|
Build the PKI backup path: three surfaces asserted a backup set that did not exist
Operator direction: back up to the per-DC jumphost creds folder BEFORE the cert cleanup, and record that the pinned secrets-storage solution must carry a certificate/credential backup procedure with this step folded into it. THE GAP, MEASURED. phase-01:594 said the workspace must be "backed up securely", :605 said it "MUST be in the per-DC backup set", and CURRENT-STATE said the inner tfstate should be added to "the site backup set" -- while cloud-snapshot.sh, the only candidate, is a juju-layer capture that mentions octavia, tfstate and terraform ZERO times. Both DCs' 10-year amphora trust roots therefore sat in one place on one VM with no copy. Losing the issuing CA key means Octavia can never sign another amphora certificate; losing the controller CA key means the controller certificate can never be reissued, which F9 says it must be at Stage 7. SHAPE: one gzipped archive per DC rather than a file-by-file tree copy -- 2 register rows instead of ~20, atomic (a half-copied tree is the dangerous state), and sha256-verifiable. The live tree on the headend stays what octavia-pki.sh verify asserts; the archive is recovery only. COST STATED RATHER THAN GLOSSED: a second at-rest copy of both encrypted CA keys beside their plaintext passphrases, so the archive's contents defeat encryption-at-rest. That is the trade D-109 option (b) was refused for; the distinction is deliberate, because that ruling governed where the authoritative artifact lives and which host the deploy reads. A recovery copy is not a second source of truth. Delivered: phase-01 step 1.0-GEN.e (build on the headend, pull to the per-DC creds folder, compare sha256 against the source BEFORE removing the staging copy -- a truncated scp would otherwise leave a verified-looking backup of nothing); 2 register rows, custody=consolidated since the creds folder is the SEC-009 location; notes key n-pki-backup. THE REGISTER CAUGHT AN INCOMPLETE CHANGE OF MINE: adding rows raised S2 EXPECTED-BUT-ABSENT twice, because the per-site manifests are DERIVED from the matrix and I had not re-rendered them. Rendered rows appended to both; S3 render drift clean, findings back to the pre-existing 7. Standing forward requirement recorded in the register rather than as a runbook comment: the pinned secrets-storage solution must include a documented process and procedure for certificate and credential backup, and this step is one of the steps that must be folded into it. The jumphost creds folder is the interim home only. Still not backed up and out of scope here: the two inner terraform.tfstate files on the headend -- gitignored, untracked, state-of-record for 20 VMs, and named as owed to the same backup set that has just been shown not to exist. Register 97 rows / 24 octavia rows. Gauntlet ALL GREEN (89), repo-lint 0 fail / 621 files. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| creds-manifests/vr1-dc0.manifest |
|---|
| creds-manifests/vr1-dc1.manifest |
|---|
| creds-matrix-notes.md |
|---|
| creds-matrix.tsv |
|---|
| docs/CURRENT-STATE.md |
|---|
| runbooks/phase-01-bundle-deploy.md |
|---|