|
R5 RULED: designate deploys at Stage 5, is configured at Stage 7 (D-106 note)
GA-R5: question and exact utterance quoted, dated, pushed before dependent work. Operator utterance: "Accept at Stage 5; rewrite Stage 7 Step 5 to configure-not-deploy (Recommended)". CORRECTION RECORDED IN THE DECISION ITSELF, not just this message. When R5 was first put to the operator, the audit claimed this option "inverts D-106's bootstrap order, which puts os-public-hostname + FQDN-SAN certs BEFORE Designate". That was WRONG. D-106's order is a CONFIGURATION sequence -- static hosts, then os-public-hostname, then Vault FQDN-SAN certs, then zones and A/AAAA, then neutron, then tenant subnets. It governs when the DNS wiring happens, not when the charm is installed. Deploying the app earlier does not invert it: the zones still follow the certs. Conflating "install the charm" with "do D-106's work" nearly cost a decision made on a false constraint, so the correction is recorded in D-106 where a future session will meet it. MEASURED BEFORE PRESENTING. All four designate applications and all EIGHT relations are deploy-ready at Stage 5 -- every relation peer (mysql-innodb-cluster, keystone, rabbitmq-server, vault, memcached, designate-bind) is created by Stage 5. But they will be FUNCTIONALLY INERT: os-public-hostname is set in NO deploy artifact, and bundle.yaml:11 records the current posture as IP-ONLY with the dual VIPs as the catalog endpoint. The charm runs; the feature does not. That is exactly the state Stage 7 exists to resolve. NEW SURFACE DEFECT FOUND BY THE MEASUREMENT: the phase-6 runbook contradicts ITSELF. Line 172 states "There is no designate: or designate-bind: application block anywhere in ..."; line 178 states "Designate is deployed in-bundle in each DC". Both cannot be true. The bundle settles it -- DOCFIX-167 put designate there on 2026-07-10 -- and the runbook needs rewriting regardless of this ruling. Option (c), setting os-public-hostname at Stage 5, was refused and the reason is worth keeping: it is the ONE branch that genuinely collides with D-106. Publishing a public FQDN endpoint before Vault has issued FQDN-SAN certs recreates the exact D-019 root cause D-106 was written to remove -- metal-only charms pulling a public FQDN endpoint they cannot resolve, which is also the D-021 amphora constraint. Option (b), suppressing designate at Stage 5, was refused because it needs machinery that does not exist and partially undoes DOCFIX-167 -- building a mechanism to satisfy a stale gate rather than fixing the gate. Execution is a DOCFIX against the phase-6 runbook (Step 1 inventory prose, Step 5 verb and gate), logged to the Phase-3 batch, not executed under this ruling. Revert: git revert this commit; the ruling note is additive. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/queued-rulings-20260727.md |
|---|
| docs/design-decisions.md |
|---|