phase-4 runbook: per-DC MAAS service-credential step (Step 2.0)
Operator-directed deployment-time task: Juju's MAAS API key is created by no
prior stage. Added Step 2.0 (before bootstrap) -- dedicated per-DC MAAS admin
service user + own API key (per-DC isolation, SEC-012/-016; Roosevelt: per-DC
cloud creds), staged in the JUMPHOST per-site creds folder
(~/vr1-<dc>-creds/maas-api-key.txt on vcloud, SEC-009) NOT a new region location,
generated from the jumphost so the key never persists on the region, never
printed, consumed by path/stdin. Corrects the earlier walkthrough's location.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
1 parent 83d9e6c commit 2f1fc427d1e1bc94b4c637d5166d39c71df73570
@JANeumatrix JANeumatrix authored 50 minutes ago
Showing 2 changed files
View
docs/changelog-20260724-caveman-disable.md
View
runbooks/dc-dc-phase4-juju-bundle-per-dc.md