|
A12: the DNS SAN check ARMS ITSELF, so F9 cannot be missed
Operator direction: make the DNS SANs part of the process so it is not a step that gets missed in future. The risk in F9 is not the defect, it is that a future session forgets. So A12 arms from the change that makes the SANs load-bearing -- os-public-hostname appearing as a real option key in the merged deploy input -- rather than from a note somebody has to read. Unarmed, it states the names are inert and why; armed, it asserts them. WHAT IT CAN ASSERT, AND A GAP IN A RULED DECISION THAT IT CANNOT. D-008 fixes the shape <service>.<cloud>.<dc>.<region>.cloud.neumatrix.local and D-106:2563 instantiates VR1 as "omega.dc1.vr1" / "dc2.vr1" -- while the substrate's DCs are vr1-dc0 and vr1-dc1. So vr1-dc1 is "dc1" by token or "dc2" by position: the DC1/DC2 ambiguity item 3.1 retired elsewhere, surviving inside a ruling, where it decides certificate identity. The REGION is unambiguous and is asserted. The DC LABEL REFUSES pending a ruling rather than blessing a name that cannot be validated. Both live certs currently say dc0.vr0 -- the VR0 region, wrong for a VR1 DC under either reading. A PRECEDENCE BUG THE HARNESS CAUGHT. Because the armed branch always refuses on the label, a definite wrong-region SAN was being reported as "could not evaluate" -- REFUSE was checked before FAIL and masked a confirmed defect. A known defect outranks an unevaluated item, so the verdict now reports FAIL first and still names the refusal, which is never lost. Harness 21/21 (was 18). T19 proves the unarmed live posture still PASSES -- without it, arming A12 would have broken every current verify, the same trap T17 guards for the deleted intermediates. T20 is F9 armed. T21 proves the right region still refuses on the unruled label. repo-lint 0 fail. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| scripts/octavia-pki.sh |
|---|
| tests/octavia-pki/run-tests.sh |
|---|