Newer
Older
openstack-caracal-dc-dc / docs / archive / changelogs / changelog-20260721-tenant-review-pin.md

Session changelog 2026-07-21 (fourth session) -- tenant-onboarding review verdict recovered + pinned

One changelog per session (GA-R2/D1). Status lives ONLY in docs/CURRENT-STATE.md; this file is narrative + reverts. Predecessor (stage-3-close session, disconnected ~21:16): docs/changelog-20260721-netem-install-verify.md.

1. Disconnected-session recovery (read-only)

  • Bootstrap reconciled clean: main at b2d4317, lint 0-fail, ledger scan matches the hand-seeded block (D=132, DOCFIX=198, BUNDLEFIX=052; 10 open SEC rows). No uncommitted traces from any disconnected session.
  • The predecessor's final undelivered message (the 3-seat committee verdict on Chat's three tenant-onboarding-runbook inserts) was recovered VERBATIM from its local session transcript and re-presented to the operator. No repo edit and no commit had resulted from that review -- the verdict existed nowhere durable.

2. Tenant-onboarding review items PINNED to deployment close (operator-directed)

  • Operator ruling this session: do NOT land the committee's recommended items now; pin all four for an end-of-deployment consideration review, because this deployment is changing posture and end goals and the items should be judged against the final shape.
  • Delivered: a self-contained compact block in docs/session-ledger.md ("Deployment-close consideration review -- tenant-onboarding items"), carrying the corrected substance of all four items plus the standing caveat that every citation gets re-verified at review time (the full verdict text lives only in the predecessor's session transcript).
  • Explicitly NOT done: no appendix-A entries, no contract edit, no dc-dc-phase6 edit, no numbering consumed (stated token-free in the ledger block per the standing counter discipline).
  • Revert: git revert this commit (records only; no live surface or script was touched).

3. Queue pass opened: D-131 sub-2 RULED (metal-admin-only forwarder scope)

  • Operator directed a working pass through the open decision queue; order presented (D-131 subs -> D-129 subs -> D-071 points -> D-068 -> G12 prep -> netem finals -> SEC-014), one ruling per exchange (GA-R5).
  • D-131 sub-2 RULED: "Metal-admin only (Recommended)" (question + utterance quoted in the D-131 Status block, the ruling authority). Scope of the rack node-DNS forwarder is fixed at the metal-admin alias only; edge keeps its own WAN-side DNS; SEC-010 untouched. Revisit trigger recorded: a D-129 (iii)/(iv) consolidation ruling.
  • Same-commit status coupling (GA-R1 C1): CURRENT-STATE D-131 sentence and the ledger machine-block D-131 line updated to sub-3..4 open. No live surface touched -- dc0-node-dns.service already runs metal-admin-only, so the ruling codifies the running shape; zero config delta.
  • Revert: git revert this commit (records only).

4. D-131 sub-3 RESOLVED by measurement (dispatch ruled "Investigate now (Recommended)")

  • Read-only investigation, split execution: agent read the shipped source over the measured rack reach (ssh -J voffice1, dc0 key, no sudo); the decisive dhcpd.conf read is root-only AND the agent's ssh+sudo was classifier-walled, so the OPERATOR ran it via the ! prefix and pasted output (capture: docs/audit/d131-sub3-dhcpd-option6-20260721.txt).
  • Result: option 6 = 10.12.8.3 ALONE. Source (maasserver/dhcp.py, snap rev 41649): allow_dns=false short-circuits get_default_dns_servers() to [] before any rack-IP prepend logic; maastemporalworker has no DNS composition of its own. The morning prepend observation was a stale pre-re-render read. NO defect; NO second LP; no live surface carried the stale claim (archived changelog stays as history).
  • Revert: git revert this commit (records only).

5. Two operator pins landed: DNS architectural review + D-132 (MAAS topology)

  • PINNED REVIEW (operator-directed, recorded in the D-131 Status block, feeds sub-4): next-deployment architectural review of the DNS setup -- (a) stack best-practice conformance, (b) forwarder security implications, (c) vendor-documented guidance for the "utility nodes" DC-to-DC traffic configuration.
  • D-132 FILED, PROPOSED / OPEN (next-free verified 132 pre-assignment): Roosevelt per-DC MAAS topology -- HA regional VMs per DC, rack-top rack controllers deferring to the site region (multi-rack DCs), cross-site regional backup custody for rebuild. Operator directive quoted verbatim in the entry; each question rules individually per GA-R5 at Roosevelt MAAS design time. Ledger next-free re-seeded D=133; CURRENT-STATE section 8 items 7-8 added (same-commit coupling).
  • Revert: git revert this commit (records only).

6. D-129 sub-decision (i) RULED: COS scrapes the edge, in-scope per-DC

  • Question grounded on D-105 (ADOPTED: COS per-DC, no Office1 roll-up) and presented per GA-R5; operator selection, exact utterance: "In-scope, per-DC (Recommended)". Recorded in the D-129 Status line (the ruling authority); the Step-10 os-node-exporter + API-backend pin is now ungated at its deployment step. No live change this session -- the install itself remains at its pinned step, operator-gated.
  • Coupled same-commit: CURRENT-STATE section 8 item 5 (four -> three open subs) + ledger machine-block D-129 line.
  • Revert: git revert this commit (records only).

7. D-129 sub-decision (ii) RULED: os-frr pinned to Roosevelt design time

  • Presented per GA-R5; operator selection, exact utterance: "Pin to Roosevelt design (Recommended)". VR1 stays static (D-124/D-125); the dynamic-routing question rules at Roosevelt inter-DC network design alongside the D-100 link spec + D-132 topology. Status line updated; CURRENT-STATE item 5 + ledger D-129 line coupled same-commit.
  • Revert: git revert this commit (records only).

8. D-129 sub-decision (iii) RULED: per-site Tailscale = dedicated node, edge excluded

  • One clarifying round (recorded verbatim in the Status block): the operator disclosed that this deployment AND Roosevelt will run a site Tailscale installation for metal-admin access at EVERY location. The agent's recommendation survived with one self-correction (edge-failure survivability is weak at DC sites -- all site egress rides the edge; the load-bearing reasons are plane-reach, blast radius, lifecycle decoupling). Selection, exact utterance: "Dedicated node per site (Recommended)". D-107 shape becomes the standing per-site pattern; edge gets no metal-admin leg; D-131 sub-2 revisit clause dead. Per-site ACL/key-custody design + SEC row queued to implementation time.
  • Revert: git revert this commit (records only).

9. D-129 sub-decision (iv) RULED: MAAS NTP hierarchy stays; D-129 decision content COMPLETE

  • Presented per GA-R5; operator selection, exact utterance: "Keep MAAS hierarchy (Recommended)". No NTP role on the edge; vendor-default nodes -> rack -> region -> upstream chain stays (measured working: tonight's dhcpd capture + commissioning proof). All FOUR D-129 sub-decisions are now ruled; Status flipped to RULED with the two remaining EXECUTION items (office1 live install, qga retrofit) re-pointed at gate G13. G13 row, CURRENT-STATE item 5, and the ledger machine block updated same-commit; D-129 drops off ledger-scan's open-decisions list by design.
  • Revert: git revert this commit (records only).

10. D-071 ADOPTED: all four update-policy points ruled (four GA-R5 exchanges)

  • Points 1-4 presented and ruled individually, all "Adopt as proposed (Recommended)": (1) monthly review trigger, security pulls forward; (2) patch-only controller jumps in routine windows; (3) standing order controller -> agents -> charms, keystone first / nova-compute last, never interleave; (4) in-channel-only refreshes, channel moves always per-decision. Status ADOPTED; ops-update-procedure is the policy vehicle. Commits: points 1-3 individually (35952b1, bdbbce4, 9121e6c), point 4 + closure couplings in this commit. G15 row updated (D-068 remainder only); CURRENT-STATE item 4 + ledger machine block coupled.
  • Revert: git revert the four commits (records only; no live surface touched).

11. D-068 item 3 delivery: A9 vault-kv auth section in cloud-assert.sh

  • Per the item-3 ruling ("Adopt + probe on VR1 now"): new section A9 delegates to the EXISTING scripts/vault-kv-health.sh (the D-068 outer driver, dynamic consumer discovery, one real 60s-TTL AppRole login per consumer) and maps its exit 0/1/2 to ok/fail/warn. SKIPS with ok when the model carries no vault application -- the pre-Stage-5 VR1 shape -- so current sweeps are unaffected. CLOUD_ASSERT_VKH env = documented test seam (offline harness stubs the driver; unset in real runs).
  • Harness: tests/cloud-assert +3 cases (T13 skip-when-no-vault, T14 pass mapping, T15 fail mapping) -- 15/15; gauntlet 76 ALL GREEN; repo-lint 0-fail. No live execution (nothing to probe until Stage 5).
  • Revert: git revert this commit (restores cloud-assert.sh + harness to pre-A9; no live surface touched).

12. G12 [R] leg CLOSED: vr1-dc1 addressing RATIFIED (D-124 amendment)

  • Prep derived every candidate from ruled patterns (D-115 supernet 10.12.64.0/19, D-101 role order, D-124 transit supernet, D-120 bands, D-131 forwarder, D-125/D-122 edge, D-126 creds); the one divergence (contiguous /22 carve -- dc0's offsets cannot fit a /19) is documented in the amendment. Operator selection, exact utterance: "Adopt scheme as derived (Recommended)".
  • Recorded as D-124 AMENDMENT (2026-07-21) with the full table + tfvar fills; G12 row flipped HELD -> OPEN with the [V] remainder named (apex confirm-free, vars, substrate root, build); CURRENT-STATE section 4 bullet updated same-commit. lib-net.sh vr1-dc1 arm stays FAIL until the apex assignment lands (its own rule).
  • No live or config surface touched -- ruling + records only.
  • Revert: git revert this commit (records only).