Purpose. Long ops sessions on this cloud routinely exceed a single context window and get COMPACTED (sometimes several times). Anything living only in the chat scrollback is lost at compaction. This ledger is the durable, committed record of what is IN FLIGHT, so any session -- after a compaction, or a fresh one -- can resume without losing pending work.
How to use it (standing practice).
bash scripts/ledger-scan.sh. Reconcile.ledger-scan.sh is the DRIFT CHECK -- it derives the open-work it reliably can (PROPOSED/OPEN decisions, OPEN security rows, next-free numbers) straight from the repo. This narrative must not claim CLOSED anything the scan shows OPEN, nor omit what it surfaces.SINGLE STREAM (collapsed 2026-07-13). This ledger previously carried three parallel, separately-owned stream sections (main-chat, jumphost, shared) plus ~30 append-only session narratives. Those streams are CLOSED and reconciled into the one list below. There is now ONE stream. Do not re-introduce per-stream sections.
Where the history went. The 2,189-line session-by-session narrative is NOT lost -- it is in git history (the parent of the collapse commit) and, in durable form, in the 65 docs/changelog-*.md files, docs/design-decisions.md, and the incident reports. This ledger deliberately carries only what is still OPEN, plus the facts that would otherwise be lost because they live nowhere else.
scripts/ledger-scan.sh; do not hand-edit)RE-SEEDED 2026-08-08 (part 3 close) from bash scripts/ledger-scan.sh. The prior seed was 2026-08-05; it had gone STALE on the SEC count (29 -> 28, SEC-031 CLOSED 2026-08-07), the DOCFIX next-free (210 -> 214) and the BUNDLEFIX next-free (053 -> 059) -- exactly the drift this block exists to prevent (the per-session summaries carried the current figures while this block did not). Re-run the scan to refresh.
docs/design-decisions.md are the only ruling authority.bash scripts/ledger-scan.sh (was 29 at the 2026-08-05 seed). SEC-031 CLOSED 2026-08-07 -- the dc1 edge was REBUILT via the proven dc0 procedure (dc-egress-check dc1 8/8), so the open-router live-exposure is resolved. Still open and notable: SEC-033 2026-08-04 (tls-certificates relation databag exposes vault's global-client private key to any juju model reader; interface-level, mitigate via juju RBAC) and SEC-020 (per-DC MAAS/creds consolidation). The SEC register of record is docs/security-ledger.md; row-level dispositions live THERE only (GA-R4/F3) -- this block carries pointer + count, never rows.docs/CURRENT-STATE.md is the authority).docs/ or runbooks/ prose -- historically a decoy token in prose inflated the next-free counter (hardened in DOCFIX-174).ledger-scan D-115 false-positive: RESOLVED. The scan keys on the LAST **Status:** line per ## D-NNN: block, not arbitrary body prose. The general hygiene -- trust the Status line over body text -- still holds.The pre-rotation bodies (~1080 lines: Live state, OPEN WORK VR1/VR0, NetBox write-path bugs, PINNED rulings, standing lessons, state facts, project- completion, NetBox import narrative) moved VERBATIM to docs/archive/session-ledger-rotated-20260719.md. Standing lessons + VR0 state facts were ROUTED to durable homes first (platform-traps already carried most; juju format=line -> appendix-A; guard discipline -> operating-discipline; VR0 cloud facts -> maas-as-built-reference.md). Open work is machine-derived above + CURRENT-STATE.md; do not re-grow bodies here -- sessions append BOUNDED summaries only (15-line cap).
Retained compact blocks (still-live obligations without another home yet):
docs/netbox-write-path-findings.md (the durable home; the rotated-body section is history). Open residue: dumper blind spot + duplicate-CIDR collapse unfixed, hardened fidelity re-run + fix re-verification owed -- ALL gated on the next NetBox WRITE campaign, none current.--public -f json, never the deprecated --long -- archive R9); (2) appendix-A entry for tenant-net-cannot-reach-public-keystone -> nodes register but stall uninitialized (auth_url in the per-cluster clouds secret is hardcoded PUBLIC at capi-helm 1.4.0; as-built carries no interface key), pointing at the phase-08 D-011.3 probe, plus a per-DC precondition line in dc-dc-phase6 Step 12; (3) tenant contract hardening list: PROPOSED -svc-only password neutralization (admin-rotate to discarded value; keystone lock_password blocks password CHANGE, not auth; NEVER lock -cluster -- it keeps PASSWORD auth permanently per D-066); (4) flavor catalog marking = commercial catalog policy, operator prioritization only. RE-VERIFY every citation at review time -- the full verdict lives in the 2026-07-21 disconnected-session transcript, not in a repo surface.The eight oldest closed-session summaries (2026-07-18 through the fifth 2026-07-21 session) moved VERBATIM to docs/archive/session-ledger-rotated-20260726.md. The live ledger was 413 lines against the 300-line cap -- a breach the 2026-07-25 close recorded as OWED. Each rotated summary still points at its own archived full body; only the summaries moved. Sessions from 2026-07-22 onward remain live below.
The three oldest live summaries (all 2026-07-23: G12 dc1 edge->commission+merge, Stage 4 OPEN+carve+mirrors, queue pass + D-068 rulings) moved VERBATIM to docs/archive/session-ledger-rotated-20260727.md. The live ledger was 317 lines against the 300-line cap. Sessions from 2026-07-24 onward remain live below.
The oldest remaining live summary (2026-07-24, caveman guardrails + DC1 proxy-build start) moved VERBATIM to docs/archive/session-ledger-rotated-20260727.md. The live ledger was 305 lines against the 300-line cap. Sessions from 2026-07-25 onward remain live below.
The TWO oldest remaining live summaries -- 2026-07-25 handoff-pack execution + recon + Chat D-136 coupling, and 2026-07-25 MAAS admin-account recovery (SEC-020) -- moved VERBATIM to docs/archive/session-ledger-rotated-20260727.md. The live ledger was 321 lines against the 300-line cap; one pass left it under. (This paragraph was left MANGLED by an earlier edit -- a sentence broke off mid-number and ran into a stray fragment of the 2026-07-25 MAAS-admin-recovery summary. Found by a 2026-07-29 sweep and repaired here; that summary's full body is at docs/archive/changelogs/changelog-20260725-maas-admin-recovery.md.)
The oldest remaining live summary ("POST-CLOSE ADDENDUM 2026-07-26 -- D-137 ADOPTED (GA-R4; 07-18/07-21 addendum precedent)") moved VERBATIM to docs/archive/session-ledger-rotated-20260727.md. The live ledger was 316 lines against the 300-line cap.
The TWO oldest live summaries -- 2026-07-26 (D-137 build + committee audit + remediation) and 2026-07-27 (creds consolidation + the STAGE 4 CLOSE-OUT) -- moved VERBATIM to docs/archive/session-ledger-rotated-20260729.md. The live ledger would otherwise have been 321 lines against the 300-line cap once this session's bookend was appended. Sessions from the 2026-07-27 grounding audit onward remain live below.
The TWO oldest live summaries -- the 2026-07-27 STAGE-5 GROUNDING AUDIT close and its 14-RULINGS post-close addendum -- moved VERBATIM to docs/archive/session-ledger-rotated-20260730.md. The live ledger stood at exactly 300 lines, so the next append would have breached the cap. Rotated HERE rather than leaving it owed, because the next session is directed straight at the juju deployment. Sessions from the 2026-07-27 Phase-0 close onward remain live below.
The TWO oldest live summaries (2026-07-30 part 3 -- Stage 5 opened, three bootstraps, D-138 + D-132 ruled; and part 4 -- dc0 region topology built, cutover blocked on a permission wall) moved VERBATIM to docs/archive/session-ledger-rotated-20260802b.md. The live ledger stood at 294 lines and this close's summary would have breached the cap.
The oldest live summary (2026-07-30 part 5 -- dc0 migrated to its own MAAS region, 10/10 Ready, four named gates green) moved VERBATIM to docs/archive/session-ledger-rotated-20260803.md. The live ledger would have breached the 300-line cap with this close's summary.
The oldest closed-session summary (2026-07-31 -- dc0 node carve COMPLETE, controller bootstrapped) moved VERBATIM to docs/archive/session-ledger-rotated-20260804.md. The live ledger stood at 292 lines and this close's summary would have breached the 300-line cap.
The oldest closed-session summary moved VERBATIM to docs/archive/session-ledger-rotated-20260731.md. The live ledger stood at 295 lines and this close's summary would have breached the 300-line cap.
The two oldest closed-session summaries (2026-07-31 prefer-ipv6/deploy-then-teardown, and 2026-08-01 snap-proxy/D-139/IPv6) moved VERBATIM to docs/archive/session-ledger-rotated-20260805.md. The live ledger stood at 315 lines and the 2026-08-05 (part 2) close breached the 300-line cap. (The 2026-08-01 rotation's own pointer -> docs/archive/session-ledger-rotated-20260801.md is subsumed here; that archive is unchanged.)
The oldest closed-session summary moved VERBATIM to docs/archive/session-ledger-rotated-20260802.md. The live ledger stood at 283 lines and this close's summary would have breached the 300-line cap.
The oldest closed-session summaries (2026-08-03 -- Stage 5 dc0 bundle DEPLOYED, controller rebuilt Path C; AND 2026-08-04 -- ovn-central cert root-caused + wired for redeploy) moved VERBATIM to docs/archive/session-ledger-rotated-20260807.md. Rotated oldest-first across the 2026-08-07 closes to keep the live ledger under the 300-line cap (GA-R4 rule 3).
The two oldest closed-session summaries (2026-08-06 -- Task #2 D-020 vault-metal-only; AND 2026-08-06 part 2 -- F4 + dc-ha-scaleup retired + memcached 1->3) moved VERBATIM to docs/archive/session-ledger-rotated-20260808.md. Rotated at the 2026-08-08 dc0-activation close to keep the live ledger under the 300-line cap (GA-R4 rule 3).
The two oldest closed-session summaries (2026-08-06 part 3 -- phase-03 core-verify F-CV1/2/3; AND 2026-08-06/07 -- Step 3.4 G3 + per-DC tailscale rulings + .7 VMs stood up) moved VERBATIM to docs/archive/session-ledger-rotated-20260809.md. Rotated at the 2026-08-08 (part 3) close (amphora build FIXED + geneve-over-v6 root-caused) to keep the live ledger under the 300-line cap.
d36d815..9216bdf (+ a final close) all pushed; voffice1 synced. Scan: 4 open decisions, SEC 29, next-free D-143 / DOCFIX-213 / BUNDLEFIX-059 (NO new numbers). Body: docs/changelog-20260807-dc0-tailscale-provisioning.md (Items 1-10). Sweep: docs/audit/queued-findings-20260807-dc0-tailscale-provisioning.txt (F1-F4)..7 DRIVEN TO CARVED-AND-READY (gated): power->commission->carve pass=8/0 (metal-admin 10.12.8.7 + provider-public 10.12.4.7, no br-ex)->deploy jammy, both legs live. C2 correction: it had already self-enlisted (known-marten). Join still blocked (PLAIN key + no Headscale ACL; .7 reachable only via vr1-office1-svc).dc-node-carve.sh is_tailscale/is_region/is_two_plane_host + lib-hosts CARVE_AUX_HOSTS (isolates aux VMs from HOSTS consumers); harness 63/0; gauntlet 101.vr1-dc0-*; D-134 AMENDMENT ("Record that as the preferred naming convention going forward") + lib-hosts comment + memory..6 (vr1-dc1-maas-01) power->recommission->carve (10.12.68.6/10.12.64.6, --profile admin)->deploy jammy; vr1-dc1-region MAAS LIVE (maas 3.7.2 + postgresql 16.14; the shared vr1-office1-svc key is ON VCLOUD ~/vr1-office1-creds/office1_svc_ed25519; reached the .6 from vcloud; snap egress via snapd proxy; operator-authorised credential one-shot, creds 0600 on the .6, never in context; 10.12.68.6:5240/MAAS/->301). PROFILE registered+verified (voffice1 tunnel -L 5243; rack vr1-dc1-maas-01, 0 machines).curl -x 400 vs snap-egress-works (tested definitively); run-logged.sh NOT opened (O3, 3rd consecutive).~/vr1-dc1-creds/ (SEC-020); RE-OPEN the voffice1:5243 tunnel after any reboot before maas vr1-dc1-region ....--profile vr1-dc1-region --expect-rack vr1-dc1-maas-01, tunnel up): dc-region-topology.sh apply (6-plane) -> maas-region-power-key.sh (.6 snap) + dc-plane-ipam.sh + DHCP + jammy image sync -> import office1_svc pubkey -> REBUILD 9 nodes+juju+.7 fresh in (delete from Office1 admin -> enlist/commission/deploy/carve, name vr1-dc1--NN). Separately dc0 Step 3.3 on a TAGGED key + Headscale.office1-netbox (live apex, DOCFIX-195) -- dc0 .7 + dc1 .6 region VM + new vr1-dc1-region + dc1 .7 (when live) + D-134 utility .4-.9 assignments + dc0 renames. Enumerated: changelog-20260807 Item 11. Status ONLY in CURRENT-STATE.md.netbox/dc-util-hosts-import.py (+harness 19/19) closing the D-134 utility-HOST IP gap; landed 8 ip-addresses into office1-netbox (186->194, ids 187-194). .4 artifact + dc1 .5/.7 DEFERRED (S3).--profile vr1-dc1-region): topology apply 40/0; IPAM carve-v6 6/6 + reserve 13/13 (check 24/0); DHCP CUTOVER off-admin->on-region, .6 sole server (no dual-serve, false-alarm resolved); power-key install 9/9 (SEC-016). Captures docs/audit/dc1-*-20260807.dc-egress-check dc1 8/8, .6 egress restored -> now a RUNBOOK (runbooks/dc-edge-rebuild.md) + tool (scripts/opnsense-console-rebuild.py) per operator "log accurately so we don't re-derive". jammy image sync TRIGGERED + downloading at close.pgrep -c dhcpd self-match false-alarm (instrument #21); recalled DHCP range .100-.200, MEASURED .201-.254; shipped opnsense-console-rebuild.py WITHOUT a harness (F1 owed); reserve skipped=6 glance owed; run-logged NOT opened (F2, 4th+ consecutive).docs/audit/queued-findings-20260807-dc1-region-sequence.txt (F1-F3 FIRST SURFACE). Body: docs/changelog-20260807-dc1-region-sequence.md. Status ONLY in CURRENT-STATE.md.a25ed99 (behind this host by 4; git pull AFTER operator push -- Step 1b). Scan: 4 open decisions, SEC 28, next-free D-143 / DOCFIX-214 / BUNDLEFIX-059 (used DOCFIX-213).vr1-dc0-region maas profile registered (in-DC regional hot-kid 10.12.8.6; key via stdin, never printed), PROVIDER network created + EXIT GATE PASS.reserved; annotated D-101/R8 + D-139; NO new D-number; lb-mgmt is v6-ULA, outside the 10.13 re-IP.fc00:5b7a:7bdc:bd86::/64 + o-hm0 up, mgmt router isolated (G18 OWED#1/#2 done). INCIDENT: amphora image build FAILS (octavia-diskimage-retrofit exit 1; dib-in-LXD hypothesis, rebuild-relevant) -> the "1 test LB" is BLOCKED (changelog Item 7).