Ledger summaries rotated 2026-08-02 (GA-R4 rule 3 / F1 -- cap restored at this close)
Moved VERBATIM from docs/session-ledger.md. The live ledger stood at 283 lines and this close's summary would have breached the 300-line cap.
- Branch
dc-dc-stage5-preconditions, 19 commits pushed (1ddb078..). NO stage opened/closed. Scan unchanged: 3 decisions, SEC 21, D 138 / DOCFIX 206 / BUNDLEFIX 053.
- >>> OPERATOR DIRECTIVE, STANDING: THE NEXT SESSION PROCEEDS TO THE JUJU DEPLOYMENT (Stage 5), NO MATTER WHAT. Verbatim: "we have to continue to juju deployment next session no matter what". Precondition polishing is DONE; further hardening is OUT OF SCOPE unless it blocks the deploy. This is the GA-F06 circuit-breaker made explicit -- do not spend the session on records.
- DOCFIX-205: Q1 WITHDRAWN -- D-117 ruled it 2026-07-13; it resurfaced only because D-117's annotation half was never executed (0 of 4) while its own Status claimed "FULLY EXECUTED". All four annotated; Status corrected. Q2 withdrawn too (D-137 fork 1 ruled 2026-07-25). Third stale premise in one findings file.
- F9 CLOSED LIVE, both DCs (gated per DC, never batched): controller certs reissued into their own zones --
omega.dc0.vr1 / omega.dc1.vr1, fresh P-256 keys, CAs untouched. Capture docs/audit/octavia-reissue-executed-20260730.txt.
octavia-pki.sh reissue SHIPPED (operator: "Full script minter now"): derived zone, printf config (F8 paid off), stage-assert-promote, single-value overlay surgery, backup-before-mint.
- VALIDATION AGENTS EARNED THEIR COST. Mutation testing deleted my three new assertions and the harness stayed GREEN every time. Six defects closed: A15 (no keyUsage/EKU minted + passed everything), A16 (
-days defaults to 30 and verify had NO validity check), A17 (overlay/workspace desync read PASS), the re-run guard REFUSING to fix broken certs, A8's vacuous negative, two overlay checks moved pre-mint.
- F8 + F9 FIXED AT SOURCE in 1.0-GEN.c -- the generation path would otherwise recreate both at the next DC standup. F10 handled: 13 mint-refs re-anchored single-pass by row id; S4 clean.
- P7: the PKI is now an actual GATE in
preflight.sh -- headend-only, NOT EVALUATED elsewhere, rc3 mapped explicitly, and it requires the literal zone line because verify exits 0 on a wrong-zone cert while inert.
scripts/lib-identity.sh -- CLOUD_NAME + CLOUD_DOMAIN in ONE file; a rebuild that renames the estate edits one file. T47 catches shell-vs-OpenTofu drift, proven able to fail.
- Backup custody done + REGISTERED (2 rows, manifests,
n-reissue-backup); the secrets-storage PIN now covers this step's creds and certs. Hazard recorded: these archives carry CA issuance state -- never restore over a workspace that has issued since.
- OWNED: I withdrew two of my own recommendations after measuring (the vr0-dc0 retirement, and the D-137 escalation framing); pushed one red-lint commit via
; instead of &&; two harness stub bugs. All corrected on-surface.
- Guard misfire tally now SEVEN -- it blocked a command that only TESTED it, then the heredoc documenting its own misfires. Hardening it needs no ruling (fork 1 is ruled).
- Gauntlet ALL GREEN (89) BOTH hosts; repo-lint 0 fail; octavia-pki 51/51; preflight 33/33; creds-matrix 65/65 + 5 pre-existing findings. verify 37/0 and P7 [ok] on both DCs.
- NEXT (Stage 5 entry): preflight is RED only on P5's pre-existing credential register -- decide accept-or-remediate at the gate, do not re-audit it. G17 arms at first boot. Bodies:
docs/changelog-20260730-docfix205-d117-annotation.md, -octavia-reissue-tool.md. Status ONLY in CURRENT-STATE.md.