as-built comparison: the proven origin config is cloud:jammy-caracal on 6 apps
Operator-directed review of past deployment YAML against current values.
Source: asbuilt/20260706-224851/bundle-exported.yaml, a juju export-bundle of
the VR0 testcloud that deployed successfully; five sibling captures agree.

The only configuration this project has ever deployed successfully is
cloud:jammy-caracal on six apps -- barbican/magnum/octavia openstack-origin,
ceph-mon/osd/radosgw source. Zero raw deb lines, zero key: options, anywhere in
any as-built capture. bundle.yaml encodes exactly that and defines the value
ONCE behind YAML anchors.

The 07-31 repoint changed two things at once and neither has ever deployed: app
count 6->15 (sound -- the other nine inherit caracal, same unreachable pocket)
and the value form cloud: -> raw deb. The form change is what dropped the key,
because the cloud: path installs ubuntu-cloud-keyring as a side effect.

Sharpens the D-135 experiment result: the MIRROR arm is what forces divergence
from the only known-good config, at the cost of a failed deploy and standing
key-rotation surface. The PROXY arm needs no override at all.

My own overlay edit violates the base bundle's convention -- it defines origin
once behind an anchor, I wrote fifteen copies of a 29-line key.

Fork left open for a GA-R5 ruling: converge dc0 on the proxy and delete the
origin block, or keep the mirror and restructure behind one anchor. Not choosing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent baa323a commit ac2b743fa09ba307b1ce903dc5cd9eafcafc65d9
@JANeumatrix JANeumatrix authored 1 day ago
Showing 3 changed files
View
docs/CURRENT-STATE.md
View
docs/audit/uca-origin-asbuilt-comparison-20260802.txt 0 → 100644
View
docs/changelog-20260802-deploy-input.md