Newer
Older
openstack-caracal-dc-dc / docs / changelog-20260721-tenant-review-pin.md

Session changelog 2026-07-21 (fourth session) -- tenant-onboarding review verdict recovered + pinned

One changelog per session (GA-R2/D1). Status lives ONLY in docs/CURRENT-STATE.md; this file is narrative + reverts. Predecessor (stage-3-close session, disconnected ~21:16): docs/changelog-20260721-netem-install-verify.md.

1. Disconnected-session recovery (read-only)

  • Bootstrap reconciled clean: main at b2d4317, lint 0-fail, ledger scan matches the hand-seeded block (D=132, DOCFIX=198, BUNDLEFIX=052; 10 open SEC rows). No uncommitted traces from any disconnected session.
  • The predecessor's final undelivered message (the 3-seat committee verdict on Chat's three tenant-onboarding-runbook inserts) was recovered VERBATIM from its local session transcript and re-presented to the operator. No repo edit and no commit had resulted from that review -- the verdict existed nowhere durable.

2. Tenant-onboarding review items PINNED to deployment close (operator-directed)

  • Operator ruling this session: do NOT land the committee's recommended items now; pin all four for an end-of-deployment consideration review, because this deployment is changing posture and end goals and the items should be judged against the final shape.
  • Delivered: a self-contained compact block in docs/session-ledger.md ("Deployment-close consideration review -- tenant-onboarding items"), carrying the corrected substance of all four items plus the standing caveat that every citation gets re-verified at review time (the full verdict text lives only in the predecessor's session transcript).
  • Explicitly NOT done: no appendix-A entries, no contract edit, no dc-dc-phase6 edit, no numbering consumed (stated token-free in the ledger block per the standing counter discipline).
  • Revert: git revert this commit (records only; no live surface or script was touched).

3. Queue pass opened: D-131 sub-2 RULED (metal-admin-only forwarder scope)

  • Operator directed a working pass through the open decision queue; order presented (D-131 subs -> D-129 subs -> D-071 points -> D-068 -> G12 prep -> netem finals -> SEC-014), one ruling per exchange (GA-R5).
  • D-131 sub-2 RULED: "Metal-admin only (Recommended)" (question + utterance quoted in the D-131 Status block, the ruling authority). Scope of the rack node-DNS forwarder is fixed at the metal-admin alias only; edge keeps its own WAN-side DNS; SEC-010 untouched. Revisit trigger recorded: a D-129 (iii)/(iv) consolidation ruling.
  • Same-commit status coupling (GA-R1 C1): CURRENT-STATE D-131 sentence and the ledger machine-block D-131 line updated to sub-3..4 open. No live surface touched -- dc0-node-dns.service already runs metal-admin-only, so the ruling codifies the running shape; zero config delta.
  • Revert: git revert this commit (records only).

4. D-131 sub-3 RESOLVED by measurement (dispatch ruled "Investigate now (Recommended)")

  • Read-only investigation, split execution: agent read the shipped source over the measured rack reach (ssh -J voffice1, dc0 key, no sudo); the decisive dhcpd.conf read is root-only AND the agent's ssh+sudo was classifier-walled, so the OPERATOR ran it via the ! prefix and pasted output (capture: docs/audit/d131-sub3-dhcpd-option6-20260721.txt).
  • Result: option 6 = 10.12.8.3 ALONE. Source (maasserver/dhcp.py, snap rev 41649): allow_dns=false short-circuits get_default_dns_servers() to [] before any rack-IP prepend logic; maastemporalworker has no DNS composition of its own. The morning prepend observation was a stale pre-re-render read. NO defect; NO second LP; no live surface carried the stale claim (archived changelog stays as history).
  • Revert: git revert this commit (records only).

5. Two operator pins landed: DNS architectural review + D-132 (MAAS topology)

  • PINNED REVIEW (operator-directed, recorded in the D-131 Status block, feeds sub-4): next-deployment architectural review of the DNS setup -- (a) stack best-practice conformance, (b) forwarder security implications, (c) vendor-documented guidance for the "utility nodes" DC-to-DC traffic configuration.
  • D-132 FILED, PROPOSED / OPEN (next-free verified 132 pre-assignment): Roosevelt per-DC MAAS topology -- HA regional VMs per DC, rack-top rack controllers deferring to the site region (multi-rack DCs), cross-site regional backup custody for rebuild. Operator directive quoted verbatim in the entry; each question rules individually per GA-R5 at Roosevelt MAAS design time. Ledger next-free re-seeded D=133; CURRENT-STATE section 8 items 7-8 added (same-commit coupling).
  • Revert: git revert this commit (records only).

6. D-129 sub-decision (i) RULED: COS scrapes the edge, in-scope per-DC

  • Question grounded on D-105 (ADOPTED: COS per-DC, no Office1 roll-up) and presented per GA-R5; operator selection, exact utterance: "In-scope, per-DC (Recommended)". Recorded in the D-129 Status line (the ruling authority); the Step-10 os-node-exporter + API-backend pin is now ungated at its deployment step. No live change this session -- the install itself remains at its pinned step, operator-gated.
  • Coupled same-commit: CURRENT-STATE section 8 item 5 (four -> three open subs) + ledger machine-block D-129 line.
  • Revert: git revert this commit (records only).