# Queued findings -- session 2026-08-06/07: phase-03 Step 3.4 + Decision C + per-DC Tailscale
# Survives-a-clear sweep (savegame Step 3). Status authority is CURRENT-STATE.md.
# Body: docs/changelog-20260806-step34-g3-probe.md. Each item says where it already lives,
# or that THIS file is its first surface.

=== FIRST SURFACE (transcript-only until this file) ===

O1  DOCFIX candidate -- octet-map surface LAGS. design-decisions.md:5954 (D-134 AMENDMENT
    2026-08-07, this session) states the STANDING utility octet map as .4 artifact / .5 Juju /
    .6 region / .7 Tailscale. The OLDER D-132 addendum at design-decisions.md:7168 still reads
    ".4 ... .5 ... .6 MAAS region" with NO .7 -- correct as of 07-30, now lagging. Append-only
    register, so it is history; but a reader grepping the map at :7168 misses .7. DOCFIX: annotate
    :7168 -> "extended to .7 Tailscale 2026-08-07, see the D-134 amendment". LOGGED, not fixed.

O2  ENV/EXECUTION TRAIT: an `ssh voffice1 '<cmd>'` session's default cwd is NOT the repo clone
    (/home/jessea123/openstack-caracal-dc-dc); git/tofu commands fail "not a git repository"
    unless the remote command LEADS with `cd $REPO`. Cost ~6 retries during this savegame's
    Step-1b sync. Prepend the cd in every remote git/tofu invocation. First surface.

O3  AS-EXECUTED LOG IS PARTIAL for this window (F6 class). `run-logged.sh` was NOT opened this
    session; the live mutations (G3 probe, four tofu applies, four MAC-pin applies) ran gated
    but unwrapped. Every action is in the changelog + CURRENT-STATE with read-backs, and the G3
    probe has its own capture (docs/audit/g3-dc0-probe-20260806.txt), but the as-executed log
    must NOT be read as complete for this window.

O4  TOFU STATE DOES NOT CARRY AUTO-GENERATED MACs. With `macs = []`, the libvirt provider does
    not read the generated MAC addresses back into tofu state (`tofu state show` shows none);
    they must be captured live via `virsh domiflist <vm>` over the qemu+ssh provider URI, then
    pinned. The region-VM comments already say "pin from virsh domiflist"; the state-blindness
    nuance is recorded here so a future session does not look for them in state.

=== ALREADY ON SURFACE (recorded where noted) ===

R1  Decision C -- phase-03 Horizon reconciled to VR1; Step 3.3 splits to its own gate row.
    Operator: "We need to pull the tailscale steps forward so we can close out horizon properly."
    -> CURRENT-STATE.md (phase-03 (c) clause) + changelog Item 5.

R2  Four Tailscale rulings (a-d), EXACT utterances, + the "both DCs" directive:
    (a) "Dedicated VM at utility .7 (Recommended)"; (b) "Star: operator->DC only (Recommended)";
    (c) "We will not be creating HA for this now. Pin HA scale up for Headscale/Tailscale.";
    (d) "SNAT ON now; pin source-IP preservation (Recommended)"; "Lets plan and push to both DC0
    and DC1 in this step." -> design-decisions.md D-129(iii) AMENDMENT 2026-08-07 + D-134
    AMENDMENT + gap-21 register row + changelog Item 6.

R3  Substrate apply scope ruling: "dc0 full + dc1 FULL (also the region VM)" -> changelog Item 9.
    Build-pace ruling: "Push, build tooling AND stand up the .7 VMs". G3 build: "Build g3-probe.sh
    + harness"; "Run G3 probe now". -> changelog Items 1/8/9.

R4  Measurements: G3 PASS live (7 ok/0 fail, teardown clean); Step 3.4 stage-1 PO: at UNIT level
    (app-aggregate hid it); both dashboard VIPs HTTPS 200 + csrftoken Secure; D-044/D-075 NOT
    applied; cert IP-SAN covers 10.12.8.58; capacity FIT 874/1024=85%; dc1 plan 4-add (region VM
    bundled); 3 VMs applied + MACs pinned + tofu clean. -> CURRENT-STATE + changelog Items 3-9 +
    substrate main.tf comments.

R5  Headscale facts: control plane tailscale.baldurkeep.com (Cloudflare-fronted, server version
    UNMEASURED, operator no access this session); Office1 node UNTAGGED (AdvertiseTags null,
    180-day key-expiry defect to fix); star ACL / autoApprovers / tagged authkey are the
    control-plane prerequisites. -> D-129(iii) amendment notes 1+4 + site-tailscale.sh header.

R6  Security note: the .7 tailscale VM attaches all six planes (node-vm module default) but
    ADVERTISES only metal-admin; the other five legs stay uncarved/unrouted. -> substrate main.tf
    comment (both DCs).

=== DELIBERATELY NOT DONE (owed, next sessions) ===

N1  Headscale-side build: tagged pre-auth key, autoApprovers (write BEFORE first advertise),
    star ACL, the join via site-tailscale.sh install, fix the Office1 untagged node. BLOCKED on
    Headscale control-plane access (operator lacks it this session).
N2  Per VM (3): start -> MAAS enlist/commission/deploy Ubuntu -> carve legs (.7 metal-admin +
    provider-public gw) -> install tailscale. All VMs currently powered off (autostart=false).
N3  dc1 MAAS-region SETUP workstream (vr1-dc1-maas-01 stood up but not configured): init /
    PostgreSQL / image sync / eventual dc1 node migration.
N4  SEC row for per-DC Tailscale key custody -- opens at authkey-mint time in the Headscale build
    (D-129(iii) amendment note).
N5  O10 (carried, pre-existing): dc0/dc1 rack ~/repo-stage/bundle.yaml STALE vs repo; re-stage
    before any redeploy. This session touched no bundle/overlay, so the staleness is unchanged.

=== GITIGNORED / THROWAWAY (Step 3d.1) ===
- Throwaway tofu saved plans on voffice1 (dc0-tailscale.tfplan, dc0-macpin.tfplan,
  dc1-full.tfplan, dc1-macpin.tfplan) -- gitignored, already applied, no durable value.
- No permission-rule (.claude/settings.local.json) changes this session.

=== STAGE-CLOSE OWED (added 2026-08-07, operator-directed "make sure the v6 posture carries forward") ===
O5  Fold the IPv6-PRIMARY posture invariant into the openstack-cloud-ops SKILL Posture section at
    the next STAGE close (the skill is the invariant home; swept at stage close). Auto-memory
    `ipv6-primary-posture.md` is the always-loaded defense NOW (added this session, pointer to
    D-101/D-139/D-141); the skill Posture line is the second surface so a stage-close skill sweep
    also carries it. The v6 posture is IPv6-primary (v6 wherever possible, v4/dual-stack only where
    forced); D-141's v4-active is the NARROW container-VIP necessity case, not a cloud-wide lean.
