DEFER ovn-central cert to a new session: bounce failed; precise defect = missing common_name
Bounce done, did not work. Three remedies exhausted, all deterministic (not the
inconsistent race): vault reissue-certificates; juju bind default->metal-internal;
full remove-relation + integrate (fresh id certificates:142). All leave
ovn-central with ca+client.cert only, no server cert.

Precise defect for the LP escalation: ovn-central/0 publishes sans:[10.12.12.122],
private-address, ingress-address, unit_name -- and NO common_name. The
tls-certificates interface needs a common_name to sign a SERVER cert; without it
vault issues only the client cert + CA. Missing CN traces to the Skipping
internal/admin/public 'no local address found' (LP #2044324).

Resume point recorded: escalate LP #2044324; decide accept-degraded vs the
UNVERIFIED os-*-network avenue. Live state carried forward: ovn-central default is
metal-internal (stays, architecturally correct); certificates:142; v4 VIPs; vault
init+unseal+root-CA; mysql ONLINE.

Process-defect note owned (operator-flagged): twice asserted an ovn-central root
cause the evidence did not support this session; next session treats my
hypotheses as unverified until measured.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent 580fc06 commit 46f3ab2038a91cc36576702ef45aa43707fe01ed
@JANeumatrix JANeumatrix authored 1 hour ago
Showing 1 changed file
View
docs/CURRENT-STATE.md