Claims status
Each scenario claim (scenarios/claims/) is a promise the docs make, run against chant’s emulator. A claim runs twice: plain, where it should pass, and broken (BREAK=1), where the claim’s own check should catch the fault it plants; a claim of several parts is caught only when each part catches the fault planted in it. npm run claims runs them; see the comment at the top of scenarios/run.ts.
The record was last written at 2026-10-10 21:02 UTC, at commit 9329873. A row run in an earlier run keeps that run’s commit and date.
A row marked “not recorded” has not been run into the record. CI does not run the template claim, which needs a Forgejo with a runner.
Each docs page names the claims that prove it, and npm run check fails when a page that is not a draft names one that does not pass plain and get caught broken here. The last column lists those pages.
| Claim | Dialect | What it says | Plain | Broken | Commit | Date | Pages |
|---|---|---|---|---|---|---|---|
| adopt | ClickHouse | yodel init –from adopts a live database without touching it, and yodel plan then shows no change; on Postgres its policies, row-level security and grants too, on ClickHouse its dictionaries, functions, roles, users, row policies and grants; yodel init –baseline records the baseline, behind the gate, in a second environment that holds the same schema, and refuses one that differs | pass | caught | 9329873 |
2026-10-10 21:02 UTC | access, adoption, from-other-tools, workflows |
| adopt | Postgres | yodel init –from adopts a live database without touching it, and yodel plan then shows no change; on Postgres its policies, row-level security and grants too, on ClickHouse its dictionaries, functions, roles, users, row policies and grants; yodel init –baseline records the baseline, behind the gate, in a second environment that holds the same schema, and refuses one that differs | pass | caught | 9329873 |
2026-10-10 21:02 UTC | access, adoption, from-other-tools, workflows |
| new | ClickHouse | yodel new writes the next migration offline, with no dev database, and it applies; on Postgres, functions, procedures and triggers too, which lint checks | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | adoption, getting-started, lint, migrations, schema, workflows |
| new | Postgres | yodel new writes the next migration offline, with no dev database, and it applies; on Postgres, functions, procedures and triggers too, which lint checks | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | adoption, getting-started, lint, migrations, schema, workflows |
| lint | ClickHouse | yodel lint –replay replays the migrations into a fresh database and each gives the schema it recorded; offline, yodel lint fails a migrations directory with a fork (exit 3), naming both migrations; a checkpoint replays alone to its recorded schema, and a fresh environment starts from it; yodel revert undoes the newest migration behind the gate, with a hand-written step for its data step, back to its parent’s recorded schema, and refuses a checkpoint or a migration before one; yodel test runs a project’s tests on databases replayed from the migrations, a seed meeting the backfill after it, fails a case whose assertion does not hold, and refuses an environment with a history; on Postgres, a unique index over rows with duplicates is refused before the gate by its generated pre-check (exit 4, naming the statement and the count), and yodel lint flags it as data-dependent | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | getting-started, lint, migrations |
| lint | Postgres | yodel lint –replay replays the migrations into a fresh database and each gives the schema it recorded; offline, yodel lint fails a migrations directory with a fork (exit 3), naming both migrations; a checkpoint replays alone to its recorded schema, and a fresh environment starts from it; yodel revert undoes the newest migration behind the gate, with a hand-written step for its data step, back to its parent’s recorded schema, and refuses a checkpoint or a migration before one; yodel test runs a project’s tests on databases replayed from the migrations, a seed meeting the backfill after it, fails a case whose assertion does not hold, and refuses an environment with a history; on Postgres, a unique index over rows with duplicates is refused before the gate by its generated pre-check (exit 4, naming the statement and the count), and yodel lint flags it as data-dependent | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | getting-started, lint, migrations |
| pr-comment | ClickHouse | the pull request comment lists the pending migrations with each statement’s class, and the digest the gate asks for | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | approval |
| pr-comment | Postgres | the pull request comment lists the pending migrations with each statement’s class, and the digest the gate asks for | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | approval |
| approval | ClickHouse | a pending migration applies only after chant approve of its plan digest, and the history records that digest; a failing pre-migration check refuses it, and so does a policy rule, read at the base commit, unless an override is recorded for that digest, for a yodel revert as for an apply; the audit log derived from the history and the ledger accounts for every approval and apply, and names one removed; a reader and a writer that are one user are refused, and the reader, its password a minted token, cannot write; an approval is refused once the migration changed after it, and nothing is applied | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | approval, audit, configuration, getting-started, migrations, workflows |
| approval | Postgres | a pending migration applies only after chant approve of its plan digest, and the history records that digest; a failing pre-migration check refuses it, and so does a policy rule, read at the base commit, unless an override is recorded for that digest, for a yodel revert as for an apply; the audit log derived from the history and the ledger accounts for every approval and apply, and names one removed; a reader and a writer that are one user are refused, and the reader, its password a minted token, cannot write; an approval is refused once the migration changed after it, and nothing is applied | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | approval, audit, configuration, getting-started, migrations, workflows |
| resume | ClickHouse | an interrupted apply resumes where it stopped: a backfill step written as yodel’s form (table, key, batch size, SQL) from its receipts, running each batch once, and a failed statement at that statement, never resending one that ran | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | from-other-tools, migrations, steps |
| resume | Postgres | an interrupted apply resumes where it stopped: a backfill step written as yodel’s form (table, key, batch size, SQL) from its receipts, running each batch once, and a failed statement at that statement, never resending one that ran | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | from-other-tools, migrations, steps |
| out-of-order | ClickHouse | a migration merged late, before one already applied, is refused unless –allow-out-of-order, and never skipped | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | from-other-tools, migrations |
| out-of-order | Postgres | a migration merged late, before one already applied, is refused unless –allow-out-of-order, and never skipped | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | from-other-tools, migrations |
| rebuild | ClickHouse | ClickHouse: a sort-key change is a ClickHouseRebuildOp step inside the migration, never an ALTER or a drop; approved, it runs and keeps every row, and without an approval it does not run; yodel cleanup drops the old table it kept only after its retention date, behind an approval on a gate of its own, sealed under a sealed environment | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | steps |
| drift | ClickHouse | yodel drift reports a declared object changed out of band, naming the property, and one dropped; on the versioned path it compares with the newest applied migration’s recorded schema, so a pending migration is not drift | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | drift, getting-started |
| drift | Postgres | yodel drift reports a declared object changed out of band, naming the property, and one dropped; on the versioned path it compares with the newest applied migration’s recorded schema, so a pending migration is not drift | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | drift, getting-started |
| declarative | ClickHouse | the declarative path: yodel plan shows the change against the live server and yodel apply makes it behind the plan-bound gate, for src/ declarations (on Postgres, functions, procedures and triggers, and access control: a role, a policy and grants, with a grant made by hand revoked; on ClickHouse, a dictionary, a function, and access control: a role, a user, a row policy and grants, with a grant made by hand revoked) and for an ORM’s exported DDL | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | access, configuration, orm, schema, workflows |
| declarative | Postgres | the declarative path: yodel plan shows the change against the live server and yodel apply makes it behind the plan-bound gate, for src/ declarations (on Postgres, functions, procedures and triggers, and access control: a role, a policy and grants, with a grant made by hand revoked; on ClickHouse, a dictionary, a function, and access control: a role, a user, a row policy and grants, with a grant made by hand revoked) and for an ORM’s exported DDL | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | access, configuration, orm, schema, workflows |
| topology | ClickHouse | ClickHouse: one migrations directory applies to a single node and to a Replicated database, and one to a sharded cluster with drift read there, each rendered for its topology | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | configuration, topology |
| template | ClickHouse | a project from the starter template, on Forgejo: apply only after approval, lint with replay and the plan comment on a pull request, and the approved change applied on merge; a sealed wave applies only on an approval sealed by a signer listed at the base, and a pr-review wave on the review of a writer other than the author; a pull request job cannot write, a forked migration fails lint and is annotated, a stale or hand-edited pipeline fails yodel ci –check, the CI image pinned by digest runs a pull request’s jobs, a command token source mints the reader’s password, and the drift watch keeps one tracking issue | pass | caught | 868ff97 |
2026-10-10 21:57 UTC | forges, lint-and-plan, notify |
| template | Postgres | a project from the starter template, on Forgejo: apply only after approval, lint with replay and the plan comment on a pull request, and the approved change applied on merge; a sealed wave applies only on an approval sealed by a signer listed at the base, and a pr-review wave on the review of a writer other than the author; a pull request job cannot write, a forked migration fails lint and is annotated, a stale or hand-edited pipeline fails yodel ci –check, the CI image pinned by digest runs a pull request’s jobs, a command token source mints the reader’s password, and the drift watch keeps one tracking issue | pass | caught | 868ff97 |
2026-10-10 21:57 UTC | forges, lint-and-plan, notify |
| template-github | ClickHouse | a project from the starter template, on GitHub Actions (act and a mock GitHub): apply only after approval, lint with replay and the plan comment on a pull request, and the approved change applied on merge; a sealed wave applies only on an approval sealed by a signer listed at the base, and a pr-review wave on the review of a writer other than the author; a pull request job cannot write, a forked migration fails lint and is annotated, a stale or hand-edited pipeline fails yodel ci –check, the CI image pinned by digest runs a pull request’s jobs, a command token source mints the reader’s password, and the drift watch keeps one tracking issue | pass | caught | 868ff97 |
2026-10-10 21:55 UTC | forges, lint-and-plan, notify |
| template-github | Postgres | a project from the starter template, on GitHub Actions (act and a mock GitHub): apply only after approval, lint with replay and the plan comment on a pull request, and the approved change applied on merge; a sealed wave applies only on an approval sealed by a signer listed at the base, and a pr-review wave on the review of a writer other than the author; a pull request job cannot write, a forked migration fails lint and is annotated, a stale or hand-edited pipeline fails yodel ci –check, the CI image pinned by digest runs a pull request’s jobs, a command token source mints the reader’s password, and the drift watch keeps one tracking issue | pass | caught | 868ff97 |
2026-10-10 21:55 UTC | forges, lint-and-plan, notify |
| template-gitlab | ClickHouse | a project from the starter template, on GitLab CI: apply only after approval, lint with replay and the plan comment on a merge request, and the approved change applied on merge; a merge request job cannot write, a forked migration fails lint and keeps its code quality report, a stale or hand-edited pipeline fails yodel ci –check, a project with ci.apply: false and no apply pipeline passes it and gets the plan comment, and the drift watch keeps one tracking issue | not recorded | not recorded | forges, lint-and-plan, notify | ||
| template-gitlab | Postgres | a project from the starter template, on GitLab CI: apply only after approval, lint with replay and the plan comment on a merge request, and the approved change applied on merge; a merge request job cannot write, a forked migration fails lint and keeps its code quality report, a stale or hand-edited pipeline fails yodel ci –check, a project with ci.apply: false and no apply pipeline passes it and gets the plan comment, and the drift watch keeps one tracking issue | not recorded | not recorded | forges, lint-and-plan, notify | ||
| lock-retry | ClickHouse | Postgres: a statement blocked behind another session’s lock times out at lock_timeout and is retried until it succeeds; Postgres and ClickHouse with Keeper: two applies at once never send a statement twice, the second waits naming the holder, and –stand-down steps aside for a newer commit | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | migrations |
| lock-retry | Postgres | Postgres: a statement blocked behind another session’s lock times out at lock_timeout and is retried until it succeeds; Postgres and ClickHouse with Keeper: two applies at once never send a statement twice, the second waits naming the holder, and –stand-down steps aside for a newer commit | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | migrations |
| column-change | Postgres | Postgres: a column rename runs as a PostgresMigrationOp step (expand, backfill, switch, contract) and keeps every value; a step that fails part way keeps its work and resumes from its receipts | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | steps |
| waves | ClickHouse | the apply pipeline runs one wave per environment, in order, each behind its gate policy read from the base commit, applies only what the wave before applied, and applies a tenant set’s migrations to every tenant behind one gate; a sealed wave counts only an approval sealed by a signer the base commit lists | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | approval, workflows |
| waves | Postgres | the apply pipeline runs one wave per environment, in order, each behind its gate policy read from the base commit, applies only what the wave before applied, and applies a tenant set’s migrations to every tenant behind one gate; a sealed wave counts only an approval sealed by a signer the base commit lists | pass | caught | c6f58a4 |
2026-10-10 20:29 UTC | approval, workflows |
