|
Execute the ruled generation host: Step 1.0-GEN and the register move to the headend
Dependent work for the D-109 ruling note (b), "Generate on voffice1 (Recommended)". Repo-side only -- no PKI has been minted. All seven RUN markers inside Step 1.0-GEN now say voffice1, with $REPO stated to mean the HEADEND clone. The 18 Octavia register rows move to host-role=headend, the Octavia entries in vm-secret-locations become headend, and host-identity binds headend -> voffice1. The Octavia locations are declared `local` rather than with the voffice1 ssh-target on purpose: that routes them through the F6 host binding, so the checker refuses to measure them from the wrong machine instead of quietly probing whatever filesystem it is standing on. Measured both ways: on vcloud -> all 8 locations report NOT PROBED, naming the host they actually live on on headend -> probed for real, reporting not-yet-minted Verdict unchanged at 7 findings on vcloud; tests/creds-matrix 65/65. Consequence recorded rather than discovered later: P5's octavia rows are now judged ONLY on voffice1, so the credential half of the Stage-5 entry gate must be read on the headend -- the same host P3/P4 already require. A narrowing of where preflight is authoritative, and a direct consequence of the ruled generation host. repo-lint 0 fail. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| creds-manifests/host-identity |
|---|
| creds-manifests/vm-secret-locations |
|---|
| creds-matrix.tsv |
|---|
| docs/CURRENT-STATE.md |
|---|
| runbooks/phase-01-bundle-deploy.md |
|---|