Skip to content

chore(evidence): retire the legacy control_evidences table now that the evidence library is the only register #813

Description

@alex-dembele

Problem

The evidence library (domain.Evidence plus EvidenceControlLink, migration 0052) is the only evidence register the product reads (gorm_compliance_repository.go:265). The old control_evidences table and the domain.ControlEvidence type (internal/domain/compliance.go:100-125) are still there for two reasons: at every boot, BackfillFromControlEvidences copies them into the library (cmd/server/main.go:1408-1415), and the entity timeline still knows the type control_evidence (internal/application/entity/timeline.go:120,141). The comment in cmd/server/schema.go:155-158 says the table stays "for a release".

Before the Evidence Fabric (#554) adds chain of custody and a hash to each proof, there must be exactly one place where evidence lives. Otherwise an auditor can find a document in a table that the chain does not cover.

Why status:blocked

Dropping a table is irreversible and falls under CLAUDE.md "any schema migration that drops or renames a column". The decision goes to the owner as D-056 in docs/DECISIONS.md.

Acceptance criteria

  1. Before anything is dropped, a SQL check proves that every control_evidences row has its counterpart in the library, on a production-like database. The query and its result are pasted here.
  2. The boot backfill is removed once criterion 1 is proven.
  3. The golang-migrate migration that drops control_evidences has a documented down (recreate the empty table) and is tested up and down.
  4. domain.ControlEvidence, its OwnershipBlock and the control_evidence timeline branch are removed. go build ./... and go test ./... are green.
  5. The Definition of Done of feat(evidence): Evidence Fabric record — collector, observation period, hash, chain of custody, freshness #554 names the library as its only register.

Definition of Done

One evidence table, no backfill at boot, no dead type, and the migration proven both ways.

Blocked on: D-056 (owner)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:backendGo, /internal, /pkgarea:dbSchema, migrationsarea:grcGovernance, risk and complianceevidenceEvidence collection and lifecyclepriority:P2Normalpriority:P2-mediumNormal milestone workstatus:readyMeets the ready definitiontier:1-product-engineProduct engine: the canonical model and the data planetype:debtTechnical debt

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions