Purpose. Long ops sessions on this cloud routinely exceed a single context window and get COMPACTED (sometimes several times). Anything living only in the chat scrollback is lost at compaction. This ledger is the durable, committed record of what is IN FLIGHT, so any session -- after a compaction, or a fresh one -- can resume without losing pending work.
How to use it (standing practice).
bash scripts/ledger-scan.sh. Reconcile.ledger-scan.sh is the DRIFT CHECK -- it derives the open-work it reliably can (PROPOSED/OPEN decisions, OPEN security rows, next-free numbers) straight from the repo. This narrative must not claim CLOSED anything the scan shows OPEN, nor omit what it surfaces.SINGLE STREAM (collapsed 2026-07-13). This ledger previously carried three parallel, separately-owned stream sections (main-chat, jumphost, shared) plus ~30 append-only session narratives. Those streams are CLOSED and reconciled into the one list below. There is now ONE stream. Do not re-introduce per-stream sections.
Where the history went. The 2,189-line session-by-session narrative is NOT lost -- it is in git history (the parent of the collapse commit) and, in durable form, in the 65 docs/changelog-*.md files, docs/design-decisions.md, and the incident reports. This ledger deliberately carries only what is still OPEN, plus the facts that would otherwise be lost because they live nowhere else.
scripts/ledger-scan.sh; do not hand-edit)Re-seeded from a 2026-07-27 scan at the STAGE 4 CLOSE (values verified against bash scripts/ledger-scan.sh in that session). Re-run the scan to refresh.
docs/design-decisions.md are the only ruling authority.bash scripts/ledger-scan.sh (was 20). SEC-025 opened 2026-07-27 -- the NetBox web-GUI admin password, a HUMAN login that had never left the VM it was minted on, now consolidated to ~/vr1-office1-creds/; the row covers the at-rest exposure the copy CREATES, not the gap it closed. (SEC-024, 2026-07-26, was the previous addition.) The SEC register of record is docs/security-ledger.md; row-level dispositions live THERE only (GA-R4/F3) -- this block carries pointer + count, never rows.docs/CURRENT-STATE.md is the authority).docs/ or runbooks/ prose -- historically a decoy token in prose inflated the next-free counter (hardened in DOCFIX-174).ledger-scan D-115 false-positive: RESOLVED. The scan keys on the LAST **Status:** line per ## D-NNN: block, not arbitrary body prose. The general hygiene -- trust the Status line over body text -- still holds.The pre-rotation bodies (~1080 lines: Live state, OPEN WORK VR1/VR0, NetBox write-path bugs, PINNED rulings, standing lessons, state facts, project- completion, NetBox import narrative) moved VERBATIM to docs/archive/session-ledger-rotated-20260719.md. Standing lessons + VR0 state facts were ROUTED to durable homes first (platform-traps already carried most; juju format=line -> appendix-A; guard discipline -> operating-discipline; VR0 cloud facts -> maas-as-built-reference.md). Open work is machine-derived above + CURRENT-STATE.md; do not re-grow bodies here -- sessions append BOUNDED summaries only (15-line cap).
Retained compact blocks (still-live obligations without another home yet):
docs/netbox-write-path-findings.md (the durable home; the rotated-body section is history). Open residue: dumper blind spot + duplicate-CIDR collapse unfixed, hardened fidelity re-run + fix re-verification owed -- ALL gated on the next NetBox WRITE campaign, none current.--public -f json, never the deprecated --long -- archive R9); (2) appendix-A entry for tenant-net-cannot-reach-public-keystone -> nodes register but stall uninitialized (auth_url in the per-cluster clouds secret is hardcoded PUBLIC at capi-helm 1.4.0; as-built carries no interface key), pointing at the phase-08 D-011.3 probe, plus a per-DC precondition line in dc-dc-phase6 Step 12; (3) tenant contract hardening list: PROPOSED -svc-only password neutralization (admin-rotate to discarded value; keystone lock_password blocks password CHANGE, not auth; NEVER lock -cluster -- it keeps PASSWORD auth permanently per D-066); (4) flavor catalog marking = commercial catalog policy, operator prioritization only. RE-VERIFY every citation at review time -- the full verdict lives in the 2026-07-21 disconnected-session transcript, not in a repo surface.The eight oldest closed-session summaries (2026-07-18 through the fifth 2026-07-21 session) moved VERBATIM to docs/archive/session-ledger-rotated-20260726.md. The live ledger was 413 lines against the 300-line cap -- a breach the 2026-07-25 close recorded as OWED. Each rotated summary still points at its own archived full body; only the summaries moved. Sessions from 2026-07-22 onward remain live below.
The three oldest live summaries (all 2026-07-23: G12 dc1 edge->commission+merge, Stage 4 OPEN+carve+mirrors, queue pass + D-068 rulings) moved VERBATIM to docs/archive/session-ledger-rotated-20260727.md. The live ledger was 317 lines against the 300-line cap. Sessions from 2026-07-24 onward remain live below.
The oldest remaining live summary (2026-07-24, caveman guardrails + DC1 proxy-build start) moved VERBATIM to docs/archive/session-ledger-rotated-20260727.md. The live ledger was 305 lines against the 300-line cap. Sessions from 2026-07-25 onward remain live below.
The TWO oldest remaining live summaries -- 2026-07-25 handoff-pack execution + recon + Chat D-136 coupling, and 2026-07-25 MAAS admin-account recovery (SEC-020) -- moved VERBATIM to docs/archive/session-ledger-rotated-20260727.md. The live ledger was 321 lines against the 300-line cap; one pass left it at 3 work appends a POST-CLOSE ADDENDUM. Details: docs/archive/changelogs/changelog-20260725-maas-admin-recovery.md.
docs/audit/creds-creation-points-20260725.md -- 55 MINT sites, and 12 declared secrets have NO mint command anywhere (ssh-keygen = ZERO hits repo-wide), plus three credential dirs outside the SEC-009 convention.docs/D-137-implementation-plan.md. THAT HAPPENED in the same-day successor session (tiers 1-3 built, six-lens committee audit, remediation, preflight P5 wired, SEC-009 demoted). Current status: CURRENT-STATE only.af1b682..1696d08 pushed. Stage 4 stays OPEN; no stage closed.stages-reached coupled by new repo-lint L12; tier 3 probe boundary; SEC-024 chmod. Ruling 4 (SEC-009 -> pointer) executed.creds-mint.sh BEFORE Stage 5 (largest minting event).docs/archive/session-20260726-d137-build.md. Status ONLY in CURRENT-STATE.md.6f5701d on main (2 parents, not squashed, 77 commits), branch retired local + remote, post-merge gauntlet ALL GREEN (81) + repo-lint 0-fail on main, close recorded in CURRENT-STATE by 1023596. Next stage branches off main..pub derived (SEC-021(b) as written -- measured first: it IS the dedicated key, and dc0 using the snap default is SEC-016's ruled design, so NO re-mint); NetBox GUI admin password consolidated (SEC-025, rows 20->21); dc1 svc .pub backfilled. Findings 13 -> 7. MAAS account set verified COMPLETE by enumeration.--ledger added; V2 had shipped with ZERO harness cases.dc-mirror.sh check asserted last-sync EXISTED (dc0 FAIL, dc1 4-day-stale RUNNING both read OK); and creds-audit CLEAN x3 alongside 13 matrix findings. Lesson repo-carried in the skill.tests/creds-matrix T24's finding-class baseline (expected-findings.txt) covers TIER 1 ONLY -- tier-2/3 classes (E1/E3/E4/V1/V2) have NO baselined red state, so a future false green there would not turn the gauntlet red. Same class as the two false greens this session fixed. Also still open from the D-137 close: creds-mint.sh is unbuilt/unruled advice and Stage 5 is the largest minting event, so it is worth ruling BEFORE the bundle deploy rather than after.dc-mirror.sh's dc1 row carrying NO warning that dc1 is proxy-only, so install dc1 would silently rebuild the removed apparatus + enabled timer + ~950G pull. Also: a WRONG causal claim in the mirror-gate capture superseded by appended correction (reset-failed cannot re-arm an inactive timer; the vector was a REBOOT via Persistent=yes); platform-traps section 5 added; the two-net-units coexistence claim marked REASONED-NOT- MEASURED. Capture docs/audit/queued-findings-20260727.txt. QUEUED: a runtime install guard for a non-mirror site (a comment is strictly weaker and prose-only prevention has already failed twice here).docs/archive/changelogs/changelog-20260727-creds-consolidation.md; stage record docs/archive/stage-records/vr1-stage4-record.md. Status ONLY in CURRENT-STATE.md.dc-dc-stage5-grounding-audit off main at 71519a2; 4 commits 514f0aa..de11bf4 pushed. NO stage opened or closed.openstack client on either host (10 scripts need it); 10th controller VM UNAUTHORED + no tag, and dc1 has exactly 9 nodes for a 9-machine bundle; osd-devices=/dev/vdb but every node has only vda; per-role tags authored nowhere; ZERO IPv6 vs D-101's RULED dual-stack; and phase-01, which Step 4 delegates to "verbatim", ABORTS on dc1.cluster_count checked nowhere so decorative HA passes; preflight ignores any sub-gate rc not in {1,2}; P3 verified ZERO of 33 channel pins (no juju on PATH). Three Stage-5 gate commands cannot execute on juju 3.6.27; four of five owed VERIFY-LIVE gates have no runbook step at all.docs/audit/stage5-readiness-20260727.md (READ FIRST), stage5-committee-raw-20260727.md (7 lenses verbatim), queued-rulings-20260727.md -- 11 blocking + 4 standing questions, ONE exchange each, NONE adopted, stage5-live-measurement-20260727.txt, charter stage5-grounding-audit-scope-*.md.tail's exit code not the script's; waved P3's 33 warns through as expected when the CAUSE was a missing binary; called the privileged creds sweep a newly-closed item when 07-26 had already done it. All four corrected in place, not silently.docs/archive/changelogs/changelog-20260727-stage5-grounding-audit.md. Status ONLY in CURRENT-STATE.md.The STAGE-5 GROUNDING AUDIT close bookend above landed while the operator was away, by design. They then returned and worked the queued rulings. This addendum records what followed rather than re-opening that entry -- the same shape as the 2026-07-26 addendum.
Operator-directed full reconciliation before Stage 5; 7-lens read-only committee + live measurement, run AUTONOMOUSLY while away. Branch dc-dc-stage5-grounding-audit, ~30 commits 514f0aa..HEAD pushed. NO stage opened or closed.
openstack client on EITHER host; the 10th controller VM is UNAUTHORED; osd-devices points at a device no node has; per-role tags authored nowhere; ZERO IPv6 vs D-101's ruling; and phase-01, which Step 4 delegates to "verbatim", ABORTS on dc1.cluster_count checked nowhere; preflight fails open on rc not in {1,2}; P3 verified ZERO of 33 channel pins. All ruled fixed (R15).docs/audit/queued-rulings-20260727.md. Execution ALL logged-not-executed.docs/archive/changelogs/changelog-20260727-stage5-grounding-audit.md. Status ONLY in CURRENT-STATE.md.