Newer
Older
openstack-caracal-dc-dc / docs / audit / d137-tier3-provenance-20260726.txt
# D-137 tier-3 VALIDITY sweep -- live + privileged, 2026-07-26
#   python3 scripts/creds-matrix.py --tier2 --tier3 --remote --privileged \
#     --pending-stage vr0-phase01 --pending-stage vr0-phase02 \
#     --pending-stage vr0-phase03 --pending-stage tenant-onboard
#
# DIGESTS ONLY. sha256sum is invoked as an external command on both sides, so only a
# 64-hex digest ever enters the checker process. No credential content is transferred.
# This is the check SEC-020's stale-trap warning has needed since it was written: the
# sha256 equality it depends on was a ONE-TIME manual act on 2026-07-25.

=== creds-matrix: tier 1 (STATIC) ===
=== creds-matrix: tier 2 (EXISTENCE) ===
=== creds-matrix: tier 3 (VALIDITY) ===
  [ok]   S1 schema: 81 rows, all enums valid, site-keys region-qualified, no duplicate (id,site,host-role,filename)
  [ok]   S3 render: 2 source field(s) SKIPPED -- rendering them needs the declared path from creds-manifests/vm-secret-locations (ruling 3); the list now EXISTS but the source-field derivation is not wired
  [ok]   S3 render drift: rendered row fields (mode, source) match checked-in; header prose and non-jumphost rows are OUT OF SCOPE of this compare
  [ok]   S4 mint-ref: every script:/runbook: reference resolves to a real location
  [ok]   S4 provenance debt: 29 row(s) are mint-ref=operator-terminal -- NOT reproducible from the repo (research FINDING 1). Admitted by design; converting them is remediation, not a checker fix.
  [ok]   S7 notes: 34 note key(s) referenced, all resolve, none orphaned
  [ok]   E0 jumphost location '~/vault-init/*' does not exist -- SKIPPED (typically a mint stage this deployment has not reached)
  [ok]   E0 jumphost location '~/octavia-pki/*' does not exist -- SKIPPED (typically a mint stage this deployment has not reached)
  [ok]   E0 jumphost location '~/octavia-pki/issuing-ca/*' does not exist -- SKIPPED (typically a mint stage this deployment has not reached)
  [ok]   E0 jumphost location '~/octavia-pki/controller-ca/*' does not exist -- SKIPPED (typically a mint stage this deployment has not reached)
  [ok]   E0 jumphost location '~/octavia-pki/controller/*' does not exist -- SKIPPED (typically a mint stage this deployment has not reached)
  [ok]   E0 headend location '/root/maas-secrets/*' read via ESCALATION (sudo -n, metadata only) after an unprivileged probe could not open it
  [ok]   E0 headend location '/var/snap/maas/current/root/.ssh/*' read via ESCALATION (sudo -n, metadata only) after an unprivileged probe could not open it
  [ok]   E0 netbox location '/root/netbox-secrets/*' read via ESCALATION (sudo -n, metadata only) after an unprivileged probe could not open it
  [ok]   E1 18 expected artifact(s) deferred as not-yet-minted (--pending-stage)
  [ok]   V1 1 multi-copy identity(ies) SKIPPED -- fewer than two copies could be digested (unresolvable path, instance template, or a location not probed). A digest that could not be taken is never a match.
  [ok]   V1 provenance: all copies byte-identical for 4 group(s): dc0-svc-key; dc0-svc-key; dc1-svc-key; maas-region-admin (declared verbatim copies)
  [FAIL] S2 vr1-dc0 EXPECTED-BUT-ABSENT: 'opnsense-api.txt' (id dc0-edge-api, SEC-021) is expected by the matrix but NOT declared in the manifest -- the credential is either missing or undeclared
  [FAIL] S2 vr1-dc0 EXPECTED-BUT-ABSENT: 'vr1-dc0-maas-power_ed25519' (id dc0-maas-power-key, SEC-021) is expected by the matrix but NOT declared in the manifest -- the credential is either missing or undeclared
  [FAIL] S2 vr1-dc0 EXPECTED-BUT-ABSENT: 'vr1-dc0-maas-power_ed25519.pub' (id dc0-maas-power-key, SEC-021) is expected by the matrix but NOT declared in the manifest -- the credential is either missing or undeclared
  [FAIL] S5 ASYMMETRY: vr1-dc0 declares id=dcN-maas-power-key file=id_ed25519 on headend (custody=off-manifest-known) with no counterpart in vr1-dc1 -- a per-DC credential must exist at BOTH DCs in the same shape
  [FAIL] S5 ASYMMETRY: vr1-dc0 declares id=dcN-maas-power-key file=maas-virsh_ed25519 on headend (custody=off-manifest-known) with no counterpart in vr1-dc1 -- a per-DC credential must exist at BOTH DCs in the same shape
  [FAIL] S5 ASYMMETRY: vr1-dc1 declares id=dcN-maas-power-key file=id_dcN_power on headend (custody=off-manifest-known) with no counterpart in vr1-dc0 -- a per-DC credential must exist at BOTH DCs in the same shape
  [FAIL] S6 IDENTITY CONFLATION: id 'maas-region-admin' serves 2 principal types (human via gui; service via api, cli-profile) -- ruling 5 requires one identity to serve one principal type
  [FAIL] E1 EXPECTED-BUT-ABSENT: dc0-edge-api 'opnsense-api.txt' expected at jumphost/vr1-dc0, not found (mint-stage stage3, SEC-021)
  [FAIL] E1 EXPECTED-BUT-ABSENT: dc0-maas-power-key 'vr1-dc0-maas-power_ed25519' expected at jumphost/vr1-dc0, not found (mint-stage stage3, SEC-021)
  [FAIL] E1 EXPECTED-BUT-ABSENT: dc0-maas-power-key 'vr1-dc0-maas-power_ed25519.pub' expected at jumphost/vr1-dc0, not found (mint-stage stage3, SEC-021)
  [FAIL] E1 EXPECTED-BUT-ABSENT: dc1-svc-key 'vr1-dc1_svc_ed25519.pub' expected at headend/vr1-dc1, not found (mint-stage stage3, SEC-022)
  [FAIL] E2 WORLD-READABLE: office1-tofu-maas-apikey 'terraform.tfstate.backup' at jumphost/vr1-office1 is mode 664
  [FAIL] E4 UNCHECKABLE: 2 row(s) have no declared location for their (role, site) and can never be verified -- add a location row or correct the matrix: capi-mgmt-kubeconfig 'config' (cloud/-); rbd-mirror-peer-token 'rbd-mirror-bootstrap-token' (unit/-)

FAIL: creds-matrix tier 1 -- 81 row(s), 17 check group(s) clean, 13 finding(s)