|
audit: transcribe the full 55-row credential inventory in-repo (matrix seed)
The capture's body previously said the per-row tables lived in the session transcript. The operator is clearing that session to start the build, so the matrix SEED would have been lost and would have cost another full inventory run to re-derive. Appendix now carries all of it: section A (25 scripted MINT rows), section B (30 runbook/prose MINT rows), section D (charm-minted, with the keystone admin password called out as in-scope per the materialization ruling), section E (MATERIALIZE/UPLOAD checked and excluded, with file:line so the exclusions are auditable), and section G (coverage boundary, incl. what was deliberately not opened). Corrected the body pointer that referenced the transcript. Notable rows the build will need: A6 the MAAS rack-enrollment secret (a mint nothing else records), B5-B12 the eight Octavia PKI artifacts, B13 the overlay that lands a CA key + plaintext passphrase inside the repo clone, B14 the juju-<dc> superusers stored nowhere, B22 the per-DC power key whose dc0 copy is missing (SEC-021), and A21-A25 which DUPLICATE A11-A14 -- one credential set, two creation locations, do not double-count. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/creds-creation-points-20260725.md |
|---|