Notarizing documentation

Upgrade notes

Developer preview. Not yet production ready. This page is rendered from docs/upgrade.md of the Notarizing repository at revision d23579e737f9d1e16e07b3c6b21a51282d64027e. It describes the behavior of that revision.

Contents

A workspace has a schema version. A new notarizing binary can add schema migrations. A command that owns the workspace applies the pending migrations when it opens the workspace: init, serve and the commands that write, for example change import. Read-only commands and mcp refuse a workspace that needs a migration. Run init on purpose after a backup, so that the migration happens at a time that you select.

Before you upgrade

  1. Stop notarizing serve. A migration needs the workspace owner lock.

  2. Make a backup with the old binary:

    notarizing backup --output /backups/ws-before-upgrade
    notarizing backup verify /backups/ws-before-upgrade
  3. Keep the backup until you have checked the upgraded workspace.

A migration is not reversible. An old binary cannot open a workspace that a new binary migrated. To go back, restore the backup with the old binary (see the operator guide).

Upgrade

  1. Install the new binary.

  2. Apply the migrations:

    notarizing --workspace /srv/notarizing/ws init
  3. Check the workspace:

    notarizing --workspace /srv/notarizing/ws doctor
  4. Start serve again.

If the workspace has a newer schema than the binary, the binary refuses it with unsupported_schema (exit code 1) and changes nothing. Install the newer binary.

Schema versions

Each migration applies once, in order, in one transaction. The workspace records the SHA-256 of each applied migration. A released migration never changes.

VersionMigrationWhat it adds
10001_evidenceReports and artifacts by digest, receipts, report IDs for retries.
20002_sourcesRegistered repositories, source snapshots, effective targets, check bindings and the assessment policy.
30003_reviewThe append-only review journal and its projections: assumptions, relationships, decisions, notes, wording drafts and saved views.
40004_graphReserved. It applies no change.
50005_searchThe search index, the embedding provider configuration, retention purges and imported evidence bundles.
60006_assessmentsImmutable assessment records and an index for the evidence of one requirement.
70007_correctionsCollector records of corrected results (evidence correct).
80008_bundle_reviewReview events and corrections of imported evidence bundles, as claims of the exporting workspace.
90009_empirical_relationsFour empirical relation kinds of the review journal: observes, hypothesizes, regresses and fixes.
100010_review_supersessionsThe scope of reviewed supersessions: a later receipt supersedes a corrected failure for one requirement and dimension.
110011_source_accessThe source access changes of registered repositories (repo access revoke and repo access restore).
120012_repository_locationsThe path changes of registered repositories (repo set-path).

The current schema version is 12. A test checks that this table names every migration of the binary.

After the upgrade

  • Search indexes stay valid when the extractor and chunker versions do not change. If notarizing search status shows a stale index, run notarizing search index --target ID.
  • Check the CLI reference for new commands. This revision adds notarizing graph whatif, notarizing repo access revoke and notarizing repo access restore.
  • Migration 11 adds an empty table. Every registered repository keeps its source access.

All Notarizing documents