Evidence ledger 24 sources Checked 05 Oct 2026

Evidence ledger

One row per claim in Everything they deleted was on the inside: ten years of HashiCorp, read from its own repositories: who published it, what grade it carries, when it was written, when the link was last checked, and the quote or figure it rests on. Nothing in the guide is cited from memory, so anything not in this table is not in the guide.

Dig: Everything they deleted was on the inside: ten years of HashiCorp, read from its own repositories. Research date 2026-10-05. One row per claim.

A note on how this was researched, because it bounds the evidence. The session's network policy allowed raw.githubusercontent.com, github.com, pkg.go.dev and www.hashicorp.com, and denied every other host, including Roblox's blog, CircleCI's forum, discuss.hashicorp.com, developer.hashicorp.com, the GitHub API and the GitHub web UI. Every file below was therefore fetched through raw.githubusercontent.com at the ref shown, and is cited to the equivalent github.com blob URL that a reader can open. Two consequences: the guide has only three distinct source hosts, which the verifier warns about and which is accepted deliberately, and no issue thread, pull request or commit-level evidence was available, so the "rejected pull request" layer of the hunt is missing and is noted as such in the guide.

# Org Title Tier Published Checked URL (fetched as raw at the ref shown) Claim taken from it Supporting quote or figure
1 HashiCorp go-plugin README source n/d, read 2026 2026-10-05 https://github.com/hashicorp/go-plugin/blob/main/README.md One subprocess plugin mechanism is shared by every product, and it is local-only by design "it is the plugin system that has been in use by HashiCorp tooling for over 4 years... additionally in use by Terraform, Nomad, Vault, Boundary, and Waypoint"; "Plugins over a real network are not supported and will lead to unexpected behavior"
2 HashiCorp Terraform Plugin Protocol adr n/d, read 2026 2026-10-05 https://github.com/hashicorp/terraform/blob/main/docs/plugin-protocol/README.md The protocol is versioned so that one plugin can serve two majors, negotiated at handshake "The versioning strategy described below was introduced with protocol version 5.0 in Terraform v0.12"; "major version 5 uses the package name tfplugin5... allows a plugin server to implement multiple major versions at once"
3 OpenTofu Plugin protocol documentation source n/d, read 2026 2026-10-05 https://github.com/opentofu/opentofu/blob/main/docs/plugin-protocol/README.md The fork inherited the boundary verbatim, including a version history that never happened "introduced with protocol version 5.0 in OpenTofu v0.12"
4 HashiCorp Terraform LICENSE at v1.5.5 source 2023 2026-10-05 https://github.com/hashicorp/terraform/blob/v1.5.5/LICENSE The last Mozilla-licensed Terraform release "Mozilla Public License, version 2.0"
5 HashiCorp Terraform LICENSE at v1.6.0 source 2023 2026-10-05 https://github.com/hashicorp/terraform/blob/v1.6.0/LICENSE The licence change landed at 1.6.0 with a four-year change date "Licensed Work: Terraform 1.6.0"; "Change Date: Four years from the date the Licensed Work is published"; "Change License: MPL 2.0"
6 HashiCorp HashiCorp adopts Business Source License blog 2023-08-10 2026-10-05 https://www.hashicorp.com/en/blog/hashicorp-adopts-business-source-license The SDKs stayed permissive; competitive hosted vendors lose future patches "HashiCorp APIs, SDKs, and almost all other libraries will remain MPL 2.0"; "will no longer be able to incorporate future releases, bug fixes, or security patches"
7 OpenTF The OpenTF manifesto blog 2023 2026-10-05 https://github.com/opentofu/manifesto/blob/main/README.md The fork's stated ask was reversal of the licence, not a different product "proposes returning it to a fully open license... avoiding fragmentation of the community"
8 HashiCorp Terraform 1.3.0 changelog source 2022 2026-10-05 https://github.com/hashicorp/terraform/blob/v1.3.0/CHANGELOG.md Five state backends were removed one minor after deprecation "The following backends, which were deprecated in v1.2.3, have now been removed: artifactory, etcd, etcdv3, manta, swift"
9 HashiCorp terraform-plugin-sdk README source n/d, read 2026 2026-10-05 https://github.com/hashicorp/terraform-plugin-sdk/blob/main/README.md The superseded SDK is still presented as the ecosystem's mainstay "The SDK is stable and broadly used across the provider ecosystem"
10 HashiCorp terraform-plugin-framework README source n/d, read 2026 2026-10-05 https://github.com/hashicorp/terraform-plugin-framework/blob/main/README.md The replacement SDK is MPL 2.0 and still targets a 2019 CLI "Providers built with this framework are compatible with Terraform version v0.12 and above"; "License: Mozilla Public License v2.0"
11 Go team terraform-plugin-framework version history source 2026 2026-10-05 https://pkg.go.dev/github.com/hashicorp/terraform-plugin-framework?tab=versions Framework dates: first tag 2021-06-24, GA 2022-12-13, latest 2026-03-10 v0.1.0 Jun 24, 2021; v1.0.0 Dec 13, 2022; v1.19.0 Mar 10, 2026
12 Go team terraform-plugin-sdk v2 version history source 2026 2026-10-05 https://pkg.go.dev/github.com/hashicorp/terraform-plugin-sdk/v2?tab=versions Both SDKs are still released, often on the same day v2.0.0 Jul 30, 2020; v2.40.0 Mar 10, 2026; v2.40.1 Apr 28, 2026
13 HashiCorp Consul CHANGELOG source 2015-2026 2026-10-05 https://github.com/hashicorp/consul/blob/main/CHANGELOG.md The log store lineage with dates, and the WAL regression 0.5.1 (May 13, 2015) "Migrating Raft log from LMDB to BoltDB"; 1.11.0 (December 14, 2021) "Use bbolt instead of the legacy boltdb implementation", "Added a configuration to disable boltdb freelist syncing"; 1.15.0 (February 23, 2023) "Added experimental wal backend for log storage"; 1.15.2 (March 30, 2023) "Fixes a bug where restoring a snapshot when using the experimental WAL storage backend causes a panic"
14 HashiCorp Consul, Experimental WAL LogStore backend overview, at v1.16.0 adr 2023 2026-10-05 https://github.com/hashicorp/consul/blob/v1.16.0/website/content/docs/agent/wal-logstore/index.mdx Why a copy-on-write B-tree is wrong for a log, and the exit criterion for the replacement "It is a single file that only ever grows"; "The metadata is proportional to the amount of free pages, so after a large burst write latencies tend to increase. In some cases, the latencies cause serious performance degradation to the cluster"; "We will continue testing before making WAL the default backend"
15 HashiCorp The same page at v1.20.0 adr 2025 2026-10-05 https://github.com/hashicorp/consul/blob/v1.20.0/website/content/docs/agent/wal-logstore/index.mdx Still experimental in the newest copy the repository carries "# Experimental WAL LogStore backend overview"; "The WAL backend is an experimental feature"
16 HashiCorp Consul telemetry, Raft replication capacity issues, at v1.16.0 vendor 2023 2026-10-05 https://github.com/hashicorp/consul/blob/v1.16.0/website/content/docs/agent/telemetry.mdx The threshold, the batch cap, and the follower that cannot rejoin "Write throughput is high (say 500 commits per second or more) and constant"; "the max batch size allowed is 64 logs"; "followers may be unable to recover from a restart if restoring takes longer than the minimum value for the current leader"; disabling free-list sync "will however increase the startup time for a server as it must scan the raft.db file for free space"
17 HashiCorp raft-wal design document adr n/d, read 2026 2026-10-05 https://github.com/hashicorp/raft-wal/blob/main/README.md The three stated gains, the rejected design, the detection limitation, still experimental "This library is still considered experimental!"; "Efficient truncations... More efficient appends due to only one fsync per append vs two in BoltDB"; "We initially designed a WAL on the same principals, however felt that the additional complexity it adds wasn't justified"; "If the segment tail file is lost after entries are committed to it... the WAL can't distinguish that from a crash during rotation"; "we don't validate checksums on every record read"
18 HashiCorp raft-boltdb README and metrics source n/d, read 2026 2026-10-05 https://github.com/hashicorp/raft-boltdb/blob/master/README.md The free-list metadata is written with every committed log "raft.boltdb.freelistBytes... When raft_boltdb.NoFreelistSync is set to false these metadata bytes must also be written to disk for each committed log"
19 HashiCorp Vault storage stanza documentation at v1.15.0 vendor 2023 2026-10-05 https://github.com/hashicorp/vault/blob/v1.15.0/website/content/docs/configuration/storage/index.mdx Integrated storage replaced Consul as the recommendation at 1.4; external storage is now second class "Integrated Storage is an embedded Vault data storage available in Vault 1.4 or later... Prior to Vault 1.4, Consul was the recommended Vault storage"; external storage "HashiCorp Supported: Limited support", "Extra network hop"; Consul "All data is in memory"
20 HashiCorp Vault integrated storage configuration at v1.15.0 vendor 2023 2026-10-05 https://github.com/hashicorp/vault/blob/v1.15.0/website/content/docs/configuration/storage/raft.mdx The defaults that set the follower recovery window and the entry ceiling "trailing_logs (integer: 10000)"; "snapshot_threshold (integer: 8192)"; "max_entry_size (integer: 1048576)"
21 HashiCorp Vault CHANGELOG source 2024-2026 2026-10-05 https://github.com/hashicorp/vault/blob/main/CHANGELOG.md Vault added the same WAL option in 1.16.0, for a different stated reason; 2.0.0 is April 2026 1.16.0: "Experimental Raft-WAL Option: Reduces risk of infinite snapshot loops for follower nodes in large-scale Integrated Storage deployments"; "## 2.0.0 ### April 14, 2026"
22 HashiCorp Nomad CHANGELOG source 2026 2026-10-05 https://github.com/hashicorp/nomad/blob/main/CHANGELOG.md The 2.0 major carried no breaking change and was driven by licence accounting "## 2.0.0 (April 21, 2026)"; features: "config: add nonproduction config option", "core (Enterprise): Enable parsing and reporting with IBM PAO licenses"; improvements: "server: Added support for raft-WAL logstore"
23 HashiCorp Consul CHANGELOG, 2.0.0 Enterprise and 2.1.0-rc1 source 2026 2026-10-05 https://github.com/hashicorp/consul/blob/main/CHANGELOG.md The acquirer's licensing system and identity products appear in the changelog; configuration itself moved into Raft 2.0.0 Enterprise (May 22, 2026): "update to go-licensing/v4 and go-census/v3 inorder to adapt to new licenses of PAO"; "a new \"rate-limit\" config entry kind... stored in Raft and automatically replicated to all servers"; 2.1.0-rc1 (September 28, 2026): "Add Raft-backed dynamic feature gate framework (Phase 1)"
24 HashiCorp consul-dataplane README source n/d, read 2026 2026-10-05 https://github.com/hashicorp/consul-dataplane/blob/main/README.md The four stated benefits of deleting the client agent "Consul Dataplane's design removes the need to run Consul client agents"; "Fewer networking requirements... Simplified set up... Additional environment and runtime support... Easier upgrades"
25 HashiCorp Consul, Simplified Service Mesh with Consul Dataplane, at v1.14.0 vendor 2022 2026-10-05 https://github.com/hashicorp/consul/blob/v1.14.0/website/content/docs/connect/dataplane/index.mdx The agent was deletable because the orchestrator had grown its job; it shipped as beta "orchestrators such as Kubernetes already include components called kubelets that support health checking and service location functions typically provided by the client agent"; "Consul Dataplane is currently in beta"
26 HashiCorp Boundary README source n/d, read 2026 2026-10-05 https://github.com/hashicorp/boundary/blob/main/README.md The newest product advertises agentlessness as a feature "does not require an agent to be installed on every end host, making it suitable for access to managed/cloud services and container-based workflows"
27 HashiCorp Otto README source 2016 2026-10-05 https://github.com/hashicorp/otto/blob/master/README.md Otto was decommissioned "Otto is no longer actively developed or maintained"
28 HashiCorp Serf README source 2024 2026-10-05 https://github.com/hashicorp/serf/blob/master/README.md The gossip library's own website was shut down "The Serf website was shut down on 10/02/2024"
29 HashiCorp Waypoint README source 2024 2026-10-05 https://github.com/hashicorp/waypoint/blob/main/README.md The community edition was abandoned "HashiCorp Waypoint Community Edition is no longer actively maintained"
30 HashiCorp Vagrant README source 2026 2026-10-05 https://github.com/hashicorp/vagrant/blob/main/README.md The hosted Vagrant service is being withdrawn, the CLI is not "HCP Vagrant is in the process of being deprecated and limited features will be available from the community edition effective November 2, 2026... This change is only for HCP Vagrant and does not apply to Vagrant CLI"
31 HashiCorp HashiCorp officially joins the IBM family blog 2025-02-27 2026-10-05 https://www.hashicorp.com/en/blog/hashicorp-officially-joins-the-ibm-family The acquisition completed on 27 February 2025 Armon Dadgar: "HashiCorp will continue to operate as a division of IBM Software with the same mission, but on a bigger stage"
32 OpenTofu State encryption design document adr n/d, read 2026 2026-10-05 https://github.com/opentofu/opentofu/blob/main/docs/state_encryption.md The fork's first substantial divergence, with inherited language constraints "The primary encryption method should be AES-GCM"; "due to the limitations on passing providers through to modules, encryption configuration is global"
33 OpenTofu The RFC process adr 2024-2026 2026-10-05 https://github.com/opentofu/opentofu/blob/main/rfc/README.md A public, dated RFC process with an amendment convention "To Accept an RFC, the majority of the OpenTofu Core Team must approve the Pull Request"; RFCs "are organized by date to help show the progression of concepts over time"
34 OpenTofu OpenTofu CHANGELOG source 2026 2026-10-05 https://github.com/opentofu/opentofu/blob/main/CHANGELOG.md The fork publishes a support horizon in the repository "The v1.14.x release series is supported until February 1 2028"
35 etcd v3.5 data inconsistency postmortem postmortem 2022-04-20 2026-10-05 https://github.com/etcd-io/etcd/blob/main/Documentation/postmortems/v3.5-data-inconsistency.md Log and state can diverge silently, and nothing verifies the invariant "Code refactor in v3.5.0 resulted in consistent index not being saved atomically"; "For single member cluster it is totally undetectable. There is no mechanism or tool for verifying that state database matches WAL"; "Main impact comes from loosing user trust into etcd reliability"
36 Dan Luu A collection of postmortems casestudy n/d, read 2026 2026-10-05 https://github.com/danluu/post-mortems/blob/master/README.md Secondary summaries of the Roblox and CircleCI incidents, the primaries being unreachable "Roblox end Oct 2021 73 hours outage. Issues with Consul streaming and BoltDB"; CircleCI April 2025: "An IAM-role gap permitted out-of-band changes to AWS WAF outside of CircleCI's Terraform pipeline... Because the change wasn't recorded in Terraform, responders deprioritized WAF as a suspect"
37 HashiCorp Terraform architecture document source n/d, read 2026 2026-10-05 https://github.com/hashicorp/terraform/blob/main/docs/architecture.md Terraform Core's internal shape and its separation from providers Repository document describing the package layout and the provider boundary
38 HashiCorp raft README source n/d, read 2026 2026-10-05 https://github.com/hashicorp/raft/blob/main/README.md The shared consensus library behind every clustered product Library README describing the LogStore and StableStore interfaces the log store implementations satisfy

Categories where the hunt came up empty, and what that means

  • No incident reports from the vendor. HashiCorp publishes no public postmortems for Consul, Vault, Nomad or Terraform. Row 35 is a postmortem from a different project in the same failure class, and row 36 is a secondary summary of two customer incidents. An architect should read this as: the operational risk record for these products is private, and your own incident history is the best evidence you will get.
  • No issue threads or rejected pull requests. The GitHub API and web UI were not reachable in this session, so the argument-in-public layer is absent. The closest substitutes used here are the rejected design recorded inside the raft-wal README and the non-goals section of OpenTofu's state encryption document.
  • No papers and no talks. None were reachable. The design documents in rows 14, 17 and 32 carry the reasoning a paper would, without the measurement.
  • No independent benchmarks. There is no public measurement of the WAL backend against BoltDB on a real workload, from HashiCorp or anyone else.