# Queued findings -- Stage 5 dc0 Step 7 (phase-03 core verify), 2026-08-06
# Survives-a-clear sweep. Full evidence: docs/audit/stage5-dc0-phase03-coreverify-20260806.txt
# Status authority is CURRENT-STATE.md (section 1 Stage-5 block + section 7 client row).

STEP 7 EXIT GATE: NOT MET (GA-R6/E3, no conditional close). Core-API layer VERIFIED;
two named items keep it OPEN: F-CV3 (Horizon TLS) + Step 3.4 (not run).

--- FINDINGS (logged, NOT fixed -- hard rule 1; operator authorized triage 2026-08-06) ---

F-CV1  [CONFIRMED root cause] designate _admin haproxy backend DOWN.
  designate/0 apache https frontend binds ONLY 10.12.8.198:8991 (metal-admin); haproxy's
  `designate-api_admin_10.12.12.110` backend dials designate-0 at 10.12.12.110:8991
  (METAL-INTERNAL), where apache has no SSL vhost -> check-ssl hits plaintext -> DOWN.
  BIND-PLANE MISMATCH, VR1 dual-metal-plane specific (D-141 .8 metal-admin vs .12 metal-internal).
  NOT Stage-7 collateral (structural). Fix (focused session, GATED): align the admin-interface
  plane -- charm binds metal-internal too, OR haproxy admin backend dials metal-admin; correct
  plane is a D-141/B1 question. Re-run haproxy sweep after.

F-CV3  [root cause NOT nailed] dashboard VIP 10.12.4.58:443 serves PLAINTEXT (Horizon exit-gate
  FAILS). Certs present under /etc/apache2/ssl/horizon/; apache :433 served by Ubuntu
  default-ssl.conf, NOT the charm's openstack_https_frontend.conf (glance, working, uses the
  charm frontend w/ SSLEngine on). Charm https frontend not effective for dashboard. SEPARATE
  finding from F-CV1 -- do NOT chase a common fix. Needs focused triage + gated remediation.

  NOTE both: certs ARE present -> NOT the ovn CN-issuance class; NOT a missing certificates
  relation. Charm apache-TLS-frontend layer. Also owed with the Horizon-access remediation:
  D-044 cookie override + D-075 root redirect (per-rebuild, not applied this rebuild).

--- OWED (not findings, just must-not-evaporate) ---

O2  dc1 RACK needs `apt-get install -y python3-openstackclient` (6.6.0-0ubuntu2) BEFORE dc1's
    Step 7 -- F-CV2 is per-DC; only the dc0 rack was done this session (== 07-30 queued-F1).
O4  Step 3.4 keystone domain-manager policy gate (PO: stage-1 + C.4 G3 behavioral, G3 mutates)
    still owed for phase-03 close.
O5  DOCFIX candidate: phase-03-admin-openrc.sh / phase-04-network-{create,verify}.sh /
    phase-04-internal-cert-san-verify.sh / vault-kv-health.sh read DC-dependent lib-net values
    WITHOUT lib_net_select_dc (harmless on dc0, WRONG+SILENT on dc1). Fix before dc1's Step 7.
O6  NAMED-GATE DEFECT (already in CURRENT-STATE): phase-03-core-verify.md Step 3.1 asserts
    non-active/idle == 1; VR1 roster yields the 4 deferred-by-design + gss. Runbook DOCFIX owed
    (-m openstack -> -m vr1-dc0; run-from-rack per D-138; the settle count).
O7  rack kernel 6.8.0-136 running vs 6.8.0-137 available -- reboot NOT taken (would bounce the
    rack + libvirt + all nodes); a maintenance-window item, logged.

--- FIRST SURFACE in this file: F-CV1 (confirmed), F-CV3, O5, O7. ---
