redistribute": true
    }
  ],
  "cdn-path": [ "AS64496:0", "AS64500:0" ]
}

(4) dCDN-C does not support the "time-policy" extension and rejects the
    request. No trigger resource is created at dCDN-C:

HTTP/1.1 400 Bad Request
Date: Tue, 1 Sep 2026 08:48:32 GMT
Content-Type: application/cdni; ptype=ci-trigger-error.v2
Content-Length: 619
Server: example-server/0.1

{
  "error": "eextension",
  "description": "extension type time-policy is not supported",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/title/index.m3u8",
        "type": "hls"
      }]
    }
  }],
  "extensions": [{
    "cit-extension-type": "time-policy",
    "cit-extension-value": {
      "unix-time-window": {
        "start": 1730174400,
        "end": 1730260800
      }
    },
    "mandatory-to-enforce": true,
    "safe-to-redistribute": true
  }],
  "cdn-id": "AS64501:0"
}

(5) uCDN-A queries the trigger resource in tCDN-B:

GET /cit/bcca1cde-ddf0-47db-b859-6a2c043baaa9 HTTP/1.1
User-Agent: example-user-agent/0.1
Host: tcdn.example
Accept: application/cdni; ptype=ci-trigger.v2

(6) tCDN-B reports the rejection from dCDN-C as an Error.v2 Description
    in its own trigger resource:

HTTP/1.1 200 OK
Date: Tue, 1 Sep 2026 08:49:05 GMT
Content-Type: application/cdni; ptype=ci-trigger.v2
Content-Length: 1833
Server: example-server/0.1

{
  "ctime": 1730018911,
  "etime": 1730019031,
  "mtime": 1730018912,
  "state": "failed",
  "state-reason": "rejected by a downstream CDN",
  "errors": [
    {
      "error": "eextension",
      "description": "extension type time-policy is not supported",
      "specs": [{
        "trigger-subject": "content",
        "cit-spec-type": "content-objectlist",
        "cit-spec-value": {
          "objects": [{
            "href": "https://www.example.com/hls/title/index.m3u8",
            "type": "hls"
          }]
        }
      }],
      "extensions": [{
        "cit-extension-type": "time-policy",
        "cit-extension-value": {
          "unix-time-window": {
            "start": 1730174400,
            "end": 1730260800
          }
        },
        "mandatory-to-enforce": true,
        "safe-to-redistribute": true
      }],
      "cdn-id": "AS64501:0"
    }
  ],
  "action": "preposition",
  "specs": [{
    "trigger-subject": "content",
    "cit-spec-type": "content-objectlist",
    "cit-spec-value": {
      "objects": [{
        "href": "https://www.example.com/hls/title/index.m3u8",
        "type": "hls"
      }]
    }
  }],
  "extensions": [
    {
      "cit-extension-type": "location-policy",
      "cit-extension-value": {
        "locations": [{
          "action": "allow",
          "footprints": [{
            "footprint-type": "countrycode",
            "footprint-value": [ "us" ]
          }]
        }]
      },
      "mandatory-to-enforce": true,
      "safe-to-redistribute": true
    },
    {
      "cit-extension-type": "time-policy",
      "cit-extension-value": {
        "unix-time-window": {
          "start": 1730174400,
          "end": 1730260800
        }
      },
      "mandatory-to-enforce": true,
      "safe-to-redistribute": true
    }
  ],
  "cdn-path": [ "AS64496:0" ]
}
         ]]></artwork>
          </figure>
     </section>


   </section>
   </section>

   <section title="IANA Considerations" anchor="iana-considerations">
   <section title="CDNI Payload Type Parameter Registrations" anchor="cdni-payload-type"><t>

   All references to RFC 8007 in the IANA registries should be replaced with
   references to this document, apart from references associated with the following registrations:</t>

   <texttable style="full"><ttcol align="left"> Payload Type</ttcol>
   <ttcol align="left">Specification</ttcol>

   <c>ci-trigger-command</c>
   <c>RFC 8007</c>

   <c>ci-trigger-status</c>
   <c>RFC 8007</c>

   <c>ci-trigger-collection</c>
   <c>RFC 8007</c>

   </texttable><t>
   

   The IANA is requested to register the following new Payload Types in
   the "CDNI Payload Types" registry defined by <xref target="RFC7736"/>, for use with
   the "application/cdni" MIME media type.</t>

   <texttable style="full"><ttcol align="left"> Payload Type</ttcol>
   <ttcol align="left"> Specification</ttcol>
   <c>ci-trigger.v2</c><c>RFCthis</c>
   <c>ci-trigger-index.v2</c><c>RFCthis</c>
   <c>ci-trigger-collection.v2</c><c>RFCthis</c>
   <c>ci-trigger-error.v2</c><c>RFCthis</c>

   <c>FCI.CITScope</c><c>RFCthis</c>
   <c>FCI.CITContentObjectType</c><c>RFCthis</c>
   <c>FCI.CITEndpoint</c><c>RFCthis</c>
   <c>FCI.CITExtendedStatus</c><c>RFCthis</c>
   <c>FCI.CITUrlType</c><c>RFCthis</c>


   </texttable>
      <t>[RFC Editor: Please replace RFCthis with the published RFC
        number for this document.]</t>

        <section anchor="IANA.CDNI.payload.ci-trigger.v2" title="CDNI ci-trigger.v2 Payload Type">
                <t>Purpose: The purpose of this payload type is to define a new CI/T trigger object 
                        (and any associated capability advertisement)</t>
          <t>Interface: CI/T</t>
          <t>Encoding: see <xref target="ci-trigger-resource"/></t>
        </section>

        <section anchor="IANA.CDNI.payload.ci-trigger-index.v2" title="CDNI ci-trigger-index.v2 Payload Type">
                <t>Purpose: The purpose of this payload type is to define a new CI/T trigger index object 
                        (and any associated capability advertisement)</t>
          <t>Interface: CI/T</t>
          <t>Encoding: see <xref target="ci-trigger-index-resource"/></t>
        </section>
        <section anchor="IANA.CDNI.payload.ci-trigger-collection.v2" title="CDNI ci-trigger-collection.v2 Payload Type">
                <t>Purpose: The purpose of this payload type is to define a new CI/T trigger collection object 
                        (and any associated capability advertisement)</t>
          <t>Interface: CI/T</t>
          <t>Encoding: see <xref target="ci-trigger-collection-resource"/></t>
        </section>
        <section anchor="IANA.CDNI.payload.ci-trigger-error.v2" title="CDNI ci-trigger-error.v2 Payload Type">
          <t>Purpose: The purpose of this payload type is to identify a standalone Error.v2 Description
                         object returned in the body of a rejected CI/T request</t>
          <t>Interface: CI/T</t>
          <t>Encoding: see <xref target="error-v2-description"/></t>
        </section>

        <section anchor="IANA-CDNI-payload-types" title="CDNI FCI CI/T Payload Types">

            <section anchor="IANA.CDNI.payload.FCI.CITEndpoint" title="CDNI FCI CI/T Endpoint Payload Type">
               <t>Purpose: The purpose of this payload type is to distinguish FCI advertisement objects for
                  CI/T Endpoint objects</t>
               <t>Interface: FCI</t>
               <t>Value: "FCI.CITEndpoint"</t> 
               <t>Encoding: see <xref target="cit-trigger-endpoints-capability-object"/></t>
            </section>

            <section anchor="IANA.CDNI.payload.FCI.CITScope" title="CDNI FCI CI/T Trigger Scope Payload Type">
               <t>Purpose: The purpose of this payload type is to distinguish FCI advertisement objects for
                  CI/T trigger scope</t>
               <t>Interface: FCI</t>
               <t>Value: "FCI.CITScope"</t> 
               <t>Encoding: see <xref target="trigger-scope-capability-object"/></t>
            </section>

             <section anchor="IANA.CDNI.payload.FCI.CITContentObjectType" title="CDNI FCI CI/T Content Object Type Payload Type">
               <t>Purpose: The purpose of this payload type is to distinguish FCI advertisement objects for
                  CI/T Content Object Type objects</t>
               <t>Interface: FCI</t>
               <t>Value: "FCI.CITContentObjectType"</t> 
               <t>Encoding: see <xref target="content-object-type-capability-object"/></t>
            </section>

             <section anchor="IANA.CDNI.payload.FCI.CITUrlType" title="CDNI FCI CI/T URL Type Payload Type">
               <t>Purpose: The purpose of this payload type is to distinguish FCI advertisement objects for
                  CI/T URL Type objects</t>
               <t>Interface: FCI</t>
               <t>Value: "FCI.CITUrlType"</t> 
               <t>Encoding: see <xref target="url-type-capability-object"/></t>
            </section>

             <section anchor="IANA.CDNI.payload.FCI.CITExtendedStatus" title="CDNI FCI CI/T Extended Status Payload Type">
               <t>Purpose: The purpose of this payload type is to distinguish FCI advertisement objects for
                  CI/T Extended Status objects</t>
               <t>Interface: FCI</t>
               <t>Value: "FCI.CITExtendedStatus"</t> 
               <t>Encoding: see <xref target="extended-status-capability-object"/></t>
            </section>
        </section>


   </section>

   <section title="&quot;CDNI CI/T Trigger Types&quot; Registry For Trigger Actions" anchor="IANA.CDNI.TriggerTypeReg">
   <t>
   In <xref target="RFC8007"/> the IANA was requested to create a new "CDNI CI/T Trigger Types"
   registry under the "Content Delivery Network Interconnection (CDNI) Parameters" registry group.
   </t>

   <t>
   Additions to the "CDNI CI/T Trigger Types" registry are made via
   the RFC Required policy as defined in <xref target="RFC8126"/>.
   </t>

   <t> 
   In this second edition of the interface, trigger types are referred to as "trigger actions". The "Trigger Types" 
   registry is used for action definitions. Furthermore, this document, and specifically <xref target="trigger-action"/>, 
   reuses the definition of "trigger types" as defined in <xref target="RFC8007"/> as trigger actions,
   and provide their specifications, with no modification compared to <xref target="RFC8007"/>.
   </t>
   </section>


   <section anchor="IANA.CDNI.TriggerSpecReg" title="&quot;CDNI CI/T Trigger Specs&quot; Registry">
   <t>
   The IANA is requested to create a new "CDNI CI/T Trigger Specs" registry in the "Content Delivery Networks 
   Interconnection (CDNI) Parameters" registry group. 

   The "CDNI CI/T Trigger Specs" namespace defines the valid trigger targets' spec values in 
   <xref target="trigger-specs"/>, used by the trigger spec object.
   </t>
   <t>
   Additions to the "CDNI CI/T Trigger Specs" registry are made via the RFC Required policy as defined in 
   <xref target="RFC8126"/>.
   </t>

   <t>
   The initial contents of the "CDNI CI/T Trigger Specs" registry consist of the names and descriptions listed in 
   <xref target="trigger-specs"/>, with this document serving as their specification.</t>
   </section>

   <section anchor="IANA.CDNI.TriggerSubjectReg" title="&quot;CDNI CI/T Trigger Subjects&quot; Registry">
   <t>
   The IANA is requested to create a new "CDNI CI/T Trigger Subjects" registry in the "Content Delivery Networks 
   Interconnection (CDNI) Parameters" registry group.  The "CDNI CI/T Trigger Subjects" namespace defines the valid 
   trigger targets' subject values in <xref target="trigger-subject"/>, used by the trigger spec object.
   </t>
   <t>
   Additions to the "CDNI CI/T Trigger Subjects" registry are made via the RFC Required policy as defined in 
   <xref target="RFC8126"/>.
   </t>

   <t>
   The initial contents of the "CDNI CI/T Trigger Subjects" registry consist of the names and descriptions listed 
   in <xref target="trigger-subject"/>, with this document serving as their specification.
   </t>
   </section>


   <section anchor="IANA.CDNI.ContentObjectTypeReg" title="&quot;CDNI CI/T Content Object Types&quot; Registry">
   <t>
   The IANA is requested to create a new "CDNI CI/T Content Object Types" registry in the "Content Delivery Networks 
   Interconnection (CDNI) Parameters" registry group. The "CDNI CI/T Content Object Types" namespace defines the valid 
   object list type values in <xref target="content-object-types"/>, used by the ContentObject object.
   </t>
   <t>
   Additions to the "CDNI CI/T Content Object Types" registry are made via the Specification Required policy as defined in 
   <xref target="RFC8126"/>.
   </t>
   <t>
   The initial contents of the "CDNI CI/T Content Object Types" registry consist of the names and descriptions listed 
   in <xref target="content-object-types"/>, with this document serving as their specification.
   </t>
   </section>
     
   <section anchor="IANA.CDNI.TriggerExtensionTypeReg" title="&quot;CDNI CI/T Trigger Extension Types&quot; Registry">
   <t>
   The IANA is requested to create a new "CDNI CI/T Trigger Extension Types" registry in the "Content Delivery Networks 
   Interconnection (CDNI) Parameters" registry group.  The "CDNI CI/T Trigger Extension Types" namespace defines the valid 
   trigger extension type values in <xref target="trigger-extensibility"/>, used by the trigger spec object.
   </t>
   <t>
   Additions to the "CDNI CI/T Trigger Extension Types" registry are made via the Specification Required policy as defined in
   <xref target="RFC8126"/>.
   </t>

   <t>
   The initial contents of the "CDNI CI/T Trigger Extension Types" registry consist of the type names and descriptions listed 
   in <xref target="trigger-extensibility"/>, with this document serving as their specification.</t>
   </section>
   
   

   <section title="&quot;CDNI CI/T Error Codes&quot; Registry" anchor="cdni-cit-error-code-registry"><t>
   In <xref target="RFC8007"/> the IANA was requested to create a new "CDNI CI/T Error Codes"
   registry under the "Content Delivery Network Interconnection (CDNI) Parameters" registry group.</t>

   <t>
   Additions to the "CDNI CI/T Error Codes" registry are made via the Specification Required policy as defined in 
   <xref target="RFC8126"/>. 
   The Designated Expert will verify that new Error Code registrations do not duplicate existing Error Code 
   definitions (in name or functionality), prevent gratuitous additions to the namespace, and
   prevent any additions to the namespace that would impair the interoperability of CDNI implementations.
   </t>

  
   <t> 
   In this second edition of the interface, the definitions of the Error Codes from <xref target="RFC8007"/> are 
   without change. Additionally, the IANA is requested to register three additional error codes, "espec", "esubject", 
   and "eextension", with the specification as defined in <xref target="error-code"/>.
   </t>

   </section>

   <section title="&quot;CDNI CI/T URL Types&quot; Registry" anchor="cdni-cit-url-types-registry">
   <t>
   The IANA is requested to create a new "CDNI CI/T URL types" registry in the "Content Delivery Networks 
   Interconnection (CDNI) Parameters" registry group. 
   The "CDNI CI/T URL Types" namespace defines the valid URL type values in <xref target="url-types"/>,
   used by <xref target="urls-spec"/>, <xref target="uri-pattern-match-spec"/>, <xref target="uri-regex-match-spec"/>, 
   and <xref target="objectlist-spec"/>.
   </t>
   <t>
   The initial contents of the "CDNI CI/T URL Types" registry consist of the names and 
   descriptions listed in <xref target="url-types"/>, with this document serving as their specification.
   </t>
   </section>
   </section>

   <section title="Security Considerations" anchor="security-considerations"><t>
   The CI/T interface provides a mechanism to allow the uCDN to generate
   requests into the dCDN and to inspect its own CI/T requests and their
   current states. The CI/T interface does not allow access to, or
   modification of, the uCDN or the dCDN metadata relating to content
   delivery or to the content itself. It can only control the presence
   of that metadata in the dCDN and the processing work and network
   utilization involved in ensuring that presence.</t>

   <t>
   By examining "preposition" requests to the dCDN, and correctly
   interpreting content and metadata URLs, an attacker could learn the
   uCDN's or content owner's predictions for future content popularity.
   By examining "invalidate" or "purge" requests, an attacker could
   learn about changes in the content owner's catalog.</t>

   <t>
   An attacker or misbehaving uCDN could inject CI/T triggers to generate
   processing workload in both the dCDN and uCDN. Similarly, a
   man-in-the-middle attacker could modify valid trigger requests from the
   uCDN to achieve the same effect.
   In both cases, that would decrease the dCDN's
   caching efficiency by causing it to unnecessarily acquire or
   reacquire content metadata and/or content.</t>

   <t>
   The dCDN implementation of CI/T MUST restrict the actions of the uCDN to
   the data corresponding to that uCDN. Failure to do so would allow
   the uCDNs to detrimentally affect each other's efficiency by generating
   unnecessary acquisition or reacquisition load.</t>

   <t>
   An origin that chooses to delegate its delivery to a CDN is trusting
   that CDN to deliver content on its behalf; the interconnection of
   CDNs is an extension of that trust to the dCDNs. That trust relationship
   is a commercial arrangement, outside the scope of the CDNI protocols.
   So, while a malicious CDN could deliberately generate load on the dCDN
   using the CI/T interface, the protocol does not otherwise attempt to
   address malicious behavior between interconnected CDNs.</t>

   <section title="Authentication, Authorization, Confidentiality, Integrity Protection" anchor="authentication-authorization">
   <t>
   A CI/T implementation MUST support Transport Layer Security (TLS)
   transport for HTTP (HTTPS) as per <xref target="RFC9110"/>.</t>

   <t>
   TLS MUST be used by the server side (dCDN) and the client side (uCDN)
   of the CI/T interface, including the authentication of the remote end,
   unless alternate methods are used to ensure the security of the
   information in the CI/T interface requests and responses (such as
   setting up an IPsec tunnel between the two CDNs or using a physically
   secured internal network between two CDNs that are owned by the same
   corporate entity).</t>

   <t>
   The use of TLS for transport of the CI/T interface allows the dCDN
   and the uCDN to authenticate each other using TLS client
   authentication and TLS server authentication.</t>

   <t>
   Once the dCDN and the uCDN have mutually authenticated each other,
   TLS allows:</t>

   <t><list style="symbols"><t>The dCDN and the uCDN to authorize each other (to ensure that they
      are receiving trigger requests from, or responding to, an
      authorized CDN).</t>

   <t>CDNI commands and responses to be transmitted with
      confidentiality.</t>

   <t>Protection of the integrity of CDNI commands and responses.</t>

   </list>
   </t>

   <t>
   When TLS is used, the general TLS usage guidance in <xref target="RFC9325"/> MUST be
   followed.</t>

   <t>
   The mechanisms for access control are dCDN-specific and are not
   standardized as part of this CI/T specification.</t>

   <t>
   HTTP requests that attempt to access or operate on CI/T data
   belonging to another CDN MUST be rejected using, for example,
   HTTP 403 ("Forbidden") or 404 ("Not Found"). This is intended to
   prevent unauthorized users from generating unnecessary load in the dCDNs
   or the uCDNs due to revalidation, reacquisition, or unnecessary
   acquisition.</t>

   </section>

   <section title="Denial of Service" anchor="denial-of-service"><t>
   This document does not define a specific mechanism to protect against
   Denial-of-Service (DoS) attacks on the CI/T interface. However, CI/T
   endpoints can be protected against DoS attacks through the use of TLS
   transport and/or via mechanisms outside the scope of the CI/T
   interface, such as firewalling or the use of Virtual Private Networks
   (VPNs).</t>

   <t>
   Depending on the implementation, triggered activity may consume
   significant processing and bandwidth in the dCDN. A malicious or
   faulty uCDN could use this to generate unnecessary load in the dCDN.
   The dCDN should consider mechanisms to avoid overload -- for example,
   by rate-limiting acceptance or processing of triggers, or by
   performing batch processing.</t>

   </section>

   <section title="Privacy" anchor="privacy"><t>
   The CI/T protocol does not carry any information about individual end
   users of a CDN; there are no privacy concerns for end users.</t>

   <t>
   The CI/T protocol does carry information that could be considered
   commercially sensitive by CDN operators and content owners. The use
   of mutually authenticated TLS to establish a secure session for the
   transport of CI/T data, as discussed in <xref target="authentication-authorization"/>, provides
   confidentiality while the CI/T data is in transit and prevents
   parties other than the authorized dCDN from gaining access to that
   data. The dCDN MUST ensure that it only exposes CI/T data related to
   the uCDN to clients it has authenticated as belonging to that uCDN.</t>

   </section>

   </section>

   </middle>

   <back>
   <references title="Normative References">
   &RFC1930;
   &RFC2119;
   &RFC3339;
   &RFC3986;
   &RFC8126;
   &RFC8259;
   &RFC8006;
   &RFC8007;
   &RFC8174;
   &RFC9110;
   &RFC9112;
   &RFC9325;
   &RFC9388;
   &RFC9562;

   </references>
   <references title="Informative References">
   &RFC6707;
   &RFC7336;
   &RFC7337;
   &RFC7736;
   &RFC7975;
   &RFC8216;

        <reference anchor="POSIX.1" target="http://pubs.opengroup.org/onlinepubs/9699919799/">
                <front>
                        <title>The Open Group Base Specifications Issue 7</title>
                        <author surname="IEEE"/>
                        <date day="31" month="Jan" year="2018"/>
                </front>
                <seriesInfo name="IEEE Std" value="1003.1 2018 Edition"/>
        </reference>

        <reference anchor="MPEG-DASH" target="https://www.iso.org/standard/65274.html">
                <front>
                        <title>
                                Information technology -- Dynamic adaptive streaming over HTTP (DASH) --
                                Part 1: Media presentation description and segment format
                        </title>
                        <author>
                                <organization>ISO</organization>
                        </author>
                        <date month="05" year="2014"/>
                </front>
                <seriesInfo name="ISO/IEC" value="23009-1:2014"/>
                <seriesInfo name="Edition" value="2"/>
        </reference>

        <reference anchor="MSS" target="https://msdn.microsoft.com/en-us/library/ff469518.aspx">
                <front>
                        <title>
                                [MS-SSTR]: Smooth Streaming Protocol
                        </title>
                        <author>
                                <organization>Microsoft</organization>
                        </author>
                        <date month="September" year="2017"/>
                </front>
                <seriesInfo name="Protocol Revision" value="8.0"/>
        </reference>

        <reference anchor="ECMA404" target="https://ecma-international.org/publications-and-standards/standards/ecma-404/">
                <front>
                        <title>ECMA-404 - The JSON data interchange syntax</title>
                        <author>
                                <organization>ECMA International</organization>
                        </author>
                        <date month="12" year="2017"/>
                </front>
                <seriesInfo name="Edition" value="2"/>
        </reference>


        <reference anchor="REST">
                <front>
                        <title>Architectural Styles and the Design of Network-based Software Architectures</title>
                        <author initials="R." surname="Fielding">
                                <organization/>
                        </author>
                        <date year="2000"/>
                </front>
                <seriesInfo name="Ph.D. Dissertation, University of California, Irvine" value=""/>
        </reference>
        <reference anchor="OpenAPI" target="https://spec.openapis.org/oas/v3.1.0.html">
          <front>
            <title>OpenAPI Specification, Version 3.1.0</title>
            <author fullname="OpenAPI Initiative"/>
            <date day="15" month="February" year="2021"/>
          </front>
          <seriesInfo name="OpenAPI Specification" value="3.1.0"/>
        </reference>


   </references>

   <section title="Acknowledgments" numbered="no" anchor="acknowledgments"><t>
   The authors thank Kevin Ma for his input, and Carsten Bormann for his
   review and formalization of the JSON data.</t>
   <t>Initial work on parts of this document was undertaken while Alan Arolovitch was affiliated with Viasat.</t>

   </section>

   </back>

   </rfc>
