Live verify result: PKI identity is correct on both DCs; only the mode defect remains
Ran scripts/octavia-pki.sh verify against both real PKI sets on the headend.

Both DCs: 23 assertions PASS, 3 FAIL, and the 3 are the same already-known mode defect.

Every IDENTITY assertion passes. CA subjects name the correct DC on both, so DC_LABEL was set
on both runs and the unguarded-variable risk did not bite. The chain verifies against the
CONTROLLER CA and correctly does NOT verify against the issuing CA -- proving two distinct
trust domains, not merely that one link works. The SAN set carries two DNS names plus each DC's
OWN provider v4 and v6 addresses, so F8's SAN-less failure mode did not occur and the D-109
v6-SAN ruling is satisfied in the artifact rather than only in the decision. Overlay mode, key
count, ASCII and gitignore all pass, and per-DC independence holds.

The only outstanding defect is the three certificates per DC at mode 664. Remediation is a
chmod and remains operator-gated.

The gate demonstrated teeth on live data rather than only in fixtures: it failed the real
defects while passing everything genuinely correct.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent 57a6f38 commit 78391c7dd642dd4eee438685b7e3f2e1ca396609
@JANeumatrix JANeumatrix authored 13 hours ago
Showing 1 changed file
View
docs/CURRENT-STATE.md