Author: Worker W4.1 (Phase 4 -- change synthesis), multi-agent container-elim pass (SCOPE-AND-EXECUTION-PLAN.md Section 4). Date: 2026-08-09. Inputs: pass0-admin-report.md (baseline + confirmed target topology), pass1-admin-report.md (planning change-set), pass2-admin-report.md (tools change-set), pass3-admin-report.md (tests change-set) -- all four read in full. READ-ONLY synthesis; no mutation; nothing here is executed. This document MERGES the planning + tools + tests change-sets into one indexed table an execution session can work from directly.
Baseline carried in (do not re-derive): Option 1 CONFIRMED (flat node VMs on vcloud libvirt + one small non-hypervisor vr1-dcN-client VM per DC); cross-DC handling (a) CONFIRMED (new vcloud-level host isolation control); MAAS region stays on vr1-dcN-maas-01; root topology (B) shared-outer + per-DC-flat RECOMMENDED (Phase-4 ratifies); THREE isolation controls confirmed distinct -- (i) the (a) cross-DC host control, (ii) the SEC-010 transit-leg successor, (iii) the MAAS power-key blast-radius mitigation; everything rides D-143 (10.12->10.13 re-IP); 13 owed artifacts (numbered #1-#13 below); tests change-set = 9 existing-change verdict-blocks / 5 existing-retire verdict-blocks / 7 new-build harnesses / 3 rides.
ID scheme: DEC- decision (not a change; an open ruling) -- TF- tofu-module -- LB- lib (lib-hosts.sh/lib-net.sh) -- SC- script/procedure -- DC- doc (deployment-workflow.md / CURRENT-STATE.md prose, non-gate) -- RB- runbook -- GT- gate (preflight/cloud-assert/G-series) -- HN- harness (A#/B#/C# tags preserved from pass3-w3-new-tests.md for cross-reference) -- SEC- security-ledger row. Axis: [CE] container-elim only, [D-143] re-IP only, [both] dual-labeled (per pass1 check 5's four confirmed dual items + this pass's extensions). Owed-artifact# refers to the 13-item list in pass2-admin-report.md Section 5 (also restated below).
pass2-admin-report.md #5)tofu destroy + emergency lever) -- 6. rides as the emergency virsh destroy loop (distinct row, same fixture library)modules/dc-site| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| DEC-01 | decision | docs/design-decisions.md -- container-elim [ARCH] ruling (D-123 amendment vs new D-number) |
new | none (root ruling; operator rules, GA-R5) | -- | [CE] |
| DEC-02 | decision | D-128 amendment ratification (Plane 2 shrinks to MAAS/NetBox; substrate build becomes wholly Plane 1) | new | DEC-01 | -- | [CE] |
| DEC-03 | decision | D-125 bridge-in retirement note (rides DEC-01) | new | DEC-01, TF-03 | -- | [CE] |
| DEC-04 | decision | D-138 concrete-host change (client VM replaces vvr1-dcN as the concrete host) |
new | DEC-01 | -- | [CE] |
| DEC-05 | decision | D-122 site-down re-earn note (one-command site-down lost; re-earned via SC-09) | new | DEC-01 | -- | [CE] |
| DEC-06 | decision | D-124 sizing-void re-cause note (rack-addressing vars deleted with TF-01) | new | DEC-01 | -- | [CE] |
| DEC-07 | decision | D-132-addendum premises note (hypervisor-fate rationale moot under Option 1) | new | DEC-01, DEC-08 | -- | [CE] |
| DEC-08 | decision | Rack-controller retirement ratification (+ live re-measure of primary_rack both DCs) |
new | live measurement (delivery-time, owed) | -- | [CE] |
| DEC-09 | decision | D-131 forwarder retire-with-evidence ratification (per-DC; dc1 asymmetry) | new | SC-15 (#13), DEC-08 | 13 | [CE] |
| DEC-10 | decision | Artifact-service (.4) placement + sizing decision |
new | SC-16 (#7 FIT ext w/ mirror sizing) | 7 | [CE] |
| DEC-11 | decision | Root topology ratification: (B) shared-outer + per-DC-flat vs merged single root | new | none (Phase 4 ratifies recommendation) | -- | [CE] |
| DEC-12 | decision | Root naming (vr1-dcN-flat vs reserving -substrate) |
new | DEC-11 | -- | [CE] |
| DEC-13 | decision | Client-VM octet .8 + name vr1-dcN-client into D-134 standing map |
new | none (recommended) | -- | [CE] |
| DEC-14 | decision | (a) control's concrete mechanism (nftables rule set / check shape / SEC-NNN) | new | none | 2 | [CE] |
| DEC-15 | decision | Concern-(iii) power-key mitigation mechanism choice (restricted key / wrapper / polkit ACL) + SEC-NNN -- CRITICAL PATH | new | none | 11 | [CE] |
| DEC-16 | decision | SEC-010 successor SEC-row disposition (new row vs amendment); endpoint ratification (client VM + voffice1, already recommended) | new | none | 3 | [CE] |
| DEC-17 | decision | wan-bridge module directory: delete vs leave-unreferenced (append-only bias) |
new | DEC-01, TF-03 | -- | [CE] |
| DEC-18 | decision | SEC-013 maas-vm-host retire-or-keep (flagged to its owner, not this pass) |
new | none | -- | [CE] |
| DEC-19 | decision | maas-fabric-prune.sh/maas_fabric_classify.py harness gap: build vs accept-as-named-exception (pre-existing, container-elim-adjacent only) |
new | none | -- | [CE-adjacent] |
| DEC-20 | decision | A11's home: fold into cloud-assert.sh vs a dedicated isolation-assert.sh |
new | DEC-14 | -- | [CE] |
| DEC-21 | decision | NetBox-migration design: rename-in-place vs concept retirement (for HN-A6/#9) | new | none | 9 | [CE] |
| DEC-22 | decision | D-127 client-VM autostart value (needed for HN-A1's new case) | new | none | -- | [CE] |
| DEC-23 | decision | State-blast-radius weighing (rides DEC-11) | new | DEC-11 | -- | [CE] |
| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| TF-01 | tofu-module | opentofu/main.tf module vvr1_dc0/_dc1 + sizing/rack-addressing/pubkey vars (variables.tf:137-156,175-194,196-244) |
retire | DEC-01, DEC-11 | -- | [CE] |
| TF-02 | tofu-module | opentofu/vr1-dc0-substrate/, vr1-dc1-substrate/ (whole inner roots + states) |
retire (as roots; module bodies re-home) | DEC-11, TF-12, TF-13 | -- | [CE] |
| TF-03 | tofu-module | modules/wan-bridge (+ vr1_dcN_wan calls, IP-less uplink NIC, br-vr1-dcN-wan netplan) |
retire | DEC-01, DEC-17 | -- | [CE] |
| TF-04 | tofu-module | modules/site-wan output rewire (feeds DC edge directly, no bridge-in) |
change | TF-03 | -- | [CE] |
| TF-05 | tofu-module | modules/cloudinit-vm (loses 2 containment calls, gains the client-VM call) |
re-home | TF-12, DEC-13 | -- | [CE] |
| TF-06 | tofu-module | modules/dc-planes (6 planes re-homed to vcloud level; same CIDRs/families/MTU) |
re-home | TF-12 | -- | [CE] (shape only; values D-139/D-143-owned) |
| TF-07 | tofu-module | modules/dc-storage-pool (2-per-DC collapses to 1) |
re-home | TF-12 | -- | [CE] |
| TF-08 | tofu-module | modules/node-vm x12/DC (unchanged body, re-homed call site) |
re-home | TF-12 | -- | [CE] |
| TF-09 | tofu-module | modules/opnsense-edge (one input re-pointed to TF-04's direct NAT) |
change | TF-04 | -- | [CE] |
| TF-10 | tofu-module | modules/base-image (re-homed call site, no logic change) |
re-home | TF-12 | -- | [CE] |
| TF-12 | tofu-module | NEW modules/dc-site (composes pool + 6 planes + edge + 12 node VMs + client VM; replaces the ~230-266-line copy-pasted per-DC inner-root bodies) |
new | DEC-11, DEC-13 | 12 | [CE] |
| TF-13 | tofu-module | NEW per-DC flat root files (shared-outer + per-DC-flat, 3 roots total) invoking modules/dc-site |
new | DEC-11, DEC-12, TF-12 | -- | [CE] |
| TF-14 | tofu-module | D-124 transit-leg re-point (Office1-leg consumer: vvr1-dcN NIC1 -> client-VM transit NIC; mesh-link/netem-link bodies unchanged) |
change | TF-12/TF-13, DEC-13 | -- | [both] (octet math D-143, bearer host CE) |
Note: modules/office1-network, mesh-link (x3), netem-link are CONFIRMED UNCHANGED (pass2 check 3/4.5) -- not itemized as rows. modules/maas-vm-host is dead/orthogonal, never instantiated -- see DEC-18, not itemized as a change row.
lib-hosts.sh / lib-net.sh| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| LB-01 | lib | scripts/lib-hosts.sh VIRSH_POWER_ADDRESS_FROM_OFFICE1/_FROM_DCREGION (:212-213,246-251) |
change | DEC-15 -- BLOCKED | feeds 11 | [CE] |
| LB-02 | lib | scripts/lib-hosts.sh REGION_HOST_SUFFIX comment (:95-100) |
change | none | -- | [CE] (comment-currency, low priority) |
| LB-03 | lib | scripts/lib-net.sh (whole file) |
change | D-143 ruling (separate axis) | -- | [D-143] (ZERO container-elim edits, grep-verified; noted here only so the axis is not conflated) |
Note: CARVE_AUX_HOSTS, NIC_PLANE_ORDER, BREX_PARENT_NIC, HOST_OCTET maps/suffixes, HOST_TAG, resolver fns -- UNCHANGED under container-elim (octet maps change under D-143 only). The client VM does NOT get a lib-hosts.sh row (resolved: it is L1 cloudinit-vm, not MAAS/virsh-power-managed; identity lives in tofu + NetBox).
| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| SC-01 | script | scripts/maas-node-power.sh invocation-site/runbook literals (no code change to the script itself -- address is $1) |
change | LB-01, DEC-15 -- BLOCKED | feeds 11 | [CE] |
| SC-02 | script | scripts/dc-rack-net.sh -- LEGS/br_of() half retires; DNS-forwarder half depends on D-131 |
change/retire (split) | DEC-09, TF-01 | -- | [CE] |
| SC-03 | script | scripts/site-headend-install.sh node_host_setup()/node_host_check() --host-nodes (~134 lines) |
retire | DEC-01 | -- | [CE] |
| SC-04 | script | scripts/site-headend-install.sh SEC-010 writer extraction (:273-320) into a role-agnostic subcommand installing BOTH ends |
change | DEC-16 | 3 | [CE] |
| SC-05 | script | scripts/site-headend-install.sh --role rack (Section 6) |
retire (contingent) | DEC-08 | -- | [CE] |
| SC-06 | script | scripts/dc-mirror.sh / dc-cache-proxy.sh / dc-snap-proxy.sh -- new host + explicit disk sizing |
change | SC-16 (#7), DEC-10 | rides 7 | [CE] |
| SC-07 | script | scripts/maas-region-power-key.sh (body unchanged; URI/key shape it installs re-derives) |
change | DEC-15 -- BLOCKED | feeds 11 | [CE] |
| SC-08 | script | scripts/site-baseleg.sh comment block (re-cite D-138 + the (a) control, not the retired qemu+ssh premise) |
change | none | -- | [CE] (doc-currency; stays a no-op) |
| SC-09 | script | NEW teardown primitive (module/root-scoped tofu destroy procedure) |
new | DEC-11 | 1 | [CE] |
| SC-10 | script | NEW (a) cross-DC host isolation control (nftables artifact) | new | DEC-14 | 2 | [CE] |
| SC-11 | script | NEW power-key blast-radius mitigation (restricted key / wrapper / polkit ACL) -- CRITICAL PATH | new | DEC-15 | 11 | [CE] |
| SC-12 | script | NEW R7 credential-revocation checklist (enumerate every vm-secret-locations row keyed to the rack host class) |
new | none (ready) | 4 | [both] |
| SC-13 | script | NEW MAAS machine-record release/delete step (+ maas rack-controller delete decommission + region+rack runbook note) |
new | DEC-08 (decommission half) | 5 | [D-143 primary, CE ride] |
| SC-14 | script | NEW emergency site-down lever (virsh destroy loop over the DC root's domain set, roster from lib-hosts.sh) |
new | DEC-11, SC-09 | 6 | [CE] |
| SC-15 | script | NEW D-131 retirement-evidence checker (dig test against each fresh region's own BIND) | new | DEC-09 | 13 | [CE] |
| SC-16 | script | scripts/dc-dc-whole-host-budget.py FIT-calculator extension (3 utility-node classes + artifact-service disk-sizing branch) + fresh vcloud capacity measurement |
change | none (ready) | 7 | [both] |
| SC-17 | script | MAC re-measurement pass (post-apply, before B.6 trusts any MAC -- likely force-replace) | change (procedure) | TF-13 | 8 | [CE] |
| SC-18 | script | netbox/dc-rack-mgmt-import.py (decommission vvr1-dcN DCIM records; register client VM + flat roster) |
change | DEC-21 | 9 | [CE] |
| SC-19 | script | scripts/geneve-encap-assert.sh -- new invocation point post-build (no code change; verbatim re-run) |
change (new invocation only) | TF-13 | 10 | [both] (MTU budget analytically unchanged, live assert still owed) |
Note: dc-node-carve.sh, dc-node-v6-carve.py, carve-host-interfaces.sh, maas-role-tags.sh, maas-profile-assert.sh, maas-role-tags.sh, dc-egress-check.sh logic bodies -- NO CODE CHANGE (grep-verified zero containment hits; pure MAAS-API, <site>-parameterized); only invocation-host currency (D-128-amendment territory) and doc comments naming vvr1-dcN need updating -- LOW priority, not itemized as separate rows.
| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| DC-01 | doc | docs/dc-dc-deployment-workflow.md Stage 3 (Build/Gate/Owns/Reuse-vs-new lines) |
change | DEC-01, DEC-11 | -- | [CE] |
| DC-02 | doc | docs/dc-dc-deployment-workflow.md Stage 4 gate-line + G17 literal |
change | DEC-08 (rack placement), D-143 address | -- | [both] |
| DC-03 | doc | docs/dc-dc-deployment-workflow.md Stage 5 literals (transit-IP re-point, e.g. docs/CURRENT-STATE.md:7829 "openstackclient ... ON THE dc0 RACK (172.31.0.2)") |
change | DEC-13 | -- | [CE] |
| DC-04 | doc | docs/dc-dc-deployment-workflow.md gap register: NEW entry for the (a) control |
new | SC-10 | 2 | [CE] |
| DC-05 | doc | docs/dc-dc-deployment-workflow.md gap register: #2 reshapes, #17 closing-mechanism note goes historical, #20 verdict re-verify (its own expiry clause triggers) |
change | TF-13 | -- | [both] |
| DC-06 | doc | docs/dc-dc-deployment-workflow.md Stage 2 -- explicit two-containment-patterns-distinction note (D-114 KEPT vs D-123 RETIRED, so name-similarity does not sweep Stage 2 in) |
new | none | -- | [CE] |
Note: Stages 1, 6, 7 and the dc-dc-office1-service-reip.md / dc-dc-phase0-vcloud-prep.md / dc-dc-phase1-office1-standup.md runbooks are CONFIRMED NO CHANGE / OUT OF SCOPE (D-114, zero containment hits) -- not itemized.
| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| RB-01 | runbook | runbooks/dc-dc-teardown-rollback.md |
change (rewrite) | DEC-11, SC-09, SC-13 | rides 1,5 | [both] |
| RB-02 | runbook | runbooks/dc-dc-phase2-tofu-dc-substrate.md |
change (heaviest rewrite) | TF-12, TF-13, SC-10 | rides 2,12 | [CE] |
| RB-03 | runbook | runbooks/dc-dc-phase3-maas-enlist-deploy.md (SSH-jump-target lines :424,430) |
change (low delta) | DEC-08 (rack/placement ruling) | -- | [CE] |
| RB-04 | runbook | runbooks/dc-dc-phase4-juju-bundle-per-dc.md (RUN-LOCATION table 3rd correction) |
change | DEC-13 | -- | [both] (overlay literals D-143, execution-host CE) |
| RB-05 | runbook | runbooks/dc-dc-phase6-designate-cos-magnum.md (:437-444 pre-existing stale-D-138 defect) |
change (ride-along fix, not a container-elim delta) | none | -- | [pre-existing; rides RB-04's sweep] |
Note: dc-dc-phase5-dr-failover-drill.md has NO DIRECT CHANGE -- it inherits RB-04's table; not itemized as its own row.
| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| GT-01 | gate | NEW Stage-1 gate for the (a) control -- --check enumerates the live bridge set for both DCs' six planes, asserts FORWARD denial between every dc0-tagged/dc1-tagged bridge pair, REFUSES if fewer than the full plane count resolves |
new | SC-10, DEC-14 | 2 | [CE] |
| GT-02 | gate | cloud-assert.sh A11a (periodic re-verify of the (a) control: post-deploy/restart/pre-change/post-incident) |
new | GT-01 | -- | [CE] |
| GT-03 | gate | preflight.sh P10 (SEC-010 successor / concern ii, DC-scoped, host-bound on the P7 model; one installer/checker covers both ends) |
new | SC-04, DEC-16 | 3 | [CE] |
| GT-04 | gate | preflight.sh P4 dependency + cloud-assert.sh A11b (power-key concern-iii verification -- negative test: a DC's region key cannot reach domains outside its own roster) -- CRITICAL PATH |
new/change | SC-11, DEC-15 | 11 | [CE] |
| GT-05 | gate | preflight.sh P8 substrate-drift loop -- extend from one hardcoded path to a DECLARED list of every post-flatten root (never a glob -- administrator amendment, a glob cannot fail on a missing/renamed root) |
change | DEC-12 | -- | [CE] |
| GT-06 | gate | preflight.sh P5 creds-matrix register rows re-point (rack-class -> client-class); NEW rows for SC-04(#3)/SC-11(#11) key material when minted |
change (data) | SC-04, SC-11 | -- | [both] |
| GT-07 | gate | preflight.sh P9 (dc-egress-check invocation-host literal, re-points to the ruled B.5 host) |
change | DEC-08 (B.5 placement ruling) | -- | [CE] |
| GT-08 | gate | docs/CURRENT-STATE.md G9/G10 successor -- single apply-and-verify gate (substrate apply + (a) --check + depth-2 boot proof + direct-NAT egress test), replacing the outer/inner pair |
change | TF-13, GT-01 | -- | [CE] |
| GT-09 | gate | docs/CURRENT-STATE.md G17 -- the one dual-cause gate-literal edit (new address family D-143 + new host container-elim, in one edit) |
change | DEC-08, D-143 ruling | -- | [both] |
| GT-10 | gate | docs/CURRENT-STATE.md G14 (indirect -- residency re-points + >=1 new SEC row are count-affecting; flag for the next ledger-scan.sh reader, instrument-currency lesson #25) |
change (flag only) | SEC-01, SEC-02 | -- | [CE] |
Note: G12 is CLOSED/historical, read as "the shape being replaced," not touched further. G18, G1-G8, G11, G13, G15, G16 and cloud-assert A0-A10 -- CONFIRMED no container-layer dependency (verified per-gate by W1.2/W3.2); not itemized.
pass3-w3-new-tests.mdA: existing -- change (9 verdict-blocks)
| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| HN-A1 | harness | tests/opentofu-validate T14/T15 (autostart pins) + new vr1-dcN-client case |
change | DEC-12 (root-naming), DEC-22 (D-127 client-VM value) | -- | [CE] |
| HN-A2 | harness | tests/node-vm T8-T11 (hardcoded INNER= path) |
change | DEC-12 | -- | [CE] |
| HN-A3 | harness | tests/site-headend-install Section-8 SEC-010 sub-case (= owed #3's harness half) |
change | SC-04 | 3 | [CE] |
| HN-A4 | harness | tests/dc-selector power-address rows (:204-247) |
change | DEC-15, SC-11 -- BLOCKED | feeds 11 | [CE] |
| HN-A5 | harness | tests/maas-region-power-key URI assertions (:67,82,102,108) -- edited TOGETHER with HN-A4, same session |
change | DEC-15, SC-11, HN-A4 -- BLOCKED | feeds 11 | [CE] |
| HN-A6 | harness | tests/dc-rack-mgmt-import vvr1 pins (:77-78, = owed #9's harness half) |
change | DEC-21, DEC-08 | 9 | [CE] |
| HN-A7 | harness | tests/maas-profile-assert office1-profile fixture (:41,68,72,80) |
change | DEC-08 | -- | [CE] |
| HN-A8 | harness | tests/dc-dc-whole-host-budget (= owed #7's harness; the one universe-boundary crossing) |
change | SC-16 | 7 | [both] |
| HN-A9 | harness | tests/pre-flight-checks -- NEW case post-#11 (live power-address must match the mitigation's issued shape) |
new (case) | SC-11, GT-04 -- BLOCKED | 11 | [CE] |
B: existing -- retire (5 verdict-blocks)
| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| HN-B1 | harness | tests/opentofu-validate T13 (D-127 containment autostart pin) |
retire | TF-01 | -- | [CE] |
| HN-B2 | harness | tests/site-headend-install --host-nodes block (~15 cases; excludes the SEC-010 sub-case = HN-A3) |
retire | SC-03 | -- | [CE] |
| HN-B3 | harness | tests/site-headend-install Section 6 (--role rack) |
retire (contingent) | DEC-08 | -- | [CE] |
| HN-B4 | harness | tests/dc-rack-net LEGS cases (T3,T5,T13,T15,T17) |
retire | SC-02 | -- | [CE] |
| HN-B5 | harness | tests/dc-rack-net DNS-forwarder cases (T4,T9,T16) + 8 hygiene cases |
retire (contingent) | DEC-09 | -- | [CE] |
C: new-build (7 harnesses, one per owed artifact)
| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| HN-C1 | harness | tests/dc-site/run-tests.sh (static fixture .tf trees) |
new | TF-12 | 12 | [CE] |
| HN-C2 | harness | (a) control offline fixture harness | new | SC-10, DEC-14 | 2 | [CE] |
| HN-C3 | harness | Teardown-primitive fixture library (+ #6 emergency lever rides the same library) | new | SC-09, DEC-11 | 1, 6 | [CE] |
| HN-C4 | harness | Power-key mitigation harness -- itself a precondition for HN-A4/HN-A5/HN-A9 | new | SC-11, DEC-15 | 11 | [CE] CRITICAL |
| HN-C5 | harness | D-131 retire-evidence checker harness (fixtures exist in the two cited changelogs) | new | SC-15 | 13 | [CE] (fixture-ready) |
| HN-C6 | harness | R7 credential-revocation checklist harness | new | SC-12 | 4 | [both] (ready) |
| HN-C7 | harness | MAAS record release/delete (+ rack decommission) harness | new | SC-13 | 5 | [D-143/CE] (ready) |
Rides (no separate build): #6 -> HN-C3's fixture library; #8 MAC re-measure -> HN-C1's MAC invariant; #10 geneve/jumbo -> geneve-encap-assert verbatim, new invocation point only (SC-19). tests/opentofu-validate T8-T10, node-vm T1-T7/T12-T15, site-headend-install Sections 1-5/7, maas-node-power (opaque pass-through arg), preflight pending-change fixture, geneve-encap-assert (all cases), site-baseleg, cloudinit-vm, d124-transit-seed, netem-link (declared grep false-positive), and the 90 no-hit harnesses are CONFIRMED STAY -- not itemized.
| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| SEC-01 | SEC | NEW SEC-NNN row for the (a) cross-DC host isolation control (concern i); next-free confirmed SEC-034 as of 2026-08-09, re-grep at mint time | new | DEC-14 | 2 | [CE] |
| SEC-02 | SEC | NEW SEC-NNN row for the power-key mitigation (concern iii) -- CRITICAL PATH | new | DEC-15 | 11 | [CE] |
| SEC-03 | SEC | SEC-010 disposition: new row vs amendment (concern ii) | new/change | DEC-16 | 3 | [CE] |
| SEC-04 | SEC | vm-secret-locations register rows (SEC-026/SEC-028/SEC-029) re-point rack-class -> client-class; rotation triggers ("if the rack is rebuilt") FIRE on this change |
change | DEC-13, SC-12 | -- | [both] |
DEC-15 (mechanism choice: restricted key / wrapper / polkit ACL) -> SEC-02 (mint the SEC row) -> SC-11 (build the #11 artifact) -> HN-C4 (harness -- itself a precondition, not just coverage) -> LB-01 (lib-hosts.sh power-address re-derivation) + SC-07 (maas-region-power-key.sh URI/key shape) -> SC-01 (maas-node-power.sh call-site literals) -> HN-A4 + HN-A5 (dc-selector / maas-region-power-key assertions, edited together, same session -- H1 hazard: a plausible-looking URI swapped in before the mechanism exists produces a false-green harness) -> HN-A9 (pre-flight-checks P4 case) + GT-04 (cloud-assert A11b) -> GT-06 (P5 register row for the new key material). Six downstream test/tool edits are frozen until DEC-15 rules (pass3 Section 4); the interim RED on HN-A4/HN-A5 once lib-hosts.sh changes is the DESIRED fail-loud state, never something to "fix" early.
DEC-14 (mechanism) -> SEC-01 (SEC row) -> SC-10 (#2 artifact) -> HN-C2 (harness) -> GT-01 (Stage-1 gate, installed + --check-verified) -> MUST PRECEDE -> TF-13 (first flat substrate apply of EITHER per-DC root, under whatever DEC-11 root shape lands -- fork-robust: a merged single root's FIRST apply can create both DCs' planes at once, so "before the second DC's apply" is not sufficient, only "before ANY flat apply" survives the fork) -> GT-02 (A11a re-verify at each apply's close) -> GT-08 (folds into the G9/G10 successor gate) -> re-verified again at Stage-5 live traffic (the first point the claim is actually tested).
SC-12 (#4 R7 credential-revocation checklist, enumerated from every vm-secret-locations row keyed to the rack host class) + HN-C6 (harness) -> run BEFORE any substrate destroy (revoking after the hosts are gone degrades to "assume it's moot") -> SC-13 (#5 MAAS machine-record release/delete + rack-controller decommission + region-side primary_rack/DHCP-reference cleanup) + HN-C7 (harness) -> TF-01/TF-02 destroy applies (inner roots first from voffice1, then outer from vcloud) -> RB-01 (teardown runbook rewrite encodes this exact order). This chain governs the CURRENT 10.12 checkpoint teardown and is largely independent of DEC-11's root-shape ruling for the NEW build.
DEC-11)Gates TF-02, TF-12, TF-13, SC-09, SC-14, HN-C3, RB-01, GT-05, HN-A1, HN-A2, DEC-12, DEC-23 -- the sequence itself is invariant to the fork (per pass1 check 2), but the teardown primitive's exact wording, the state blast radius, and every root-naming literal are NOT. Ratify DEC-11 early; it unblocks the largest single cluster of "ready once ratified" rows.
| Category | Rows |
|---|---|
| decision (DEC) | 23 |
| tofu-module (TF) | 13 |
| lib (LB) | 3 |
| script (SC) | 19 |
| doc (DC) | 6 |
| runbook (RB) | 5 |
| gate (GT) | 10 |
| harness (HN) | 21 (9 change + 5 retire + 7 new-build) |
| SEC | 4 |
| Total | 104 |
Cross-check against source counts: harness total (21) matches pass3 Section 2's 9-existing-change + 5-existing-retire + 7-new-build decomposition exactly; owed-artifact references (13 distinct #-tags) all appear at least once across TF/SC/GT/HN/SEC rows, with no double-counting (rack decommission folds into SC-13/#5; artifact-service sizing rides SC-16/#7; the SEC-010-writer extraction IS SC-04/#3's implementation shape -- all per pass2 Section 5's explicit "not double-counted" note, carried forward here).
Author = W4.1 (no model name asserted). This document is a MERGE of pass1-admin-report.md Sections 2-6, pass2-admin-report.md Sections 3-6, and pass3-admin-report.md Sections 2-5 -- no new repo reads were performed beyond the four admin reports and their stated verification notes; every row's artifact path/line traces to a citation already verified in one of those four reports (see each report's own Section verifying "Verification note" / "Adversarial-check results" for the underlying grep/read evidence). READ-ONLY; nothing executed; findings LOGGED only.