QUEUED FINDINGS -- session 2026-08-08 (dc0 activation checkpoint: F3 fix, provider net, G18 ruling, Octavia core, retrofit incident)
Sweep method: model read the session, grepped each candidate. FIRST SURFACE items lead.
Status authority is docs/CURRENT-STATE.md; this file is a sweep record, not status.
Session body (what/why/revert per item): docs/changelog-20260808-dc0-activation.md (Items 1-7).

================================================================================
FIRST SURFACE (existed ONLY in transcript / gitignored -- would be lost on a clear)
================================================================================

F1. GITIGNORED PERMISSION RULES added to .claude/settings.local.json (allow[]) -- VERBATIM
    (always-sweep #1; lost on any rebuild of that gitignored file). Eight rules, all tightly
    scoped to the dc0 rack (172.31.0.2) staged phase-04/05 scripts + the octavia
    configure-resources action (the auto-mode classifier walls these despite a broad
    Bash(ssh *); targeted rules clear the wall -- the project's known pattern):
      Bash(ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region bash ~/repo-stage/scripts/phase-04-*)
      Bash(timeout * ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region bash ~/repo-stage/scripts/phase-04-*)
      Bash(ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region bash ~/repo-stage/scripts/phase-05-*)
      Bash(timeout * ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region bash ~/repo-stage/scripts/phase-05-*)
      Bash(ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region MODEL=vr1-dc0 bash ~/repo-stage/scripts/phase-05-*)
      Bash(timeout * ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region MODEL=vr1-dc0 bash ~/repo-stage/scripts/phase-05-*)
      Bash(ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'juju run octavia/leader configure-resources -m vr1-dc0 *)
      Bash(timeout * ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'juju run octavia/leader configure-resources -m vr1-dc0 *)

F2. AMPHORA RETROFIT BUILD INCIDENT (rebuild-relevant; blocks the F6 "1 test LB"). Body:
    changelog Item 7. octavia-diskimage-retrofit action 72 exit 1 at the `-O raw` dib step;
    base uploaded ok (glance id 04c982c2-8906-48b9-8ddc-2febce82c9ef) but NO octavia-amphora
    image. Unit itself active/idle. Hypothesis (UNCONFIRMED, needs sudo on the unit):
    dib-in-LXD-container privilege/loop-device. appendix-A has NO matching symptom -> a new
    appendix-A entry is owed once diagnosed. OWED diagnosis: capture dib stderr via sudo on
    octavia-diskimage-retrofit/0; check loop devices + disk space in the snap common dir.

F3. AMPHORA SCRIPT MODEL DEFAULT = openstack (VR0) -- rebuild-tooling defect. scripts/
    phase-05-amphora-pipeline.sh defaults MODEL=openstack; VR1 needs MODEL=vr1-dc0 (first run
    failed "model ...openstack not found"). Not flagged prominently in the runbook. Rebuild
    tooling should derive/ default the model per-site. Body: changelog Item 7.

F4. CLIENT PACKAGES absent on the dc0 rack but AVAILABLE from the dc0 mirror (D-135):
    python3-octaviaclient (Candidate 3.7.0-0ubuntu1), python3-designateclient (6.0.1-0ubuntu1).
    Both the Octavia LB smoke test and the Designate zone test need their client installed on
    the rack (a gated apt install; exercises D-135). Not yet installed. (Octavia/Designate
    activation itself does NOT need them -- only the smoke tests do.)

F5. G18 OWED#3 (o-hm0 MTU, LP#2018998) NOT yet checked -- an adjacent Stage-5 Octavia
    obligation, independent of the G18 ruling. OWED read-only: verify o-hm0 MTU matches
    lb-mgmt-net's, measured. (G18 OWED#1 prefix + #2 router-isolation ARE done -- changelog Item 6.)

================================================================================
ALREADY ON SURFACE (verified present -- recorded for completeness)
================================================================================

- F3/D-138 co-location gap RESOLVED: phase-04 scripts MAAS_PROFILE-aware (DOCFIX-213), rack
  vr1-dc0-region profile registered (-> hot-kid 10.12.8.6:5240 in-DC regional), provider
  network created + EXIT GATE PASS -> changelog Items 1,3; committed f85daa7.
- G18 RULED (GA-R5 option b) -> CURRENT-STATE G18 row CLOSED + D-101/R8 + D-139 annotations;
  changelog Item 4; committed 0e8b659. Exact utterance recorded (ruling fidelity OK).
- Octavia CORE activated (configure-resources op 67) -> changelog Item 6; committed 295185d.
  lb-mgmt-subnetv6 = fc00:5b7a:7bdc:bd86::/64 (charm ULA); mgmt router external_gateway_info=None.
- Designate decision: REAL D-106/D-117 Stage-7 (operator choice) + scope flag (os-public-hostname
  flip) -> changelog Item 5. D-106 puts Designate CONFIG at Stage 7 (design-decisions.md:2924).
- Re-IP ruling-prep package -> docs/audit/reip-1013-ga-r5-ruling-prep-20260808.md (committed
  f85daa7); CURRENT-STATE pivot pointer. STILL OWED: 3 live-free checks (Headscale routes,
  live office1-netbox, live vr0-dc0) before the operator can rule.
- G18 ruling-prep package -> docs/audit/g18-lb-mgmt-ipam-ruling-prep-20260808.md (committed 0e8b659).
- REBUILD finding: vvr1-dc0/vvr1-dc1 outer hosts are MAAS rack controllers under OFFICE1 admin,
  NOT their DC regionals -> changelog Item 1 (operator directive: racks register up to DC regional).
- F3-original correction (F3 said phase-05 needs maas -- FALSE) -> changelog Item 3.

================================================================================
ALWAYS-SWEEP FIVE
================================================================================
1. GITIGNORED STATE: see F1 (8 permission rules, verbatim). No other gitignored artifact created.
   Credential used read-only: ~/vr1-dc0-creds/maas-region-api-key.txt (piped to `maas login -`
   via stdin, never printed) -- it is the vr1-dc0-region admin API key (proven by the profile
   resolving to hot-kid + returning the provider subnet).
2. DANGLING REFS: commits f85daa7/0e8b659/295185d/a6340e6 cite reip-1013-..., g18-lb-mgmt-...,
   changelog-20260808-..., the two phase-04 scripts + harnesses -- all resolve.
3. RULING FIDELITY: G18 exact utterance recorded (CURRENT-STATE G18 row + D-101/R8 annotation).
   Re-IP ruling NOT yet made (owed, blocked on live-free checks). Designate + F3-fix decisions
   are operator AskUserQuestion selections, recorded in changelog Items 5/1.
4. AS-EXECUTED LOG GAP: run-logged.sh NOT opened (structurally unusable -- interactive
   `script -aqe` cannot wrap tool-driven Bash). Declared in changelog Item 3. The changelog +
   this sweep + the session transcript ARE the as-executed record for this session's mutations
   (profile login, network-create, configure-resources, amphora pipeline x2).
5. CONTRADICTION DETECTOR: G18 OWED#2 (charm mgmt router external_gateway_info=None) settles
   R8's explicitly-unasserted external-gateway question favourably (recorded, changelog Item 6).
   No measurement left contradicting a standing doc unrecorded.

================================================================================
OWNED (own-mistakes, all caught + corrected this session)
================================================================================
- grep -viE 'active.*idle' mis-filter on juju oneline (idle precedes active) returned everything;
  caught immediately, re-queried with an explicit blocked|error|waiting grep.
- my own `echo` string contained the literal "maas list" -> tripped the DOCFIX-016 guard
  (regex matches string literals anywhere in the command, not just live invocations); rephrased.
- first amphora run used the script's MODEL=openstack default (VR0) -> failed fast at the
  config gate (no partial state); fixed with MODEL=vr1-dc0 (now F3 above).
- earlier framed firing configure-resources as "deciding G18 by execution" (advisor concern);
  the G18 prep showed R8 already ruled the substance, so G18 was only apex-recording -- corrected
  before the ruling was put to the operator.

NEXT: (1) diagnose the retrofit incident (F2, sudo on octavia-diskimage-retrofit/0) -> unblocks
the LB test; (2) Designate real D-106/D-117 Stage-7 (confirm os-public-hostname-flip depth);
(3) wrap gates (cloud-assert --capture, controller backup, verify-live) + G18 OWED#3 MTU;
(4) re-IP ruling live-free checks -> present the re-IP GA-R5 ruling (Task #6). Operator PUSH the
4 commits (f85daa7..a6340e6) -> then voffice1 git pull. Status ONLY in CURRENT-STATE.md.
