Newer
Older
openstack-caracal-dc-dc / docs / audit / container-elim-pass / pass4-w1-master-change-inventory.md

Pass 4 / W4.1 -- MASTER CHANGE INVENTORY (container-layer elimination)

Author: Worker W4.1 (Phase 4 -- change synthesis), multi-agent container-elim pass (SCOPE-AND-EXECUTION-PLAN.md Section 4). Date: 2026-08-09. Inputs: pass0-admin-report.md (baseline + confirmed target topology), pass1-admin-report.md (planning change-set), pass2-admin-report.md (tools change-set), pass3-admin-report.md (tests change-set) -- all four read in full. READ-ONLY synthesis; no mutation; nothing here is executed. This document MERGES the planning + tools + tests change-sets into one indexed table an execution session can work from directly.

Baseline carried in (do not re-derive): Option 1 CONFIRMED (flat node VMs on vcloud libvirt + one small non-hypervisor vr1-dcN-client VM per DC); cross-DC handling (a) CONFIRMED (new vcloud-level host isolation control); MAAS region stays on vr1-dcN-maas-01; root topology (B) shared-outer + per-DC-flat RECOMMENDED (Phase-4 ratifies); THREE isolation controls confirmed distinct -- (i) the (a) cross-DC host control, (ii) the SEC-010 transit-leg successor, (iii) the MAAS power-key blast-radius mitigation; everything rides D-143 (10.12->10.13 re-IP); 13 owed artifacts (numbered #1-#13 below); tests change-set = 9 existing-change verdict-blocks / 5 existing-retire verdict-blocks / 7 new-build harnesses / 3 rides.

ID scheme: DEC- decision (not a change; an open ruling) -- TF- tofu-module -- LB- lib (lib-hosts.sh/lib-net.sh) -- SC- script/procedure -- DC- doc (deployment-workflow.md / CURRENT-STATE.md prose, non-gate) -- RB- runbook -- GT- gate (preflight/cloud-assert/G-series) -- HN- harness (A#/B#/C# tags preserved from pass3-w3-new-tests.md for cross-reference) -- SEC- security-ledger row. Axis: [CE] container-elim only, [D-143] re-IP only, [both] dual-labeled (per pass1 check 5's four confirmed dual items + this pass's extensions). Owed-artifact# refers to the 13-item list in pass2-admin-report.md Section 5 (also restated below).


0. The 13 owed artifacts (for cross-reference; full spec in pass2-admin-report.md #5)

  1. Teardown primitive (root-scoped tofu destroy + emergency lever) -- 6. rides as the emergency virsh destroy loop (distinct row, same fixture library)
  2. The (a) cross-DC host isolation control (concern i)
  3. SEC-010 transit-leg successor (concern ii)
  4. R7 credential-revocation checklist
  5. MAAS machine-record release/delete step (+ rack-controller decommission)
  6. FIT-calculator extension + capacity measure (+ artifact-service sizing)
  7. MAC re-measurement pass (post-apply)
  8. NetBox DCIM migration
  9. Post-build live asserts (geneve/jumbo)
  10. Power-key blast-radius mitigation (concern iii) -- critical path
  11. modules/dc-site
  12. D-131 retirement-evidence step

1. MASTER CHANGE-INVENTORY TABLE

1.1 Decisions (open rulings -- not changes; gate the change rows below)

ID category artifact change depends-on owed-artifact# axis
DEC-01 decision docs/design-decisions.md -- container-elim [ARCH] ruling (D-123 amendment vs new D-number) new none (root ruling; operator rules, GA-R5) -- [CE]
DEC-02 decision D-128 amendment ratification (Plane 2 shrinks to MAAS/NetBox; substrate build becomes wholly Plane 1) new DEC-01 -- [CE]
DEC-03 decision D-125 bridge-in retirement note (rides DEC-01) new DEC-01, TF-03 -- [CE]
DEC-04 decision D-138 concrete-host change (client VM replaces vvr1-dcN as the concrete host) new DEC-01 -- [CE]
DEC-05 decision D-122 site-down re-earn note (one-command site-down lost; re-earned via SC-09) new DEC-01 -- [CE]
DEC-06 decision D-124 sizing-void re-cause note (rack-addressing vars deleted with TF-01) new DEC-01 -- [CE]
DEC-07 decision D-132-addendum premises note (hypervisor-fate rationale moot under Option 1) new DEC-01, DEC-08 -- [CE]
DEC-08 decision Rack-controller retirement ratification (+ live re-measure of primary_rack both DCs) new live measurement (delivery-time, owed) -- [CE]
DEC-09 decision D-131 forwarder retire-with-evidence ratification (per-DC; dc1 asymmetry) new SC-15 (#13), DEC-08 13 [CE]
DEC-10 decision Artifact-service (.4) placement + sizing decision new SC-16 (#7 FIT ext w/ mirror sizing) 7 [CE]
DEC-11 decision Root topology ratification: (B) shared-outer + per-DC-flat vs merged single root new none (Phase 4 ratifies recommendation) -- [CE]
DEC-12 decision Root naming (vr1-dcN-flat vs reserving -substrate) new DEC-11 -- [CE]
DEC-13 decision Client-VM octet .8 + name vr1-dcN-client into D-134 standing map new none (recommended) -- [CE]
DEC-14 decision (a) control's concrete mechanism (nftables rule set / check shape / SEC-NNN) new none 2 [CE]
DEC-15 decision Concern-(iii) power-key mitigation mechanism choice (restricted key / wrapper / polkit ACL) + SEC-NNN -- CRITICAL PATH new none 11 [CE]
DEC-16 decision SEC-010 successor SEC-row disposition (new row vs amendment); endpoint ratification (client VM + voffice1, already recommended) new none 3 [CE]
DEC-17 decision wan-bridge module directory: delete vs leave-unreferenced (append-only bias) new DEC-01, TF-03 -- [CE]
DEC-18 decision SEC-013 maas-vm-host retire-or-keep (flagged to its owner, not this pass) new none -- [CE]
DEC-19 decision maas-fabric-prune.sh/maas_fabric_classify.py harness gap: build vs accept-as-named-exception (pre-existing, container-elim-adjacent only) new none -- [CE-adjacent]
DEC-20 decision A11's home: fold into cloud-assert.sh vs a dedicated isolation-assert.sh new DEC-14 -- [CE]
DEC-21 decision NetBox-migration design: rename-in-place vs concept retirement (for HN-A6/#9) new none 9 [CE]
DEC-22 decision D-127 client-VM autostart value (needed for HN-A1's new case) new none -- [CE]
DEC-23 decision State-blast-radius weighing (rides DEC-11) new DEC-11 -- [CE]

1.2 OpenTofu roots/modules

ID category artifact change depends-on owed-artifact# axis
TF-01 tofu-module opentofu/main.tf module vvr1_dc0/_dc1 + sizing/rack-addressing/pubkey vars (variables.tf:137-156,175-194,196-244) retire DEC-01, DEC-11 -- [CE]
TF-02 tofu-module opentofu/vr1-dc0-substrate/, vr1-dc1-substrate/ (whole inner roots + states) retire (as roots; module bodies re-home) DEC-11, TF-12, TF-13 -- [CE]
TF-03 tofu-module modules/wan-bridge (+ vr1_dcN_wan calls, IP-less uplink NIC, br-vr1-dcN-wan netplan) retire DEC-01, DEC-17 -- [CE]
TF-04 tofu-module modules/site-wan output rewire (feeds DC edge directly, no bridge-in) change TF-03 -- [CE]
TF-05 tofu-module modules/cloudinit-vm (loses 2 containment calls, gains the client-VM call) re-home TF-12, DEC-13 -- [CE]
TF-06 tofu-module modules/dc-planes (6 planes re-homed to vcloud level; same CIDRs/families/MTU) re-home TF-12 -- [CE] (shape only; values D-139/D-143-owned)
TF-07 tofu-module modules/dc-storage-pool (2-per-DC collapses to 1) re-home TF-12 -- [CE]
TF-08 tofu-module modules/node-vm x12/DC (unchanged body, re-homed call site) re-home TF-12 -- [CE]
TF-09 tofu-module modules/opnsense-edge (one input re-pointed to TF-04's direct NAT) change TF-04 -- [CE]
TF-10 tofu-module modules/base-image (re-homed call site, no logic change) re-home TF-12 -- [CE]
TF-12 tofu-module NEW modules/dc-site (composes pool + 6 planes + edge + 12 node VMs + client VM; replaces the ~230-266-line copy-pasted per-DC inner-root bodies) new DEC-11, DEC-13 12 [CE]
TF-13 tofu-module NEW per-DC flat root files (shared-outer + per-DC-flat, 3 roots total) invoking modules/dc-site new DEC-11, DEC-12, TF-12 -- [CE]
TF-14 tofu-module D-124 transit-leg re-point (Office1-leg consumer: vvr1-dcN NIC1 -> client-VM transit NIC; mesh-link/netem-link bodies unchanged) change TF-12/TF-13, DEC-13 -- [both] (octet math D-143, bearer host CE)

Note: modules/office1-network, mesh-link (x3), netem-link are CONFIRMED UNCHANGED (pass2 check 3/4.5) -- not itemized as rows. modules/maas-vm-host is dead/orthogonal, never instantiated -- see DEC-18, not itemized as a change row.

1.3 lib-hosts.sh / lib-net.sh

ID category artifact change depends-on owed-artifact# axis
LB-01 lib scripts/lib-hosts.sh VIRSH_POWER_ADDRESS_FROM_OFFICE1/_FROM_DCREGION (:212-213,246-251) change DEC-15 -- BLOCKED feeds 11 [CE]
LB-02 lib scripts/lib-hosts.sh REGION_HOST_SUFFIX comment (:95-100) change none -- [CE] (comment-currency, low priority)
LB-03 lib scripts/lib-net.sh (whole file) change D-143 ruling (separate axis) -- [D-143] (ZERO container-elim edits, grep-verified; noted here only so the axis is not conflated)

Note: CARVE_AUX_HOSTS, NIC_PLANE_ORDER, BREX_PARENT_NIC, HOST_OCTET maps/suffixes, HOST_TAG, resolver fns -- UNCHANGED under container-elim (octet maps change under D-143 only). The client VM does NOT get a lib-hosts.sh row (resolved: it is L1 cloudinit-vm, not MAAS/virsh-power-managed; identity lives in tofu + NetBox).

1.4 Scripts

ID category artifact change depends-on owed-artifact# axis
SC-01 script scripts/maas-node-power.sh invocation-site/runbook literals (no code change to the script itself -- address is $1) change LB-01, DEC-15 -- BLOCKED feeds 11 [CE]
SC-02 script scripts/dc-rack-net.sh -- LEGS/br_of() half retires; DNS-forwarder half depends on D-131 change/retire (split) DEC-09, TF-01 -- [CE]
SC-03 script scripts/site-headend-install.sh node_host_setup()/node_host_check() --host-nodes (~134 lines) retire DEC-01 -- [CE]
SC-04 script scripts/site-headend-install.sh SEC-010 writer extraction (:273-320) into a role-agnostic subcommand installing BOTH ends change DEC-16 3 [CE]
SC-05 script scripts/site-headend-install.sh --role rack (Section 6) retire (contingent) DEC-08 -- [CE]
SC-06 script scripts/dc-mirror.sh / dc-cache-proxy.sh / dc-snap-proxy.sh -- new host + explicit disk sizing change SC-16 (#7), DEC-10 rides 7 [CE]
SC-07 script scripts/maas-region-power-key.sh (body unchanged; URI/key shape it installs re-derives) change DEC-15 -- BLOCKED feeds 11 [CE]
SC-08 script scripts/site-baseleg.sh comment block (re-cite D-138 + the (a) control, not the retired qemu+ssh premise) change none -- [CE] (doc-currency; stays a no-op)
SC-09 script NEW teardown primitive (module/root-scoped tofu destroy procedure) new DEC-11 1 [CE]
SC-10 script NEW (a) cross-DC host isolation control (nftables artifact) new DEC-14 2 [CE]
SC-11 script NEW power-key blast-radius mitigation (restricted key / wrapper / polkit ACL) -- CRITICAL PATH new DEC-15 11 [CE]
SC-12 script NEW R7 credential-revocation checklist (enumerate every vm-secret-locations row keyed to the rack host class) new none (ready) 4 [both]
SC-13 script NEW MAAS machine-record release/delete step (+ maas rack-controller delete decommission + region+rack runbook note) new DEC-08 (decommission half) 5 [D-143 primary, CE ride]
SC-14 script NEW emergency site-down lever (virsh destroy loop over the DC root's domain set, roster from lib-hosts.sh) new DEC-11, SC-09 6 [CE]
SC-15 script NEW D-131 retirement-evidence checker (dig test against each fresh region's own BIND) new DEC-09 13 [CE]
SC-16 script scripts/dc-dc-whole-host-budget.py FIT-calculator extension (3 utility-node classes + artifact-service disk-sizing branch) + fresh vcloud capacity measurement change none (ready) 7 [both]
SC-17 script MAC re-measurement pass (post-apply, before B.6 trusts any MAC -- likely force-replace) change (procedure) TF-13 8 [CE]
SC-18 script netbox/dc-rack-mgmt-import.py (decommission vvr1-dcN DCIM records; register client VM + flat roster) change DEC-21 9 [CE]
SC-19 script scripts/geneve-encap-assert.sh -- new invocation point post-build (no code change; verbatim re-run) change (new invocation only) TF-13 10 [both] (MTU budget analytically unchanged, live assert still owed)

Note: dc-node-carve.sh, dc-node-v6-carve.py, carve-host-interfaces.sh, maas-role-tags.sh, maas-profile-assert.sh, maas-role-tags.sh, dc-egress-check.sh logic bodies -- NO CODE CHANGE (grep-verified zero containment hits; pure MAAS-API, <site>-parameterized); only invocation-host currency (D-128-amendment territory) and doc comments naming vvr1-dcN need updating -- LOW priority, not itemized as separate rows.

1.5 Doc (workflow doc + gate-table prose, non-runbook)

ID category artifact change depends-on owed-artifact# axis
DC-01 doc docs/dc-dc-deployment-workflow.md Stage 3 (Build/Gate/Owns/Reuse-vs-new lines) change DEC-01, DEC-11 -- [CE]
DC-02 doc docs/dc-dc-deployment-workflow.md Stage 4 gate-line + G17 literal change DEC-08 (rack placement), D-143 address -- [both]
DC-03 doc docs/dc-dc-deployment-workflow.md Stage 5 literals (transit-IP re-point, e.g. docs/CURRENT-STATE.md:7829 "openstackclient ... ON THE dc0 RACK (172.31.0.2)") change DEC-13 -- [CE]
DC-04 doc docs/dc-dc-deployment-workflow.md gap register: NEW entry for the (a) control new SC-10 2 [CE]
DC-05 doc docs/dc-dc-deployment-workflow.md gap register: #2 reshapes, #17 closing-mechanism note goes historical, #20 verdict re-verify (its own expiry clause triggers) change TF-13 -- [both]
DC-06 doc docs/dc-dc-deployment-workflow.md Stage 2 -- explicit two-containment-patterns-distinction note (D-114 KEPT vs D-123 RETIRED, so name-similarity does not sweep Stage 2 in) new none -- [CE]

Note: Stages 1, 6, 7 and the dc-dc-office1-service-reip.md / dc-dc-phase0-vcloud-prep.md / dc-dc-phase1-office1-standup.md runbooks are CONFIRMED NO CHANGE / OUT OF SCOPE (D-114, zero containment hits) -- not itemized.

1.6 Runbooks

ID category artifact change depends-on owed-artifact# axis
RB-01 runbook runbooks/dc-dc-teardown-rollback.md change (rewrite) DEC-11, SC-09, SC-13 rides 1,5 [both]
RB-02 runbook runbooks/dc-dc-phase2-tofu-dc-substrate.md change (heaviest rewrite) TF-12, TF-13, SC-10 rides 2,12 [CE]
RB-03 runbook runbooks/dc-dc-phase3-maas-enlist-deploy.md (SSH-jump-target lines :424,430) change (low delta) DEC-08 (rack/placement ruling) -- [CE]
RB-04 runbook runbooks/dc-dc-phase4-juju-bundle-per-dc.md (RUN-LOCATION table 3rd correction) change DEC-13 -- [both] (overlay literals D-143, execution-host CE)
RB-05 runbook runbooks/dc-dc-phase6-designate-cos-magnum.md (:437-444 pre-existing stale-D-138 defect) change (ride-along fix, not a container-elim delta) none -- [pre-existing; rides RB-04's sweep]

Note: dc-dc-phase5-dr-failover-drill.md has NO DIRECT CHANGE -- it inherits RB-04's table; not itemized as its own row.

1.7 Gates (preflight / cloud-assert / G-series)

ID category artifact change depends-on owed-artifact# axis
GT-01 gate NEW Stage-1 gate for the (a) control -- --check enumerates the live bridge set for both DCs' six planes, asserts FORWARD denial between every dc0-tagged/dc1-tagged bridge pair, REFUSES if fewer than the full plane count resolves new SC-10, DEC-14 2 [CE]
GT-02 gate cloud-assert.sh A11a (periodic re-verify of the (a) control: post-deploy/restart/pre-change/post-incident) new GT-01 -- [CE]
GT-03 gate preflight.sh P10 (SEC-010 successor / concern ii, DC-scoped, host-bound on the P7 model; one installer/checker covers both ends) new SC-04, DEC-16 3 [CE]
GT-04 gate preflight.sh P4 dependency + cloud-assert.sh A11b (power-key concern-iii verification -- negative test: a DC's region key cannot reach domains outside its own roster) -- CRITICAL PATH new/change SC-11, DEC-15 11 [CE]
GT-05 gate preflight.sh P8 substrate-drift loop -- extend from one hardcoded path to a DECLARED list of every post-flatten root (never a glob -- administrator amendment, a glob cannot fail on a missing/renamed root) change DEC-12 -- [CE]
GT-06 gate preflight.sh P5 creds-matrix register rows re-point (rack-class -> client-class); NEW rows for SC-04(#3)/SC-11(#11) key material when minted change (data) SC-04, SC-11 -- [both]
GT-07 gate preflight.sh P9 (dc-egress-check invocation-host literal, re-points to the ruled B.5 host) change DEC-08 (B.5 placement ruling) -- [CE]
GT-08 gate docs/CURRENT-STATE.md G9/G10 successor -- single apply-and-verify gate (substrate apply + (a) --check + depth-2 boot proof + direct-NAT egress test), replacing the outer/inner pair change TF-13, GT-01 -- [CE]
GT-09 gate docs/CURRENT-STATE.md G17 -- the one dual-cause gate-literal edit (new address family D-143 + new host container-elim, in one edit) change DEC-08, D-143 ruling -- [both]
GT-10 gate docs/CURRENT-STATE.md G14 (indirect -- residency re-points + >=1 new SEC row are count-affecting; flag for the next ledger-scan.sh reader, instrument-currency lesson #25) change (flag only) SEC-01, SEC-02 -- [CE]

Note: G12 is CLOSED/historical, read as "the shape being replaced," not touched further. G18, G1-G8, G11, G13, G15, G16 and cloud-assert A0-A10 -- CONFIRMED no container-layer dependency (verified per-gate by W1.2/W3.2); not itemized.

1.8 Harnesses (tests/) -- A/B/C tags preserved from pass3-w3-new-tests.md

A: existing -- change (9 verdict-blocks)

ID category artifact change depends-on owed-artifact# axis
HN-A1 harness tests/opentofu-validate T14/T15 (autostart pins) + new vr1-dcN-client case change DEC-12 (root-naming), DEC-22 (D-127 client-VM value) -- [CE]
HN-A2 harness tests/node-vm T8-T11 (hardcoded INNER= path) change DEC-12 -- [CE]
HN-A3 harness tests/site-headend-install Section-8 SEC-010 sub-case (= owed #3's harness half) change SC-04 3 [CE]
HN-A4 harness tests/dc-selector power-address rows (:204-247) change DEC-15, SC-11 -- BLOCKED feeds 11 [CE]
HN-A5 harness tests/maas-region-power-key URI assertions (:67,82,102,108) -- edited TOGETHER with HN-A4, same session change DEC-15, SC-11, HN-A4 -- BLOCKED feeds 11 [CE]
HN-A6 harness tests/dc-rack-mgmt-import vvr1 pins (:77-78, = owed #9's harness half) change DEC-21, DEC-08 9 [CE]
HN-A7 harness tests/maas-profile-assert office1-profile fixture (:41,68,72,80) change DEC-08 -- [CE]
HN-A8 harness tests/dc-dc-whole-host-budget (= owed #7's harness; the one universe-boundary crossing) change SC-16 7 [both]
HN-A9 harness tests/pre-flight-checks -- NEW case post-#11 (live power-address must match the mitigation's issued shape) new (case) SC-11, GT-04 -- BLOCKED 11 [CE]

B: existing -- retire (5 verdict-blocks)

ID category artifact change depends-on owed-artifact# axis
HN-B1 harness tests/opentofu-validate T13 (D-127 containment autostart pin) retire TF-01 -- [CE]
HN-B2 harness tests/site-headend-install --host-nodes block (~15 cases; excludes the SEC-010 sub-case = HN-A3) retire SC-03 -- [CE]
HN-B3 harness tests/site-headend-install Section 6 (--role rack) retire (contingent) DEC-08 -- [CE]
HN-B4 harness tests/dc-rack-net LEGS cases (T3,T5,T13,T15,T17) retire SC-02 -- [CE]
HN-B5 harness tests/dc-rack-net DNS-forwarder cases (T4,T9,T16) + 8 hygiene cases retire (contingent) DEC-09 -- [CE]

C: new-build (7 harnesses, one per owed artifact)

ID category artifact change depends-on owed-artifact# axis
HN-C1 harness tests/dc-site/run-tests.sh (static fixture .tf trees) new TF-12 12 [CE]
HN-C2 harness (a) control offline fixture harness new SC-10, DEC-14 2 [CE]
HN-C3 harness Teardown-primitive fixture library (+ #6 emergency lever rides the same library) new SC-09, DEC-11 1, 6 [CE]
HN-C4 harness Power-key mitigation harness -- itself a precondition for HN-A4/HN-A5/HN-A9 new SC-11, DEC-15 11 [CE] CRITICAL
HN-C5 harness D-131 retire-evidence checker harness (fixtures exist in the two cited changelogs) new SC-15 13 [CE] (fixture-ready)
HN-C6 harness R7 credential-revocation checklist harness new SC-12 4 [both] (ready)
HN-C7 harness MAAS record release/delete (+ rack decommission) harness new SC-13 5 [D-143/CE] (ready)

Rides (no separate build): #6 -> HN-C3's fixture library; #8 MAC re-measure -> HN-C1's MAC invariant; #10 geneve/jumbo -> geneve-encap-assert verbatim, new invocation point only (SC-19). tests/opentofu-validate T8-T10, node-vm T1-T7/T12-T15, site-headend-install Sections 1-5/7, maas-node-power (opaque pass-through arg), preflight pending-change fixture, geneve-encap-assert (all cases), site-baseleg, cloudinit-vm, d124-transit-seed, netem-link (declared grep false-positive), and the 90 no-hit harnesses are CONFIRMED STAY -- not itemized.

1.9 Security-ledger (SEC) rows

ID category artifact change depends-on owed-artifact# axis
SEC-01 SEC NEW SEC-NNN row for the (a) cross-DC host isolation control (concern i); next-free confirmed SEC-034 as of 2026-08-09, re-grep at mint time new DEC-14 2 [CE]
SEC-02 SEC NEW SEC-NNN row for the power-key mitigation (concern iii) -- CRITICAL PATH new DEC-15 11 [CE]
SEC-03 SEC SEC-010 disposition: new row vs amendment (concern ii) new/change DEC-16 3 [CE]
SEC-04 SEC vm-secret-locations register rows (SEC-026/SEC-028/SEC-029) re-point rack-class -> client-class; rotation triggers ("if the rack is rebuilt") FIRE on this change change DEC-13, SC-12 -- [both]

2. Critical-path dependency chains

Chain A -- Power-key blast-radius mitigation (owed #11; the single largest blocker)

DEC-15 (mechanism choice: restricted key / wrapper / polkit ACL) -> SEC-02 (mint the SEC row) -> SC-11 (build the #11 artifact) -> HN-C4 (harness -- itself a precondition, not just coverage) -> LB-01 (lib-hosts.sh power-address re-derivation) + SC-07 (maas-region-power-key.sh URI/key shape) -> SC-01 (maas-node-power.sh call-site literals) -> HN-A4 + HN-A5 (dc-selector / maas-region-power-key assertions, edited together, same session -- H1 hazard: a plausible-looking URI swapped in before the mechanism exists produces a false-green harness) -> HN-A9 (pre-flight-checks P4 case) + GT-04 (cloud-assert A11b) -> GT-06 (P5 register row for the new key material). Six downstream test/tool edits are frozen until DEC-15 rules (pass3 Section 4); the interim RED on HN-A4/HN-A5 once lib-hosts.sh changes is the DESIRED fail-loud state, never something to "fix" early.

Chain B -- The (a)-control-before-any-flat-apply invariant (owed #2)

DEC-14 (mechanism) -> SEC-01 (SEC row) -> SC-10 (#2 artifact) -> HN-C2 (harness) -> GT-01 (Stage-1 gate, installed + --check-verified) -> MUST PRECEDE -> TF-13 (first flat substrate apply of EITHER per-DC root, under whatever DEC-11 root shape lands -- fork-robust: a merged single root's FIRST apply can create both DCs' planes at once, so "before the second DC's apply" is not sufficient, only "before ANY flat apply" survives the fork) -> GT-02 (A11a re-verify at each apply's close) -> GT-08 (folds into the G9/G10 successor gate) -> re-verified again at Stage-5 live traffic (the first point the claim is actually tested).

Chain C -- R7 + MAAS-release before destroy (Part A of the teardown sequence)

SC-12 (#4 R7 credential-revocation checklist, enumerated from every vm-secret-locations row keyed to the rack host class) + HN-C6 (harness) -> run BEFORE any substrate destroy (revoking after the hosts are gone degrades to "assume it's moot") -> SC-13 (#5 MAAS machine-record release/delete + rack-controller decommission + region-side primary_rack/DHCP-reference cleanup) + HN-C7 (harness) -> TF-01/TF-02 destroy applies (inner roots first from voffice1, then outer from vcloud) -> RB-01 (teardown runbook rewrite encodes this exact order). This chain governs the CURRENT 10.12 checkpoint teardown and is largely independent of DEC-11's root-shape ruling for the NEW build.

Cross-cutting: the root-topology fork (DEC-11)

Gates TF-02, TF-12, TF-13, SC-09, SC-14, HN-C3, RB-01, GT-05, HN-A1, HN-A2, DEC-12, DEC-23 -- the sequence itself is invariant to the fork (per pass1 check 2), but the teardown primitive's exact wording, the state blast radius, and every root-naming literal are NOT. Ratify DEC-11 early; it unblocks the largest single cluster of "ready once ratified" rows.


3. Count summary by category

Category Rows
decision (DEC) 23
tofu-module (TF) 13
lib (LB) 3
script (SC) 19
doc (DC) 6
runbook (RB) 5
gate (GT) 10
harness (HN) 21 (9 change + 5 retire + 7 new-build)
SEC 4
Total 104

Cross-check against source counts: harness total (21) matches pass3 Section 2's 9-existing-change + 5-existing-retire + 7-new-build decomposition exactly; owed-artifact references (13 distinct #-tags) all appear at least once across TF/SC/GT/HN/SEC rows, with no double-counting (rack decommission folds into SC-13/#5; artifact-service sizing rides SC-16/#7; the SEC-010-writer extraction IS SC-04/#3's implementation shape -- all per pass2 Section 5's explicit "not double-counted" note, carried forward here).


4. Verification note

Author = W4.1 (no model name asserted). This document is a MERGE of pass1-admin-report.md Sections 2-6, pass2-admin-report.md Sections 3-6, and pass3-admin-report.md Sections 2-5 -- no new repo reads were performed beyond the four admin reports and their stated verification notes; every row's artifact path/line traces to a citation already verified in one of those four reports (see each report's own Section verifying "Verification note" / "Adversarial-check results" for the underlying grep/read evidence). READ-ONLY; nothing executed; findings LOGGED only.