Newer
Older
openstack-caracal-dc-dc / docs / audit / d137-location-listing-20260726.txt
# D-137 declared-location STAT LISTING -- measured 2026-07-26
#
# WHY THIS FILE EXISTS: docs/CURRENT-STATE.md previously asserted specific remote
# filenames and modes citing d137-tier2-privileged-20260726.txt, which is a checker
# VERDICT file and contains none of them (committee lens 3/5 finding). GA-R1 rule 2
# requires measurements be quoted from captured command output. This is that output.
#
# Metadata only: stat -c '%n %a'. No file content read. sudo -n used ONLY for the
# two root-owned directories.

## jumphost (vcloud) -- SEC-009 convention folders
# /home/jessea123/vr1-office1-creds
  /home/jessea123/vr1-office1-creds/maas-admin-password 600
  /home/jessea123/vr1-office1-creds/maas-operator-password 600
  /home/jessea123/vr1-office1-creds/office1_svc_ed25519 600
  /home/jessea123/vr1-office1-creds/office1_svc_ed25519.pub 644
  /home/jessea123/vr1-office1-creds/opnsense-api.txt 600
  /home/jessea123/vr1-office1-creds/opnsense-root-hash 600
  /home/jessea123/vr1-office1-creds/opnsense-root-password 600
  /home/jessea123/vr1-office1-creds/README 600
  /home/jessea123/vr1-office1-creds/tailscale-authkey.txt 600
  /home/jessea123/vr1-office1-creds/vr1-netbox.env 600
  /home/jessea123/vr1-office1-creds/vr1-netbox-sandbox.env 600
  /home/jessea123/vr1-office1-creds/vr1-office1.env 600
  /home/jessea123/vr1-office1-creds/vr1-stage1.env 600
# /home/jessea123/vr1-dc0-creds
  /home/jessea123/vr1-dc0-creds/maas-api-key.txt 600
  /home/jessea123/vr1-dc0-creds/vr1-dc0-edge_ed25519 600
  /home/jessea123/vr1-dc0-creds/vr1-dc0-edge_ed25519.pub 644
  /home/jessea123/vr1-dc0-creds/vr1-dc0_svc_ed25519 600
  /home/jessea123/vr1-dc0-creds/vr1-dc0_svc_ed25519.pub 644
# /home/jessea123/vr1-dc1-creds
  /home/jessea123/vr1-dc1-creds/maas-api-key.txt 600
  /home/jessea123/vr1-dc1-creds/opnsense-api.txt 600
  /home/jessea123/vr1-dc1-creds/vr1-dc1-edge_ed25519 600
  /home/jessea123/vr1-dc1-creds/vr1-dc1-edge_ed25519.pub 644
  /home/jessea123/vr1-dc1-creds/vr1-dc1-maas-power_ed25519 600
  /home/jessea123/vr1-dc1-creds/vr1-dc1-maas-power_ed25519.pub 644
  /home/jessea123/vr1-dc1-creds/vr1-dc1_svc_ed25519 600
  /home/jessea123/vr1-dc1-creds/vr1-dc1_svc_ed25519.pub 644

## headend (voffice1) -- SEC-022 shadow stores
  /home/jessea123/vr1-dc0-creds/maas-virsh_ed25519 600
  /home/jessea123/vr1-dc0-creds/vr1-dc0_svc_ed25519 600
  /home/jessea123/vr1-dc0-creds/vr1-dc0_svc_ed25519.pub 644
  /home/jessea123/vr1-dc1-creds/vr1-dc1_svc_ed25519 600
## headend -- CLI profile, juju client store
# CORRECTION (measured this run): ~/.maas.cli does NOT exist. The MAAS snap CLI stores its
# profile + API key in ~/snap/maas/current/.maascli.db (a SQLite DB), NOT the path the
# matrix inferred. Note the `current` symlink -- same per-revision snap fragility class as
# the power keys.
  stat: cannot statx '/home/jessea123/.maas.cli': No such file or directory
  /home/jessea123/.local/share/juju/clouds.yaml 600
  /home/jessea123/.local/share/juju/credentials.yaml 600
  /home/jessea123/.local/share/juju/public-clouds.yaml 600
## headend -- region secrets dir (SEC-020) + snap ssh + enroll secret [PRIVILEGED]
  /root/maas-secrets/admin.apikey 600
  /root/maas-secrets/admin.pass 600
  /root/maas-secrets/db.pass 600
  /root/maas-secrets/lxd-trust.pass 600
  /var/snap/maas/current/root/.ssh/config 644
  /var/snap/maas/current/root/.ssh/id_dc1_power 600
  /var/snap/maas/current/root/.ssh/id_ed25519 600
  /var/snap/maas/current/root/.ssh/known_hosts 600
  /var/snap/maas/current/root/.ssh/known_hosts.old 644
  /var/snap/maas/common/maas/secret 640

## netbox VM (office1-netbox) -- founding SEC-009 miss [PRIVILEGED]
  /root/netbox-secrets/admin.pass 600
  /root/netbox-secrets/api.token 600
  /root/netbox-secrets/secret_key 600

## headend -- REAL MAAS CLI profile store (measured after the ~/.maas.cli miss)
  /home/jessea123/snap/maas/current/.maascli.db 600