Conformance: dc0 deploy inputs vs the D-139 specs -- the VIP overlay FAILS
Every ruled row of D-139 ruling A, ruling B, the "B plus C" narrowing and the OOB
amendment compared to the ARTIFACT (live MAAS, apex, deploy overlays), not to another
document. Capture: docs/audit/d139-conformance-dc0-20260801.txt.

BLOCKER: overlays/vr1-dc0-vips.yaml carries an R2 sextet per service, and 26 of its 39
v6 VIP legs are ULA (13 metal-admin :220::, 13 metal-internal :221::). Those 26 are
exactly the 26 dependents the step-1 dry run reports inside the retiring ULA /64s --
the same objects, confirmed by description. Deploying after steps 1-3 alone would place
26 VIP legs on prefixes ruling B retires, while their GUA replacements exist in apex and
MAAS but appear nowhere in the deploy input. Overlay must be re-rendered before Step 4.

Also measured: lib-net.sh contains ZERO IPv6, so step 4's "update the v6 arm" has no arm
to update; and no gate compares D-139's tables to any artifact, so this drift class has
no detector. Provider-public conforms in both families; all nine nodes match MAAS (G19).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent a858e9d commit 939928c4858e2ca28ca8d8b1052df609629c2770
@JANeumatrix JANeumatrix authored 8 hours ago
Showing 2 changed files
View
docs/CURRENT-STATE.md
View
docs/audit/d139-conformance-dc0-20260801.txt 0 → 100644