ANALYSIS + RECOMMENDATION PACKAGE, NOT A RULING. Mutates no authoritative surface. Every "pull forward" is a candidate for a gated operator exchange (GA-R5 to un-defer a ruling; presented-and-approved to change implementation timing). Companion to docs/audit/open-items-review-20260809.md.
docs/design-decisions.md (every D-block + amendment) for decisions/sub-decisions whose RULING or IMPLEMENTATION is held to Roosevelt / "the next deployment" / end-of-deployment review. Full raw enumeration is reproduced in Section 5.The operator's premise: enough has changed to reevaluate what is still correctly held for the future. The material changes since these deferrals were set:
10.13.0.0/16 (D-143, ruled today) is a near-term SECOND full build. dc0 finishes as a checkpoint, then the substrate is torn down and redeployed.>>> THE DISAMBIGUATION THAT PREVENTS THE OBVIOUS ERROR. <<< In these decisions, "next deployment" means Roosevelt -- the next DISTINCT, bare-metal build with real hardware specs -- NOT the intra-VR1 re-IP redeploy. The 10.13 redeploy is a re-build of the same VR1 rehearsal on the same nested VMs; it has no real switch/NIC inventory, no IPMI/BMC, no bare-metal capacity. So it CANNOT exercise anything hardware- or scale-bound (bonds/trunks, NIC budgets, HA at scale, hardware edge plugins). Treating the redeploy as "the next deployment" would wrongly pull those forward.
But the redeploy IS a fresh-build opportunity for anything that (a) is exercised at ANY full build and (b) does not need bare metal: the credential lifecycle, the Vault init, the v6 re-carve. Those are the genuine pull-forwards. The recommendation groups below split exactly on that line.
These retire naturally at the redeploy because the redeploy re-runs the exact build step they govern. No new ruling needed for most -- this is implementation timing.
-m model-target DEFECT before the next Vault init, put R2's off-host transport question to the operator, build + test the QoL there.Research is cheap; these are reviews that can be conducted now without the future deployment, feeding a future ruling. Doing them now de-risks the eventual ruling.
references/opentofu-provider-docs.md provider-capability read now so the end-of-deployment ruling is ready; keep the ruling itself deferred..7 routers on 10.13, which is the natural moment to bring them up TAGGED with the star ACL, and doing so would also retire the note-1 key-expiry outage risk the untagged nodes carry. HONEST COUNTERWEIGHT: the deferral has a HARD blocker that has not changed -- the Headscale control plane is Cloudflare-fronted and the operator has no access to it (note 4, measured). Without that access the tagged/ACL work cannot be built regardless of the risk calculus. Recommendation: SURFACED for reconsideration -- the collision moved this from theoretical to demonstrated, so it is worth pulling forward to the redeploy iff Headscale control-plane access is obtainable. If access stays blocked, it correctly remains deferred, and the star boundary stays a KNOWN, accepted VR1 exposure (as D-129(iii)(b) already records).Each of these needs real hardware, real scale, or an external spec the redeploy does not supply. The reevaluation CONFIRMS the deferral. No action.
| Decision | What is held | Why it genuinely stays |
|---|---|---|
| D-052(a)/(b) | dedicated corosync heartbeat ring; dedicated live-migration plane + QEMU-native TLS | need dedicated planes/hardware; hardening, not blocking (QEMU-TLS is VM-testable if ever wanted, low value) |
| D-059 | four-NIC collapse | gated on Roosevelt hardware sheets (NIC budget) |
| D-100 | netem inter-DC link profile | awaiting the external Roosevelt link spec |
| D-104 | 3-unit Juju controller HA | "when bare-metal resources allow"; VR1 VM capacity is ~85% FIT |
| D-108 | rbd-mirror daemon HA | Roosevelt scale-up |
| D-121 | Vault HA backend Raft-vs-etcd | Raft is a 1.16-charm feature, incompatible now; coupled to the D-068 vault-version path |
| D-129 os-frr | dynamic routing at the edge | Roosevelt inter-DC design (needs the D-100 link spec + D-132 topology) |
| D-129 metal-edge profile | os-smart / os-nut / os-cpu-microcode / os-lldpd | hardware-specific (SMART disks, UPS, CPU microcode) -- inert on VMs |
| D-129 security hardening | Suricata / crowdsec / Zenarmor / SIEM | deferred by the closed-test posture to post-teardown/Roosevelt |
| D-129(iii)(c)/(d) | two-router Tailscale HA; per-operator source-IP preservation | HA scale-up class (D-121-coupled) |
| D-132 Q1/Q2/Q3 | HA-region sub-questions; rack-top rack controllers; cross-site backup custody | multi-rack / HA / cross-site scale -- the redeploy has one rack per DC |
| D-133 part 2 | hardware-faithful NIC topology (bonds/trunks) | needs real switch/NIC inventory; the redeploy is still 6-flat-NIC VMs |
| D-139 VPN (:e0); external v6 routing | operator-access VPN; external v6 transit | Roosevelt edge design; the VR1 edge has no v6 transport |
| D-029 | Keystone SSO (k8s-keystone-auth) for workload clusters |
can't be exercised -- Magnum/CAPI is deferred to the redeploy (no workload clusters to run SSO on), and D-029's dependency is the Roosevelt cloud-internal-DNS + trusted-cert foundation. D-106's Designate reactivation is a partial move toward that foundation but does NOT discharge D-029 |
| D-068 item 2 (listener TLS) | Vault listener-TLS at the region | a "Roosevelt build requirement -- lands at Roosevelt Vault standup with its own runbook step"; VR1 stays cleartext by ruling |
| D-068 item 3 (AppRole lifecycle) | TTL audit, renewable/auto-renew TTLs, per-consumer auth probe | "all three legs are Roosevelt build requirements" (the per-consumer probe already ships into cloud-assert.sh for VR1; the rest is Roosevelt) |
| D-069 auto-unseal | evaluate transit/cloud-KMS auto-unseal | a SEPARATE future decision, and version-bound -- transit/KMS auto-unseal capability tracks the Vault version the D-068 item-1 Q2 path hasn't ruled, so the redeploy cannot settle it |
| D-136 automation/CI half | F2/F3 (CI runner / event delivery / status-back); Jenkins job placement | "the Roosevelt shape once D-132 ratifies" -- gated on D-132 (which itself stays, Group 4) |
magnum-capi-helm==1.4.0) shipped the capability; the interim dev-commit path is retired. Listed only to close the loop.netbox.baldurkeep.com ("a maybe" at end-of-deployment) -- the re-IP re-carves the working apex on 10.13 under the new B2 role, which changes what would merge back. Recommendation: revisit the merge-back plan when the re-IP re-carve is done; still a "maybe," now with a different payload.| # | Decision(s) | Recommendation | When |
|---|---|---|---|
| 1 | D-137 / R7 | Build the teardown credential-revocation checklist | at the re-IP teardown |
| 2 | D-142 / R6 | Fix the -m model defect; build+test the vault-init QoL; put R2 to operator |
before the 10.13 Vault init |
| 3 | D-136 | Fold the IPv6 octet-convention review into the B2 v6 re-carve | with the D-143 re-carve |
| 4 | D-069 / SEC-003 | Decide unseal custodians + rehearse second-person unseal (needs a ruling to un-defer) | at the redeploy Vault init |
| 5 | D-131 sub-4 | Conduct the pinned node-DNS architectural review now (ruling stays Roosevelt) | this deployment |
| 6 | D-140 | Do the provider-capability READ now (ruling stays end-of-deployment) | anytime before the review |
| 7 | D-129(iii) ACL | Reconsider tagged-identity + star ACL at the redeploy IFF Headscale access is obtainable | redeploy, access-gated |
| 8 | D-068 item 1 | Re-baseline the V1-V5 probes opportunistically (Q2 path stays Roosevelt) | low priority |
| -- | Group 4 (18 rows) | Deferral CONFIRMED -- bare-metal / scale / version / Magnum-bound; no action | Roosevelt |
| -- | D-019 / D-042 / D-010 | Record hygiene only | -- |
Bottom line: the operator's instinct is right for a specific, bounded subset. The re-IP redeploy is the lever -- it makes the build-process deferrals (D-137 revocation, D-142 vault-QoL, D-136 v6 octet, D-069 custodian) actionable now, and it makes the D-129(iii) tailnet-ACL worth reconsidering because the collision proved the exposure. The analysis-only items (D-131 sub-4, D-140 provider read, D-068 probes) can be done now regardless. But the majority (Group 4, 18 rows) genuinely stay -- they are bare-metal / scale / version / Magnum-bound and the redeploy is still nested VMs, so reevaluation confirms rather than overturns them. The reevaluation's honest yield is ~4 pull-forwards (D-137/D-142/D-136-octet/D-069-custodian) + ~3 analysis-now (D-131-sub4/D-140/D-068-probes) + 1 access-gated reconsideration (D-129(iii) ACL), not a wholesale un-deferral.
Section A = held to Roosevelt/next-deployment/end-of-deployment; Section B = held to a specific VR1 step (near-term, not future-deployment); Section C = checked, NOT held.
Section A (future-deployment held): D-010 (NetBox merge-back, end-of-deploy, :204); D-019 (Designate, v2/Roosevelt, :384 -- superseded for VR1 by D-106); D-029 (Keystone SSO, Roosevelt, :535); D-052 (corosync ring :899; live-migration plane + QEMU TLS :901); D-059 (four-NIC collapse, Roosevelt sheets, :1090/:1104); D-068 (item1 Q2 path :5813-5819; item2 listener TLS :1660; item3 AppRole :1665); D-069 (custodian assignment/SEC-003 :1769; auto-unseal :1786); D-100 (netem profile :2239); D-104 (Juju HA :2808); D-108 (rbd-mirror HA :3049); D-121 (Vault Raft-vs-etcd :4542/:4628); D-129 (os-frr :5411; metal-edge profile :5439; security hardening :5443; two-router HA :5548; source-IP :5553; tagged/ACL :5579-5611); D-131 (sub-4 + arch review :5677-5683); D-132 (Q1 HA sub-qs / Q2 / Q3 :7137-7172); D-133 (part 2 hardware NIC :5842-5847); D-136 (automation F2/F3; octet convention; Jenkins placement :6421-6426/:6709); D-137 (rotation/revocation post-teardown :7008); D-139 (VPN :e0 :7649; external v6 routing :7403); D-140 (OpenTofu-Juju, end-of-deploy :7783); D-142 (vault-init QoL, next opportunity :8034).
Section B (VR1-step held, near-term -- NOT future deployment): D-129 edge profiles (phase-2 :5434); os-node_exporter (phase-6 Step 10 :5441); D-135 item 2 images/simplestreams (Stage 5 :6267); D-135 item 3 charmhub/snaps (measure-at-Stage-5 :6270); D-134 v6 bands (after the GUA carve :6014).
Section C (checked, NOT held): D-042 (discharged -- 1.4.0 shipped, :665); D-134 (applies now; VIP headroom is a Roosevelt-analog only). Excluded per scope: D-105 and the many "[ARCH] a Roosevelt build session greps this" A1-test lines (ADOPTED-and-apply-now).
What the advisor caught on the drafted review, and what changed:
CONSENSUS -- the agreed final position (both reviewers):