Date: 2026-07-25. Branch: dc-dc-stage4-phase3-maas-deploy. Convened by: operator ("Deploy a committee for a full decision recon. Are there any other reconciliations that should be queued afterwards?").
Status: ADVISORY / audit record. Reconciles RULED decisions against the authoritative surfaces; adopts nothing. docs/CURRENT-STATE.md remains the sole status authority (GA-R1). Companion to docs/audit/committee-20260724-track2-bundle-render.md and docs/audit/stage5-expansion-review-20260724.md.
Method: four independent READ-ONLY reviewers, each a recon dimension (IPAM prefixes/bands; VLAN/space/fabric; node/tag/MAC/power; decision-status + backlog), reconciling from COMMITTED surfaces: the office1-netbox apex snapshot netbox/draft/vr1-office1-current-20260725.json, scripts/lib-net.sh + lib-hosts.sh, bundle.yaml + overlays/, opentofu/, the MAAS carve captures (docs/audit/stage4-carve-verify-20260723.txt, stage4-discovery-20260723.txt), and docs/design-decisions.md + docs/CURRENT-STATE.md. Live-truth items are flagged NEEDS-LIVE-VERIFY.
| Layer | In the apex? | Verdict |
|---|---|---|
| VLANs | zero | CORRECT BY DESIGN -- VR1 is untagged-per-fabric (D-133); VLANs are a MAAS-layer construct, never NetBox |
| Plane /22s, transit, uplink, v6 GUA/ULA, aggregates | all present, drift-free | COMPLETE -- all 12 planes + both transit/uplink + both /48s, matching lib-net value-for-value |
| D-134 per-DC bands (utility/VIP/node/dynamic) | absent | GAP -- exist only as decision prose; not in NetBox OR lib-net |
| The 33 VIP addresses (.50-.60 x 3 legs) | absent | GAP -- overlay-only literals; a generator has nothing to pull |
Prefix-layer COMPLETE + ZERO DRIFT across netbox <-> lib-net <-> artifacts:
scope_site-scoped + role-tagged.opentofu/variables.tf twin honor "change one, change both"). GAP = sub-prefix only:overlays/vr1-dc1-vips.yaml (internally consistent with bundle octet-for-octet, but not an apex projection). [blocks-coupling]static: links, no .103/.104 sub-interfaces). A VLAN object would document tagging that does not exist on the wire -- exactly what design-decisions.md:217 prohibits.VLAN 5005 (dc0) = MAAS db-id of the untagged boot fabric; dc1 twin = fabric-142/vid 0. 10 named plane fabrics + 2 boot = 12.main.tf <-> lib-hosts HOST_BOOT_MAC (:01) <-> bundle ovn-chassis (:02 compute provider) <-> discovery; per-DC power isolation intact (SEC-012 dc0 172.31.0.2 / SEC-016 dc1 172.31.0.6, distinct IdentityFile; keys off-repo).juju-controller-vr1-dc1 tag, no role tag).Session-touched decisions (D-104 amendment, BUNDLEFIX-052, the render, Fork 2/3 as OPS, the coupling routed to Chat) are mutually consistent across CURRENT-STATE + changelog + design-decisions; ledger-scan PROPOSED/OPEN {D-068, D-131, D-132} matches CURRENT-STATE section 8. Stale surfaces found (to fix -- deferred per operator):
runbooks/dc-dc-phase4-juju-bundle-per-dc.md:192 still says bundle "ships NO designate" (contradicts ADOPTED D-106 + the actual bundle:830).opentofu/main.tf:18-19 comment says netem "not instantiated yet" (it is, :353).| Prio | Recon | Surfaces | When | Blocks |
|---|---|---|---|---|
| P0 | VIP-overlay collision + vault-VIP completeness | vr1-dc1-vips vs ipv6-family-matrix (both own vip:); rendered vault (no vip) vs D-020 |
before dc1 deploy | dc1 deploy |
| P0 | rendered bundle/overlays <-> apex | bundle + overlays (VIP band, tags, ovn MACs) vs the apex dump | before deploy (--dc vr1-dc1 + --dry-run) |
deploy correctness |
| P1 | extend netbox/sandbox-fidelity-check.py (STALE) |
the tool: covers only D-115/117/120, diffs the frozen 90-prefix draft not the 139-prefix apex; blind to D-124/D-134 | before the coupling design | trustworthy apex recons |
| P1 | lib-net/lib-hosts literals <-> apex | 28 IP + 26 IP/MAC literals vs current apex | at coupling design; on any apex mutation | coupling adoption |
| P1 | MAAS live <-> NetBox | D-134 bands + the 12 VLANs / 6 spaces (MAAS-only) vs apex | end-of-deploy + coupling | apex completeness / merge-back |
| P2 | post-deploy cloud <-> decisions (BOM) | cloud-assert --capture vs D-121 HA / D-020 vault / D-108 / Ceph size/CRUSH / cluster_count | after dc1 deploys | Stage-5 close |
| P2 | IPv6 / dual-stack | ipv6-family-matrix v6 tokens vs apex v6 | once v6 rendered (depends on P0 phasing) | dual-stack |
| P2 | office1-netbox -> netbox.baldurkeep.com merge-back | 4.6.4 apex -> 4.5.8 frozen v1 reference | end-of-deployment (DOCFIX-195) | IPAM-of-record loop |
| P2 | SEC-ledger <-> reality | security-ledger 15 open rows vs rotations/scope | G14 reconcile now; bulk at v1 close | security close-out |
Sequencing insight: extend the fidelity tool FIRST -- it is the prerequisite that makes every apex recon (bundle<->apex, libs<->apex, MAAS<->NetBox) trustworthy, and the coupling's whole value proposition is eliminating the hand-render/carried-literal drift those recons chase.
The recon VALIDATES the coupling's scope precisely: the gap is NOT the plane/prefix modeling (already faithful, drift-free) -- it is the sub-prefix band + VIP-address layer living in prose/overlays. So the coupling should: (1) model the D-134 bands + VIP addresses IN the apex; (2) generate the overlays from them; (3) reconcile the two VIP overlays into one per-app string; (4) ride an EXTENDED fidelity check. VLAN/space/ fabric stays MAAS-sourced (NetBox = IPAM only).