08 — Contribute
What is needed
Prometheus deliberately has no central operator and no tenant market. There is nothing to invest in — what is needed is collaboration, not capital: six concrete contributions.
Wanted
Six concrete contributions
They attach at five places in the system — the map shows where each contribution docks.
Mirror hosting in the EU
For the Phase 1 pilot period — foundation sponsorship, university data center, or OSS foundation. Requirements: 1 vCPU, 8 GB RAM, 500 GB SSD, ClickHouse-capable, publicly accessible via HTTPS. EU hosting is preferred; other regions are allowed, but then the GDPR responsibility lies with the operator.
Attaches to: Mirror
Pilot library
A popular JS or Python package whose maintainers are willing to integrate the SDK in a pre-release version and make the Phase 1 telemetry publicly available. This is the most honest test of the entire approach.
Attaches to: SDK in the library
Research partner
University or OSS analytics group that tests the K6 acceptance test: Can a researcher answer the reach-doubling question in under two minutes from the Open Data dump? If not, the data format is not suitable.
Attaches to: Open Data
Open Data license legal clearance
CC-BY-4.0 is resolved, and Phase 1 snapshots already appear under it — with a Provisional clause in the manifest. The final Foundation legal clearance is sought. If it is rejected, the published snapshot remains valid and a re-issue follows under a new snapshot ID.
Attaches to: Licence & law
Anti-Sybil threshold calibration
The mechanism is in place: rate limit per DID, cross-mode plausibility, and burn-in — Proof-of-Work was deliberately rejected. Empirical data is needed on the threshold values: Is the factor of 10 between Track A and Track D appropriate, does the spike flag work in practice, is the 7-day period useful?
Attaches to: Protocol & code
Security disclosure
Re-identification demos are explicitly welcome — via the path in
SECURITY.md, with a 90-day deadline. Anyone who shows that
k-anonymity breaks helps the project more than any approval.
Attaches to: Protocol & code
Where to go with what
Channels and responsibilities
Which path is the right one for which concern.
| Concern | Path |
|---|---|
| Bug or feature | Issue in the repository, preferably with a label |
| Security vulnerability | Path in SECURITY.md — not the issue tracker |
| Re-identification demo | Also SECURITY.md, with 90 days disclosure period |
| Concept question | Issue with label concept |
| Mirror onboarding | Issue with label federation and mirror DID proposal |
| Become a maintainer | Pull request against MAINTAINERS.md, two existing maintainers co-sign |
Demarcation
What Prometheus is not
What Prometheus explicitly is not — so that no one invests time in a wrong expectation.