|
tfstate backup path built; E2/E3 closed live; a gate disagreement found and fixed
BACKUP PROVEN BY RESTORE, not by existence. Both PKI archives were extracted and compared byte-for-byte against the live tree: 12/12 sha256 MATCH across both DCs, covering both encrypted CA keys, both passphrases, both CA serials and both controller bundles. Archives are 600 inside 700 folders and differ between DCs, so per-DC independence survives into the backup. E2/E3 CLOSED LIVE. Operator ran the chmod and the intermediate removal; octavia-pki.sh verify now reads PASS 26/0 on BOTH DCs, workspaces 12 -> 10 files, and P5 on the headend fell 18 -> 8. A GATE DISAGREEMENT, recorded as the pattern rather than the incident. verify read 26/0 while creds-matrix E2 still reported the CA serial mode 664 on both DCs. The chmod list predated the serial being declared, and verify's mode assertions covered six private files and three certs -- the serial was in neither. Two gates that can both see a file must not disagree about it. Fixed in three places: verify now mode-checks the serial (integrity, not secrecy -- rewriting it forces the next issuance to reuse a serial), the generator's chmod includes it, and T18 pins it. The harness then caught its own fixture creating the serial at the inherited umask; baseline went red until the fixture matched the corrected generator. 18/18. TFSTATE BACKUP as dc-dc-phase2 step 13, 2 rows, notes key n-tfstate-backup. Register 99 rows; schema, render-drift, mint-ref and notes checks clean. Three deliberate differences from the PKI backup: tfstate is DYNAMIC so the serial is recorded both sides and the step must be re-run after every apply (restoring a stale state is actively dangerous -- tofu then believes everything created since does not exist); the pull block proves RESTORE by decompressing to check the archive parses as JSON and reports a serial, because a truncated gzip passes a size check; and mint-stage is stage3, which is REACHED, so P5 correctly reports these EXPECTED-BUT-ABSENT until the step runs rather than deferring them. Classification recorded honestly: the outer state is credential-bearing (DOCFIX-175, MAAS API key in plaintext); the inner states show no credential-shaped key names, consistent with the inner root using only libvirt over qemu+ssh. Strong evidence, NOT proof -- a name-based absence cannot exclude material inside a value -- so they are registered and stored as if sensitive. Uncertainty resolves toward more auditing, and an unaudited backup directory beside audited ones is how the SEC-022 shadow stores happened. Two of my own defects caught by the gates: repo-lint L9 rejected a hardcoded clone name in the new step (the repo has been renamed once, D-110) -- now $REPO; and two mint-refs had drifted when a later edit added lines above their anchors, which S4 cannot catch because it only checks line <= EOF. Both re-anchored. Also corrected: phase-01:605 said the overlay must be in the backup set. It is derivable from the archived workspace by 1.0-GEN.d, so the line implied a gap that does not exist. Known, not fixed: both live inner states are 664, group-writable, and they are the authority tofu trusts. Tightening needs its own gated change plus proof the provider preserves the mode. creds-matrix 65/65, octavia-pki 18/18, repo-lint 0 fail / 621 files. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| creds-manifests/vr1-dc0.manifest |
|---|
| creds-manifests/vr1-dc1.manifest |
|---|
| creds-matrix-notes.md |
|---|
| creds-matrix.tsv |
|---|
| docs/CURRENT-STATE.md |
|---|
| runbooks/dc-dc-phase2-tofu-dc-substrate.md |
|---|
| runbooks/phase-01-bundle-deploy.md |
|---|
| scripts/octavia-pki.sh |
|---|
| tests/octavia-pki/run-tests.sh |
|---|