The service is the only SQLite writer. The agent durably spools events and
submits them idempotently over the pod-local API; globally unique ids make
retries safe. SQLite runs in a worker thread so health and SSE never block.
Schema (v1)
audit_events, chat_messages, tombstones, deployment_events, media,
media_analyses, jobs, meta. Payloads are JSON validated by shared types;
schema version lives in PRAGMA user_version.
Compatibility rule
Forward-only, bounded migrations. Release N must leave every value it can
write readable by release N-1: schema, enum/JSON values, session file, event
spool, archive index, media metadata, API cursors. Destructive cleanup waits
until the previous revision stopped reading the shape. CI proves it by
running previous -> candidate -> previous.
Retention and archives
Audit 90 days hot, chat one year hot; rows move exactly once into immutable
monthly zstd JSONL segments with versioned sidecar indexes. A crash between
publish and delete reconciles by segment membership. Timeline and recall
merge hot and cold transparently. Tombstones filter archived chat forever.
Maintenance
Service-scheduled: hourly archive cycle + incremental vacuum + tmp
reconcile, daily quick_check. Storage thresholds: warn under 20% free, stop
under 10% (new model work and media pause; reads, queue, audit, recovery,
and notification writes continue from reserved capacity).
# Data
## Ownership
The service is the only SQLite writer. The agent durably spools events and
submits them idempotently over the pod-local API; globally unique ids make
retries safe. SQLite runs in a worker thread so health and SSE never block.
## Schema (v1)
audit_events, chat_messages, tombstones, deployment_events, media,
media_analyses, jobs, meta. Payloads are JSON validated by shared types;
schema version lives in `PRAGMA user_version`.
## Compatibility rule
Forward-only, bounded migrations. Release N must leave every value it can
write readable by release N-1: schema, enum/JSON values, session file, event
spool, archive index, media metadata, API cursors. Destructive cleanup waits
until the previous revision stopped reading the shape. CI proves it by
running previous -> candidate -> previous.
## Retention and archives
Audit 90 days hot, chat one year hot; rows move exactly once into immutable
monthly zstd JSONL segments with versioned sidecar indexes. A crash between
publish and delete reconciles by segment membership. Timeline and recall
merge hot and cold transparently. Tombstones filter archived chat forever.
## Maintenance
Service-scheduled: hourly archive cycle + incremental vacuum + tmp
reconcile, daily quick_check. Storage thresholds: warn under 20% free, stop
under 10% (new model work and media pause; reads, queue, audit, recovery,
and notification writes continue from reserved capacity).