Rotated from docs/session-ledger.md on 2026-08-04 (GA-R4 rule 3 / F1 -- cap restored at this close)
SESSION CLOSE 2026-07-31 -- dc0 node carve COMPLETE, controller BOOTSTRAPPED, deploy blocked on prefer-ipv6 (bounded, GA-R4)
- Branch
dc-dc-stage5-preconditions, 11 commits pushed (a859352..80510f4). NO stage opened/closed. Scan: 3 decisions, SEC 25 (SEC-028, -029 opened), D 139 / DOCFIX 207 / BUNDLEFIX 053.
scripts/dc-node-carve.sh SHIPPED (harness 48/48) -- the last no-tool gap. dc0 v4 carve COMPLETE 10/10, named gate 134/0, and the diff against the pre-migration capture is EMPTY: every node's six legs match Office1 address for address. v6 carve 54/54; the controller's own v6 restored separately (the tool walks only the nine tagged role nodes).
- >>> JUJU CONTROLLER LIVE:
vr1-dc0-controller, active/idle. <<< FOURTH attempt, first success; the three failures were each a real defect one layer deeper, closed by D-138, the under-carve fix, and D-132 q1 respectively. Agent binaries resolved on attempt 1.
- Model
vr1-dc0 created, spaces gate PASS (6/6), apt-mirror set to the DC mirror -- key VERIFIED against the live client, not guessed; URL asserted on dists/jammy/Release content.
- 2 RULINGS (GA-R5, quoted): "Mint juju-vr1-dc0 on the new region (Recommended)"; "Copy dc0's PKI overlay to the dc0 rack (Recommended)". Both registered BEFORE use -- SEC-028 (juju service credential;
vm-secret-locations gained its first rack rows) and SEC-029 (PKI overlay residency). Key proven to AUTHENTICATE before bootstrap, never printed, sha256-verified at every hop.
- DOCFIX-206: Step 2.0's credential gate was NOT region-scoped, and I hit it -- credential listed, folder present, user existed, all in OFFICE1. The SKIP branch would have led to an auth failure that reads as a network fault.
- >>> BUNDLE DEPLOY ATTEMPT 1 FAILED; NOTHING IS HALF-APPLIED (model measured EMPTY). <<<
unknown option "prefer-ipv6" on barbican. The dry-run PASSED and the deploy did not -- --dry-run does not validate config option NAMES. Measured plan is 56 apps / 108 relations, not the 50/97 preflight still quotes.
- Root cause measured against CHARMHUB's own schema: 7 of 13 VIP charms declare
prefer-ipv6, 6 do not, and barbican never had it at ANY channel -- so R2's uniform application was never valid. RULED: "Research what those 6 charms do with v6 VIPs first (Recommended)" -- overlay NOT edited, R2 NOT amended. STAGE 5 IS BLOCKED ON THAT RESEARCH.
- FINDING, logged not fixed:
preflight.sh is REGION-BLIND -- 19 false negatives for dc0 ("not enrolled in MAAS") because it defaults to the Office1 profile. MAAS_PROFILE=vr1-dc0-region drops them to zero. A blanket refusal would be WRONG: dc1's nodes still live in Office1.
- Mutation testing earned its cost again: a first pass proved less than it looked (deleting an assertion's MESSAGE only proves it exists), and the sharper pass found the
br-ex static compare could not fail. Added a fixture, re-proved the kill.
- OWNED -- three instrument errors, all one shape: a capture parsed at the wrong field, a
systemctl poll racing an async start, and a charmhub query with a wrong field name returning a uniform "no config" across 13 charms. The last two were caught by the SHAPE of the answer being implausible, not by discipline; that detector is now in auto-memory.
- Gauntlet ALL GREEN (93); repo-lint 0 fail; creds-matrix 65/65. Permission allowlist +12 read-only rules (all pinned to check/verify/assert/plan subcommands).
- NEXT: the prefer-ipv6 research, then re-deploy. Steps 1-3.5 and the controller are DONE and need no repeat. Body:
docs/changelog-20260730-dc0-node-carve.md (11 items). Status ONLY in CURRENT-STATE.md.