Newer
Older
openstack-caracal-dc-dc / docs / archive / memory-20260718 / project-posture-closed-test.md

name: project-posture-closed-test description: VR1 is a closed in-house test -- prioritize deployment tooling/runbooks/hardening over real-world security metadata: node_type: memory type: feedback

originSessionId: 75c0e0cb-822c-4f42-ab63-04d3175865f4

VR1 (the DC-DC buildout) is a CLOSED IN-HOUSE TEST cloud, not a live/shared/production environment.

What to prioritize (operator ruling, 2026-07-15): deployment steps, configuration tuning, OpenTofu/juju/deployment-tool scripting and hardening, and runbook draft updates.

What is DEFERRED: real-world deployment security -- credential rotation/revocation, non-shared tokens, flip-to-private, second-person unseal, etc. Those come AFTER the tests are complete, during the teardown-and-redeploy cycles (test2/3/4/...). The security-ledger rows (SEC-001..008) stay OPEN as tracked obligations but are NOT blockers on test progress.

Why: validating the deployment mechanics, tooling, and runbooks is the point of this phase; locking down credentials on a closed test would spend effort where it does not yet matter. Security hygiene that IS done now is the DATA-LOSS-preventing kind (see [[creds-folder-convention]]), not the lockdown kind.

How to apply: when weighing a security hardening task vs a deployment/tooling/runbook task in VR1, prefer the latter unless the security item is also a data-loss or continuity risk. Do not gate test progress on the deferred SEC obligations. Still surface real exposures to the ledger (don't hide them), just don't treat them as must-fix-now.