Every source behind this page, graded. This guide was built almost
entirely from primary repository artefacts, which is both its strength and its limit:
nineteen of these are files HashiCorp or OpenTofu wrote for their own engineers, and only
one is a published incident report.
Postmortem
etcd2022-04
v3.5 data inconsistency postmortem
A structured incident document kept in the repository: summary, background, root
cause, trigger, detection, lessons. A refactor left the consistent index writable
outside the apply path, so a crash could leave the state machine claiming an entry
it never applied.
Carry forward"There is no mechanism or tool for verifying that state database matches WAL." If you cannot verify the invariant, you cannot claim it.
github.com/etcd-io/etcd/blob/main/Documentation/postmortems/v3.5-data-inconsistency.md
Decision record
HashiCorpread 2026-10
raft-wal: design, limitations and the rejected alternative
A forty-kilobyte design document in the repository of the replacement log store. It
states the three advantages over BoltDB, names the page-aligned design that was
written and then dropped as unjustified complexity, and lists the limitations
including the one that matters most: a lost tail segment is indistinguishable from a
crash during rotation.
Carry forward"This library is still considered experimental!" is the sentence to look for before you believe a storage migration is finished.
github.com/hashicorp/raft-wal/blob/main/README.md
Decision record
HashiCorp2023
Experimental WAL LogStore backend overview
The clearest public explanation of why a copy-on-write B-tree is the wrong substrate
for a replicated log, written by the team that chose it originally. It also documents
the verification method, including exhaustive crash simulation with ALICE, and the
condition for promoting the backend to default.
Carry forwardPublishing the exit criterion for an experiment is what makes it an experiment rather than a permanent second code path.
github.com/hashicorp/consul/blob/v1.16.0/website/content/docs/agent/wal-logstore/index.mdx
Decision record
HashiCorpread 2026-10
Terraform plugin protocol: versioning strategy
Written for people building SDKs rather than providers, which is why it is candid.
Major version in the protobuf package name, handshake negotiation, minor versions
strictly additive, and the user-visible error text when a provider and a core binary
cannot agree.
Carry forwardThe ability to serve two major protocol versions from one binary is what buys you the right to make a breaking change at all.
github.com/hashicorp/terraform/blob/main/docs/plugin-protocol/README.md
Source
OpenTofuread 2026-10
The same protocol document, inherited by the fork
OpenTofu's copy of the protocol documentation, including the sentence placing
protocol 5.0 in "OpenTofu v0.12", a release that never existed. The fork kept the
wire format, the package names and the .proto file naming convention
unchanged.
Carry forwardA fork can replace the licence, the governance and the maintainers. It cannot replace the boundary its users' binaries are compiled against.
github.com/opentofu/opentofu/blob/main/docs/plugin-protocol/README.md
Source
HashiCorpread 2026-10
go-plugin: the boundary every product shares
Subprocess plugins over loopback gRPC, used by Packer, Terraform, Nomad, Vault,
Boundary and Waypoint. The README is explicit that the design assumes a local
reliable network and that remote plugins "will lead to unexpected behavior".
Carry forwardA process boundary you do not need for performance can be exactly the boundary you need for independent release cycles.
github.com/hashicorp/go-plugin/blob/main/README.md
Source
HashiCorp2015-2026
Consul CHANGELOG, eleven years of storage decisions
The log store lineage with dates: LMDB to BoltDB in 0.5.1, BoltDB 1.3.1 pinned in
1.0.0, bbolt and the free-list toggle in 1.11.0, the write-capacity metric in 1.12.0,
the experimental WAL backend in 1.15.0, and the snapshot-restore panic in that
backend fixed in 1.15.2 five weeks later.
Carry forwardA changelog read in version order is the cheapest architecture decision record available, and it includes the regressions.
github.com/hashicorp/consul/blob/main/CHANGELOG.md
Source
HashiCorp2026-04
Nomad CHANGELOG, the 2.0.0 entry
A major version with no breaking changes, whose features are a non-production config
option and IBM licence reporting, and whose one architectural line is opt-in support
for the WAL log store.
Carry forwardAfter an acquisition, read version numbers as commercial artefacts until the changelog proves otherwise.
github.com/hashicorp/nomad/blob/main/CHANGELOG.md
Source
HashiCorp2024-2026
Vault CHANGELOG, including the Raft-WAL option
Vault 1.16.0 added the same experimental log store with a different stated motive:
it "reduces risk of infinite snapshot loops for follower nodes in large-scale
Integrated Storage deployments". Vault 2.0.0 is dated 14 April 2026.
Carry forwardThe same engine change is justified differently in each product, which tells you which failure each product was actually hitting.
github.com/hashicorp/vault/blob/main/CHANGELOG.md
Vendor docs
HashiCorp2023
Consul telemetry: Raft replication capacity issues
A documentation section that reads like a postmortem with the incident removed. It
describes the state a cluster gets into, names the three metrics whose relationship
matters, and gives the trade-off for disabling free-list sync, which is slower
startup because the file must be scanned for free space.
Carry forwardLog retention minus restore time is a number you should be able to recite for any replicated system you run.
github.com/hashicorp/consul/blob/v1.16.0/website/content/docs/agent/telemetry.mdx
Source
HashiCorpread 2026-10
consul-dataplane: the agent removal, in its own words
Four stated benefits of deleting the client agent: no gossip connectivity
requirement, no gossip key to distribute, support for runtimes that forbid
hostPort and DaemonSet, and upgrades decoupled from the
servers.
Carry forwardWhen the platform underneath you grows the capability your sidecar exists to provide, the sidecar becomes a liability, not a feature.
github.com/hashicorp/consul-dataplane/blob/main/README.md
Vendor docs
HashiCorp2022
Simplified service mesh with Consul Dataplane, at tag v1.14.0
The documentation as shipped with the release, including the beta warning and the
reasoning that orchestrators "already include components called kubelets that support
health checking and service location functions typically provided by the client
agent".
Carry forwardReading docs at the release tag rather than on the live site is how you recover what the vendor believed at the time.
github.com/hashicorp/consul/blob/v1.14.0/website/content/docs/connect/dataplane/index.mdx
Vendor docs
HashiCorp2023
Vault storage backends: integrated against external
The page that retires a founding promise. Integrated storage is recommended "for
most use cases", external storage is rated "Limited support", and the Consul
comparison notes that with Consul "all data is in memory" while integrated storage
keeps data on disk.
Carry forwardA pluggable interface with one supported implementation is not a plugin system, it is a migration in progress.
github.com/hashicorp/vault/blob/v1.15.0/website/content/docs/configuration/storage/index.mdx
Source
HashiCorp2023
LICENSE at tags v1.5.5 and v1.6.0
The licence change as a sixteen-kilobyte file replaced by a three-kilobyte one. The
new file names the licensed work as "Terraform 1.6.0", sets the change date four
years out and the change licence back to MPL 2.0, and carries the additional use
grant excluding competitive hosted or embedded offerings.
Carry forwardDiff the licence file across tags. It dates the decision more precisely than any announcement.
github.com/hashicorp/terraform/blob/v1.6.0/LICENSE
Eng blog
HashiCorp2023-08-10
HashiCorp adopts Business Source License
The announcement, with the two sentences that matter for architects: APIs, SDKs and
almost all other libraries stay MPL 2.0, and competitive hosted vendors "will no
longer be able to incorporate future releases, bug fixes, or security patches".
Carry forwardThe company closed the binary and kept the extension surface open, because the extension surface was never really theirs to close.
www.hashicorp.com/en/blog/hashicorp-adopts-business-source-license
Eng blog
HashiCorp2025-02-27
HashiCorp officially joins the IBM family
Armon Dadgar's post on the day the acquisition completed, stating that HashiCorp
"will continue to operate as a division of IBM Software with the same mission" and
naming the integrations planned with Ansible, OpenShift and Guardium.
Carry forwardFourteen months later the acquirer's licensing system is visible in the open-source changelogs. Integration reaches the artefacts before it reaches the architecture.
www.hashicorp.com/en/blog/hashicorp-officially-joins-the-ibm-family
Decision record
OpenTofuread 2026-10
State encryption: goals, future goals, non-goals
The design document for the fork's first significant divergence. It is disciplined
about scope, naming partial encryption and provider-supplied key providers as
aspirations, and records a constraint it inherited: because of limits on passing
providers to modules, "encryption configuration is global".
Carry forwardA fork inherits the language constraints along with the protocol. Divergence happens in the features, not the shape.
github.com/opentofu/opentofu/blob/main/docs/state_encryption.md
Decision record
OpenTofuread 2026-10
The OpenTofu RFC process, and how an RFC is amended
Dated RFC files in the repository, a core-team majority to accept, tracking issues
to translate a design into work, and an explicit convention for annotating an older
RFC when a later one invalidates its decision.
Carry forwardThe amendment convention is the part most RFC processes lack, and it is what stops a decision record becoming a lie.
github.com/opentofu/opentofu/blob/main/rfc/README.md
Source
HashiCorp2016-2026
Four obituaries in four READMEs
Otto "is no longer actively developed or maintained"; the Serf website "was shut down
on 10/02/2024"; Waypoint Community Edition "is no longer actively maintained"; HCP
Vagrant is "in the process of being deprecated" with community features limited from
2 November 2026, explicitly not affecting the Vagrant CLI.
Carry forwardThe README of an archived repository is the most honest document a vendor publishes. Read them before you adopt a sibling product.
github.com/hashicorp/waypoint/blob/main/README.md
Source
HashiCorpread 2026-10
Two SDKs, released in lockstep
Version histories showing the framework at v1.19.0 on 10 March 2026 and the
superseded SDK at v2.40.0 the same day, with matching release dates in February 2026,
September 2025 and May 2025. The SDK's own README still describes itself as "stable
and broadly used across the provider ecosystem".
Carry forwardBudget for maintaining the old extension surface indefinitely, because the replacement does not retire it, it joins it.
pkg.go.dev/github.com/hashicorp/terraform-plugin-sdk/v2?tab=versions
Source
HashiCorp2026
Consul 2.x: configuration moves into the Raft log
Two 2026 additions change what configuration is. A global rate limit becomes a config
entry "stored in Raft and automatically replicated to all servers", described as
critical "for emergency scenarios where the cluster is under excessive load", and
2.1.0-rc1 adds a "Raft-backed dynamic feature gate framework" whose agents "fail
closed until the first generation is delivered".
Carry forwardThe interior kept moving after the acquisition: settings that used to require a restart became replicated state with a fail-closed default.
github.com/hashicorp/consul/blob/main/CHANGELOG.md
Case studies
Dan Luuread 2026-10
A curated collection of postmortems
Used here for two entries: Roblox's 73-hour outage at the end of October 2021,
attributed to "issues with Consul streaming and BoltDB", and CircleCI's April 2025
incident where an out-of-band change outside the Terraform pipeline sent responders
down the wrong diagnostic path.
Carry forwardA secondary summary is worth citing when the primary is unreachable, as long as you say which one you read.
github.com/danluu/post-mortems/blob/master/README.md
Source
HashiCorp2022
Terraform 1.3.0 changelog: five backends removed
artifactory, etcd, etcdv3, manta and swift removed one minor release after being
deprecated in 1.2.3, along with the legacy azure backend name.
Carry forwardA two-release deprecation window is enough for configuration, and nowhere near enough for compiled artefacts. The difference is the whole lesson.
github.com/hashicorp/terraform/blob/v1.3.0/CHANGELOG.md
Eng blog
OpenTFread 2026-10
The OpenTF manifesto
The short document that started the fork, asking HashiCorp to "switch Terraform back
to an open source license, avoiding fragmentation of the community", and pointing at
a repository under a name that no longer exists.
Carry forwardThe ask was reversal, not replacement. Forks happen when the perimeter moves and the users cannot follow.
github.com/opentofu/manifesto/blob/main/README.md