-- What a change replaces (novox/hq ADR 0217, to-be 44). -- -- Two records the mesh did not keep, and each time a change took effect unseen it was the one -- missing. A settings layer is replaced whole, and the layer it replaced was nowhere: on 2026-10-05 -- one placement set for one module on one machine dropped that machine's whole layer for it, and -- the old one was read back from a database backup (novox/hq issue 304). And of what a machine was sent the -- mesh kept only a digest — enough to say *whether* it changed, never *what*. -- Every layer that was replaced or cleared, with when it had been set and when it went. Not a -- foreign key to settings: the row it was is the row being replaced. create table settings_history ( node uuid references node(id) on delete cascade, module text not null, values jsonb not null, set_at timestamptz, replaced_at timestamptz not null default now(), -- set · clear replaced_by text not null ); create index settings_history_by_layer on settings_history (module, node, replaced_at desc); -- What a machine was last sent, summarised: per resource its id, type, a digest of it and of each -- field, and a container's mounts. Not the declaration: a file's content may carry a secret, and -- this lands in the store's backups. Read only to compare a plan with what was sent; what a machine -- *should* be is composed from the mesh's records every time, as before (migration 0014). alter table node add column sent_summary jsonb;